Skip to content

bug: block proofs are never cryptographically verified in apply_proof #2383

Description

@Sertug17

Summary

verify_block_proof in crates/store/src/state/apply_proof.rs only deserializes the proof bytes it never performs cryptographic verification. Any byte sequence that parses as a valid BlockProof struct is accepted and written to disk.

Code

// crates/store/src/state/apply_proof.rs
fn verify_block_proof(_block_num: BlockNumber, proof_bytes: &[u8]) -> anyhow::Result<()> {
    let _proof =
        BlockProof::read_from_bytes(proof_bytes).context("failed to deserialize block proof")?;

    // TODO: perform verification.
    Ok(())
}

Impact

  • This function is called from apply_proof, which is used by both the sequencer's ProofScheduler and the full-node's ProofSync
  • Unverified proofs are persisted to disk and broadcast to all replica subscribers via proof_cache
  • An attacker can submit a structurally valid but cryptographically invalid proof and it will be accepted

Expected behavior

The proof should be cryptographically verified before returning Ok(()).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    Status
    In progress

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions