Skip to content

fix: enforce unique receiver identities in signature verification#457

Merged
zsculac merged 3 commits into
mainfrom
fix/duplicate-receiver-identities
Mar 11, 2026
Merged

fix: enforce unique receiver identities in signature verification#457
zsculac merged 3 commits into
mainfrom
fix/duplicate-receiver-identities

Conversation

@zsculac

@zsculac zsculac commented Mar 10, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds a unique identity count check in _verifySignatures() for KnowledgeCollection
  • Prevents a single node from faking multi-party attestation by submitting duplicate identity IDs that pass individual signature verification
  • Reverts with "Insufficient unique receiver identities" only when the number of unique identities falls below minimumRequiredSignatures — duplicates are tolerated if enough unique identities remain

Test plan

  • New test: all-duplicate receiver identities revert
  • All 6 KnowledgeCollection unit tests pass

🤖 Generated with Claude Code


Note

High Risk
Touches signature-threshold enforcement in a Solidity contract; mistakes here can allow forged multi-party attestation or inadvertently reject valid submissions.

Overview
Prevents meeting minimumRequiredSignatures via duplicated receiver identityIds by counting unique identities in KnowledgeCollection._verifySignatures and reverting when the unique count is below the threshold.

Adds unit coverage for the new behavior: all-duplicate receiver lists now revert with "Insufficient unique receiver identities", while mixed lists with enough unique identities still succeed.

Written by Cursor Bugbot for commit bd0f4d2. This will update automatically on new commits. Configure here.

Prevent a single node from faking multi-party attestation by submitting
duplicate identity IDs. The new check counts unique identities and
reverts if the count falls below minimumRequiredSignatures.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Comment thread contracts/KnowledgeCollection.sol Outdated
Address CI review: early-exit once uniqueCount reaches
minimumRequiredSignatures to cap gas on large receiver sets, and add
positive tests proving duplicates are accepted when enough unique
identities remain.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Comment thread contracts/KnowledgeCollection.sol
…arrays from config

Single external call to parametersStorage.minimumRequiredSignatures()
reused across length check, uniqueness check, and short-circuit.
Tests now derive receiver array sizes from ParametersStorage so they
stay correct if the config value changes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@zsculac
zsculac merged commit 4593134 into main Mar 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant