Skip to content

Signing Drops Extra and Non-WitnessArgs Witnesses #3514

Description

@phroi

Hello folks at Nervos,

I noticed that Neuron drops every witness at index inputs.length or higher when it signs a transaction, and replaces input-aligned witnesses that are not WitnessArgs.

CKB allows witnesses past the inputs, and the default lock signs them too, so protocols use them for metadata. For example, a bridge deposit can carry its request in an extra witness.

TransactionSender.sign builds one entry per input, then replaces the whole list with tx.witnesses = witnessSigningEntries.map(w => w.witness). signMultisig does the same.

Input-aligned witnesses are not safe either: any witness that is not a WitnessArgs is replaced with an empty one before signing, so a raw witness at an input's index is lost too.

Offline Sign keeps them on import: Transaction.fromObject maps every witness. So a transaction built elsewhere in Neuron's offline-sign JSON arrives with its extra witnesses, and signing then drops them.

Witnesses are not part of the transaction hash, so the signed transaction is still valid. It just goes out without its extra witnesses, for example moving funds into a bridge lock without the request that says where they go.

Is there a reason signing drops them? The imported transaction carries them on purpose, and protocols rely on them.

Keep up the Great Work,
Phroi %58

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions