Skip to content

test(messaging): reject malformed cross-chain messages at intake - #1241

Merged
mijinummi merged 1 commit into
MDTechLabs:mainfrom
barry01-hash:test/1165-malformed-message-rejection
Sep 28, 2026
Merged

mijinummi merged 1 commit into
MDTechLabs:mainfrom
barry01-hash:test/1165-malformed-message-rejection

Conversation

@barry01-hash

Copy link
Copy Markdown
Contributor

Reject structurally malformed cross-chain messages at intake so a bad message can never occupy a duplicate-detector window slot, be retried, or emit a transaction.

Closes #1165

What changed

  • New message-validator module in apps/relayer-service (validateCrossChainMessage, isValidCrossChainMessage, assertValidCrossChainMessage) covering normal, boundary and failure scenarios for every envelope field, plus per-chain address-format checks (EVM, Stellar/Soroban, Solana) that deployers can enable.
  • MessageQueue.enqueue() now validates before dedupe. Rejections emit a message-rejected event ({ messageId?, reason: 'malformed', errors: [{ field, code, message }] }) and are tracked via getValidationStats(), mirroring how duplicates are handled today.
  • Backward compatible: placeholder addresses used by existing integrations still validate; validation: false restores previous behavior and address-format checks are opt-in.
  • Docs: new docs/CROSS_CHAIN_MESSAGE_VALIDATION.md (rules, events, ordering, config, troubleshooting); cross-linked from docs/CROSS_CHAIN_DUPLICATE_MESSAGE_DETECTION.md.
  • CI: added a "Test relayer service" step so the relayer's jest suites actually run (previously only built).

Verification evidence

  • Package tests: 253 passing (8 suites), up from 79 baseline → 174 new tests across 3 suites.
    • message-validator.spec.ts — validator unit tests, 100% statement/branch/function/line coverage.
    • malformed-message-rejection.spec.ts — queue intake rejection, duplicate-detector isolation, observability/stats, config opt-out.
    • message-delivery-pipeline.spec.ts — end-to-end: mixed indexer batch → queue → mocked EvmExecutor; malformed messages never reach the RPC (only 3 eth_sendTransaction calls, one per valid message).
  • tsc --noEmit clean; npm run build succeeds in apps/relayer-service.
  • Message queue coverage 96.55%; only uncovered lines are pre-existing retryFailed paths.

Add structural validation for CrossChainMessage so a malformed message is
rejected before it reaches the duplicate detector or a chain executor.

- New message-validator module: validateCrossChainMessage, an accumulating
  validator covering normal, boundary and failure cases for every envelope
  field, plus per-chain address-format checks (EVM, Stellar/Soroban, Solana)
  that can be enabled per deployment.
- MessageQueue.enqueue now validates before dedupe: a malformed message
  cannot consume a detector window slot, cannot be retried, and never emits a
  transaction. Rejections surface as a message-rejected event the way
  duplicates surface today, with getValidationStats() as the intake metric.
- Backward compatible: existing callers using placeholder addresses are
  unaffected; validation can be disabled with validation: false and address
  format checks are opt-in.
- 174 new tests (253 total in the package): validator unit coverage at 100%
  statements/branches/functions, queue intake rejection, detector isolation
  and an end-to-end pipeline proving malformed messages never reach the EVM
  executor.
- Docs: new CROSS_CHAIN_MESSAGE_VALIDATION.md, cross-links from the
  duplicate-detection doc, and a CI step to run relayer-service tests.

Closes MDTechLabs#1165
@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@barry01-hash Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@mijinummi
mijinummi merged commit 9b37360 into MDTechLabs:main Sep 28, 2026
1 check failed
@grantfox-oss grantfox-oss Bot mentioned this pull request Sep 28, 2026
12 tasks
barry01-hash added a commit to barry01-hash/BridgeWise that referenced this pull request Sep 28, 2026
…ion merge

Merging upstream main brought in malformed-message validation (PR MDTechLabs#1241),
which rejects messages whose sourceChainId equals destinationChainId. Our
reconciler and pipeline fixtures used 'ethereum' for both. Point the
fixtures at an 'arbitrum' source so they stay valid under the new intake
validation while still exercising the EVM destination path.

Full suite: 295 tests passing (11 suites).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add malformed message rejection tests

2 participants