From 277a0c69e46cfb53312648fbd8c798d483608a06 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Wed, 26 Aug 2026 23:42:27 -0700 Subject: [PATCH] Skip bulk block verification entirely if public key is invalid. --- src/assembly/index.ts | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/src/assembly/index.ts b/src/assembly/index.ts index 10af850..4d4e4f5 100644 --- a/src/assembly/index.ts +++ b/src/assembly/index.ts @@ -191,21 +191,25 @@ export function verify_blocks (count: i32): void { // Clear local buffers verify_blocks_pub.fill(0) - // Copy input buffer to local parameters, then clear input buffer + // Copy public key input buffer to local parameter, then clear input buffer memory.copy(changetype(verify_blocks_pub), changetype(PUB_BUFFER), KEY_BYTELENGTH) PUB_BUFFER.fill(0) - // Verify public key, then clear local input - const validPubkey = crypto_verify_pubkey(verify_blocks_pub) - - // Iterate over block hash/signature pairs - for (let i = 0; i < count; i++) { - // Copy message buffer to local block hash/signature buffers - memory.copy(changetype(verify_blocks_msg), changetype(MESSAGE_BUFFER) + (96 * i), BLOCKHASH_BYTELENGTH) - memory.copy(changetype(verify_blocks_sig), changetype(MESSAGE_BUFFER) + BLOCKHASH_BYTELENGTH + (96 * i), SIGNATURE_BYTELENGTH) - - // Verify hash and signature, then copy local result to output buffer - verify_blocks_out[i] = u8(validPubkey | crypto_verify_relaxed(verify_blocks_sig, verify_blocks_msg, BLOCKHASH_BYTELENGTH, verify_blocks_pub)) + // Set all output to false so errors fail closed + OUTPUT_BUFFER.fill(255) + + // Verify public key before proceeding with signature verification + if (crypto_verify_pubkey(verify_blocks_pub) { + + // Iterate over block hash/signature pairs + for (let i = 0; i < count; i++) { + // Copy message buffer to local block hash/signature buffers + memory.copy(changetype(verify_blocks_msg), changetype(MESSAGE_BUFFER) + (96 * i), BLOCKHASH_BYTELENGTH) + memory.copy(changetype(verify_blocks_sig), changetype(MESSAGE_BUFFER) + BLOCKHASH_BYTELENGTH + (96 * i), SIGNATURE_BYTELENGTH) + + // Verify hash and signature + verify_blocks_out[i] = u8(crypto_verify_relaxed(verify_blocks_sig, verify_blocks_msg, BLOCKHASH_BYTELENGTH, verify_blocks_pub)) + } } // Clear local input -- 2.52.0