2017-07-05 10:28:15 +00:00
|
|
|
pragma solidity ^0.4.11;
|
|
|
|
|
|
|
|
|
|
|
|
import './payment/PullPayment.sol';
|
|
|
|
import './lifecycle/Destructible.sol';
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @title Bounty
|
|
|
|
* @dev This bounty will pay out to a researcher if they break invariant logic of the contract.
|
|
|
|
*/
|
|
|
|
contract Bounty is PullPayment, Destructible {
|
|
|
|
bool public claimed;
|
|
|
|
mapping(address => address) public researchers;
|
|
|
|
|
|
|
|
event TargetCreated(address createdAddress);
|
|
|
|
|
|
|
|
/**
|
2018-07-10 07:18:19 +00:00
|
|
|
* @dev Fallback function allowing the contract to receive funds, if they haven't already been claimed.
|
2017-07-05 10:28:15 +00:00
|
|
|
*/
|
2018-06-28 16:08:45 +00:00
|
|
|
function() external payable {
|
2017-07-05 10:28:15 +00:00
|
|
|
if (claimed) {
|
2018-07-11 23:49:00 +00:00
|
|
|
revert();
|
2017-07-05 10:28:15 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dev Create and deploy the target contract (extension of Target contract), and sets the
|
|
|
|
* msg.sender as a researcher
|
|
|
|
* @return A target contract
|
|
|
|
*/
|
2018-07-04 17:20:51 +00:00
|
|
|
function createTarget() public returns(Target) {
|
2017-07-05 10:28:15 +00:00
|
|
|
Target target = Target(deployContract());
|
|
|
|
researchers[target] = msg.sender;
|
2018-06-27 08:35:38 +00:00
|
|
|
emit TargetCreated(target);
|
2017-07-05 10:28:15 +00:00
|
|
|
return target;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dev Internal function to deploy the target contract.
|
|
|
|
* @return A target contract address
|
|
|
|
*/
|
|
|
|
function deployContract() internal returns(address);
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dev Sends the contract funds to the researcher that proved the contract is broken.
|
|
|
|
* @param target contract
|
|
|
|
*/
|
2018-07-04 17:20:51 +00:00
|
|
|
function claim(Target target) public {
|
2017-07-05 10:28:15 +00:00
|
|
|
address researcher = researchers[target];
|
2018-06-12 09:05:49 +00:00
|
|
|
if (researcher == address(0)) {
|
2018-07-11 23:49:00 +00:00
|
|
|
revert();
|
2017-07-05 10:28:15 +00:00
|
|
|
}
|
|
|
|
// Check Target contract invariants
|
|
|
|
if (target.checkInvariant()) {
|
2018-07-11 23:49:00 +00:00
|
|
|
revert();
|
2017-07-05 10:28:15 +00:00
|
|
|
}
|
2018-07-05 12:32:32 +00:00
|
|
|
asyncSend(researcher, address(this).balance);
|
2017-07-05 10:28:15 +00:00
|
|
|
claimed = true;
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @title Target
|
|
|
|
* @dev Your main contract should inherit from this class and implement the checkInvariant method.
|
|
|
|
*/
|
|
|
|
contract Target {
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @dev Checks all values a contract assumes to be true all the time. If this function returns
|
|
|
|
* false, the contract is broken in some way and is in an inconsistent state.
|
|
|
|
* In order to win the bounty, security researchers will try to cause this broken state.
|
|
|
|
* @return True if all invariant values are correct, false otherwise.
|
|
|
|
*/
|
2018-07-04 17:20:51 +00:00
|
|
|
function checkInvariant() public returns(bool);
|
2017-07-05 10:28:15 +00:00
|
|
|
}
|