Hard Audit: don't let users borrow from reserves (#827)

* don't borrow from reserves

* use safesub and throw error
This commit is contained in:
Denali Marsh 2021-02-16 15:45:57 +01:00 committed by GitHub
parent 58573e7b26
commit 53eab47c07
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
4 changed files with 67 additions and 47 deletions

View File

@ -97,6 +97,7 @@ var (
ErrAccountNotFound = types.ErrAccountNotFound ErrAccountNotFound = types.ErrAccountNotFound
ErrBorrowEmptyCoins = types.ErrBorrowEmptyCoins ErrBorrowEmptyCoins = types.ErrBorrowEmptyCoins
ErrBorrowExceedsAvailableBalance = types.ErrBorrowExceedsAvailableBalance ErrBorrowExceedsAvailableBalance = types.ErrBorrowExceedsAvailableBalance
ErrExceedsProtocolBorrowableBalance = types.ErrExceedsProtocolBorrowableBalance
ErrBorrowNotFound = types.ErrBorrowNotFound ErrBorrowNotFound = types.ErrBorrowNotFound
ErrBorrowNotLiquidatable = types.ErrBorrowNotLiquidatable ErrBorrowNotLiquidatable = types.ErrBorrowNotLiquidatable
ErrBorrowedCoinsNotFound = types.ErrBorrowedCoinsNotFound ErrBorrowedCoinsNotFound = types.ErrBorrowedCoinsNotFound
@ -121,6 +122,7 @@ var (
ErrPreviousAccrualTimeNotFound = types.ErrPreviousAccrualTimeNotFound ErrPreviousAccrualTimeNotFound = types.ErrPreviousAccrualTimeNotFound
ErrPriceNotFound = types.ErrPriceNotFound ErrPriceNotFound = types.ErrPriceNotFound
ErrSuppliedCoinsNotFound = types.ErrSuppliedCoinsNotFound ErrSuppliedCoinsNotFound = types.ErrSuppliedCoinsNotFound
ErrReservesExceedCash = types.ErrReservesExceedCash
GovDenom = types.GovDenom GovDenom = types.GovDenom
KeyMoneyMarkets = types.KeyMoneyMarkets KeyMoneyMarkets = types.KeyMoneyMarkets
ModuleCdc = types.ModuleCdc ModuleCdc = types.ModuleCdc

View File

@ -116,6 +116,20 @@ func (k Keeper) ValidateBorrow(ctx sdk.Context, borrower sdk.AccAddress, amount
return types.ErrBorrowEmptyCoins return types.ErrBorrowEmptyCoins
} }
// The reserve coins aren't available for users to borrow
hardMaccCoins := k.supplyKeeper.GetModuleAccount(ctx, types.ModuleName).GetCoins()
reserveCoins, foundReserveCoins := k.GetTotalReserves(ctx)
if !foundReserveCoins {
reserveCoins = sdk.NewCoins()
}
fundsAvailableToBorrow, isNegative := hardMaccCoins.SafeSub(reserveCoins)
if isNegative {
return sdkerrors.Wrapf(types.ErrReservesExceedCash, "reserves %s > cash %s", reserveCoins, hardMaccCoins)
}
if amount.IsAnyGT(fundsAvailableToBorrow) {
return sdkerrors.Wrapf(types.ErrExceedsProtocolBorrowableBalance, "requested borrow %s > available to borrow %s", amount, fundsAvailableToBorrow)
}
// Get the proposed borrow USD value // Get the proposed borrow USD value
moneyMarketCache := map[string]types.MoneyMarket{} moneyMarketCache := map[string]types.MoneyMarket{}
proprosedBorrowUSDValue := sdk.ZeroDec() proprosedBorrowUSDValue := sdk.ZeroDec()

View File

@ -220,7 +220,7 @@ func (suite *KeeperTestSuite) TestBorrow() {
}, },
errArgs{ errArgs{
expectPass: false, expectPass: false,
contains: "exceeds module account balance:", contains: "exceeds borrowable module account balance",
}, },
}, },
{ {

View File

@ -65,4 +65,8 @@ var (
ErrInvalidIndexFactorDenom = sdkerrors.Register(ModuleName, 29, "no index factor found for denom") ErrInvalidIndexFactorDenom = sdkerrors.Register(ModuleName, 29, "no index factor found for denom")
// ErrBelowMinimumBorrowValue error for when a proposed borrow position is less than the minimum USD value // ErrBelowMinimumBorrowValue error for when a proposed borrow position is less than the minimum USD value
ErrBelowMinimumBorrowValue = sdkerrors.Register(ModuleName, 30, "invalid proposed borrow value") ErrBelowMinimumBorrowValue = sdkerrors.Register(ModuleName, 30, "invalid proposed borrow value")
// ErrExceedsProtocolBorrowableBalance for when a requested borrow exceeds the module account's borrowable balance
ErrExceedsProtocolBorrowableBalance = sdkerrors.Register(ModuleName, 31, "exceeds borrowable module account balance")
// ErrReservesExceedCash for when the protocol is insolvent because available reserves exceeds available cash
ErrReservesExceedCash = sdkerrors.Register(ModuleName, 32, "insolvency - protocol reserves exceed available cash")
) )