code-423n4 / 2024-03-zksync-findings

1 stars 1 forks source link

QA Report #122

Open c4-bot-8 opened 4 months ago

c4-bot-8 commented 4 months ago

See the markdown file with the details of this report here.

razzorsec commented 3 months ago

The first “QA” was considered medium by us!

c4-judge commented 2 months ago

alex-ppg marked the issue as grade-a

c4-judge commented 2 months ago

alex-ppg marked the issue as selected for report

alex-ppg commented 2 months ago

This submission was graded as the best due to exceeding the 50% accuracy threshold whilst containing valid and thoroughly elaborated findings in an easily digestible format. To note, the first QA finding will be upgraded accordingly once judging concludes and this exhibit is split into a second one as a duplicate of #97.

Bauchibred commented 2 months ago

Hi @alex-ppg, thanks for judging the contest, I'd like to ask if it's possible you have any comments in regards to the upgradability of some of the listed borderline low/medium issues, a couple were attached here in the QA report as an attempt on not spamming the judging repo with reports that could end up being finalised as QA, I'd appreciate a quick glance on this borderline issues to see if any could be upgraded.

To ease the re-review, I believe grepping the markdown file with the word medium would pinpoint most of these issues, however I'd appreciate re-review as not all have been linked with the medium word, thanks once again for your time.

alex-ppg commented 2 months ago

Hey @Bauchibred, appreciate the in-depth analysis of the QA report and your contribution to the PJQA process! I have evaluated all findings that infer a medium upgrade as follows:

I believe that the present ruling is fair, but will make sure to notify the sponsor for a re-evaluation of QA-02 in case it merits an upgrade. It definitely is a mistake in the code, but I do not believe its ramifications to be impactful as nodes utilize events as highlighted in other exhibits such as #112.

DecentralDisco commented 2 months ago

Regarding validity of items in this QA report, per conversation with the judge @alex-ppg:

The only clear mistake is QA-06, and the rest are passable NC / L / I recommendations. As such, I confirm that all QA items except for QA-06 are valid.

As such, QA-06 will be excluded from the final audit report.