Skip to content

feat: bind validator PoP to chainId and registrantAddress - #88

Merged
ItsANameToo merged 1 commit into
feat/mainsailfrom
feat/bls-pop-registrant
Oct 9, 2026
Merged

ItsANameToo merged 1 commit into
feat/mainsailfrom
feat/bls-pop-registrant

Conversation

@shahin-hq

@shahin-hq shahin-hq commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Closes: https://app.clickup.com/t/2570579/86e3gp5cw

Binds the validator BLS proof of possession (PoP) to the chainId and the registrant address, as Mainsail now requires. Without this, a PoP could be replayed by another sender or on another chain.

  • BuildValidatorRegistration, BuildValidatorUpdate, EncodeValidatorRegistrationData, EncodeValidatorUpdateData, FromMnemonic and BuildProofOfPossession take a new registrantAddress parameter.
  • The PoP now signs abi.encodePacked(uint256 chainId, address registrant, bytes pk) under the MAINSAIL_BLS_POP_BLS12381G2_XMD:SHA-256_SSWU_RO_POP_ domain tag. chainId comes from the configured network.
  • The registrant address is validated, including the EIP-55 checksum. An invalid address returns ErrInvalidProofOfPossession.
  • Adds tests for Mainsail's reference vector (chainId 10_000), the chainId and address binding, and invalid addresses. The validator transaction fixtures and the multi-language BLS fixture are regenerated.

Checklist

  • Documentation (if necessary)
  • Tests (if necessary)
  • Ready to be merged

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ItsANameToo
ItsANameToo merged commit e98979e into feat/mainsail Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants