Skip to content

feat: falcon integration - #7

Open
ruseinov wants to merge 10 commits into
v0.2from
ru/feat/falcon-integ
Open

ruseinov wants to merge 10 commits into
v0.2from
ru/feat/falcon-integ

Conversation

@ruseinov

Copy link
Copy Markdown
Collaborator

✄ -----------------------------------------------------------------------------

Thank you for your Pull Request! 🙏 Please make sure it follows the contribution guidelines outlined in this
document
and fill out the
sections below. Once you're ready to submit your PR for review, please delete this section and leave only the text under
the "Description" heading.

Description

A concise description of what your PR is doing, and what potential issue it is solving. Use Github semantic
linking

to link the PR to an issue that must be closed once this is merged.

Integration

In depth notes about how this PR should be integrated by downstream projects. This part is
mandatory, and should be reviewed by reviewers, if the PR does NOT have the
R0-no-crate-publish-required label. In case of a R0-no-crate-publish-required, it can be
ignored.

Review Notes

In depth notes about the implementation details of your PR. This should be the main guide for reviewers to
understand your approach and effectively review it. If too long, use
<details>
.

Imagine that someone who is depending on the old code wants to integrate your new code and the only information that
they get is this section. It helps to include example usage and default value here, with a diff code-block to show
possibly integration.

Include your leftover TODOs, if any, here.

Checklist

  • My PR includes a detailed description as outlined in the "Description" and its two subsections above.
  • My PR follows the labeling requirements of this project (at minimum one label for T required)
    • External contributors: Use /cmd label <label-name> to add labels
    • Maintainers can also add labels manually
  • I have made corresponding changes to the documentation (if applicable)
  • I have added tests that prove my fix is effective or that my feature works (if applicable)

Bot Commands

You can use the following bot commands in comments to help manage your PR:

Labeling (Self-service for contributors):

  • /cmd label T1-FRAME - Add a single label
  • /cmd label T1-FRAME R0-no-crate-publish-required - Add multiple labels
  • /cmd label T6-XCM D2-substantial I5-enhancement - Add multiple labels at once
  • See label documentation for all available labels

Other useful commands:

  • /cmd fmt - Format code (cargo +nightly fmt and taplo)
  • /cmd prdoc - Generate PR documentation
  • /cmd bench - Run benchmarks
  • /cmd update-ui - Update UI tests
  • /cmd --help - Show help for all available commands

You can remove the "Checklist" section once all have been checked. Thank you for your contribution!

✄ -----------------------------------------------------------------------------

Back the new fixed-buffer H2 and H4 suites with pqhybridsign and pin byte-exact upstream golden parity.

The [patch] section is a LOCAL-ONLY development override and must be reworked to a pushed pqhybridsign rev (cfa5913 or successor) before anything is pushed.
Add the H4 hybrid VRF and switch BABE/GRANDPA, keystore dispatch, and CLI schemes to H4/H2.
pqhybridsign-core was merged into the pqhybridsign crate upstream;
consumers now import the composite foundation from pqhybridsign::<mod>
directly. The two git dependencies collapse into one with the alloc
feature, and pqhybridsign-core drops out of the lockfile.
@augmentcode

augmentcode Bot commented Aug 22, 2026

Copy link
Copy Markdown
🤖 Augment PR Summary

Summary: This PR replaces the in-tree hybrid signature composition engine with adapters over the pinned pqhybridsign library.

Changes:

  • Migrates H1 and H3 (Ed25519/SR25519 + ML-DSA-44) key derivation, signing, and verification.
  • Adds H2 and H4 suites using FN-DSA-512 with fixed 929-byte public keys and padded 731-byte signatures.
  • Adds key and signature parsing adapters, semantic component validation, and golden-vector coverage for all four suites.
  • Introduces Substrate/app-crypto wrappers for H2 GRANDPA and H4 BABE.
  • Switches CLI insertion and local-keystore dispatch to the new h244 and h444 crypto IDs.
  • Moves BABE consensus primitives to the H4 VRF implementation and updates SCALE metadata for 731-byte signatures.
Technical notes: H1/H3 seed derivation changes because the library includes each null-terminated suite label in HKDF info; H2/H4 use delta-encoded FN-DSA wire signatures.

🤖 Was this summary useful? React with 👍 or 👎

@augmentcode augmentcode Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed. 1 suggestion posted.

Fix All in Augment

Comment augment review to trigger a new review at any time.

else {
return false;
};
Sr25519FnDsa512::verify(&public, &message, b"", &binding_signature)

@augmentcode augmentcode Bot Aug 22, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

vrf_verify accepts any valid H4 binding signature, but cannot establish that it was produced with binding_nonce; FN-DSA signatures vary with that nonce. A validator can therefore generate multiple valid bindings for one sr25519 pre-output and select one whose hashed output passes the BABE threshold, making leader election and accumulated epoch randomness grindable.

Severity: high

Fix This in Augment

🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.

SEC-1: VrfOutput derives from the sr25519 pre-output alone; the PQ
binding is verified and never enters output derivation (delegates to
pqhybridsign::vrf; same fix for the H3 wrapper).
SEC-3: ordinary Pair::sign uses a dedicated domain context, distinct
from the VRF binding label.
SEC-7: exact =0.0.0-rc7 pin. Q-1: cache the expanded suite secret in
Pair (no per-sign PQ keygen). Q-2: frame/babe comment corrected.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant