AggLayer: onchain verification of metadata hash during faucet registration
- 主要语言
- Rust
- 星标
- 132
- 派生
- 167
- 平均合并
- 1 天 23 小时
- 30 天内合并 PR
- 110
描述
During faucet registration (`register_faucet` in `bridge_config.masm`), the bridge should verify that the faucet's stored `metadata_hash` matches `keccak256(abi.encode(name, symbol, decimals))` computed from the faucet's actual storage values.
Currently the metadata hash is trusted from the faucet deployer with no on-chain verification. A malicious or misconfigured deployer could set an incorrect hash, causing bridge-out claims to fail on the EVM side.
Prerequisites:
- #2585 (token name in faucet storage)
- Implement `abi.encode(string, string, uint8)` in MASM
The verification would:
1. FPI to the faucet to read name, symbol, decimals
2. ABI-encode them in MASM
3. Keccak256 the encoded bytes
4. FPI to the faucet to read the stored metadata hash
5. Assert they match
There is a TODO in `bridge_config.masm::register_faucet` tracking as of PR #2583
Related: #2453
贡献指南
评估
这个 Issue 还没有评估数据。