Skip to content

Signer: allow forwarded signers not to sign the authorization message - #70

Open
mcintyre94 wants to merge 1 commit into
mainfrom
submit-double-sign
Open

mcintyre94 wants to merge 1 commit into
mainfrom
submit-double-sign

Conversation

@mcintyre94

@mcintyre94 mcintyre94 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Currently a forwarded signer, ie a signer required for the execution message not provided as a PDA signer, is required to sign twice. They must sign the authorization message, because the Submit instruction of the signer program verifies its signatures. They must also sign the relay message containing that instruction, because nothing else can promote them to be a signer.

This is workable if the forwarded signer is a hot keypair, the transaction submit CLI command was able to hide this complexity. But if a forwarded signer is required to stay offline, as is the case for migrating valuable assets to a PDA, this is a very challenging UX

This commit updates the verification logic. We now require only that all required signers of the authorization message have either provided a signature for the authorization message (eg. transaction sign), or are signers on the relay transaction. However, we only promote the PDA to a signer for those that have provided a signature for the authorization message. Signing the relay transaction only, does not promote your PDA to signer. This prevents CPI to the signer program being used to promote the PDA for an authorization message without explicit signoff

The result of this is:

  • A signer that is only authorising a PDA must sign the authorization message, eg using transaction sign, as before. It does not need to sign the relay transaction, as before
  • A signer that is a required signer of the authorization message itself must sign the relay transaction, as before. It no longer needs to provide a signature on the authorization message, but the authorization message is part of the relay transaction that it has signed
  • In the case of an account that is both used as a required signer itself, and authorizing a PDA, it still must sign both the authorization message and the relay transaction

The primary benefit is to make migration far simpler. Suppose we're migrating a stake account withdrawer using a current durable nonce. We have as forwarded signers the current withdrawer, the durable nonce authority, and potentially a custodian. All of these could be different accounts and could be required to sign offline. These all now only need to sign once: on the relay transaction at the very end. They no longer need to separately provide a signature for the authorisation message.

If one of them (likely the withdrawer) is chosen to be the authority for the new PDA, then they will also need to sign the authorisation message. This is unchanged. But in the case of a migrate, this will almost certainly be at most 1 address needing to sign twice, and can easily be avoided by using a new account as the PDA authority. It is now possible to avoid needing to sign twice, while before this was necessary for all forwarded signers.

Currently a forwarded signer, ie a signer required for the execution
message not provided as a PDA signer, is required to sign twice. They
must sign the authorization message, because the `Submit` instruction of
the signer program verifies its signatures. They must also sign the
relay message containing that instruction, because nothing else can
promote them to be a signer.

This is workable if the forwarded signer is a hot keypair, the
`transaction submit` CLI command was able to hide this complexity. But
if a forwarded signer is required to stay offline, as is the case for
migrating valuable assets to a PDA, this is a very challenging UX

This commit updates the verification logic. We now require only that all
required signers of the authorization message have either provided a
signature for the authorization message (eg. `transaction sign`), or are
signers on the relay transaction. However, we only promote the PDA to a
signer for those that have provided a signature for the authorization
message. Signing the relay transaction only, does not promote your PDA
to signer. This prevents CPI to the signer program being used to promote
the PDA for an authorization message without explicit signoff

The result of this is:

- A signer that is only authorising a PDA must sign the authorization
  message, eg using `transaction sign`, as before. It does not need to
  sign the relay transaction, as before
- A signer that is a required signer of the authorization message itself
  must sign the relay transaction, as before. It no longer needs to
  provide a signature on the authorization message, but the
  authorization message is part of the relay transaction that it has
  signed
- In the case of an account that is both used as a required signer
  itself, and authorizing a PDA, it still must sign both the
  authorization message and the relay transaction
@mcintyre94 mcintyre94 mentioned this pull request Oct 1, 2026
56 of 98 tasks
@mcintyre94
mcintyre94 added this pull request to stack #72 October 1, 2026 16:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant