0xMiden / 0xMiden/protocol

AggLayer: onchain verification of metadata hash during faucet registration

Aperta
#2,586 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
agglayer
Lingua principale
Rust
Stelle
132
Fork
167
Merge medio
1g 23h
PR unite (30g)
110

Descrizione

During faucet registration (`register_faucet` in `bridge_config.masm`), the bridge should verify that the faucet's stored `metadata_hash` matches `keccak256(abi.encode(name, symbol, decimals))` computed from the faucet's actual storage values.

Currently the metadata hash is trusted from the faucet deployer with no on-chain verification. A malicious or misconfigured deployer could set an incorrect hash, causing bridge-out claims to fail on the EVM side.

Prerequisites:
- #2585 (token name in faucet storage)
- Implement `abi.encode(string, string, uint8)` in MASM

The verification would:
1. FPI to the faucet to read name, symbol, decimals
2. ABI-encode them in MASM
3. Keccak256 the encoded bytes
4. FPI to the faucet to read the stored metadata hash
5. Assert they match

There is a TODO in `bridge_config.masm::register_faucet` tracking as of PR #2583

Related: #2453

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.