The Dividend Paid in Ghost Shares — JavaScript Bug Hunt

Modelled on Samsung Securities' "ghost shares" (April 2018): an employee paying the dividend to the employee stock ownership plan entered 1,000 shares per…

  • Language: JavaScript
  • Layer: Database
  • Difficulty: Easy
  • Concepts: Money, Validation
  • Modelled on: Samsung Securities · 2018
  • Visible tests: a cash dividend is paid per share held; 1,000 shares per share is refused
  • Reward: 50 XP for a complete fix

Briefing

Modelled on Samsung Securities' "ghost shares" (April 2018): an employee paying the dividend to the employee stock ownership plan entered 1,000 shares per share instead of 1,000 won per share. The system credited about 2.8 billion shares that did not exist — many times the company's actual share count — and some employees sold millions of them before the error was contained.

This project is a reconstruction. payout.js will pay a dividend in either unit and never asks whether the shares it credits exist.

Fix applyDividend so it validates the instruction and can never credit shares beyond those issued.

Bug report

BUG-SS-0406 · Priority: Critical · Reported by: settlement

applyDividend(ledger, { amount, unit }):

  • amount must be a positive integer and unit "KRW" or "SHARES"; otherwise throw and change nothing
  • "KRW": every account's cash += shares * amount
  • "SHARES": every account's shares += shares * amount — but only if the total shares held across all accounts afterwards is <= ledger.sharesIssued; otherwise throw and change NOTHING (no partial credit)
  • returns { unit, total } where total is the sum credited across accounts

Observed: an instruction of 1,000 SHARES was accepted and credited 150,000 shares against 1,000 issued.

Logs

[esop] dividend unit=SHARES amount=1000 accounts=2 credited=150000
[settlement] holdings 150150 exceed shares issued 1000
[trading] sell orders placed from ESOP accounts against credited shares

The code as shipped

src/esop/payout.js (editable)

// Pays the ESOP dividend. instruction: { amount, unit: "KRW" | "SHARES" }.
exports.applyDividend = function (ledger, instruction) {
  var total = 0;
  for (var i = 0; i < ledger.accounts.length; i++) {
    var acct = ledger.accounts[i];
    var credit = acct.shares * instruction.amount;
    if (instruction.unit === "SHARES") acct.shares += credit;
    else acct.cash += credit;
    total += credit;
  }
  return { unit: instruction.unit, total: total };
};

Read-only context: src/esop/ledger.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.