Skip to content

fix: use abi.encode in calculateMultiRequestId - #416

Open
OBrezhniev wants to merge 1 commit into
mainfrom
fix/multirequest-id-abi-encode
Open

OBrezhniev wants to merge 1 commit into
mainfrom
fix/multirequest-id-abi-encode

Conversation

@OBrezhniev

@OBrezhniev OBrezhniev commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

calculateMultiRequestId hashed (requestIds, groupIds, creatorAddress) with solidityPacked, which is abi.encodePacked. Packing two dynamic uint256[] arrays is ambiguous, so different splits of the same IDs collide:

requestIds groupIds packed (old) abi.encode (new)
[1, 2] [3] 37295…76984 66503…32039
[1] [2, 3] 37295…76984 91988…61768

(creator 0xf39F…2266)

This PR switches to AbiCoder.defaultAbiCoder().encode, matching the Verifier contract fix in iden3/contracts: iden3/contracts#464.

⚠️ Breaking change

IDs differ from the previous formula. Use this version with Verifier contracts that hash with abi.encode (UniversalVerifier ≥ 3.1.0). Against a contract that hasn't been upgraded, and vice versa, setMultiRequest reverts with MultiRequestIdNotValid(expected, given). Existing multiRequests are unaffected, because the ID is only checked when a multiRequest is created. Suggest releasing as a major version, close to the contract upgrades on each network.

Tests

Added calculateMultiRequestId cases to tests/utils/utils.test.ts: fixed vectors, and a check that different splits give different IDs. Locally I could only check prettier and tsc on the changed files. vitest couldn't run because of a local dependency-install issue, so this PR's CI is the first test run.

🤖 Generated with Claude Code

abi.encodePacked of two dynamic uint256[] arrays is ambiguous, so
e.g. ([1, 2], [3]) and ([1], [2, 3]) produced the same multiRequestId.
Matches the Verifier contract change (iden3/contracts VerifierLib).

BREAKING CHANGE: ids now differ from the previous formula. Use with
Verifier contracts that hash multiRequestId with abi.encode
(UniversalVerifier >= 3.1.0).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants