Skip to content

fix(ceremony): hold X and GitHub ids to the REQ-PLAT-06 grammar - #85

Open
xgreenx wants to merge 2 commits into
mainfrom
fix/canonical-platform-ids
Open

xgreenx wants to merge 2 commits into
mainfrom
fix/canonical-platform-ids

Conversation

@xgreenx

@xgreenx xgreenx commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The X and GitHub Platform Verifiers recorded ids that REQ-PLAT-06 and the browser refuse: X took any string between the quotes, GitHub took 0 and ids past 2^64 - 1.

Changes

  • Grammar: CeremonyFields.isCanonicalNonzeroUint64 (CeremonyFields.sol:577) holds an id to ^[1-9][0-9]{0,19}$, at most 2^64 - 1.
  • Verifier: TlsNotaryVerifierBase reverts NoncanonicalUserId(bytes) on any other id (TlsNotaryVerifierBase.sol:447), for both profiles; REQ-PLAT-08's rejections stay.
  • Tests: test_zeroIsCanonical becomes test_readsZeroWhichIsNoUserId; unit and verifier tests cover 0, leading zero, 21 digits, 2^64 - 1 accepted, 2^64 rejected, non-digit X ids.
  • Reference copy: TranscriptReference.sol carries the rule as a digit scan; a differential fuzz (TranscriptEquivalence.t.sol:971) compares the two.
  • Gas snapshot: +1,421 per GitHub claim, +2,772 per X claim.
  • Docs: _identityFields states the id rule a new profile must meet.

Verified

  • forge fmt --check, forge build, forge lint -D notes: clean.
  • forge test: 39 suites, 662 tests pass.
  • Gas snapshot regenerated from empty matches the committed one.
  • Generated-table and storage-layout checks pass.
  • Rust: vendored artifacts from this tree, cargo test --all: 38 tests pass.
  • Review mutations (check removed; bound widened to < 10^20) fail the unit, verifier and differential tests.

Not verified / known issues

  • Changes X and GitHub verifier bytecode: it takes effect only after a contracts release and a verifier upgrade, which the owner schedules.
  • Every TLSNotary profile inherits the check; a future profile with non-numeric ids needs it behind a profile hook.

🤖 Generated with Claude Code

REQ-PLAT-06 requires an X or GitHub id to match ^[1-9][0-9]{0,19}$
with a value at most 2^64 - 1. The X reader returned any string between
the quotes and the GitHub reader accepted 0 and ids past uint64, so the
registry could record an id the browser and the spec refuse. Both now
revert with NoncanonicalUserId. The reference copy takes the rule too,
so the differential tests still hold. Costs 1.4k gas per GitHub claim
and 2.8k per X claim.

Assisted-by: Claude Opus 5.5
Signed-off-by: xgreenx <xgreenx9999@gmail.com>
The base holds every profile's id to REQ-PLAT-06, so a new profile
learns the rule from the _identityFields doc rather than a revert.
The GitHub test that rejects 0 takes the X test's name: 0 is inside
uint64 but outside the grammar. The reference copy's doc names its
one change the way the file's other library does.

Assisted-by: Claude Opus 5.5
Signed-off-by: xgreenx <xgreenx9999@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant