mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 00:16:59 +00:00
Audit of the compressed-proof work found one real defect and one coverage gap. Defect: a hostile BOLT12 proof/offer can carry a 9+ byte `invoice_amount` (or any tu64 field) that parses as a valid TLV. `TlvStream.tu64` then called the strict `Bolt12Values.tu64`, which throws `require(size <= 8)`. On the `amy bolt12 verify` path (`Bolt12ZapActions.validate`, no surrounding catch) that surfaced as an uncaught exception and abnormal exit instead of a clean `Invalid`; the Android ingest path was already contained by LocalCache's broad catch. Make the nullable stream accessor `TlvStream.tu64` return null for an over-8-byte value so every amount read (invoice_amount, invreq_amount, offer amount) degrades to a clean rejection. Regression-tested at the codec level. Coverage: the writer's `proof_note` (1005) branch and the `with_note` vector's note were never exercised. Add a `Bolt12PayerProof.proofNote()` reader and thread the vector's note through the writer round-trip so 1005 is asserted. The forged-proof, DoS, and reconstruction-accounting paths were reviewed and found sound (the reconstructed root is only ever a BIP-340 message; the NIP offer-binding gate still pins invoice_node_id to the offer's issuer). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SpgpWLKzgD7vS9Fs4CXTR3