Skip to content

[F49] [LOW] Return param name 'ethAmount'/'tokenAmount' is a misnomer for a unitless ratio and risks scale confusion #100

Description

@thedavidmeister

LSTPerToken() names its return 'ethAmount' and tokensPerLST() names its return 'tokenAmount', as though they were absolute balances. But both values are exchange-rate ratios (per-1e18-token / per-1e18-LST), as the consumer LibDineroFlrEth confirms ('For each 1e18 FLRETH, this is how many ETH are deposited' / 'For each 1e18 ETH, this is how many FLRETH are minted'). Calling a ratio 'ethAmount' invites a reader to treat the value as a wei balance rather than a 1e18-scaled rate, the class of unit/scale mistake that produces 1e18x pricing errors in exchange-rate math. The names match neither the function names' 'per' semantics nor the documented 1e18 ratio meaning.

File(s): src/interface/IDineroFlrEth.sol
Lines: 8,12

Proposed fix
Rename the return identifiers to convey 'ratio at 1e18 scale', paired with the NatSpec above: returns (uint256 ethPerToken18) for LSTPerToken() and returns (uint256 tokenPerLst18) for tokensPerLST(). Keep the function names unchanged (they mirror the external Dinero ABI and must match it).

Filed by the audit skill (dimension 5-correctness). Findings are problems, not fixes — triage decides disposition.

Co-Authored-By: Claude noreply@anthropic.com

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions