▐ homomorph ▌

rules / HM009

HM009 uninitialized-handle LOW

ACL call on a mapping entry that may still be an uninitialised (zero) handle

Why it matters

Entries of `mapping(address => euintX)` start as handle zero. Arithmetic on a zero handle is silently treated as encrypted zero by the library, but ACL calls are not: `FHE.allow(balances[user], viewer)` on an empty entry grants access to nothing, and when a real handle is written later the viewer still cannot decrypt it. `FHE.isSenderAllowed(zeroHandle)` likewise never succeeds. The bug only appears for first-time users, which is exactly the path most test suites skip.

Fix

Check first: `require(FHE.isInitialized(balances[msg.sender]), "no balance yet");` or initialise entries explicitly (`balances[u] = FHE.asEuint64(0); FHE.allowThis(balances[u]);`) on first touch.

Check locally

homomorph scan . --rules HM009