Repository navigation
Conversation
Add structural validation for CrossChainMessage so a malformed message is rejected before it reaches the duplicate detector or a chain executor. - New message-validator module: validateCrossChainMessage, an accumulating validator covering normal, boundary and failure cases for every envelope field, plus per-chain address-format checks (EVM, Stellar/Soroban, Solana) that can be enabled per deployment. - MessageQueue.enqueue now validates before dedupe: a malformed message cannot consume a detector window slot, cannot be retried, and never emits a transaction. Rejections surface as a message-rejected event the way duplicates surface today, with getValidationStats() as the intake metric. - Backward compatible: existing callers using placeholder addresses are unaffected; validation can be disabled with validation: false and address format checks are opt-in. - 174 new tests (253 total in the package): validator unit coverage at 100% statements/branches/functions, queue intake rejection, detector isolation and an end-to-end pipeline proving malformed messages never reach the EVM executor. - Docs: new CROSS_CHAIN_MESSAGE_VALIDATION.md, cross-links from the duplicate-detection doc, and a CI step to run relayer-service tests. Closes MDTechLabs#1165
|
@barry01-hash Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
12 tasks
barry01-hash
added a commit
to barry01-hash/BridgeWise
that referenced
this pull request
Sep 28, 2026
…ion merge Merging upstream main brought in malformed-message validation (PR MDTechLabs#1241), which rejects messages whose sourceChainId equals destinationChainId. Our reconciler and pipeline fixtures used 'ethereum' for both. Point the fixtures at an 'arbitrum' source so they stay valid under the new intake validation while still exercising the EVM destination path. Full suite: 295 tests passing (11 suites).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reject structurally malformed cross-chain messages at intake so a bad message can never occupy a duplicate-detector window slot, be retried, or emit a transaction.
Closes #1165
What changed
message-validatormodule inapps/relayer-service(validateCrossChainMessage,isValidCrossChainMessage,assertValidCrossChainMessage) covering normal, boundary and failure scenarios for every envelope field, plus per-chain address-format checks (EVM, Stellar/Soroban, Solana) that deployers can enable.MessageQueue.enqueue()now validates before dedupe. Rejections emit amessage-rejectedevent ({ messageId?, reason: 'malformed', errors: [{ field, code, message }] }) and are tracked viagetValidationStats(), mirroring how duplicates are handled today.validation: falserestores previous behavior and address-format checks are opt-in.docs/CROSS_CHAIN_MESSAGE_VALIDATION.md(rules, events, ordering, config, troubleshooting); cross-linked fromdocs/CROSS_CHAIN_DUPLICATE_MESSAGE_DETECTION.md.Verification evidence
message-validator.spec.ts— validator unit tests, 100% statement/branch/function/line coverage.malformed-message-rejection.spec.ts— queue intake rejection, duplicate-detector isolation, observability/stats, config opt-out.message-delivery-pipeline.spec.ts— end-to-end: mixed indexer batch → queue → mockedEvmExecutor; malformed messages never reach the RPC (only 3eth_sendTransactioncalls, one per valid message).tsc --noEmitclean;npm run buildsucceeds inapps/relayer-service.retryFailedpaths.