Skip to content

get_pending_verifications() is an unbounded public function — no deprecation notice, no guard, unlimited reads #83

Description

@cybermax4200

Why this matters now:
The paged alternative get_pending_verifications_paged was added precisely because the unbounded variant is unsafe at scale, yet get_pending_verifications() remains a fully public, undeprecated entry point. Any oracle or off-chain indexer that calls it on a production contract with thousands of pending verifications will exceed Soroban transaction limits. The function will become the default path for any integrator who reads the ABI without consulting the source.

Problem / What:
RewardEngine::get_pending_verifications calls collect_pending(&e, 0, u32::MAX) — it passes u32::MAX as the limit, iterating the entire VerificationList. This also delegates to the broken cursor logic (Issue 3). The function must either be removed from the public ABI, marked deprecated with a compile-time #[deprecated] attribute and a hard entry-point guard that panics, or have its implementation replaced with a hard cap.

Key Challenges:

  • Soroban contracts cannot use Rust's #[deprecated] to produce compile warnings in external callers; the deprecation must be enforced at runtime with a panic and documented in the function's doc comment.
  • Removing it from the ABI entirely is a breaking change; the contract is not yet on mainnet, so now is the right time.
  • Coordinate with the get_pending_verifications_paged fix (Issue 3) so both are addressed together.

Acceptance Criteria:

  • get_pending_verifications() either panics immediately with "engine: use get_pending_verifications_paged" or is removed from the public ABI.
  • If retained, its doc comment contains a # Deprecated section pointing to get_pending_verifications_paged.
  • All test references to get_pending_verifications() are migrated to the paged variant.
  • CHANGELOG updated.

Relevant files/functions:

  • contracts/reward-engine/src/verification.rs — get_pending_verifications, collect_pending

Out of scope: Cursor fix (Issue 3), limit cap (Issue 6).

Activity

  1. Jerry-Tekh commented on Aug 26, 2026

    @Jerry-Tekh
    Contributor

    Hello manager. i will implement the required fix. Please get me assigned to this issue and i will get it done correctly. thank you .

  2. grantfox-oss commented on Aug 26, 2026

    @grantfox-oss

    🦊 GrantFox — @Jerry-Tekh has been assigned to this issue as part of the Third Campaign campaign!

    Next steps:

    1. Open a Pull Request referencing this issue (e.g., Closes #83)
    2. Your PR will be reviewed by the ecotask-network maintainers

    Good luck! Track your progress on GrantFox.

  3. added a commit that references this issue on Aug 26, 2026
  4. added 2 commits that reference this issue on Aug 29, 2026
  5. grantfox-oss commented on Aug 29, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox as part of the Third Campaign campaign!

    @Jerry-Tekh's PR #87 was approved and merged by @cybermax4200.

    🏆 @Jerry-Tekh: You earned 40 FoxPoints for this contribution! Your current tier: Builder (1,059 total points). Track your full progress on GrantFox.

    👏 Great work, @Jerry-Tekh! Keep contributing to ecotask-network.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions