strkey: enforce SEP-23 payload lengths in Decode and DecodeAny - #5977
Merged
Merged
Conversation
karthikiyer56
added a commit
that referenced
this pull request
Aug 10, 2026
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Consolidates liquidity-pool ordering checks and adds canonical SEP-23 payload-length validation.
Changes:
- Delegates pool ordering validation to XDR after asset conversion.
- Validates fixed-length and signed-payload StrKeys centrally.
- Removes redundant checks and updates tests and changelogs.
Reviewed changes
Copilot reviewed 27 out of 27 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
xdr/signer_key.go |
Removes redundant signer length check. |
xdr/muxed_account.go |
Removes redundant account length checks. |
xdr/claimable_balance_id.go |
Delegates payload length validation. |
xdr/claimable_balance_id_test.go |
Updates expected validation error. |
xdr/asset.go |
Removes unreachable error branches. |
xdr/account_id.go |
Removes redundant address length check. |
txnbuild/restore_footprint.go |
Delegates contract length validation. |
txnbuild/restore_footprint_test.go |
Updates expected error. |
txnbuild/liquidity_pool_withdraw.go |
Removes premature ordering check. |
txnbuild/liquidity_pool_withdraw_test.go |
Tests malformed asset errors. |
txnbuild/liquidity_pool_id.go |
Delegates ordering to XDR. |
txnbuild/liquidity_pool_deposit.go |
Removes premature ordering check. |
txnbuild/liquidity_pool_deposit_test.go |
Tests malformed asset errors. |
txnbuild/invoke_host_function.go |
Delegates contract length validation. |
txnbuild/invoke_host_function_test.go |
Updates expected error. |
txnbuild/CHANGELOG.md |
Documents ordering behavior. |
strkey/signed_payload.go |
Centralizes structural validation. |
strkey/signed_payload_test.go |
Covers nonempty payload boundaries. |
strkey/muxed_account.go |
Removes redundant checks. |
strkey/main.go |
Adds version-specific payload validation. |
strkey/isvalid_length_test.go |
Tests validation helpers. |
strkey/decode_length_test.go |
Tests canonical lengths and padding. |
keypair/main.go |
Deprecates ErrInvalidKey. |
keypair/from_address.go |
Delegates key length validation. |
keypair/from_address_test.go |
Updates expected errors. |
ingest/producer_test.go |
Simplifies datastore mock setup. |
CHANGELOG.md |
Documents breaking StrKey changes; error-propagation wording needs correction. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
karthikiyer56
force-pushed
the
fix/asset-ordering-followups
branch
from
August 10, 2026 05:24
4339f64 to
e8b88dc
Compare
Decode and DecodeAny checked the version byte and CRC16 checksum but never the payload length, so a 33-byte ed25519 payload with a valid checksum decoded successfully and every IsValid* helper reported it valid. SEP-23 fixes the payload length per version byte; enforce it inside Decode/DecodeAny: exact canonical sizes for the fixed-length version bytes, and structural validation for signed payloads (32-byte signer key, declared length 1-64 per CAP-40, zero padding to a multiple of four). Fallout folded in: - NewSignedPayload rejects empty payloads so SignedPayload.Encode output stays decodable (CAP-40 fails empty-payload signers with SET_OPTIONS_BAD_SIGNER/txMALFORMED). - DecodeSignedPayload drops its now-dead short-payload check and the redundant XDR re-parse; Decode already validated the structure. - Caller-level length re-checks removed as dead code: xdr AccountId/MuxedAccount/SignerKey SetAddress, xdr ClaimableBalanceId.DecodeFromStrkey, strkey muxed account helpers, txnbuild contract-address parsing. Their wrong-length errors are replaced by strkey's. - keypair.ParseAddress wraps every decode failure with ErrInvalidKey so errors.Is(err, ErrInvalidKey) keeps matching wrong-length keys — and now also matches checksum/encoding failures, which previously returned the bare strkey error. Parse's seed fallback compares against strkey.ErrInvalidVersionByte with errors.Is instead of != so it survives the wrapping. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The strkey muxed-account helpers swallow Decode errors into generic messages, and xdr.MuxedAccount.SetAddress rejects on encoded string length before decoding — so "callers now surface strkey's error" was only true for the xdr and txnbuild callers. Say exactly that. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
karthikiyer56
force-pushed
the
fix/asset-ordering-followups
branch
from
August 10, 2026 18:51
53b7e87 to
e80a5f2
Compare
Shaptic
approved these changes
Aug 12, 2026
This was referenced Aug 14, 2026
hypekostas
pushed a commit
to stellar/stellar-disbursement-platform-backend
that referenced
this pull request
Aug 17, 2026
… updates (#1185) Yes — the previous response still rendered the Markdown. You want the **literal Markdown source**, with no HTML tags at all. ```markdown Bumps the minor-and-patch group with 7 updates in the `/` directory: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.43.0` | `1.43.5` | | [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.31` | `1.32.36` | | [github.com/aws/aws-sdk-go-v2/service/ses](https://github.com/aws/aws-sdk-go-v2) | `1.37.0` | `1.37.5` | | [github.com/aws/aws-sdk-go-v2/service/sns](https://github.com/aws/aws-sdk-go-v2) | `1.42.0` | `1.42.5` | | [github.com/stellar/go-stellar-sdk](https://github.com/stellar/go-stellar-sdk) | `0.6.0` | `0.7.2` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.54.0` | `0.55.0` | | [golang.org/x/net](https://github.com/golang/net) | `0.57.0` | `0.58.0` | Updates `github.com/aws/aws-sdk-go-v2` from 1.43.0 to 1.43.5 ### Commits - [`a14f5f1`](aws/aws-sdk-go-v2@a14f5f1) Release 2026-08-10 - [`339f0b6`](aws/aws-sdk-go-v2@339f0b6) Regenerated Clients - [`0978e3d`](aws/aws-sdk-go-v2@0978e3d) Update API model - [`3cc614d`](aws/aws-sdk-go-v2@3cc614d) Fix codegen mp ([#3508](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3508)) - [`1434b18`](aws/aws-sdk-go-v2@1434b18) generate response snapshots for json ([#3507](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3507)) - [`ad58f77`](aws/aws-sdk-go-v2@ad58f77) Checkout smithy-go on PRs at the commit pointed out by SMITHY_GO_CODEGEN_VERS... - [`c002860`](aws/aws-sdk-go-v2@c002860) feat: move close-body, logger, and service-metadata work out of the middlewar... - [`f152336`](aws/aws-sdk-go-v2@f152336) Release 2026-08-07 - [`37d88d7`](aws/aws-sdk-go-v2@37d88d7) Regenerated Clients - [`c54b278`](aws/aws-sdk-go-v2@c54b278) Update endpoints model - Additional commits viewable in [compare view](aws/aws-sdk-go-v2@v1.43.0...v1.43.5) Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.31 to 1.32.36 ### Commits - [`a14f5f1`](aws/aws-sdk-go-v2@a14f5f1) Release 2026-08-10 - [`339f0b6`](aws/aws-sdk-go-v2@339f0b6) Regenerated Clients - [`0978e3d`](aws/aws-sdk-go-v2@0978e3d) Update API model - [`3cc614d`](aws/aws-sdk-go-v2@3cc614d) Fix codegen mp ([#3508](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3508)) - [`1434b18`](aws/aws-sdk-go-v2@1434b18) generate response snapshots for json ([#3507](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3507)) - [`ad58f77`](aws/aws-sdk-go-v2@ad58f77) Checkout smithy-go on PRs at the commit pointed out by SMITHY_GO_CODEGEN_VERS... - [`c002860`](aws/aws-sdk-go-v2@c002860) feat: move close-body, logger, and service-metadata work out of the middlewar... - [`f152336`](aws/aws-sdk-go-v2@f152336) Release 2026-08-07 - [`37d88d7`](aws/aws-sdk-go-v2@37d88d7) Regenerated Clients - [`c54b278`](aws/aws-sdk-go-v2@c54b278) Update endpoints model - Additional commits viewable in [compare view](aws/aws-sdk-go-v2@config/v1.32.31...config/v1.32.36) Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.30 to 1.19.35 ### Commits - [`a14f5f1`](aws/aws-sdk-go-v2@a14f5f1) Release 2026-08-10 - [`339f0b6`](aws/aws-sdk-go-v2@339f0b6) Regenerated Clients - [`0978e3d`](aws/aws-sdk-go-v2@0978e3d) Update API model - [`3cc614d`](aws/aws-sdk-go-v2@3cc614d) Fix codegen mp ([#3508](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3508)) - [`1434b18`](aws/aws-sdk-go-v2@1434b18) generate response snapshots for json ([#3507](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3507)) - [`ad58f77`](aws/aws-sdk-go-v2@ad58f77) Checkout smithy-go on PRs at the commit pointed out by SMITHY_GO_CODEGEN_VERS... - [`c002860`](aws/aws-sdk-go-v2@c002860) feat: move close-body, logger, and service-metadata work out of the middlewar... - [`f152336`](aws/aws-sdk-go-v2@f152336) Release 2026-08-07 - [`37d88d7`](aws/aws-sdk-go-v2@37d88d7) Regenerated Clients - [`c54b278`](aws/aws-sdk-go-v2@c54b278) Update endpoints model - Additional commits viewable in [compare view](aws/aws-sdk-go-v2@credentials/v1.19.30...credentials/v1.19.35) Updates `github.com/aws/aws-sdk-go-v2/service/ses` from 1.37.0 to 1.37.5 ### Commits - [`b4784c1`](aws/aws-sdk-go-v2@b4784c1) Release 2026-07-01 - [`97c0201`](aws/aws-sdk-go-v2@97c0201) Regenerated Clients - [`6687238`](aws/aws-sdk-go-v2@6687238) Update endpoints model - [`995297f`](aws/aws-sdk-go-v2@995297f) Update API model - [`c26cfc6`](aws/aws-sdk-go-v2@c26cfc6) Fix bump smithy-go to cover multiple issues ([#3461](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3461)) - [`fae66b8`](aws/aws-sdk-go-v2@fae66b8) Set transfer manager error as the first error seen, preventing race condition... - [`cf0eabd`](aws/aws-sdk-go-v2@cf0eabd) Release 2026-06-30 - [`ad0c091`](aws/aws-sdk-go-v2@ad0c091) Regenerated Clients - [`196e961`](aws/aws-sdk-go-v2@196e961) Update endpoints model - [`1529ead`](aws/aws-sdk-go-v2@1529ead) Update API model - Additional commits viewable in [compare view](aws/aws-sdk-go-v2@v1.37.0...service/pi/v1.37.5) Updates `github.com/aws/aws-sdk-go-v2/service/sns` from 1.42.0 to 1.42.5 ### Commits - [`dcbed91`](aws/aws-sdk-go-v2@dcbed91) Release 2026-01-09 - [`08120e8`](aws/aws-sdk-go-v2@08120e8) Regenerated Clients - [`1d7a925`](aws/aws-sdk-go-v2@1d7a925) Update endpoints model - [`482067d`](aws/aws-sdk-go-v2@482067d) Update API model - [`4662404`](aws/aws-sdk-go-v2@4662404) remove example ([#3282](https://redirect.github.com/aws/aws-sdk-go-v2/issues/3282)) - [`c28a6f4`](aws/aws-sdk-go-v2@c28a6f4) Release 2026-01-07 - [`2fa7a72`](aws/aws-sdk-go-v2@2fa7a72) Regenerated Clients - [`077cbaa`](aws/aws-sdk-go-v2@077cbaa) Update endpoints model - [`3282dbc`](aws/aws-sdk-go-v2@3282dbc) Update API model - [`3daa74a`](aws/aws-sdk-go-v2@3daa74a) Release 2026-01-06 - Additional commits viewable in [compare view](aws/aws-sdk-go-v2@v1.42.0...service/amp/v1.42.5) Updates `github.com/stellar/go-stellar-sdk` from 0.6.0 to 0.7.2 ### Release Notes Source: [github.com/stellar/go-stellar-sdk releases](https://github.com/stellar/go-stellar-sdk/releases) #### v0.7.2 ##### What's Changed - xdr: compare assets by their XDR encoding, and use Equals for asset equality by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5974](https://redirect.github.com/stellar/go-stellar-sdk/pull/5974) - txnbuild: consolidate liquidity pool ordering guards; xdr and ingest cleanups by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5978](https://redirect.github.com/stellar/go-stellar-sdk/pull/5978) - strkey: enforce SEP-23 payload lengths in Decode and DecodeAny by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5977](https://redirect.github.com/stellar/go-stellar-sdk/pull/5977) **Full Changelog:** [v0.7.1...v0.7.2](stellar/go-stellar-sdk@v0.7.1...v0.7.2) #### v0.7.1 ##### What's Changed - stellartoml: validate domain in GetStellarToml for parity with sibling by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5970](https://redirect.github.com/stellar/go-stellar-sdk/pull/5970) - ingest: one ledger walk — ExtractLedgerTxParts + EventsFromTxParts/FeesFromTxParts (supersedes the extractor bundles) by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5966](https://redirect.github.com/stellar/go-stellar-sdk/pull/5966) **Full Changelog:** [v0.7.0...v0.7.1](stellar/go-stellar-sdk@v0.7.0...v0.7.1) #### v0.7.0 ##### What's Changed - ingest,network,xdr: zero-copy XDR view extractors for full-history ingestion by [@chowbao](https://github.com/chowbao) in [stellar/go-stellar-sdk#5949](https://redirect.github.com/stellar/go-stellar-sdk/pull/5949) - xdr,xdrgen,ingest: extend xdr views (decoded discriminants, typed opaque, count validation, Fields) and rebuild the view extractors on them by [@tamirms](https://github.com/tamirms) in [stellar/go-stellar-sdk#5951](https://redirect.github.com/stellar/go-stellar-sdk/pull/5951) - protocols/rpc: add UseUpgradedAuth flag to SimulateTransactionRequest by [@Ryang-21](https://github.com/Ryang-21) in [stellar/go-stellar-sdk#5948](https://redirect.github.com/stellar/go-stellar-sdk/pull/5948) - protocols/rpc: Add LedgerCloseTime to GetHealthResponse by [@felixl256](https://github.com/felixl256) in [stellar/go-stellar-sdk#5958](https://redirect.github.com/stellar/go-stellar-sdk/pull/5958) - ingest/loadtest: expand loadtest functionality to handle multiple ledger bundles by [@cjonas9](https://github.com/cjonas9) in [stellar/go-stellar-sdk#5959](https://redirect.github.com/stellar/go-stellar-sdk/pull/5959) - ingest: expose fee-bump inner hashes on the view extractors by [@tamirms](https://github.com/tamirms) in [stellar/go-stellar-sdk#5964](https://redirect.github.com/stellar/go-stellar-sdk/pull/5964) - ingest/ledgerbackend: Update captive-core-pubnet.cfg: swap SP with Obsrvr by [@drebelsky](https://github.com/drebelsky) in [stellar/go-stellar-sdk#5963](https://redirect.github.com/stellar/go-stellar-sdk/pull/5963) - Protocol 28 (CAP-0085) by [@sisuresh](https://github.com/sisuresh) in [stellar/go-stellar-sdk#5965](https://redirect.github.com/stellar/go-stellar-sdk/pull/5965) ##### New Contributors - [@Ryang-21](https://github.com/Ryang-21) made their first contribution in [stellar/go-stellar-sdk#5948](https://redirect.github.com/stellar/go-stellar-sdk/pull/5948) - [@felixl256](https://github.com/felixl256) made their first contribution in [stellar/go-stellar-sdk#5958](https://redirect.github.com/stellar/go-stellar-sdk/pull/5958) **Full Changelog:** [v0.6.0...v0.7.0](stellar/go-stellar-sdk@v0.6.0...v0.7.0) #### v0.6.1 ##### What's Changed - Backports for Horizon 27.0.1 (release-0.6.1) by [@karthikiyer56](https://github.com/karthikiyer56) in [stellar/go-stellar-sdk#5979](https://redirect.github.com/stellar/go-stellar-sdk/pull/5979) **Full Changelog:** [v0.6.0...v0.6.1](stellar/go-stellar-sdk@v0.6.0...v0.6.1) ### Changelog Source: [github.com/stellar/go-stellar-sdk changelog](https://github.com/stellar/go-stellar-sdk/blob/main/CHANGELOG.md) # Changelog This repository adheres to [Go module Versioning](https://go.dev/doc/modules/version-numbers). This monorepo contains a number of SDKs: - `horizonclient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/horizonclient/CHANGELOG.md)) - `txnbuild` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/txnbuild/CHANGELOG.md)) - `rpcclient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/rpcclient/CHANGELOG.md)) - `corelient` ([changelog](https://github.com/stellar/go-stellar-sdk/blob/main/clients/stellarcore/CHANGELOG.md)) Official project releases may be found here: [https://github.com/stellar/go-stellar-sdk/releases](https://github.com/stellar/go-stellar-sdk/releases) ## Pending ### New Features - protocols/rpc: Add `LatestLedgerCloseTime` and `OldestLedgerCloseTime` to `GetHealthResponse`, exposing the latest and oldest ledgers' close times (unix seconds) on the `getHealth` response ([#5958](https://redirect.github.com/stellar/go-stellar-sdk/pull/5958)) ### Breaking Changes - strkey: `Decode` and `DecodeAny` now validate the payload length against the version byte per [SEP-23](https://github.com/stellar/stellar-protocol/blob/master/ecosystem/sep-0023.md). Fixed-length keys (account ID, seed, muxed account, contract, liquidity pool, claimable balance, hashTx, hashX) must decode to their exact canonical size, and signed payloads must carry a declared payload length of 1–64 bytes matched by their zero padding. Inputs with a valid checksum but a wrong-length payload — previously accepted by `Decode`, `DecodeAny`, and every `IsValid*` helper — are now rejected ([#5977](https://redirect.github.com/stellar/go-stellar-sdk/pull/5977)). - `NewSignedPayload` rejects empty payloads, matching CAP-40 (the protocol fails such signers with `SET_OPTIONS_BAD_SIGNER`/`txMALFORMED`) and keeping `SignedPayload.Encode` output decodable. - Length re-checks that `Decode` now subsumes were removed from `xdr.AccountId.SetAddress`, `xdr.MuxedAccount.SetAddress`, `xdr.SignerKey.SetAddress`, `xdr.ClaimableBalanceId.DecodeFromStrkey`, `strkey.DecodeMuxedAccount`, `strkey.MuxedAccount.SetAccountID`, and txnbuild contract-address parsing. For wrong-length inputs, the xdr and txnbuild callers now return strkey's `invalid payload length` error instead of their own; the strkey muxed-account helpers keep their generic `invalid muxed account` / `invalid ed25519 public key` errors; `xdr.MuxedAccount.SetAddress` is unchanged (it rejects on encoded string length before decoding). - `keypair.ParseAddress` wraps every decode failure with `ErrInvalidKey`, so `errors.Is(err, ErrInvalidKey)` keeps matching wrong-length keys (and now also matches checksum/encoding failures, which previously returned the bare strkey error). - `DecodeSignedPayload` delegates structure validation to `Decode`; structurally invalid inputs now uniformly error with `invalid signed payload` (previously `signed payload too short: ...` or `invalid signed payload padding`). - xdr: `Asset.LessThan` now orders assets the way the protocol does — by the raw 32-byte issuer key — instead of by base32 strkey text, and `xdr.NewPoolId` requires strictly `a < b`, rejecting reversed and identical pairs ([#5974](https://redirect.github.com/stellar/go-stellar-sdk/pull/5974)) - txnbuild: liquidity pool operations reject asset pairs that are not strictly ordered; see the [txnbuild changelog](https://github.com/stellar/go-stellar-sdk/blob/main/txnbuild/CHANGELOG.md) ([#5974](https://redirect.github.com/stellar/go-stellar-sdk/pull/5974)) ### Bug Fixes - processors/token_transfer: trustline revocation now compares liquidity pool assets by value instead of pointer identity, fixing wrong-leg selection when burning pool shares ([#5974](https://redirect.github.com/stellar/go-stellar-sdk/pull/5974)) ## [0.7.0] ### New Features - xdr: Protocol 28 support (CAP-0083, CAP-0085). XDR regenerated from [stellar-xdr@9c9c1459](stellar/stellar-xdr@9c9c145), the commit stellar-core 28.0.0 pins; both CAPs are ungated upstream so `XDR_FEATURES` is now empty. ### Commits - [`b46a463`](stellar/go-stellar-sdk@b46a463) strkey: enforce SEP-23 payload lengths in Decode and DecodeAny ([#5977](https://redirect.github.com/stellar/go-stellar-sdk/issues/5977)) - [`f8cd5df`](stellar/go-stellar-sdk@f8cd5df) txnbuild: consolidate liquidity pool ordering guards; xdr and ingest cleanups... - [`d2f530f`](stellar/go-stellar-sdk@d2f530f) xdr: compare assets by their XDR encoding, and use Equals for asset equality ... - [`3114a80`](stellar/go-stellar-sdk@3114a80) ingest: one ledger walk — ExtractLedgerTxParts + EventsFromTxParts/FeesFromTx... - [`3c3872f`](stellar/go-stellar-sdk@3c3872f) stellartoml: validate domain in GetStellarToml for parity with sibling ([#5970](https://redirect.github.com/stellar/go-stellar-sdk/issues/5970)) - [`2b16db0`](stellar/go-stellar-sdk@2b16db0) Protocol 28 Support ([#5969](https://redirect.github.com/stellar/go-stellar-sdk/issues/5969)) - [`e5d0cb9`](stellar/go-stellar-sdk@e5d0cb9) Merge main into protocol-next ahead of the Protocol 28 GA merge - [`149b994`](stellar/go-stellar-sdk@149b994) Finalize Protocol 28: pin stellar-xdr @ `9c9c1459` ([#5968](https://redirect.github.com/stellar/go-stellar-sdk/issues/5968)) - [`82df764`](stellar/go-stellar-sdk@82df764) Protocol 28 (CAP-0085) XDR regeneration ([#5965](https://redirect.github.com/stellar/go-stellar-sdk/issues/5965)) - [`8dd9cad`](stellar/go-stellar-sdk@8dd9cad) Update captive-core-pubnet.cfg: swap SP with Obsrvr ([#5963](https://redirect.github.com/stellar/go-stellar-sdk/issues/5963)) - Additional commits viewable in [compare view](stellar/go-stellar-sdk@v0.6.0...v0.7.2) Updates `golang.org/x/crypto` from 0.54.0 to 0.55.0 ### Commits - [`f44d03d`](golang/crypto@f44d03d) go.mod: update golang.org/x dependencies - [`5ed4944`](golang/crypto@5ed4944) crypto/internal/poly1305: provide optimised assembly for riscv64 - [`b07833c`](golang/crypto@b07833c) ssh: return window credit for discarded extended data - [`d701c51`](golang/crypto@d701c51) acme: fix nil pointer dereference in pebble test error reporting - [`999d053`](golang/crypto@999d053) ssh: fix parsing of GSSAPI payloads offering multiple mechanisms - [`90f76b8`](golang/crypto@90f76b8) ssh: reject certificate signature keys before recursing - [`b53964a`](golang/crypto@b53964a) ssh: permit empty but non-nil HostKeyAlgorithms, KeyExchanges, Ciphers, MACs - [`626e40f`](golang/crypto@626e40f) ssh: drain stderr on forwarded TCP and Unix channels - [`31914c6`](golang/crypto@31914c6) x509roots/fallback: update bundle - [`f2135b8`](golang/crypto@f2135b8) all: clean up minor issues found by staticcheck - Additional commits viewable in [compare view](golang/crypto@v0.54.0...v0.55.0) Updates `golang.org/x/net` from 0.57.0 to 0.58.0 ### Commits - [`acc78e0`](golang/net@acc78e0) go.mod: update golang.org/x dependencies - [`90d10f0`](golang/net@90d10f0) internal/http3: delete invalid Content-Length if declared in server handler - [`08abf4d`](golang/net@08abf4d) internal/http3: infer headers when Content-Encoding is set but is empty - [`8d10596`](golang/net@8d10596) http2: avoid deadlocks in wrapped ClientConn state callback - [`99c3b0a`](golang/net@99c3b0a) http2/hpack: build the table lookup maps lazily, only for encoders - [`5a920b1`](golang/net@5a920b1) http3: rework registration to allow using a fake network - [`7fd2842`](golang/net@7fd2842) quic: return an error from Accept after PacketConn reader exits - [`825111d`](golang/net@825111d) quic: avoid busy-loop when keep-alive is blocked by congestion control - [`a02ddfa`](golang/net@a02ddfa) http/httpproxy: prioritize lowercase proxy environment variables - [`574e5eb`](golang/net@574e5eb) quic: halt conn goroutines on close when listener exits early - Additional commits viewable in [compare view](golang/net@v0.57.0...v0.58.0) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. --- You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove all of the ignore conditions of the specified dependency ```
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
strkey.Decode/DecodeAnynow validate the payload length against the version byte per SEP-23. Breaking: inputs with a valid checksum but a wrong-length payload — previously accepted byDecode,DecodeAny, and everyIsValid*helper — are now rejected.NewSignedPayloadrejects empty payloads.Decodenow subsumes were removed from keypair, xdr, and txnbuild callers;keypair.ParseAddresswraps decode failures withErrInvalidKeysoerrors.Ismatching keeps working.Details
checkPayloadLengthinsideDecode/DecodeAny: exact 32 bytes for account ID/seed/contract/liquidity pool/hashTx/hashX, 33 for claimable balance, 40 for muxed account.SET_OPTIONS_BAD_SIGNER/txMALFORMEDtreatment and js-stellar-base).NewSignedPayloadrejects empty payloads soSignedPayload.Encodeoutput stays decodable;DecodeSignedPayloaddrops its now-unreachable short-payload check and redundant XDR re-parse.xdr.AccountId.SetAddress,xdr.MuxedAccount.SetAddress,xdr.SignerKey.SetAddress,xdr.ClaimableBalanceId.DecodeFromStrkey,strkey.DecodeMuxedAccount/SetAccountID, txnbuild contract-address parsing. For wrong-length inputs, the xdr and txnbuild callers now return strkey'sinvalid payload lengtherror; the strkey muxed-account helpers keep their generic messages;xdr.MuxedAccount.SetAddressis unchanged (it rejects on encoded string length before decoding).ParseAddresswraps every decode failure withErrInvalidKey(via%w), so the sentinel keeps matching wrong-length keys — and now also matches checksum/encoding failures, which previously returned the bare strkey error.Parse's seed fallback compares againststrkey.ErrInvalidVersionBytewitherrors.Isinstead of!=so it survives the wrapping.Decode/DecodeAnyand theIsValid*helpers, signed-payload boundaries (1/64 valid; 0/65, truncated header, declared-vs-actual mismatch, nonzero padding invalid), and the SEP-23 invalid signed-payload vectors asserted directly onDecode.CHANGELOG.md.🤖 Generated with Claude Code