feat(crypto): add strict ECDSA validation - #57
Federico2014 wants to merge 5 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
All reported issues were addressed across 34 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
8cae787 to
4bca8c9
Compare
What does this PR do?
Why are these changes required?
Malformed signatures and unused trailing bytes can produce inconsistent validation or unnecessary storage and response costs. These changes harden signature handling while retaining legacy consensus recovery before governance activation.
Related TIP: tronprotocol/tips#935
This PR has been tested by:
Follow up
Add maintenance-boundary integration coverage for activation and pending-transaction revalidation. Complete affected-client measurements and migration notices before rollout.
Extra details
Targets v4.8.3. Admission and auxiliary-query length checks take effect upon upgrade; strict consensus recovery is governance-controlled. Clients producing padded signatures, including 68-byte signatures, must migrate to 65-byte encoding.
Summary by cubic
Adds governance-controlled strict ECDSA signature validation (proposal 99, block version 38) that rejects malformed signatures and padding across admission, query, and consensus paths.
Previously, padded signatures up to 68 bytes were accepted at admission and truncated during query recovery. Now signatures must be exactly 65 bytes at admission and auxiliary-query entry points, which return
SIGNATURE_FORMAT_ERRORwithout hashing or recovery. When the proposal activates, consensus recovery also enforces scalar bounds, recovery-id limits, and rejects point-at-infinity public keys; witness-signature trailing bytes are trimmed during block sanitization and the transaction verification cache is invalidated at activation.Migration
Related TIP: tronprotocol/tips#935
Written for commit 4bca8c9. Summary will update on new commits.