fix(dex): refund at-cap LP deposits instead of erroring the whole batch - #474
Merged
Conversation
ezeike
approved these changes
Jul 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(dex): refund at-cap LP deposits instead of erroring the whole batch
A remote liquidity deposit from a brand-new LP into a pool already at
MaxLiquidityProviders (50k) caused HandleBatchDeposit to return
ErrInvalidLiquidityPool for the entire batch. Since remote batches bypass
the enqueue-time cap check and begin_block DEX settlement aborts the whole
block on error, the poison batch was deterministically re-served every
block and could never rotate - deadlocking the nested chain (no fix via
pod restart, as the failing input is committed root state).
HandleBatchDeposit now enforces the LP holder cap per-deposit: an at-cap
deposit from a new holder is skipped (and refunded from the holding pool
on the local/escrow side) rather than erroring the batch. Point issuance
is computed from accepted deposits only, so a rejected deposit's share no
longer leaks to the dead address as phantom dust. Both chains run the
identical logic over mirrored pool points, keeping accept/reject decisions
in sync.
Tests: replace the remote at-cap error test with a skip-without-error
test; add local-refund and mixed accept/refund coverage.