Skip to content

chore: sync from monorepo @ce410a0 - #78

Closed
WomB0ComB0 wants to merge 1 commit into
mainfrom
sync/monorepo-ce410a0
Closed

WomB0ComB0 wants to merge 1 commit into
mainfrom
sync/monorepo-ce410a0

Conversation

@WomB0ComB0

Copy link
Copy Markdown
Member

Automated sync from the internal monorepo at ce410a0.

Review before merging — direct pushes to standalone repos are preserved.

@github-actions github-actions Bot added the size/XXL Huge PR (1000 or more lines changed) label Sep 23, 2026
@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 41 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b14ab33c-f36e-4ee3-9d02-a00957a23f48

📥 Commits

Reviewing files that changed from the base of the PR and between d625d4e and c3cbda1.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • vendor/solana-program-test/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (25)
  • Anchor.toml
  • Cargo.toml
  • README.md
  • resq-airspace/src/error.rs
  • resq-airspace/src/instructions/grant_permit.rs
  • resq-airspace/src/instructions/initialize_property.rs
  • resq-airspace/src/instructions/record_crossing.rs
  • resq-airspace/src/instructions/update_policy.rs
  • resq-airspace/src/instructions/update_treasury.rs
  • resq-airspace/src/lib.rs
  • resq-airspace/src/state/airspace_account.rs
  • resq-airspace/src/state/mod.rs
  • resq-airspace/src/state/permit.rs
  • resq-airspace/tests/host_init_regression.rs
  • resq-airspace/tests/integration.rs
  • resq-delivery/src/error.rs
  • resq-delivery/src/instructions/mod.rs
  • resq-delivery/src/instructions/record_delivery.rs
  • resq-delivery/src/lib.rs
  • resq-delivery/src/state/delivery_record.rs
  • resq-delivery/src/state/mod.rs
  • resq-delivery/tests/integration.rs
  • resq-gating/Cargo.toml
  • resq-gating/src/lib.rs
  • resq-gating/tests/integration.rs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added pkg:delivery Changes to the resq-delivery on-chain program A-Build Build configuration (tsdown, tsconfig) A-Vendor Vendored third-party code under vendor/ pkg:airspace Changes to the resq-airspace on-chain program C-Chore Chore: deps, tooling, or config with no public API change labels Sep 23, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​tokio@​1.50.0 ⏵ 1.53.158 -110093100100
Updatedcargo/​tokio@​1.50.0 ⏵ 1.48.060 +210093100100
Addedcargo/​thiserror@​2.0.178010093100100
Addedcargo/​solana-keypair@​3.0.110010093100100
Addedcargo/​test-case@​3.3.110010093100100
Addedcargo/​log@​0.4.2810010093100100
Addedcargo/​solana-cluster-type@​3.0.010010093100100
Addedcargo/​solana-commitment-config@​3.0.010010093100100
Addedcargo/​solana-cpi@​3.0.010010093100100
Addedcargo/​solana-instructions-sysvar@​3.0.110010093100100
Addedcargo/​solana-msg@​3.0.010010093100100
Addedcargo/​solana-program-entrypoint@​3.1.010010093100100
Addedcargo/​solana-sdk-ids@​3.0.010010093100100
Addedcargo/​solana-signer@​3.0.110010093100100
Addedcargo/​solana-stable-layout@​3.0.010010093100100
Addedcargo/​solana-sysvar-id@​3.0.010010093100100
Updatedcargo/​anchor-lang@​1.0.0-rc.2 ⏵ 1.0.0-rc.410010093100100
Updatedcargo/​solana-account@​4.1.0 ⏵ 4.6.010010093100100
Updatedcargo/​solana-account@​4.1.0 ⏵ 3.2.010010093100100
Updatedcargo/​solana-account-info@​3.1.0 ⏵ 3.1.110010093100100
Updatedcargo/​solana-account-info@​3.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-address@​2.3.0 ⏵ 2.7.010010093100100
Updatedcargo/​solana-clock@​3.0.1 ⏵ 3.0.010010093100100
Updatedcargo/​solana-epoch-rewards@​3.0.1 ⏵ 3.0.010010093100100
Updatedcargo/​solana-fee-calculator@​3.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-instruction@​3.2.0 ⏵ 3.5.010010093100100
Updatedcargo/​solana-instruction@​3.2.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-message@​4.0.0 ⏵ 3.0.110010093100100
Updatedcargo/​solana-program@​4.0.0 ⏵ 4.1.010010093100100
Updatedcargo/​solana-program@​4.0.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-pubkey@​4.1.0 ⏵ 4.3.010010093100100
Updatedcargo/​solana-rent@​4.1.0 ⏵ 3.0.010010093100100
Updatedcargo/​solana-sdk@​4.0.1 ⏵ 4.1.010010093100100
See 6 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: cargo openssl is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: vendor/solana-program-test/Cargo.lock → cargo/solana-runtime@3.1.10 → cargo/openssl@0.10.74

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/openssl@0.10.74. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

Copy link
Copy Markdown

Airspace Program Audit - Pull Request #78

I have completed a security and logic audit of the changes in this PR. Below are my findings:

1. Critical Compilation Error

Location: resq-airspace/src/instructions/record_crossing.rs:137

The system_program::transfer call incorrectly uses ctx.accounts.system_program.key() as the first argument to CpiContext::new. In Anchor, CpiContext::new expects an AccountInfo or a type that implements ToAccountInfo, but .key() returns a Pubkey.

Suggested Fix:

system_program::transfer(
    CpiContext::new(
        ctx.accounts.system_program.to_account_info(),
        system_program::Transfer {
            from: ctx.accounts.drone.to_account_info(),
            to: ctx.accounts.treasury.to_account_info(),
        },
    ),
    airspace.fee_lamports,
)?;

2. Drone Identity & Signing Inconsistency

Location: resq-airspace/src/instructions/grant_permit.rs and record_crossing.rs

There is a mismatch in how drone identities are handled:

  • grant_permit creates a Permit account seeded with a drone_pda: Pubkey argument, explicitly described as a Program-Derived Address.
  • record_crossing requires the drone to be a Signer and uses drone.key() in the seeds for the same Permit account.

Problem: A PDA cannot sign a top-level transaction. If the drone is indeed a PDA (e.g., owned by the resq-delivery program), it can only "sign" via CPI. If it is a physical drone with its own keypair, the terminology and seed derivation should be updated to reflect that it is a wallet/authority key rather than a PDA.

3. Weak Geometric Validation

Location: resq-airspace/src/instructions/initialize_property.rs (L75)

The instruction allows a vertex_count as low as 1. A valid polygon requires at least 3 vertices to define a 2D area. Persisting a 1- or 2-vertex "polygon" may lead to logic errors in future geometric checking code (e.g., point-in-polygon tests).

Suggested Fix: Change the requirement to vertex_count >= 3 && vertex_count <= 8.

4. Observations on resq-gating

The resq-gating program is exceptionally well-implemented, with robust checks for Ed25519 precompile offsets, timestamp drift, and coordinate sanity (finite float checks). This sets a high standard for the workspace.

Summary

The audit FAILs primarily due to the compilation error in the record_crossing instruction and the identity inconsistency between permit granting and crossing recording. These must be addressed before merging.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

Generated by ai-auditor for issue #78 · ◷

@WomB0ComB0

Copy link
Copy Markdown
Member Author

Superseded by a newer monorepo sync (@b35fdb0); closing this stale sync PR.

@WomB0ComB0 WomB0ComB0 closed this Sep 23, 2026
@WomB0ComB0
WomB0ComB0 deleted the sync/monorepo-ce410a0 branch September 23, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-Build Build configuration (tsdown, tsconfig) A-Vendor Vendored third-party code under vendor/ C-Chore Chore: deps, tooling, or config with no public API change pkg:airspace Changes to the resq-airspace on-chain program pkg:delivery Changes to the resq-delivery on-chain program size/XXL Huge PR (1000 or more lines changed)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant