eth: preserve signed integer encodings - #189
Open
benma-agent wants to merge 1 commit into
Open
benma-agent wants to merge 1 commit into
benma-agent wants to merge 1 commit into
Conversation
benma-agent
added a commit
to benma-agent/bitbox-api-ts
that referenced
this pull request
Oct 2, 2026
EIP-712 intN values are sent as signed big-endian two's-complement bytes. The JavaScript-number path strips the leading zero supplied by the signed serializer, so e.g. int16(128) becomes -128 on the device. String and bigint inputs already preserve the sign correctly. Use bigIntToSignedBytesBE directly for all accepted input types, without stripping its sign byte. Add positive, negative and zero boundary cases that check identical encodings for number, string and bigint inputs. Unsigned integer encoding and the firmware protocol are unchanged. No firmware version gate is needed. Related PRs: - Go: BitBoxSwiss/bitbox02-api-go#189 - Rust: BitBoxSwiss/bitbox-api-rs#135
benma-agent
added a commit
to benma-agent/bitbox-api-rs
that referenced
this pull request
Oct 2, 2026
EIP-712 intN values are sent as signed big-endian two's-complement bytes. The JSON-number path strips the leading zero supplied by the signed BigInt serializer, so e.g. int16(128) becomes -128 on the device. The string path already preserves the sign correctly. Use to_signed_bytes_be directly for JSON numbers as well, without stripping its sign byte. Add boundary cases for positive values, negative values and zero, checking that numeric and string inputs produce the same encoding. Unsigned integer encoding and the firmware protocol are unchanged. No firmware version gate is needed. Related PRs: - Go: BitBoxSwiss/bitbox02-api-go#189 - TypeScript: BitBoxSwiss/bitbox-api-ts#14
benma-agent
force-pushed
the
benma-agent/eip712-signed-integers
branch
from
October 2, 2026 10:39
4607105 to
6972319
Compare
This was referenced Oct 2, 2026
EIP-712 intN values are sent as signed big-endian two's-complement bytes. Using big.Int.Bytes for a positive value loses its sign when the most significant bit is set, so e.g. int16(128) is interpreted as -128. Keep the existing two's-complement conversion. Prepend 0x00 to nonnegative values when a sign byte is needed, and represent zero with one byte. Trim redundant 0xff sign extension for negative values such as -128. Unsigned integer encoding is unchanged. Add sign-boundary and width tests, plus a simulator regression that verifies the signature against an independently computed EIP-712 digest. The encoding uses the existing firmware protocol and needs no firmware version gate. Related PRs: - Rust: BitBoxSwiss/bitbox-api-rs#135 - TypeScript: BitBoxSwiss/bitbox-api-ts#14
benma-agent
force-pushed
the
benma-agent/eip712-signed-integers
branch
from
October 2, 2026 10:49
6972319 to
81d1804
Compare
benma
marked this pull request as ready for review
October 2, 2026 10:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
EIP-712 intN values are sent as signed big-endian two's-complement bytes.
Using big.Int.Bytes for a positive value loses its sign when the most
significant bit is set, so e.g. int16(128) is interpreted as -128.
Keep the existing two's-complement conversion. Prepend 0x00 to nonnegative
values when a sign byte is needed, and represent zero with one byte. Trim
redundant 0xff sign extension for negative values such as -128. Unsigned
integer encoding is unchanged.
Add sign-boundary and width tests, plus a simulator regression that verifies
the signature against an independently computed EIP-712 digest. The encoding
uses the existing firmware protocol and needs no firmware version gate.
Related PRs: