0xMiden / 0xMiden/node

bug: block proofs are never cryptographically verified in `apply_proof`

Abierto
#2,383 5 comentarios 0 reacciones 1 asignado Reclamado por @sergerad Ver en GitHub
blocked
Lenguaje dominante
Rust
Estrellas
104
Forks
138
Merge medio
1 d 13 h
PR fusionados (30 d)
56

Descripción

## Summary

`verify_block_proof` in `crates/store/src/state/apply_proof.rs` only deserializes the proof bytes it never performs cryptographic verification. Any byte sequence that parses as a valid `BlockProof` struct is accepted and written to disk.

## Code

```rust
// crates/store/src/state/apply_proof.rs
fn verify_block_proof(_block_num: BlockNumber, proof_bytes: &[u8]) -> anyhow::Result<()> {
let _proof =
BlockProof::read_from_bytes(proof_bytes).context("failed to deserialize block proof")?;

// TODO: perform verification.
Ok(())
}
```

## Impact

- This function is called from `apply_proof`, which is used by both the sequencer's `ProofScheduler` and the full-node's `ProofSync`
- Unverified proofs are persisted to disk and broadcast to all replica subscribers via `proof_cache`
- An attacker can submit a structurally valid but cryptographically invalid proof and it will be accepted

## Expected behavior

The proof should be cryptographically verified before returning `Ok(())`.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.