Skip to content

fix(pyth): keep vaa verification within wasm local limit - #2084

Merged
troian merged 1 commit into
akash-network:mainfrom
chalabi2:fix/pyth-vaa-wasm-locals
Oct 6, 2026
Merged

troian merged 1 commit into
akash-network:mainfrom
chalabi2:fix/pyth-vaa-wasm-locals

Conversation

@chalabi2

@chalabi2 chalabi2 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Reduces optimized function locals from 137 to 83. Validated with wasmvm v3.0.8 and 29 passing tests.

Signed-off-by: Joseph Chalabi <chalabi.joseph@gmail.com>
@chalabi2
chalabi2 requested a review from a team as a code owner October 5, 2026 20:27
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: akash-network/node/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 082752a7-a6ad-4942-8e24-50ecdb4a3b7f
📥 Commits

Reviewing files that changed from the base of the PR and between 9962f09 and 6ca21db.

📒 Files selected for processing (1)
  • contracts/pyth_vaa/src/router.rs

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


Walkthrough

Signature verification now bounds-checks and processes the declared signature region in fixed-size chunks. A helper performs per-signature validation. Tests check malformed signature bytes and invalid recovery IDs at each of three signer positions.

Changes

Router signature verification

Layer / File(s) Summary
Chunked signature checks
contracts/pyth_vaa/src/router.rs
The verification loop processes the declared signature region in fixed-size chunks and returns InvalidVAA when the region is incomplete. A helper validates router indices, decodes signatures, recovers keys, and checks addresses. Tests cover malformed signature bytes and recovery IDs at three signer positions.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix

Suggested reviewers: boz

Merge Risk: ⚪ Minimal · up to 6ca21

No merge-blocking issue is identified in the router signature-verification change; it is ready for normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 6ca21

The change affects 1 system.

Changed systems: contracts

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — contracts (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in contracts/pyth_vaa/src/router.rs: Signature verification now bounds-checks and chunks the declared signature region, verifies its first signature and then each remaining signature, and retains ascending router-index checks. This replaces the indexed loop’s per-iteration length check and offset tracking; an incomplete declared signature region returns InvalidVAA.
  • observed — Modified behavior in contracts/pyth_vaa/src/router.rs: Adds a non-inlined verify_router_signature helper to validate each router index, decode the signature and recovery ID, recover the key from the VAA hash, and compare its address with the configured router. These checks were previously performed inline in the loop.
  • observed — Modified behavior in contracts/pyth_vaa/src/router.rs: Adds a test that independently zeroes signature data and sets an invalid recovery ID to 4 at each of three signature positions, asserting that both cases return CannotDecodeSignature.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the change: keeping Pyth VAA verification within the WASM local limit.
Description check ✅ Passed The description relates to the changeset and reports the reduction in function locals and validation results.
Docstring Coverage ✅ Passed Docstring coverage is 80.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks each signature with care
Chunks pass in order through the code
Three signers meet malformed bytes
Recovery IDs face their tests
The rabbit hops along the route
And leaves the checks in tidy rows

Comment @coderabbitai help to get the list of available commands.

@troian
troian merged commit 5193e54 into akash-network:main Oct 6, 2026
24 of 32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants