0xMiden / 0xMiden/node

bug: block proofs are never cryptographically verified in `apply_proof`

未关闭
#2,383 5 条评论 0 个 reaction 已指派 1 人 已被 @sergerad 认领 在 GitHub 查看
blocked
主要语言
Rust
星标
104
派生
138
平均合并
1 天 13 小时
30 天内合并 PR
56

描述

## Summary

`verify_block_proof` in `crates/store/src/state/apply_proof.rs` only deserializes the proof bytes it never performs cryptographic verification. Any byte sequence that parses as a valid `BlockProof` struct is accepted and written to disk.

## Code

```rust
// crates/store/src/state/apply_proof.rs
fn verify_block_proof(_block_num: BlockNumber, proof_bytes: &[u8]) -> anyhow::Result<()> {
let _proof =
BlockProof::read_from_bytes(proof_bytes).context("failed to deserialize block proof")?;

// TODO: perform verification.
Ok(())
}
```

## Impact

- This function is called from `apply_proof`, which is used by both the sequencer's `ProofScheduler` and the full-node's `ProofSync`
- Unverified proofs are persisted to disk and broadcast to all replica subscribers via `proof_cache`
- An attacker can submit a structurally valid but cryptographically invalid proof and it will be accepted

## Expected behavior

The proof should be cryptographically verified before returning `Ok(())`.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。