Commit d4fb9f9
fix: reject the zero address in initializers and setters
AlignedLayerServiceManager and BatcherPaymentService both validate every
address they are initialized with, but AlignedProofAggregationService
validates none of them. A zero newOwner there permanently disables
_authorizeUpgrade and every setter, with no way back.
Apply the same InvalidAddress check the sibling contracts already use:
- AlignedProofAggregationService.initialize: newOwner,
alignedAggregatorAddress, sp1VerifierAddress, risc0VerifierAddress
- setSP1VerifierAddress and setRisc0VerifierAddress, which would otherwise
point verification at an empty address
- BatcherPaymentService.withdrawFromServiceManager: withdrawAddress, where
transfer() to address(0) succeeds and burns the funds
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 2b65191 commit d4fb9f9
3 files changed
Lines changed: 23 additions & 0 deletions
File tree
- contracts/src/core
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
57 | 69 | | |
58 | 70 | | |
59 | 71 | | |
| |||
152 | 164 | | |
153 | 165 | | |
154 | 166 | | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
155 | 170 | | |
156 | 171 | | |
157 | 172 | | |
158 | 173 | | |
159 | 174 | | |
160 | 175 | | |
161 | 176 | | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
162 | 180 | | |
163 | 181 | | |
164 | 182 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
194 | 194 | | |
195 | 195 | | |
196 | 196 | | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
197 | 200 | | |
198 | 201 | | |
199 | 202 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
| 64 | + | |
| 65 | + | |
64 | 66 | | |
0 commit comments