Skip to content

Fix WIRE-377: bind finalizer registration proofs to accounts - #656

Closed
huangminghuang wants to merge 1 commit into
masterfrom
fix/wire-377
Closed

huangminghuang wants to merge 1 commit into
masterfrom
fix/wire-377

Conversation

@huangminghuang

@huangminghuang huangminghuang commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bind regfinkey proofs to the finalizer account and public key using REG_BLS_V1:<standard PoP>:<account signature>, preserving the standard BLS proof-of-possession check.
  • Add sys-util bls create pop --finalizer ACCOUNT and update registration fixtures, Python callers, and producer documentation. Ordinary BIOS PoPs remain unchanged.
  • Rebuild the system-contract WASM; action fields and ABI remain unchanged.

Why

WIRE-377 addresses cross-account replay of a published finalizer proof to squat the corresponding key. Registration now verifies both the standard PoP and a signature over domain-separated account and public-key bytes. Strict versioned framing rejects legacy and malformed registration proofs while retaining rogue-key protection.

Validation

  • 117 JIT contract cases passed across finalizer registration, producer eligibility/ranking, peer keys, snapshot attestation, and BIOS suites; 7,478 assertions.
  • Five native snapshot-attestation cases passed; 108 assertions.
  • CLI BLS tests passed, including canonical account validation; generated proof exactly matches the pinned C++/TypeScript vector.
  • Rechecked the three replay/proof/vector regression cases before publication; 78 assertions passed.
  • Native targets built; tracked WASM matches the build output and ABI is byte-for-byte unchanged.

Companion PRs

  • wire-tools-ts #110: generates the required account-bound proof during producer registration. Review and land the pair together; deploy the matching CLI/Tools behavior with the updated system contract. No SDK schema release is required.

Change-Id: I1e41d6d42bc96bb8506de451b6aa76a1eec093ef

@heifner heifner left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is needed. I say we close this and the associated Wire-Network/wire-tools-ts#110 . You have to be producer to do this. To be a producer you have to had put up slashable amounts on ETH/SOL. Even if someone did this it can be easily ignored and a new key generated. The attacker can't sign with the key. Also easy to prove someone did this, put up a multisig to slash them with proof. As noted in JIRA I think we should only verify the producer is active. Please create a PR to add the active (producer_rank::is_eligible_operator) check.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants