Uh oh!
There was an error while loading. Please reload this page.
fix: validate ATA derivation in both idempotent and non-idempotent paths - #2250
fix: validate ATA derivation in both idempotent and non-idempotent paths#2250ananas-block wants to merge 3 commits into
Conversation
Audit issue #3 (MEDIUM): validate_ata_derivation was only called inside the IDEMPOTENT block, so non-idempotent ATA creation never verified the PDA derivation. Move validation before the IDEMPOTENT check so both code paths enforce correct ATA derivation.
📝 WalkthroughWalkthroughThe ATA derivation validation logic is refactored to perform validation uniformly in both idempotent and non-idempotent modes, then optimize the idempotent path by combining the early-return condition into a single check when the ATA is owned by LIGHT_CPI_SIGNER. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Run cargo fmt on create_ata.rs and update test_create_ata_failing test 5 to expect error 3 (InvalidAccountData) since validate_ata_derivation now catches wrong bumps before account creation.
Summary