Skip to content

fix(crypto-transaction): reject non-canonical rlp encodings - #1521

Open
oXtxNt9U wants to merge 4 commits into
developfrom
fix/crypto-transaction/canonical-rlp-decoding
Open

oXtxNt9U wants to merge 4 commits into
developfrom
fix/crypto-transaction/canonical-rlp-decoding

Conversation

@oXtxNt9U

@oXtxNt9U oXtxNt9U commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

The transaction deserializer accepted some encodings that re-serialize to different bytes. Nodes rebuild stored transactions with the serializer when serving blocks, so a validator could commit a block whose served bytes no longer match its payloadSize, and syncing nodes would reject that block forever.

Fixes

  • Reject an 11th RLP field. The field-count guard was off by one.
  • Reject an empty legacy second signature field. It was treated as "no signature".
  • Decode RLP lengths without 32-bit overflow. << wrapped overlong length prefixes to valid lengths.

Tests

  • A unit test for each fix.
  • deserializer.fuzz.test.ts: a seeded fuzz test checking that every accepted encoding re-serializes to identical bytes. It runs 10,000 random cases plus fixed boundary inputs. FUZZ_SEED / FUZZ_RUNS reproduce a failure or run a longer campaign.

Checklist

  • Documentation (if necessary)
  • Tests (if necessary)
  • Ready to be merged

@oXtxNt9U oXtxNt9U changed the title fix(crypto-transaction): reject non-canonical rlp transaction encodings fix(crypto-transaction): reject non-canonical rlp encodings Oct 6, 2026
@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.62%. Comparing base (c39bb16) to head (abf63b3).

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #1521      +/-   ##
===========================================
+ Coverage    80.31%   80.62%   +0.31%     
===========================================
  Files          952      963      +11     
  Lines        17162    17620     +458     
  Branches      2599     2698      +99     
===========================================
+ Hits         13784    14207     +423     
- Misses        3373     3405      +32     
- Partials         5        8       +3     
Flag Coverage Δ
contracts 91.95% <ø> (?)
packages 80.34% <100.00%> (+0.02%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant