What happened
Slither fails to build IR for Uniswap Calibur's ERC7739._isValidTypedDataSig, which destructures a calldata tuple returned by OpenZeppelin's draft-ERC7739Utils through using ERC7739Utils for *. The parse error is:
'NoneType' object has no attribute 'parameters'
The damaging part is the failure mode: every contract that inherits Calibur is then dropped from analysis entirely, while the run still completes and reports zero findings for them. We proved the silent drop by injecting an arbitrary low-level call into a subclass: zero findings; the identical injection in a non-inheriting contract was flagged immediately.
Reproduction
git clone --recurse-submodules https://github.com/Uniswap/calibur
cd calibur
slither .
Or, for the silent-drop demonstration specifically: our repo keeps a canary test that plants a known vulnerability in a Calibur-inheriting fixture and asserts Slither misses it: https://github.com/xanderslabs/avok.js/blob/main/contracts/test/SlitherCanary.t.sol
Note via_ir cannot be disabled as a workaround: Calibur does not compile without it (stack too deep).
Versions
Reproduced on Slither 0.11.5 and 0.11.6 (latest at time of filing), Python via pipx, solc 0.8.29, macOS. (Aderyn 0.6.8 also panics on the same project, for what it's worth.)
Impact
Calibur is an audited, deployed EIP-7702 delegate that projects are encouraged to subclass; any such subclass currently gets a clean Slither run that has analyzed nothing. A hard error on IR failure (or a per-contract 'not analyzed' report) would make this failure loud instead of silent.
What happened
Slither fails to build IR for Uniswap Calibur's
ERC7739._isValidTypedDataSig, which destructures a calldata tuple returned by OpenZeppelin'sdraft-ERC7739Utilsthroughusing ERC7739Utils for *. The parse error is:The damaging part is the failure mode: every contract that inherits Calibur is then dropped from analysis entirely, while the run still completes and reports zero findings for them. We proved the silent drop by injecting an arbitrary low-level call into a subclass: zero findings; the identical injection in a non-inheriting contract was flagged immediately.
Reproduction
Or, for the silent-drop demonstration specifically: our repo keeps a canary test that plants a known vulnerability in a Calibur-inheriting fixture and asserts Slither misses it: https://github.com/xanderslabs/avok.js/blob/main/contracts/test/SlitherCanary.t.sol
Note
via_ircannot be disabled as a workaround: Calibur does not compile without it (stack too deep).Versions
Reproduced on Slither 0.11.5 and 0.11.6 (latest at time of filing), Python via pipx, solc 0.8.29, macOS. (Aderyn 0.6.8 also panics on the same project, for what it's worth.)
Impact
Calibur is an audited, deployed EIP-7702 delegate that projects are encouraged to subclass; any such subclass currently gets a clean Slither run that has analyzed nothing. A hard error on IR failure (or a per-contract 'not analyzed' report) would make this failure loud instead of silent.