Signer: allow forwarded signers not to sign the authorization message - #70
Open
mcintyre94 wants to merge 1 commit into
Open
mcintyre94 wants to merge 1 commit into
mcintyre94 wants to merge 1 commit into
Conversation
Currently a forwarded signer, ie a signer required for the execution message not provided as a PDA signer, is required to sign twice. They must sign the authorization message, because the `Submit` instruction of the signer program verifies its signatures. They must also sign the relay message containing that instruction, because nothing else can promote them to be a signer. This is workable if the forwarded signer is a hot keypair, the `transaction submit` CLI command was able to hide this complexity. But if a forwarded signer is required to stay offline, as is the case for migrating valuable assets to a PDA, this is a very challenging UX This commit updates the verification logic. We now require only that all required signers of the authorization message have either provided a signature for the authorization message (eg. `transaction sign`), or are signers on the relay transaction. However, we only promote the PDA to a signer for those that have provided a signature for the authorization message. Signing the relay transaction only, does not promote your PDA to signer. This prevents CPI to the signer program being used to promote the PDA for an authorization message without explicit signoff The result of this is: - A signer that is only authorising a PDA must sign the authorization message, eg using `transaction sign`, as before. It does not need to sign the relay transaction, as before - A signer that is a required signer of the authorization message itself must sign the relay transaction, as before. It no longer needs to provide a signature on the authorization message, but the authorization message is part of the relay transaction that it has signed - In the case of an account that is both used as a required signer itself, and authorizing a PDA, it still must sign both the authorization message and the relay transaction
mcintyre94
force-pushed
the
submit-double-sign
branch
from
September 30, 2026 17:55
2a88972 to
8f11fbf
Compare
56 of 98 tasks
mcintyre94
added this pull request to stack #72
October 1, 2026 16:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Currently a forwarded signer, ie a signer required for the execution message not provided as a PDA signer, is required to sign twice. They must sign the authorization message, because the
Submitinstruction of the signer program verifies its signatures. They must also sign the relay message containing that instruction, because nothing else can promote them to be a signer.This is workable if the forwarded signer is a hot keypair, the
transaction submitCLI command was able to hide this complexity. But if a forwarded signer is required to stay offline, as is the case for migrating valuable assets to a PDA, this is a very challenging UXThis commit updates the verification logic. We now require only that all required signers of the authorization message have either provided a signature for the authorization message (eg.
transaction sign), or are signers on the relay transaction. However, we only promote the PDA to a signer for those that have provided a signature for the authorization message. Signing the relay transaction only, does not promote your PDA to signer. This prevents CPI to the signer program being used to promote the PDA for an authorization message without explicit signoffThe result of this is:
transaction sign, as before. It does not need to sign the relay transaction, as beforeThe primary benefit is to make migration far simpler. Suppose we're migrating a stake account withdrawer using a current durable nonce. We have as forwarded signers the current withdrawer, the durable nonce authority, and potentially a custodian. All of these could be different accounts and could be required to sign offline. These all now only need to sign once: on the relay transaction at the very end. They no longer need to separately provide a signature for the authorisation message.
If one of them (likely the withdrawer) is chosen to be the authority for the new PDA, then they will also need to sign the authorisation message. This is unchanged. But in the case of a migrate, this will almost certainly be at most 1 address needing to sign twice, and can easily be avoided by using a new account as the PDA authority. It is now possible to avoid needing to sign twice, while before this was necessary for all forwarded signers.