From dd6b86d09d7c040ad673376cf170c4628495273a Mon Sep 17 00:00:00 2001 From: Pierrick Turelier Date: Thu, 17 Sep 2026 16:18:26 -0500 Subject: [PATCH] test: fix uint128 overflow in IndexingMath round-trip fuzz `_EXP_SCALED_ONE` is a uint56, so Solidity evaluated `_EXP_SCALED_ONE + index - 1` in uint128. Any index within 1e12 of `type(uint128).max` overflowed that addition. The test then reverted with Panic(0x11) before reaching its assertion. This failed the suite on roughly 1 in 20 fuzz seeds. Widen the headroom computation to uint256. Pin the top of the index range with a deterministic regression test. --- test/IndexingMath.t.sol | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/test/IndexingMath.t.sol b/test/IndexingMath.t.sol index 3cf0be9..ec5adaf 100644 --- a/test/IndexingMath.t.sol +++ b/test/IndexingMath.t.sol @@ -311,7 +311,9 @@ contract IndexingMathTests is Test { // NOTE: Rounding up twice can inflate the principal by up to `ceil(EXP_SCALED_ONE / index)`, so reserve the // full worst-case headroom for the current `index` before the round trip. - uint112 maxRoundTripInflation_ = uint112((_EXP_SCALED_ONE + index - 1) / index); + // NOTE: Widen to uint256 before adding, since `_EXP_SCALED_ONE + index` overflows a uint128 for indexes + // within 1e12 of `type(uint128).max`. + uint112 maxRoundTripInflation_ = uint112((uint256(_EXP_SCALED_ONE) + index - 1) / index); uint112 boundedPrincipal_ = uint112(bound(principal, 0, type(uint112).max - maxRoundTripInflation_)); // Rounding the present amount up and back up can never deflate the principal. @@ -323,6 +325,13 @@ contract IndexingMathTests is Test { ); } + /// @dev Pins the round trip at the top of the index range, where the worst-case inflation headroom is computed. + /// Regression: the headroom used to be derived in uint128 arithmetic, which overflowed here. + function test_roundTrip_atMaxIndex() external view { + this.testFuzz_roundTrip(1, type(uint128).max); + this.testFuzz_roundTrip(type(uint112).max, type(uint128).max); + } + function testFuzz_getSafePrincipalAmountRoundedUp(uint112 principal, uint128 index, uint112 maxPrincipalAmount) external view