Proto commits in bnb-chain/tss-lib

These 50 commits are when the Protocol Buffers files have changed:

Commit:1387cb7
Author:ycen

eddsa/resharing: give the new committee something of its own to check round 1 against The ECDSA half of this got the session binding earlier; the EdDSA half did not, and it is the half where the whole package consumes no session value at all. A complete old->new transcript recorded in one execution was accepted by a different execution's new committee: every new party completed and persisted shares byte-equal to the recorded run's, in a session whose own nonce differed and in which no old-committee party existed. Nothing in the package could have caught it. There was no ssid to compare, and adding a unanimity check alone would not have been enough either -- unanimity compares the old committee's declarations only to EACH OTHER, so a recorded transcript agrees with itself. Nor can the new committee recompute the ssid: the pre-image of getSSID is the OLD committee's save data, which a new party does not hold. So DGRound1Message gains ssid and session_nonce_hash, mirroring the ECDSA message field for field. The old committee derives the ssid (curve, roster, BigXj, round, nonce -- eddsa/keygen's shape plus BigXj, so two re-shares of two different keys never collide) and declares SHA512_256 of the agreed nonce. Each new party compares that hash against its OWN Parameters before it adopts anything and before it ACKs. It is a hash rather than the nonce so the wire does not hand a passive observer the identifier of a session it is not in. ValidateBasic requires the field: an absent hash is exactly what a transcript recorded before the field existed carries, and it must not be laundered into "nothing to compare". The nonce requirement is stated once, before the role split in round 1, for both roles -- the old committee needs it to derive the ssid, the new committee needs it to check what the old committee declares -- so a party lacking it fails having exchanged nothing rather than after a full round. Attribution follows the ECDSA rule: a fault visible in a single message names its sender; a disagreement BETWEEN messages names nobody, because slot 0 is the array's first element and not a witness, and n_old = t+1 is a legal committee in which the tolerated corrupt parties are a strict majority. SCOPE, stated in the code too: this makes a transcript non-portable between sessions for a peer that cannot rewrite bytes. It does NOT authenticate the sender. Transport authentication remains the host's job, as for the rest of the protocol. BREAKING: EdDSA re-sharing round-1 messages carry two new required-ish fields, so old and new builds cannot re-share with each other, and every party must now have a session nonce set before Start(). Also regenerates ecdsa-resharing.pb.go with protoc-gen-go v1.36.11, which is what generated the other seven .pb.go files in the tree; an earlier commit had regenerated that one alone with a v1.28.0 binary. And replaces the five re-sharing line-number locators in doc/maintenance-invariants.md with declaration references: three of the five had already gone stale, one of them before this change. Tests cover the recorded-transcript rejection, its own-session negative control, the split committee, the empty declaration and the missing nonce. Full suite green. Co-Authored-By: Claude Code <noreply@anthropic.com>

Commit:b73eea7
Author:ycen

resharing, signing: bind each execution's own session nonce into what receivers check Two places where a value that identifies the execution was believed to separate two runs and did not. Both were measured, not inferred; both fixes change bytes on the wire or the SSID value, which this v4 branch already accepts. RE-SHARING. A complete old->new transcript captured from one execution was accepted by a different execution's new committee: all its parties completed and persisted shares byte-equal to the captured run's, in a session whose own nonce was different and in which no old-committee party existed. The unanimity check added earlier does not reach this, and cannot: it compares the old committee's ssid declarations only to EACH OTHER, so a transcript is unanimous with itself. Nor can the new committee recompute the ssid to compare -- its pre-image is the OLD committee's save data, which a new party does not hold, and that was confirmed by calling the production getSSID() on the new side and watching it fail on an all-nil BigXj. So DGRound1Message gains a session_nonce_hash, the old committee declares SHA512_256 of the agreed nonce, and each new party compares it against its OWN Parameters before anything is adopted. It is a hash rather than the nonce so the wire does not hand a passive observer the identifier of a session it is not in. ValidateBasic requires the field: an absent hash is exactly what a pre-existing transcript carries, and it must not be laundered into "nothing to compare". SCOPE, stated in the code as well: this makes a transcript non-portable between sessions for a peer that cannot forge messages. It does NOT authenticate the sender. Nothing here signs or MACs a message, so an adversary who can rewrite arbitrary bytes can substitute the expected hash and splice the rest of a captured transcript. Transport authentication remains the host's job, as it is for the rest of the protocol. SIGNING. fullBytesLen decides what is actually signed -- fixed-width FillBytes when set, m.Bytes() when not -- but the SSID pre-image hashes magnitudes only, so two executions differing ONLY in fullBytesLen shared an SSID while binding different byte strings. Measured on ed25519, where the two runs' signatures do not cross-verify; on secp256k1 both encodings reduce to the same integer, so the value signed is unchanged there and only the recorded data.M differs. Under the shared SSID a range proof and a commitment/Schnorr pair minted in one run were accepted by the other run's production verifiers, on both curves. fullBytesLen is now part of the pre-image on both curves. It is also a per-party argument that no message carries and nothing compares, so binding it here is what makes a disagreement observable at all. Tests cover both directions. Full suite green. Co-Authored-By: Claude Code <noreply@anthropic.com>

Commit:61d2e85
Author:ycen

docs: say what the NTilde ModProof attests, and cite gates by declaration Two corrections to comments across ECDSA keygen and re-sharing. Comment-only: no verifier's decision changes and no wire format changes. What the proof attests. ProofMod.Verify(Session, N) takes the modulus as its only statement input, so it can attest properties of N alone. Comments that described it as establishing safe-primality of NTilde's factors claimed more than that signature can deliver -- the factors never enter Verify, only their product does -- and it constrains neither h1 nor h2. What establishes <h1> == <h2> for a peer's ring is the two-directional DLN proof pair, verified in round 4. The comments now name that gate instead of the wrong one. How gates are cited. References that pointed at a file and a line number went stale as soon as an unrelated edit shifted the file: a comment-only change to one file invalidated seven such references elsewhere, generated mirrors included. Every one of them now cites the declaration (path#Decl) rather than a line number, so it survives edits above the target. Two costs are worth recording. A drift probe was run and did not separate the two reference forms at the window size chosen, so this commit does not claim symbolic references are measurably more drift-resistant -- only that the failure mode observed here cannot occur. And a declaration reference spans the whole declaration, so "off by N lines" is no longer expressible, and therefore no longer detectable either. Generated files are byte-identical apart from the comment text. Co-Authored-By: Claude Code <noreply@anthropic.com>

Commit:726937a
Author:ycen

fix: bind resharing peer NTilde to ModProof ECDSA resharing was the last ⚠️ P1 item in the ZKP audit. Keygen already linked peer NTilde to a Blum-integer ModProof in `6ba5e0d` (via `KGRound2Message2.nTildeModProof`, verified in ecdsa/keygen/round_3.go before NTildej is saved). Resharing didn't carry the same binding: `DGRound2Message1` shipped Paillier ModProof + NTilde + H1 + H2 + two DLN proofs, and round_4_new_step_2 saved NTildej / H1j / H2j after the Paillier and DLN checks — leaving NTilde itself only "locally plausible" rather than proven to be the safe-prime product the QR-group argument assumes. This commit mirrors the keygen pattern in resharing: - protob/ecdsa-resharing.proto: `DGRound2Message1` gains a `repeated bytes nTildeModProof = 8` field. Optional on the wire so v3-vintage peers that omit it can be accepted under `params.NoProofMod()`; v4 default mode (the production setting in this branch's e2e test, see `0f67b50` removing the resharing SetNoProofMod) requires the proof. - ecdsa/resharing/messages.go: `NewDGRound2Message1` takes the new `nTildeModProof` argument; `UnmarshalNTildeModProof` mirrors the keygen helper. - ecdsa/resharing/round_2_new_step_1.go: generate the proof alongside the Paillier ModProof, using the safe-prime factors derived from `LocalPreParams.P/Q` (same fix shape as keygen's `6ba5e0d`). - ecdsa/resharing/round_4_new_step_2.go: verify the proof in the same goroutine as the Paillier ModProof, attributing failures to the peer via `paiProofCulprits`. Honors `NoProofMod()` for v3 backward compatibility. Other regenerated `.pb.go` diffs in the commit are protoc-tooling churn from `make protob` rebuilding all protos; no semantic changes to other messages. Full e2e ecdsa/resharing and eddsa/resharing suites still pass. Closes the last ⚠️ P1 row in `_local_only/ZKP_BASIC_PROPERTY_AUDIT.md`. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

Commit:5946f07
Author:ycen

fix: prove NTilde structure during keygen (SRC-2026-754 / #11) Add a ModProof for each party's own NTilde to KGRound2Message2 so the receiver can verify that NTilde is a Blum-integer product of safe primes — closing the smooth-subgroup NTilde injection path that the existing 2048-bit bit-length check cannot detect. - protob/ecdsa-keygen.proto: new repeated bytes field `nTildeModProof` on KGRound2Message2 (proto field 3). - ecdsa/keygen/round_2.go: each peer creates a second ModProof using LocalPreParams.{P, Q} (the safe primes of NTilde, NOT the Paillier SK primes) and includes it in the round-2 broadcast. - ecdsa/keygen/round_3.go: verify the NTildeModProof against round.save.NTildej[j]. Backward compatible — peers shipping an empty NTildeModProof are accepted under the existing NoProofMod() compatibility branch with a warning log, matching the Paillier-N ModProof's compatibility handling. - ecdsa/keygen/messages.go: NewKGRound2Message2 takes the new proof and writes it into the wire field; adds UnmarshalNTildeModProof. Resharing path is unaffected (NTilde comes from the existing keygen save data); the smooth-N concern there is mitigated by the resharing round_4 bit-length gate added in B21. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

Commit:1a14f3a
Author:ZhAnGeek
Committer:GitHub

Ecdsa proof session byte (#256) * Add modProof in ECDSA-keygen * Reduce test param to reduce github workflow load * Add test fixtures * Fix EDDSA keygen example * Restore test fixtures * Compress modproof * use warning instead of fatal in logger to prevent panic * Add more checks in range proof * Regenerate preparams for older version * Reset test params and regenerate fixtures * Update ecdsa-resharing with Paillier key proofs * Add a switch to optional turn off Pai key proofs * Update README for caution of preparams updated * add: ecdsa proof session byte --------- Co-authored-by: ycen <yycen@live.com> Co-authored-by: ZhAnGeek <lecky.z@nodereal.io>

The documentation is generated from this commit.

Commit:1f7785a
Author:ycen

Update ecdsa-resharing with Paillier key proofs

Commit:4a3428b
Author:ycen

Add modProof in ECDSA-keygen

Commit:3d95e54
Author:ycen
Committer:GitHub

ECDSA protocol security updates (#252) * ECDSA protocol security updates * Update proofs.go * Limit y in Mta in range and prove * Add checks in proofFac * Add checks in MtA * Remove unnecessary assignments * Update unbiased reject sample * Make compatible for old parties with no facProof * Revert "Make compatible for old parties with no facProof" This reverts commit 4c9fa888180256f77380b4b49eebaa403dd783df. * Revised compatible for old parties with no facProof * Update facProof condition test * Allow empty proofFac, roll back rejectSample for compatibility --------- Co-authored-by: Wan Ziyi <40668033+Derrick-Wan@users.noreply.github.com>

Commit:7308ecd
Author:ycen

Revert "Make compatible for old parties with no facProof" This reverts commit 4c9fa888180256f77380b4b49eebaa403dd783df.

Commit:4c9fa88
Author:ycen

Make compatible for old parties with no facProof

Commit:b19124e
Author:ycen
Committer:ycen

ECDSA protocol security updates

Commit:b1c4838
Author:ycen

Add chaincode negoation in ecdsa-keygen

Commit:76a51ee
Author:ycen

Add dlnp proof into internal-mobile-wrapper

Commit:dc233a9
Author:Plamen Hristov

Fixed bad signature.proto

Commit:05b0624
Author:Plamen Hristov

Updated Google protobuf dependency and fixed type clash

Commit:1aa0a75
Author:Fitz
Committer:FitzLu

cherry pick > curve as parameter (#137) * move curve into tss.Parameters * regen proto with full package name * pass curve through parameter * add curve name in ecpoint json serialization

Commit:856d77b
Author:Fitz
Committer:GitHub

Curve as parameter (#137) * move curve into tss.Parameters * regen proto with full package name * pass curve through parameter * add curve name in ecpoint json serialization

Commit:78830ed
Author:FitzLu

regen proto with full package name

Commit:ed6f648
Author:froyobin
Committer:GitHub

remove unused paillier sk and avoid sender choosing h_1,h_2,Ntilde (#129) * remove unused paillier sk and fix the error in choosing h_1,h_2,Ntilde * remove the witness in keysign as the verifier only trust its own Ntilde,h1,h2 Co-authored-by: Ford Betelgeuse <ford.betelgeusedent@gmail.com>

Commit:aa7164a
Author:ackratos
Committer:ackratos

fix things for binance tss product

Commit:f896de9
Author:Ford Betelgeuse
Committer:Ford Betelgeuse

thorchain gg20

Commit:9d8889d
Author:cong
Committer:GitHub

Internal mobile wrapper eddsa (#124) * [R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict * Update readme about EdDSA (#91) * update readme about eddsa * minor fix * S in eddsa signature is not encoded correctly * fix msg in eddsa hasn't to be a int. * fix unit test * register DGRound4Message for eddsa resharing (#99) Co-authored-by: yutianwu <wzxingbupt@gmail.com> Co-authored-by: dylenfu <dylenfu@126.com>

Commit:6b19c75
Author:yutianwu
Committer:ackratos

[R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict

Commit:b2335ba
Author:Luke Plaster
Committer:Luke Plaster

ecdsa/signing: implement 'type 5' identified abort (blame)

Commit:3e35a67
Author:Luke Plaster

protob/eddsa-resharing: minor fix for eddsa protobuf name when regenerated

Commit:232b11e
Author:Luke Plaster

ecdsa/signing: simplify, use rSigmaI in FinalizeGetOurSigShare

Commit:90a8736
Author:Luke Plaster

eddsa/signing: add identifable abort for phase 7

Commit:f380443
Author:Luke Plaster

ecdsa/signing: add the one-round signing API

Commit:e03efd4
Author:Luke Plaster
Committer:Luke Plaster

ecdsa/signing: populate and save the one-round state struct

Commit:4d92512
Author:Luke Plaster

ecdsa/signing: implement round 5 ZKP of consistency between Rdash_i and E_i(k_i) ported from the kzen impl: https://git.io/Jf69a

Commit:b88bfac
Author:Luke Plaster

ecdsa/signing: implement the remaining rounds for gg20

Commit:51932c3
Author:Luke Plaster

ecdsa/signing: implement gg20 round 3

Commit:7ddac3f
Author:Luke Plaster

protob: update message defs for gg20

Commit:aad9998
Author:Luke Plaster

ecdsa/signing: rename 'theta' to 'delta' for correctness

Commit:da6040f
Author:Luke Plaster
Committer:Luke Plaster

protob: fix go package of signature protobuf source

Commit:abd66f8
Author:yutianwu
Committer:GitHub

[R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict

Commit:769ccf7
Author:Luke Plaster
Committer:Luke Plaster

[security] ecdsa: add proof of discrete log to prove that the two elements h_1, h_2 generate the same group mod N

Commit:1e5e2dd
Author:Luke Plaster
Committer:GitHub

[security] resharing: wait for final acks from the new committee before ending (#75) This is the fix for a vulnerability reported by Omer Shlomovits of KZen Networks (ZenGo). It adds a final ack round to the re-sharing protocol where the new committee sends acks to members of both the old and new committees before they save any data to disk. Other Changes: * readme: mention the UpdateFromBytes bool arg changes, misc edits * resharing: edit a comment in round 4 * remove the confusing to committee bools * resharing: remove a redundant line in round 5

Commit:570cd35
Author:Luke Plaster
Committer:Luke Plaster

protob: add copyright headers

Commit:641f146
Author:Luke Plaster
Committer:Luke Plaster

add SignatureData protobuf message to replace LocalSignData and use it in the mobile interface

Commit:69b9de0
Author:Luke Plaster
Committer:Luke Plaster

docs: add comments about PartyIDs

Commit:c6f5674
Author:Luke Plaster
Committer:Luke Plaster

protobuf: refactored message structure to include routing data in a wrapper message for mobile apps

Commit:e761090
Author:Luke Plaster
Committer:GitHub

resharing: remove unused big-X_j data/commitments (#66) * ecdsa/resharing: remove unused big-X_j data/commitments fixes #60

Commit:2629d2e
Author:Luke Plaster
Committer:Luke Plaster

ecdsa/regroup: rename to resharing

Commit:bfd8c29
Author:Luke Plaster
Committer:Luke Plaster

protob: improve messaging interfaces to abstract away protobufs

Commit:6ece436
Author:Luke Plaster
Committer:Luke Plaster

protob: WIP wire message format

Commit:d4d8eb1
Author:Luke Plaster
Committer:Luke Plaster

protob: WIP protobuf conversion - working signing and regroup

Commit:752ea52
Author:Luke Plaster
Committer:Luke Plaster

protob: WIP protobuf conversion

Commit:bcd330f
Author:Luke Plaster
Committer:Luke Plaster

protob: add initial protobuf defs