We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
hyh
Gas is overspent on storage access and operations.
claimReward function has some excess operations and the number of times it reads storage can be reduced: https://github.com/code-423n4/2021-11-streaming/blob/main/Streaming/src/Locke.sol#L555
Save repeatedly accessed storage variables to memory and use them, simplify the logic:
Now:
... cumulativeRewardPerToken = rewardPerToken(); // update user rewards ts.rewards = earned(ts, cumulativeRewardPerToken); // update users last cumulative reward per token ts.lastCumulativeRewardPerToken = cumulativeRewardPerToken; lastUpdate = lastApplicableTime(); uint256 rewardAmt = ts.rewards; ts.rewards = 0; require(rewardAmt > 0, "amt"); // transfer the tokens ERC20(rewardToken).safeTransfer(msg.sender, rewardAmt); ...
To be:
... uint256 _cumulativeRewardPerToken = rewardPerToken(); uint256 rewardAmt = earned(ts, _cumulativeRewardPerToken); require(rewardAmt > 0, "amt"); cumulativeRewardPerToken = _cumulativeRewardPerToken; lastUpdate = lastApplicableTime(); // update users last cumulative reward per token and rewards ts.lastCumulativeRewardPerToken = _cumulativeRewardPerToken; ts.rewards = 0; // transfer the tokens ERC20(rewardToken).safeTransfer(msg.sender, rewardAmt); ...
The text was updated successfully, but these errors were encountered:
hyh issue #70
e50ad0d
No branches or pull requests
Handle
hyh
Vulnerability details
Impact
Gas is overspent on storage access and operations.
Proof of Concept
claimReward function has some excess operations and the number of times it reads storage can be reduced:
https://github.com/code-423n4/2021-11-streaming/blob/main/Streaming/src/Locke.sol#L555
Recommended Mitigation Steps
Save repeatedly accessed storage variables to memory and use them, simplify the logic:
Now:
To be:
The text was updated successfully, but these errors were encountered: