The Onre protocol is a Solana program built with the Anchor framework which facilitates the sale of real world assets via an offers system. The protocol allows an authorized user to create offers specifying the buy and sell tokens, a sale price and a maximum amount of tokens available to purchase. The user can then choose to fill these orders (completely or partially) by paying the quoted price. This audit is a diff audit focusing on the following: - The addition of an intermediary account which handles moving buy and sell tokens between the user and the protocol. - `initialize.rs` adds some extra code to handle initializing the permissionless account. - `take_offer_one_permissionless.rs` is new, but largely duplicate code from the `take_offer_one()` function logic. - All remaining code is unchanged. Overall, the code changes are well engineered and adheres to good security practices. The audit review found some missing input validation, missing documentation and duplicate code which we recommend to be addressed. The updates indicate that finding `ONRE-1` as well as Suggestions S1 and S2 have all been successfully fixed, addressing the previously identified vulnerabilities. However, Suggestion S3 has been acknowledged, with the client recognizing the issue of code duplication but opting to defer resolution until a new version of the program is released.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | - | - | - | - | 0 |
Fixed | 1 | - | - | - | 1 |
| Total | 1 | 0 | 0 | 0 | 1 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |