Problem
classify_take_reply (rust/src/mostro/pending.rs) accepts a malformed pay-bond-invoice reply as a successful take:
- A
PaymentRequest payload with an empty invoice is returned as TakeAccepted with bond: Some(BondRequest { invoice: "" , .. }).
- The bond amount falls back to
0 (.unwrap_or(0)) when both amount and the SmallOrder amount are absent, zero or negative — u64::try_from only rejects negatives, so 0 also passes.
Those values flow through bond_requested into BondInfo and get persisted on the trade row, parking the trade at WaitingTakerBond with a bond the user cannot pay.
Expected
Only a non-empty bolt11 invoice with a positive bond amount yields TakeAccepted with WaitingTakerBond. Anything else is Rejected { reason: "InvalidBondInvoice" }, the same marker already used for a non-PaymentRequest payload.
Tasks
Context
Flagged by CodeRabbit on #407 (#407 (review)) as an outside-diff finding. The code predates #407 (it landed with the taker bond work, see #208), so it was split out rather than blocking that PR. See docs/ANTI_ABUSE_BOND.md §6.1.
Problem
classify_take_reply(rust/src/mostro/pending.rs) accepts a malformedpay-bond-invoicereply as a successful take:PaymentRequestpayload with an empty invoice is returned asTakeAcceptedwithbond: Some(BondRequest { invoice: "" , .. }).0(.unwrap_or(0)) when bothamountand theSmallOrderamount are absent, zero or negative —u64::try_fromonly rejects negatives, so0also passes.Those values flow through
bond_requestedintoBondInfoand get persisted on the trade row, parking the trade atWaitingTakerBondwith a bond the user cannot pay.Expected
Only a non-empty bolt11 invoice with a positive bond amount yields
TakeAcceptedwithWaitingTakerBond. Anything else isRejected { reason: "InvalidBondInvoice" }, the same marker already used for a non-PaymentRequestpayload.Tasks
Action::PayBondInvoicebranch.unwrap_or(0)fallback; require the resolved amount to be> 0.amountfield and theSmallOrderfallback).add-bond-invoice/ order creation) has the same fallback.Context
Flagged by CodeRabbit on #407 (#407 (review)) as an outside-diff finding. The code predates #407 (it landed with the taker bond work, see #208), so it was split out rather than blocking that PR. See
docs/ANTI_ABUSE_BOND.md§6.1.