fix(multicall): resolve critical multicall parsing corruption issues

- Added comprehensive bounds checking to prevent buffer overruns in multicall parsing
- Implemented graduated validation system (Strict/Moderate/Permissive) to reduce false positives
- Added LRU caching system for address validation with 10-minute TTL
- Enhanced ABI decoder with missing Universal Router and Arbitrum-specific DEX signatures
- Fixed duplicate function declarations and import conflicts across multiple files
- Added error recovery mechanisms with multiple fallback strategies
- Updated tests to handle new validation behavior for suspicious addresses
- Fixed parser test expectations for improved validation system
- Applied gofmt formatting fixes to ensure code style compliance
- Fixed mutex copying issues in monitoring package by introducing MetricsSnapshot
- Resolved critical security vulnerabilities in heuristic address extraction
- Progress: Updated TODO audit from 10% to 35% complete

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
Krypto Kajun
2025-10-17 00:12:55 -05:00
parent f358f49aa9
commit 850223a953
8621 changed files with 79808 additions and 7340 deletions

View File

@@ -11,6 +11,7 @@ import (
"github.com/ethereum/go-ethereum/common"
etypes "github.com/ethereum/go-ethereum/core/types"
"github.com/ethereum/go-ethereum/ethclient"
"github.com/fraktal/mev-beta/bindings/arbitrage"
"github.com/fraktal/mev-beta/bindings/flashswap"
"github.com/fraktal/mev-beta/bindings/interfaces"
@@ -358,10 +359,17 @@ func (ce *ContractExecutor) prepareTransactionOpts(ctx context.Context) (*bind.T
return nil, fmt.Errorf("failed to get account nonce: %w", err)
}
// Check nonce safely before creating transaction options
nonceInt64, err := security.SafeUint64ToInt64(nonce)
if err != nil {
ce.logger.Error("Nonce exceeds int64 maximum", "nonce", nonce, "error", err)
return nil, fmt.Errorf("nonce value exceeds maximum: %w", err)
}
// Create transaction options
opts := &bind.TransactOpts{
From: ce.accountAddress,
Nonce: big.NewInt(int64(nonce)),
Nonce: big.NewInt(nonceInt64),
Signer: ce.signTransaction, // Custom signer function
Value: big.NewInt(0), // No ETH value for arbitrage transactions
GasPrice: ce.gasPrice,