Skip to content

Bump verifiable crate to rev 19b03de - #19

Merged
peetzweg merged 1 commit into
mainfrom
upgrade-verifiable-19b03de
Jun 23, 2026
Merged

peetzweg merged 1 commit into
mainfrom
upgrade-verifiable-19b03de

Conversation

@peetzweg

Copy link
Copy Markdown
Member

Summary

Upgrades the verifiable crate dependency from rev f65b39d to rev 19b03de (upstream mainline, merge of paritytech/verifiable#59).

No JS API surface change. Proofs, signatures, ring roots, and member encodings remain wire-compatible with the previous rev — all existing cross-validation tests (JS vs Rust proof equality, commitment round-trips) pass unchanged.

What this pulls in from upstream

The previous pin matched the no-point-validation state; this moves onto mainline and picks up the hardening work from paritytech/verifiable#56–#59:

  • Curve-point validation on decode re-enabled — Member, MembersCommitment (ring root), MembersSet, and StaticChunk bytes are validated (on-curve + correct subgroup) when decoded, so malformed input fails cleanly at decode instead of risking panics in downstream crypto.
  • Identity point rejected as a member (Reject identity point in member validation and construction verifiable#57) — previously the neutral element passed is_member_valid but made commitment construction panic (a wasm trap). Both paths now reject it with a proper error. A regression test covering is_member_valid and members_root is added in this PR.
  • Canonical KZG verifier-key pinning (Pin canonical KZG verifier key in member validation verifiable#58) — validate / validate_with_commitment / is_valid / batch_validate reject a ring root whose embedded trusted-setup key is not the canonical Bandersnatch one, closing a membership-forgery vector for attacker-supplied commitments.
  • Static verifier/prover caches (Refactory verifiable#59) — ring-context parameters are no longer recomputed on every call, speeding up repeated verification within a session.
  • secret-split bundled into std — side-channel resistant secret scalar multiplication now applies to the wasm prover paths (one_shot, sign). Uses the OS RNG via getrandom, which works under wasm through the already-enabled getrandom/js feature.
  • Transitive ark-vrf bump 0.5.0 → 0.5.1.

Changes

  • packages/verifiablejs/Cargo.toml / Cargo.lock: rev bump (+ ark-vrf 0.5.1)
  • packages/verifiablejs/src/lib.rs: new test_identity_point_member_rejected regression test
  • .changeset/upgrade-verifiable-19b03de.md: changeset (minor) for the next release

Testing

  • cargo check --target wasm32-unknown-unknown clean
  • pnpm build (both bundler and nodejs wasm-pack targets) clean
  • pnpm test: all 26 wasm tests pass (25 existing + 1 new regression test)

Moves off the no-point-validation state onto upstream mainline. No JS API
surface change; wire formats are unchanged.

Behavioral changes pulled in from upstream:
- curve-point validation on decode re-enabled for Member, MembersSet,
  MembersCommitment and StaticChunk
- identity point rejected in is_member_valid and commitment construction
  (previously a wasm trap); regression test added
- canonical KZG verifier-key pinning in validate/batch_validate
- static verifier/prover caches for the Bandersnatch suite
- secret-split (side-channel hardened scalar multiplication) bundled in std

Also bumps transitive ark-vrf 0.5.0 -> 0.5.1.
@peetzweg
peetzweg merged commit 3e977eb into main Jun 23, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant