Skip to content

refactor: update PoP to include registrantAddress and chainId - #210

Merged
ItsANameToo merged 1 commit into
feat/mainsailfrom
feat/pop-registrant-chain-binding
Oct 9, 2026
Merged

ItsANameToo merged 1 commit into
feat/mainsailfrom
feat/pop-registrant-chain-binding

Conversation

@shahin-hq

@shahin-hq shahin-hq commented Oct 6, 2026 •

Copy link
Copy Markdown

Closes: https://app.clickup.com/t/2570579/86e3kj5jt

Summary

Validator proofs of possession are now tied to the account that registers the validator and to the network it's registered on. Before this, a proof could be copied and reused by another account or on another chain.

Changes

  • validatorPassphrase(passphrase) is renamed to validatorProof(passphrase, registrantAddress) on the validator registration and update builders.
  • TransactionEncoder.validatorRegistration and validatorUpdate also take the registrant address.
  • The network comes from the SDK's configured network, so callers don't pass it.
  • An invalid or mistyped address (including a wrong checksum) throws an error instead of silently producing a proof for the wrong account.

Summary

Checklist

  • Documentation (if necessary)
  • Tests (if necessary)
  • Ready to be merged

Bind the validator BLS proof of possession to the registering account and
the configured network so it can't be replayed by another sender or on
another chain.

- DST is now MAINSAIL_BLS_POP_BLS12381G2_XMD:SHA-256_SSWU_RO_POP_
- message = abi.encodePacked(uint256 chainId, address registrantAddress, bytes pk)
- chainId is read from Network.get()
- registrantAddress must pass EIP-55 checksum validation, otherwise
  InvalidProofOfPossessionException is thrown
- validatorPassphrase(passphrase) is renamed to
  validatorProof(passphrase, registrantAddress) on the registration and
  update builders; TransactionEncoder.validatorRegistration/validatorUpdate
  take registrantAddress too
- tests cover Mainsail's reference vector (chainId 10_000), binding,
  address validation, and the regenerated bls-keys.json dataset; builder
  fixtures are regenerated

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@shahin-hq
shahin-hq marked this pull request as ready for review October 6, 2026 10:59
@shahin-hq
shahin-hq requested a review from ItsANameToo as a code owner October 6, 2026 10:59
@ItsANameToo
ItsANameToo merged commit b6fbb9f into feat/mainsail Oct 9, 2026
2 checks passed
@ItsANameToo
ItsANameToo deleted the feat/pop-registrant-chain-binding branch October 9, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants