No upper bound on milestone delivery duration
initialize accepts any delivery duration. A very large value leaves the deal with no reachable dispute window and no auto-release, locking the principal with no escape for simple escrows.
Description
initialize applies no ceiling to _timeToDeliverDays or to any element of
_milestoneTimeToDeliverDays. A large value is not rejected and not self-limiting: deposit
succeeds, and the deal then has no reachable dispute window and no auto-release, because
_currentDisputableMilestoneIndex reverts TooEarlyToDispute and autoReleaseMilestone reverts
BuyerObjectionWindowActive for as long as the deadline is in the future.
This affects simple escrows as well as milestone deals, and simple escrows are worse off — they
have no abandonUncommencedMilestones escape at all. For a milestone deal, milestone 0 is
auto-commenced at funding, so its slice is committed before the buyer could notice.
This is not an overflow issue: overflow needs roughly 1e72 days, while a merely large value such as 1e12 days produces a deadline centuries away with no revert. The outcome is a stalemate in which the seller cannot be paid and the buyer cannot be refunded — plausible as a unit-conversion or UI error, not only as an adversarial input.
Recommendation
Enforce a protocol maximum on timeToDeliverDays and on every milestone duration at creation, and
construct all deadlines with explicitly bounded arithmetic.
Resolution
Fixed. MAX_DELIVERY_DAYS is 730 and enforced at creation for both simple and milestone deals.
Affected files
Escrow.sol#L198-L200, #L317-L319, #L321-L389, #L599-L619, #L918-L944