Skip to content

Commit d4fb9f9

Browse files
0xrlawrenceclaude
andcommitted
fix: reject the zero address in initializers and setters
AlignedLayerServiceManager and BatcherPaymentService both validate every address they are initialized with, but AlignedProofAggregationService validates none of them. A zero newOwner there permanently disables _authorizeUpgrade and every setter, with no way back. Apply the same InvalidAddress check the sibling contracts already use: - AlignedProofAggregationService.initialize: newOwner, alignedAggregatorAddress, sp1VerifierAddress, risc0VerifierAddress - setSP1VerifierAddress and setRisc0VerifierAddress, which would otherwise point verification at an empty address - BatcherPaymentService.withdrawFromServiceManager: withdrawAddress, where transfer() to address(0) succeeds and burns the funds Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 2b65191 commit d4fb9f9

3 files changed

Lines changed: 23 additions & 0 deletions

File tree

‎contracts/src/core/AlignedProofAggregationService.sol‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,18 @@ contract AlignedProofAggregationService is
5454
bytes32 _risc0AggregatorProgramImageId,
5555
bytes32 _sp1AggregatorProgramVKHash
5656
) public initializer {
57+
if (newOwner == address(0)) {
58+
revert InvalidAddress("newOwner");
59+
}
60+
if (_alignedAggregatorAddress == address(0)) {
61+
revert InvalidAddress("alignedAggregatorAddress");
62+
}
63+
if (_sp1VerifierAddress == address(0)) {
64+
revert InvalidAddress("sp1VerifierAddress");
65+
}
66+
if (_risc0VerifierAddress == address(0)) {
67+
revert InvalidAddress("risc0VerifierAddress");
68+
}
5769
__Ownable_init();
5870
__UUPSUpgradeable_init();
5971
_transferOwnership(newOwner);
@@ -152,13 +164,19 @@ contract AlignedProofAggregationService is
152164
/// @notice Sets the address of the Risc0 verifier contract
153165
/// @param _risc0VerifierAddress The new address for the Risc0 verifier contract
154166
function setRisc0VerifierAddress(address _risc0VerifierAddress) external onlyOwner {
167+
if (_risc0VerifierAddress == address(0)) {
168+
revert InvalidAddress("risc0VerifierAddress");
169+
}
155170
risc0VerifierAddress = _risc0VerifierAddress;
156171
emit Risc0VerifierAddressUpdated(_risc0VerifierAddress);
157172
}
158173

159174
/// @notice Sets the address of the SP1 verifier contract
160175
/// @param _sp1VerifierAddress The new address for the SP1 verifier contract
161176
function setSP1VerifierAddress(address _sp1VerifierAddress) external onlyOwner {
177+
if (_sp1VerifierAddress == address(0)) {
178+
revert InvalidAddress("sp1VerifierAddress");
179+
}
162180
sp1VerifierAddress = _sp1VerifierAddress;
163181
emit SP1VerifierAddressUpdated(_sp1VerifierAddress);
164182
}

‎contracts/src/core/BatcherPaymentService.sol‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -194,6 +194,9 @@ contract BatcherPaymentService is
194194
uint256 amount,
195195
address withdrawAddress
196196
) public payable onlyOwner {
197+
if (withdrawAddress == address(0)) {
198+
revert InvalidAddress("withdrawAddress");
199+
}
197200
alignedLayerServiceManager.withdraw(amount); // reverts if InsufficientBalance
198201
// money is now in this contract
199202
// we transfer it to the withdraw address

‎contracts/src/core/IAlignedProofAggregationService.sol‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,4 +61,6 @@ interface IAlignedProofAggregationService {
6161
error InvalidProvingSystemId(uint8 actual);
6262

6363
error ProvingSystemIdMismatch(uint8 expected, uint8 received);
64+
65+
error InvalidAddress(string param);
6466
}

0 commit comments

Comments
 (0)