Repository navigation
Fix WIRE-377: bind finalizer registration proofs to accounts - #656
Closed
huangminghuang wants to merge 1 commit into
Closed
huangminghuang wants to merge 1 commit into
huangminghuang wants to merge 1 commit into
Conversation
Change-Id: I1e41d6d42bc96bb8506de451b6aa76a1eec093ef
heifner
requested changes
Sep 30, 2026
heifner
left a comment
Contributor
There was a problem hiding this comment.
I don't think this is needed. I say we close this and the associated Wire-Network/wire-tools-ts#110 . You have to be producer to do this. To be a producer you have to had put up slashable amounts on ETH/SOL. Even if someone did this it can be easily ignored and a new key generated. The attacker can't sign with the key. Also easy to prove someone did this, put up a multisig to slash them with proof. As noted in JIRA I think we should only verify the producer is active. Please create a PR to add the active (producer_rank::is_eligible_operator) check.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
regfinkeyproofs to the finalizer account and public key usingREG_BLS_V1:<standard PoP>:<account signature>, preserving the standard BLS proof-of-possession check.sys-util bls create pop --finalizer ACCOUNTand update registration fixtures, Python callers, and producer documentation. Ordinary BIOS PoPs remain unchanged.Why
WIRE-377 addresses cross-account replay of a published finalizer proof to squat the corresponding key. Registration now verifies both the standard PoP and a signature over domain-separated account and public-key bytes. Strict versioned framing rejects legacy and malformed registration proofs while retaining rogue-key protection.
Validation
Companion PRs