Skip to content

Comments

fix: add membership verification during add_signature#465

Merged
kbizikav merged 6 commits intodevfrom
fix-membership-verification
Oct 29, 2025
Merged

fix: add membership verification during add_signature#465
kbizikav merged 6 commits intodevfrom
fix-membership-verification

Conversation

@kbizikav
Copy link
Collaborator

Fix problem imunifi report 56733.
Added verification for pubkey membership besides signature verification.

Copilot AI review requested due to automatic review settings October 24, 2025 06:40
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds security validation to the add_signature method by verifying that a public key exists in the proposal memo before accepting its signature. This prevents unauthorized signatures from being added to blocks.

Key Changes:

  • Added membership verification for public keys in the signature acceptance flow
  • Implemented consistent error handling for unauthorized public key attempts

Reviewed Changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
block-builder/src/app/storage/redis_storage.rs Added pubkey membership check before signature verification in Redis storage implementation
block-builder/src/app/storage/memory_storage.rs Added pubkey membership check before signature verification in memory storage implementation

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

kbizikav and others added 4 commits October 24, 2025 13:43
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@kbizikav kbizikav merged commit f3a34a2 into dev Oct 29, 2025
5 checks passed
@kbizikav kbizikav deleted the fix-membership-verification branch October 29, 2025 12:13
signature18632 added a commit that referenced this pull request Oct 31, 2025
* feat: Integrated gnark (#448)

* chore: update intmax2-zkp deps

* feat: delete circuit dependency

* feat: add some data

* docs: update readme & testdata

* chore: update proof

* chore: fix limb error

* Single history status (#453)

* feat: entry status replace

* feat: wip strategy replacement

* feat: impl seperate group

* feat: optional cursor

* feat: impl fetch batch

* feat: impl fetch batch wasm

---------

Co-authored-by: kbizikav <132550763+kbizikav@users.noreply.github.com>

* change os (#458)

* feat: add get used memo func for wasm (#469)

* feat: add get used memo func for wasm

* fix: fix typo for ci

* docs: added comprehensive docs for all nodes (#446)

* chore: update docs

* docs: add block builder docs

* docs: add balance prover readme

* docs: client sdk

* docs: fix client sdk docs

* docs: add validity prover docs

* docs: add block builder data structure

* docs: update block builder

* docs: add withdrawal server docs

* docs: add validity prover worker tasks

* docs: delete legacy store vault server

* docs: add pruning docs

* docs: update validity prover docs

* docs: update

* docs: interface

* docs: add Troubleshooting

* fix: add membership verification during `add_signature` (#465)

* fix: add membership verification during add_signature to prevent future panic

* Update block-builder/src/app/storage/memory_storage.rs

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update block-builder/src/app/storage/memory_storage.rs

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: typo for ci

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* feat: add rate limit & reduce max batch size (#464)

* feat: add rate limit & reduce max batch size

* feat: use wasm time

* feat: longer rate limit

* feat: remove AGENTS.md

* fix: typo

* Retry 502 error (#470)

---------

Co-authored-by: Baby Bear <132609968+smallbabybear@users.noreply.github.com>

---------

Co-authored-by: kbizikav <132550763+kbizikav@users.noreply.github.com>
Co-authored-by: signature18632 <intmax18@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
signature18632 added a commit that referenced this pull request Nov 13, 2025
* feat: Integrated gnark (#448)

* chore: update intmax2-zkp deps

* feat: delete circuit dependency

* feat: add some data

* docs: update readme & testdata

* chore: update proof

* chore: fix limb error

* Single history status (#453)

* feat: entry status replace

* feat: wip strategy replacement

* feat: impl seperate group

* feat: optional cursor

* feat: impl fetch batch

* feat: impl fetch batch wasm

---------

Co-authored-by: kbizikav <132550763+kbizikav@users.noreply.github.com>

* change os (#458)

* feat: add get used memo func for wasm (#469)

* feat: add get used memo func for wasm

* fix: fix typo for ci

* docs: added comprehensive docs for all nodes (#446)

* chore: update docs

* docs: add block builder docs

* docs: add balance prover readme

* docs: client sdk

* docs: fix client sdk docs

* docs: add validity prover docs

* docs: add block builder data structure

* docs: update block builder

* docs: add withdrawal server docs

* docs: add validity prover worker tasks

* docs: delete legacy store vault server

* docs: add pruning docs

* docs: update validity prover docs

* docs: update

* docs: interface

* docs: add Troubleshooting

* fix: add membership verification during `add_signature` (#465)

* fix: add membership verification during add_signature to prevent future panic

* Update block-builder/src/app/storage/memory_storage.rs

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update block-builder/src/app/storage/memory_storage.rs

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: typo for ci

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* feat: add rate limit & reduce max batch size (#464)

* feat: add rate limit & reduce max batch size

* feat: use wasm time

* feat: longer rate limit

* feat: remove AGENTS.md

* fix: typo

* Retry 502 error (#470)

---------

Co-authored-by: Baby Bear <132609968+smallbabybear@users.noreply.github.com>

* fix(client): consume only invalid (#473)

---------

Co-authored-by: kbizikav <132550763+kbizikav@users.noreply.github.com>
Co-authored-by: signature18632 <intmax18@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants