stacks-network / stacks-network/stacks-core

Signature ordering validation bug

Open
#6,907 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
3.1k
Forks
762
Avg merge
4d 6h
Merged PRs (30d)
76

Description

Describe the bug
The signature ordering check has a logic error where last_index is only set on the first iteration and never updated thereafter. This allows signatures to be provided in non-ascending order as long as all signer indices are greater than the first signer's index. This is a leftover. Currently not affecting the functionality.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the signature ordering check in stackslib/src/chainstate/nakamoto/mod.rs, lines 900-909. Trace how signer indices are compared and verify that non-ascending signatures are rejected while valid ascending signatures remain accepted.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
blockchain
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
50/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.