Commit ae104fa
authored
fix(validator): reject a manifest that reuses one key for both signing roles (#1185)
* fix(validator): reject a manifest that reuses one key for both signing roles
ValidatorEntry documents that the attestation and proposal keys must be
separate so a validator can sign both a proposal and an attestation in the
same slot without one-time-signature state reuse. Nothing enforced it: the
registry loader assigned keys without comparing them, so a manifest carrying
the same key in both fields loaded silently. Both signatures then advanced
their own copy of the shared key from the pre-advance state, consuming
overlapping XMSS one-time state — a key-compromise-class failure that stayed
invisible because both loads and both signatures verify individually.
Reject the misconfiguration at load time by comparing the manifest's two
public keys, which leaves the secret bytes untouched. This turns the
docstring invariant into a client-checkable rule and discharges the formal
model's distinctness assumption at construction.
Closes #1184
* test(bootstrap): give the fixture manifest distinct signing keys
The one-validator fixture manifest reused one placeholder public key for both
roles. The registry loader now rejects that, so make the two keys differ, as
a real manifest does.1 parent 57d4339 commit ae104fa
3 files changed
Lines changed: 48 additions & 5 deletions
File tree
- src/lean_spec/node/validator
- tests
- cli
- node/validator
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
214 | 214 | | |
215 | 215 | | |
216 | 216 | | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
217 | 228 | | |
218 | 229 | | |
219 | 230 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
| 121 | + | |
121 | 122 | | |
122 | 123 | | |
123 | 124 | | |
| |||
130 | 131 | | |
131 | 132 | | |
132 | 133 | | |
133 | | - | |
| 134 | + | |
134 | 135 | | |
135 | 136 | | |
136 | 137 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
64 | 67 | | |
65 | 68 | | |
66 | 69 | | |
67 | | - | |
| 70 | + | |
68 | 71 | | |
69 | 72 | | |
70 | 73 | | |
| |||
168 | 171 | | |
169 | 172 | | |
170 | 173 | | |
171 | | - | |
| 174 | + | |
172 | 175 | | |
173 | 176 | | |
174 | 177 | | |
175 | 178 | | |
176 | 179 | | |
177 | 180 | | |
178 | | - | |
| 181 | + | |
179 | 182 | | |
180 | 183 | | |
181 | 184 | | |
| |||
506 | 509 | | |
507 | 510 | | |
508 | 511 | | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
509 | 540 | | |
510 | 541 | | |
511 | 542 | | |
| |||
0 commit comments