Skip to content

Conversation

@Shvandre
Copy link
Collaborator

@Shvandre Shvandre commented Aug 18, 2025

Closes #102

Copilot AI review requested due to automatic review settings August 18, 2025 11:46
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR fixes a security vulnerability in the calculateJettonWallet function by adding return stack length restriction to the RUNVM operation. The change addresses stack poisoning attacks by limiting the number of return values and using proper RUNVM mode flags.

  • Updated RUNVM call to use mode 277 (combination of flags +1, +4, +16, +256) instead of mode 53
  • Added stack length restriction by expecting only 1 return value using flag +256
  • Updated stack cleanup from 3 BLKDROP to 2 BLKDROP to match the new return pattern

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
You can also share your feedback on Copilot code review for a chance to win a $100 gift card. Take the survey.

@Shvandre
Copy link
Collaborator Author

Merged #103, that was the reason of failing CI here

@Shvandre Shvandre requested a review from skywardboundd August 18, 2025 17:38
Copy link

@skywardboundd skywardboundd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

solid work

@Shvandre Shvandre merged commit b1463c6 into main Aug 18, 2025
1 check passed
@Shvandre Shvandre deleted the runvm-security branch August 18, 2025 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Check the size of RUNVM return stack, to prevent stack poisoning

2 participants