==============================================================================
TEST 1 - distributeRewards double-pays the same accrual window
==============================================================================
after distributeRewards at t=100: alice received 10000 tokens
alice then calls claimReward at t=200: receives 20000 tokens

reward actually owed for 200s at rewardRate=100 : 20000
reward actually paid out                        : 30000
overpayment                                     : 10000  (50.0% inflation)

cause: distributeRewards zeroes rewards[u] but leaves userRewardPerTokenPaid[u] at
its old value, so earned(u) re-accrues the window that was already paid.

==============================================================================
TEST 2 - unauthenticated setRewardRate bricks the contract
==============================================================================
normal operation: bob staked 5 ETH, rewardRate=100
attacker calls setRewardRate(2**200) - no owner check on that function
  stake              REVERTS (uint256 overflow -> EVM revert)
  withdraw           REVERTS (uint256 overflow -> EVM revert)
  claimReward        REVERTS (uint256 overflow -> EVM revert)
  distributeRewards  REVERTS (uint256 overflow -> EVM revert)

rewardPerToken() is evaluated inside the updateReward modifier, so every user-facing
function reverts. Bob's 5 ETH cannot be withdrawn.

==============================================================================
TEST 3 - the overflow margin is small enough to be reached by a plausible value
==============================================================================
  rewardRate=1e30  dt=1000s -> ok
  rewardRate=1e50  dt=1000s -> ok
  rewardRate=1e55  dt=1000s -> ok
  rewardRate=1e56  dt=1000s -> ok
  rewardRate=1e57  dt=1000s -> OVERFLOW, contract unusable
  rewardRate=1e60  dt=1000s -> OVERFLOW, contract unusable

dt * rewardRate * 1e18 must stay under 2^256 = 115792089237316195423570985008687907853269984665640564039457584007913129639936
exact ceiling for rewardRate at dt=1000s: 115792089237316195423570985008687907853269984665640564039 (~1e56)
anything above that permanently disables the vault, and setRewardRate is open to any address.
