Skip to content
Request an audit

‹ All findings

Call _updateMarkPrice() whenever markPrice is changed

MediumNftperp Matching Engine·Three Sigma · NFT perpetuals · 29th January, 20243S-NFTPerp-L01

Description

Functions addLiquidity() and removeLiquidity() change mark price but don't call _updateMarkPrice().

Since these functions are meant to add/remove liquidity, the price isn't expected to fluctuate drastically, but numerical approximations and the use of virtual reserves can lead to some price fluctuation.

Calling _updateMarkPrice() would take a new snapshot of the price ensuring consistency between the markPrice variable and the snapshots on storage, as well as protect users in case of price fluctuation.

Recommendation

Call _updateMarkPrice() to update the markPrice instead of changing this variable directly

Status

Addressed in #1423a79