rules / HM009
HM009 uninitialized-handle LOW
ACL call on a mapping entry that may still be an uninitialised (zero) handle
Why it matters
Entries of `mapping(address => euintX)` start as handle zero. Arithmetic on a zero handle is silently treated as encrypted zero by the library, but ACL calls are not: `FHE.allow(balances[user], viewer)` on an empty entry grants access to nothing, and when a real handle is written later the viewer still cannot decrypt it. `FHE.isSenderAllowed(zeroHandle)` likewise never succeeds. The bug only appears for first-time users, which is exactly the path most test suites skip.
Fix
Check first: `require(FHE.isInitialized(balances[msg.sender]), "no balance yet");` or initialise entries explicitly (`balances[u] = FHE.asEuint64(0); FHE.allowThis(balances[u]);`) on first touch.
Check locally
homomorph scan . --rules HM009