• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

tari-project / tari / 25668659908

11 May 2026 11:57AM UTC coverage: 61.174% (+1.0%) from 60.199%
25668659908

push

github

web-flow
fix(security): add payload integrity signature to harden offline signing (fixes #7796) (#7804)

## Summary

Fixes the MITM vulnerability disclosed in issue #7796 - the offline
signer accepted any prepared JSON payload without verifying it came from
the legitimate view wallet.

An attacker who intercepts the payload file (e.g. on the USB drive
passed between online and offline wallets) could swap the recipient
address, inflate amounts, or substitute inputs to redirect funds, and
the signer had no way to detect the tampering.

## Root cause

`sign_locked_transaction` (and the multisig variants) called the builder
directly on the deserialized request with no integrity check. The
`prepare_*` functions on the view-wallet side produced no authenticating
material for the signer to verify.

## Fix

The view wallet now signs the canonical payload bytes with a
domain-separated Schnorr signature over the view private key. The
offline signer performs two checks before using any spend-key material:

1. **Key identity** - the `view_public_key` embedded in the payload must
match the signer's own view public key (ensures payload was prepared by
this wallet instance, not a foreign one).
2. **Signature validity** - the Schnorr signature must verify over the
canonical payload bytes (all JSON fields except `payload_signature`
itself, which is stripped before hashing). Any modification to any field
— recipient address, amount, inputs, fee, tx_id, etc. — changes the
canonical bytes and causes the signature check to fail.

## Changes

- **`hashing/src/domains.rs`** - new `OfflineSigningPayloadHashDomain`
(`com.tari.base_layer.wallet.offline_signing.payload_integrity`, v1)
- **`offline_signing/models.rs`** - bump `SUPPORTED_VERSION` 4→5; add
`PayloadIntegritySignature` struct; `canonical_payload_bytes()` helper;
`payload_signature` field on all three `Prepare*` result types
- **`offline_signing/offline_signer.rs`** - `payload_challenge()`,
`sign_payload()`, `verify_payload_s... (continued)

230 of 243 new or added lines in 8 files covered. (94.65%)

47 existing lines in 9 files now uncovered.

71315 of 116578 relevant lines covered (61.17%)

222956.02 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

75.34
/base_layer/node_components/src/blocks/chain_block.rs
1
//  Copyright 2025, The Tari Project
2
//
3
//  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
4
//  following conditions are met:
5
//
6
//  1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following
7
//  disclaimer.
8
//
9
//  2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
10
//  following disclaimer in the documentation and/or other materials provided with the distribution.
11
//
12
//  3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote
13
//  products derived from this software without specific prior written permission.
14
//
15
//  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
16
//  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
17
//  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
18
//  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
19
//  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
20
//  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
21
//  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
22

23
use std::{fmt, fmt::Display, sync::Arc};
24

25
use tari_common_types::types::HashOutput;
26
use tari_transaction_components::aggregated_body::AggregateBody;
27

28
use crate::blocks::{Block, BlockHeader, BlockHeaderAccumulatedData};
29

30
/// A block linked to a chain.
31
/// A ChainBlock MUST have the same or stronger guarantees than `ChainHeader`
32
#[derive(Debug, Clone, PartialEq)]
33
pub struct ChainBlock {
34
    accumulated_data: BlockHeaderAccumulatedData,
35
    block: Arc<Block>,
36
}
37

38
impl Display for ChainBlock {
39
    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
×
40
        writeln!(f, "{}", self.accumulated_data)?;
×
41
        writeln!(f, "{}", self.block)?;
×
42
        Ok(())
×
43
    }
×
44
}
45

46
impl ChainBlock {
47
    /// Attempts to construct a `ChainBlock` from a `Block` and associate `BlockHeaderAccumulatedData`. Returns None if
48
    /// the Block and the BlockHeaderAccumulatedData do not correspond (i.e have different hashes)
49
    pub fn try_construct(block: Arc<Block>, accumulated_data: BlockHeaderAccumulatedData) -> Option<Self> {
1,973✔
50
        if accumulated_data.hash != block.hash() {
1,973✔
51
            return None;
×
52
        }
1,973✔
53

54
        Some(Self {
1,973✔
55
            accumulated_data,
1,973✔
56
            block,
1,973✔
57
        })
1,973✔
58
    }
1,973✔
59

60
    pub fn height(&self) -> u64 {
1,002✔
61
        self.block.header.height
1,002✔
62
    }
1,002✔
63

64
    pub fn hash(&self) -> &HashOutput {
1,583✔
65
        &self.accumulated_data.hash
1,583✔
66
    }
1,583✔
67

68
    /// Returns a reference to the inner block
69
    pub fn block(&self) -> &Block {
2,042✔
70
        &self.block
2,042✔
71
    }
2,042✔
72

73
    /// Returns a reference to the inner block's header
74
    pub fn header(&self) -> &BlockHeader {
4,800✔
75
        &self.block.header
4,800✔
76
    }
4,800✔
77

78
    /// Returns the inner block wrapped in an atomically reference counted (ARC) pointer. This call is cheap and does
79
    /// not copy the block in memory.
80
    pub fn to_arc_block(&self) -> Arc<Block> {
637✔
81
        self.block.clone()
637✔
82
    }
637✔
83

84
    pub fn accumulated_data(&self) -> &BlockHeaderAccumulatedData {
2,762✔
85
        &self.accumulated_data
2,762✔
86
    }
2,762✔
87

88
    pub fn to_chain_header(&self) -> ChainHeader {
1,266✔
89
        // NOTE: Panic is impossible, a ChainBlock cannot be constructed if inconsistencies between the header and
90
        // accum data exist
91
        ChainHeader::try_construct(self.block.header.clone(), self.accumulated_data.clone()).unwrap()
1,266✔
92
    }
1,266✔
93
}
94

95
/// A block linked to a chain.
96
/// A ChainHeader guarantees (i.e cannot be constructed) that the block and accumulated data correspond by hash.
97
#[derive(Debug, Clone, PartialEq)]
98
pub struct ChainHeader {
99
    header: BlockHeader,
100
    accumulated_data: BlockHeaderAccumulatedData,
101
}
102

103
impl Display for ChainHeader {
104
    fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
×
105
        writeln!(f, "{}", self.header)?;
×
106
        writeln!(f, "{}", self.accumulated_data)?;
×
107
        Ok(())
×
108
    }
×
109
}
110

111
impl ChainHeader {
112
    /// Attempts to construct a `ChainHeader` from a `BlockHeader` and associate `BlockHeaderAccumulatedData`. Returns
113
    /// None if the Block and the BlockHeaderAccumulatedData do not correspond (i.e have different hashes)
114
    pub fn try_construct(header: BlockHeader, accumulated_data: BlockHeaderAccumulatedData) -> Option<Self> {
10,318✔
115
        if accumulated_data.hash != header.hash() {
10,318✔
UNCOV
116
            return None;
×
117
        }
10,318✔
118

119
        Some(Self {
10,318✔
120
            header,
10,318✔
121
            accumulated_data,
10,318✔
122
        })
10,318✔
123
    }
10,318✔
124

125
    pub fn height(&self) -> u64 {
4,666✔
126
        self.header.height
4,666✔
127
    }
4,666✔
128

129
    pub fn timestamp(&self) -> u64 {
2,234✔
130
        self.header.timestamp.as_u64()
2,234✔
131
    }
2,234✔
132

133
    pub fn hash(&self) -> &HashOutput {
2,891✔
134
        &self.accumulated_data.hash
2,891✔
135
    }
2,891✔
136

137
    pub fn header(&self) -> &BlockHeader {
11,224✔
138
        &self.header
11,224✔
139
    }
11,224✔
140

141
    pub fn accumulated_data(&self) -> &BlockHeaderAccumulatedData {
4,282✔
142
        &self.accumulated_data
4,282✔
143
    }
4,282✔
144

145
    pub fn into_parts(self) -> (BlockHeader, BlockHeaderAccumulatedData) {
300✔
146
        (self.header, self.accumulated_data)
300✔
147
    }
300✔
148

149
    pub fn into_header(self) -> BlockHeader {
×
150
        self.header
×
151
    }
×
152

153
    pub fn upgrade_to_chain_block(self, body: AggregateBody) -> ChainBlock {
×
154
        // NOTE: Panic cannot occur because a ChainBlock has the same guarantees as ChainHeader
155
        ChainBlock::try_construct(Arc::new(Block::new(self.header, body)), self.accumulated_data).unwrap()
×
156
    }
×
157
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc