Repository navigation
Conversation
Cover passkey paths in validateUserOp that had no tests: - a passkey signature over the wrong hash returns 1 - a passkey can sign a replayable (nonce key 8453) UserOp, and the signature stays valid after a chain ID change - a removed passkey owner's signature reverts with InvalidOwnerBytesLength - the FreshCryptoLib fallback verifier accepts the same signature (Foundry can't etch over the P-256 precompile at 0x100, so it is called directly) Rename the contract in ExecuteBatch.t.sol from TestExecuteWithoutChainIdValidation to TestExecuteBatch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
v1.1.0 validateUserOp decodes executeWithoutChainIdValidation calls to check upgrade targets, so the test's bare selector made decoding revert. Pass an empty bytes[] instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Collaborator
🟡 Heimdall Review Status
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
src/MagicSpend.sol— MagicSpend paymaster contract with 7 security fixes appliedtest/MagicSpend.t.sol— 6 Forge tests covering the fixed behaviourSecurity fixes
Tests
All 6 passing.