forked from sass/tipibot
Fix money-safety bugs in economy (heist, blackjack, bail) #3
Reference in New Issue
Block a user
Delete Branch "fix/economy-money-safety"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Multi-agent audit of the money-moving economy modules surfaced three
confirmed correctness bugs. All three are fixed here with regression tests.
heist (core/economy/heist.py):
house = await get_user(house.HOUSE_ID)shadowed the importedhousemodule for the whole function, so
house.HOUSE_IDraised UnboundLocalErroron every successful heist (win payout was entirely dead) and on the
fail-path compensation branch. Rename the local to
house_rec.house was debited only min(total, balance), so a poor house paid out more
than it lost. Cap the pot at the balance and debit exactly what is paid
(house debit == sum of payouts). No mint, no leak.
_is_jailedimport (do_heist_check referenced it unimported).blackjack (commands/economy_games_commands.py):
as its own task, so double-clicking Stand within the dealer-reveal window
paid out twice (mint), and double-clicking Double/Split deducted the extra
bet twice. Add a synchronous
_busyguard (matching the existing RpsGameidiom) on all four callbacks plus a
_resolvedidempotency flag onsettlement, so a game can only pay out once.
bail (core/economy/jail.py, commands/economy_extra_commands.py):
BailView from a re-run /jailbreak charged bail twice, destroying coins (bail
is a pure sink). Make do_bail a no-op when the user is not jailed, and add a
UI reentrancy guard + "already free" message.
Tests: 47 passed (4 new regression tests covering heist coin-conservation and
bail idempotency).
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com