-
Notifications
You must be signed in to change notification settings - Fork 12.3k
Prevent revert in isModuleInstalled for fallback modules on short additionalContext #5961
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Prevent revert in isModuleInstalled for fallback modules on short additionalContext #5961
Conversation
|
WalkthroughUpdated contracts/account/extensions/draft-AccountERC7579.sol to modify isModuleInstalled handling for MODULE_TYPE_FALLBACK. The function now checks that additionalContext length is at least 4; if shorter, it returns false. It extracts the selector as bytes4(additionalContext[0:4]) and compares _fallbacks[selector] to the provided module. This replaces the prior direct access without length validation, preventing reverts on short contexts. Public interfaces and function signatures remain unchanged. Pre-merge checks and finishing touches✅ Passed checks (3 passed)
✨ Finishing touches🧪 Generate unit tests
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (9)
🔇 Additional comments (1)
Tip 👮 Agentic pre-merge checks are now available in preview!Pro plan users can now enable pre-merge checks in their settings to enforce checklists before merging PRs.
Please see the documentation for more information. Example: reviews:
pre_merge_checks:
custom_checks:
- name: "Undocumented Breaking Changes"
mode: "warning"
instructions: |
Pass/fail criteria: All breaking changes to public APIs, CLI flags, environment variables, configuration keys, database schemas, or HTTP/GraphQL endpoints must be documented in the "Breaking Change" section of the PR description and in CHANGELOG.md. Exclude purely internal or private changes (e.g., code not exported from package entry points or explicitly marked as internal).Please share your feedback with us on this Discord post. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thank you @GarmashAlex for this contribution.
|
|
Note: we have two options to fix that
return _fallbacks[bytes4(additionalContext)] == module;-> No length check
return additionalContext.length > 3 && _fallbacks[bytes4(additionalContext[0:4])] == module;-> Current approach |
…itionalContext (#5961) Co-authored-by: Hadrien Croubois <[email protected]> Co-authored-by: ernestognw <[email protected]> Signed-off-by: Hadrien Croubois <[email protected]>
This change adds a length check before slicing additionalContext[0:4] in isModuleInstalled for fallback modules. The ERC-7579 IERC7579ModuleConfig.isModuleInstalled requires returning true/false rather than reverting. Previously, providing fewer than 4 bytes caused an out-of-bounds slice and a revert. Now, malformed context returns false, aligning behavior with the spec and avoiding unexpected reverts in external status queries.