Skip to content

chore: sync from monorepo @3b1f741 - #75

Closed
WomB0ComB0 wants to merge 1 commit into
mainfrom
sync/monorepo-3b1f741
Closed

WomB0ComB0 wants to merge 1 commit into
mainfrom
sync/monorepo-3b1f741

Conversation

@WomB0ComB0

Copy link
Copy Markdown
Member

Automated sync from the internal monorepo at 3b1f741.

Review before merging — direct pushes to standalone repos are preserved.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 38 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1a6c7e93-7f4f-46f5-b32d-96192a660182

📥 Commits

Reviewing files that changed from the base of the PR and between d625d4e and 4f129d7.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • vendor/solana-program-test/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (29)
  • .gitattributes
  • .gitignore
  • Anchor.toml
  • Cargo.toml
  • README.md
  • docs/solana-v4-migration.md
  • osv-scanner.toml
  • resq-airspace/src/error.rs
  • resq-airspace/src/instructions/grant_permit.rs
  • resq-airspace/src/instructions/initialize_property.rs
  • resq-airspace/src/instructions/record_crossing.rs
  • resq-airspace/src/instructions/update_policy.rs
  • resq-airspace/src/instructions/update_treasury.rs
  • resq-airspace/src/lib.rs
  • resq-airspace/src/state/airspace_account.rs
  • resq-airspace/src/state/mod.rs
  • resq-airspace/src/state/permit.rs
  • resq-airspace/tests/host_init_regression.rs
  • resq-airspace/tests/integration.rs
  • resq-delivery/src/error.rs
  • resq-delivery/src/instructions/mod.rs
  • resq-delivery/src/instructions/record_delivery.rs
  • resq-delivery/src/lib.rs
  • resq-delivery/src/state/delivery_record.rs
  • resq-delivery/src/state/mod.rs
  • resq-delivery/tests/integration.rs
  • resq-gating/Cargo.toml
  • resq-gating/src/lib.rs
  • resq-gating/tests/integration.rs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added size/XXL Huge PR (1000 or more lines changed) pkg:delivery Changes to the resq-delivery on-chain program A-Build Build configuration (tsdown, tsconfig) A-Vendor Vendored third-party code under vendor/ pkg:airspace Changes to the resq-airspace on-chain program C-Chore Chore: deps, tooling, or config with no public API change labels Sep 22, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​tokio@​1.50.0 ⏵ 1.53.158 -110093100100
Updatedcargo/​tokio@​1.50.0 ⏵ 1.48.060 +210093100100
Addedcargo/​thiserror@​2.0.178010093100100
Addedcargo/​solana-keypair@​3.0.110010093100100
Addedcargo/​test-case@​3.3.110010093100100
Addedcargo/​log@​0.4.2810010093100100
Addedcargo/​solana-cluster-type@​3.0.010010093100100
Addedcargo/​solana-commitment-config@​3.0.010010093100100
Addedcargo/​solana-cpi@​3.0.010010093100100
Addedcargo/​solana-instructions-sysvar@​3.0.110010093100100
Addedcargo/​solana-msg@​3.0.010010093100100
Addedcargo/​solana-program-entrypoint@​3.1.010010093100100
Addedcargo/​solana-sdk-ids@​3.0.010010093100100
Addedcargo/​solana-signer@​3.0.110010093100100
Addedcargo/​solana-stable-layout@​3.0.010010093100100
Addedcargo/​solana-sysvar-id@​3.0.010010093100100
Updatedcargo/​anchor-lang@​1.0.0-rc.2 ⏵ 1.0.0-rc.410010093100100
Updatedcargo/​solana-account@​4.1.0 ⏵ 4.6.010010093100100
Updatedcargo/​solana-account@​4.1.0 ⏵ 3.2.010010093100100
Updatedcargo/​solana-account-info@​3.1.0 ⏵ 3.1.110010093100100
Updatedcargo/​solana-account-info@​3.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-address@​2.3.0 ⏵ 2.7.010010093100100
Updatedcargo/​solana-clock@​3.0.1 ⏵ 3.0.010010093100100
Updatedcargo/​solana-epoch-rewards@​3.0.1 ⏵ 3.0.010010093100100
Updatedcargo/​solana-fee-calculator@​3.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-instruction@​3.2.0 ⏵ 3.5.010010093100100
Updatedcargo/​solana-instruction@​3.2.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-message@​4.0.0 ⏵ 3.0.110010093100100
Updatedcargo/​solana-program@​4.0.0 ⏵ 4.1.010010093100100
Updatedcargo/​solana-program@​4.0.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-pubkey@​4.1.0 ⏵ 4.3.010010093100100
Updatedcargo/​solana-rent@​4.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-sdk@​4.0.1 ⏵ 4.1.010010093100100
See 6 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: cargo openssl is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: vendor/solana-program-test/Cargo.lock → cargo/solana-runtime@3.1.10 → cargo/openssl@0.10.74

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/openssl@0.10.74. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

Copy link
Copy Markdown

AI Audit Results for PR #75

I have audited the changes in this pull request for security vulnerabilities, logic bugs, and performance issues. Here are my findings:

1. Logic Bug: Missing On-chain Geographic Enforcement in record_crossing

The record_crossing instruction in resq-airspace records a drone"s latitude and longitude but does not verify if these coordinates fall within the defined polygon (poly) of the AirspaceAccount. Without this on-chain check, the AccessPolicy enforcement is incomplete: a drone could technically record a crossing for an incorrect property or claim to be in a nearby "Open" airspace to bypass a "Deny" policy or fee requirement.
Suggestion: Implement a point-in-polygon (PIP) check in the record_crossing handler to validate coordinates against the airspace boundary.

2. Logic Issue: Insufficient Validation for vertex_count

In initialize_property, the validation allows vertex_count to be as low as 1. A valid geographic polygon should have at least 3 vertices. Allowing 1 or 2 vertices may cause issues for future geographic verification logic.
Suggestion: Update validation to require!(vertex_count >= 3 && vertex_count <= 8, AirspaceError::InvalidVertexCount).

3. Performance Optimization in resq-gating

In submit_attestation, the telemetry payload is reconstructed using a Vec<u8> and multiple extend_from_slice calls.
Suggestion: For better Compute Unit (CU) efficiency, consider using a fixed-size byte array or a dedicated struct for the payload reconstruction.

Overall, the implementation is high-quality, especially the Ed25519 precompile integration in resq-gating which follows security best practices.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

Generated by ai-auditor for issue #75 · ◷

@WomB0ComB0

Copy link
Copy Markdown
Member Author

Superseded by #76 (regenerated from the corrected sync workflow). Like #74, this PR's rsync --delete wrongly removed .gitignore, .gitattributes, osv-scanner.toml, and docs/solana-v4-migration.md; #76 preserves them. Closing to prevent an accidental merge of those deletions.

@WomB0ComB0 WomB0ComB0 closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-Build Build configuration (tsdown, tsconfig) A-Vendor Vendored third-party code under vendor/ C-Chore Chore: deps, tooling, or config with no public API change pkg:airspace Changes to the resq-airspace on-chain program pkg:delivery Changes to the resq-delivery on-chain program size/XXL Huge PR (1000 or more lines changed)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant