This repository has been archived by the owner on Jul 7, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
C4-300: Add storage gap to ERC20, ERC4626, BaseUpgradeable (#47)
* Add storage gap and tests
- Loading branch information
Showing
10 changed files
with
1,420 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,215 @@ | ||
// SPDX-License-Identifier: AGPL-3.0-only | ||
pragma solidity >=0.8.0; | ||
|
||
import {Initializable} from "@openzeppelin/contracts-upgradeable/proxy/utils/Initializable.sol"; | ||
|
||
/// @notice Modern and gas efficient ERC20 + EIP-2612 implementation. | ||
/// @author Solmate (https://github.com/Rari-Capital/solmate/blob/main/src/tokens/ERC20.sol) | ||
/// @author Modified from Uniswap (https://github.com/Uniswap/uniswap-v2-core/blob/master/contracts/UniswapV2ERC20.sol) | ||
/// @dev Do not manually set balances without updating totalSupply, as the sum of all user balances must not exceed it. | ||
abstract contract ERC20UpgradeableDangerous is Initializable { | ||
/*////////////////////////////////////////////////////////////// | ||
EVENTS | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
event Transfer(address indexed from, address indexed to, uint256 amount); | ||
|
||
event Approval(address indexed owner, address indexed spender, uint256 amount); | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
METADATA STORAGE | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
string public name; | ||
|
||
string public symbol; | ||
|
||
uint8 public decimals; | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
ERC20 STORAGE | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
uint256 public totalSupply; | ||
|
||
mapping(address => uint256) public balanceOf; | ||
|
||
mapping(address => mapping(address => uint256)) public allowance; | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
EIP-2612 STORAGE | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
uint256 internal INITIAL_CHAIN_ID; | ||
|
||
bytes32 internal INITIAL_DOMAIN_SEPARATOR; | ||
|
||
mapping(address => uint256) public nonces; | ||
|
||
// New storage variable that we do NOT account for in the gap | ||
uint256 public dangerousVariable; | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
CONSTRUCTOR | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
function __ERC20Upgradeable_init( | ||
string memory _name, | ||
string memory _symbol, | ||
uint8 _decimals | ||
) internal onlyInitializing { | ||
name = _name; | ||
symbol = _symbol; | ||
decimals = _decimals; | ||
|
||
INITIAL_CHAIN_ID = block.chainid; | ||
INITIAL_DOMAIN_SEPARATOR = computeDomainSeparator(); | ||
} | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
ERC20 LOGIC | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
function approve(address spender, uint256 amount) public virtual returns (bool) { | ||
allowance[msg.sender][spender] = amount; | ||
|
||
emit Approval(msg.sender, spender, amount); | ||
|
||
return true; | ||
} | ||
|
||
function transfer(address to, uint256 amount) public virtual returns (bool) { | ||
balanceOf[msg.sender] -= amount; | ||
|
||
// Cannot overflow because the sum of all user | ||
// balances can't exceed the max uint256 value. | ||
unchecked { | ||
balanceOf[to] += amount; | ||
} | ||
|
||
emit Transfer(msg.sender, to, amount); | ||
|
||
return true; | ||
} | ||
|
||
function transferFrom( | ||
address from, | ||
address to, | ||
uint256 amount | ||
) public virtual returns (bool) { | ||
uint256 allowed = allowance[from][msg.sender]; // Saves gas for limited approvals. | ||
|
||
if (allowed != type(uint256).max) allowance[from][msg.sender] = allowed - amount; | ||
|
||
balanceOf[from] -= amount; | ||
|
||
// Cannot overflow because the sum of all user | ||
// balances can't exceed the max uint256 value. | ||
unchecked { | ||
balanceOf[to] += amount; | ||
} | ||
|
||
emit Transfer(from, to, amount); | ||
|
||
return true; | ||
} | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
EIP-2612 LOGIC | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
function permit( | ||
address owner, | ||
address spender, | ||
uint256 value, | ||
uint256 deadline, | ||
uint8 v, | ||
bytes32 r, | ||
bytes32 s | ||
) public virtual { | ||
require(deadline >= block.timestamp, "PERMIT_DEADLINE_EXPIRED"); | ||
|
||
// Unchecked because the only math done is incrementing | ||
// the owner's nonce which cannot realistically overflow. | ||
unchecked { | ||
address recoveredAddress = ecrecover( | ||
keccak256( | ||
abi.encodePacked( | ||
"\x19\x01", | ||
DOMAIN_SEPARATOR(), | ||
keccak256( | ||
abi.encode( | ||
keccak256("Permit(address owner,address spender,uint256 value,uint256 nonce,uint256 deadline)"), | ||
owner, | ||
spender, | ||
value, | ||
nonces[owner]++, | ||
deadline | ||
) | ||
) | ||
) | ||
), | ||
v, | ||
r, | ||
s | ||
); | ||
|
||
require(recoveredAddress != address(0) && recoveredAddress == owner, "INVALID_SIGNER"); | ||
|
||
allowance[recoveredAddress][spender] = value; | ||
} | ||
|
||
emit Approval(owner, spender, value); | ||
} | ||
|
||
function DOMAIN_SEPARATOR() public view virtual returns (bytes32) { | ||
return block.chainid == INITIAL_CHAIN_ID ? INITIAL_DOMAIN_SEPARATOR : computeDomainSeparator(); | ||
} | ||
|
||
function computeDomainSeparator() internal view virtual returns (bytes32) { | ||
return | ||
keccak256( | ||
abi.encode( | ||
keccak256("EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"), | ||
keccak256(bytes(name)), | ||
versionHash(), | ||
block.chainid, | ||
address(this) | ||
) | ||
); | ||
} | ||
|
||
function versionHash() internal view virtual returns (bytes32); | ||
|
||
/*////////////////////////////////////////////////////////////// | ||
INTERNAL MINT/BURN LOGIC | ||
//////////////////////////////////////////////////////////////*/ | ||
|
||
function _mint(address to, uint256 amount) internal virtual { | ||
totalSupply += amount; | ||
|
||
// Cannot overflow because the sum of all user | ||
// balances can't exceed the max uint256 value. | ||
unchecked { | ||
balanceOf[to] += amount; | ||
} | ||
|
||
emit Transfer(address(0), to, amount); | ||
} | ||
|
||
function _burn(address from, uint256 amount) internal virtual { | ||
balanceOf[from] -= amount; | ||
|
||
// Cannot underflow because a user's balance | ||
// will never be larger than the total supply. | ||
unchecked { | ||
totalSupply -= amount; | ||
} | ||
|
||
emit Transfer(from, address(0), amount); | ||
} | ||
|
||
/// @dev This empty reserved space is put in place to allow future versions to add new | ||
/// variables without shifting down storage in the inheritance chain. | ||
uint256[50] private __gap; | ||
} |
Oops, something went wrong.