diff --git a/docs/erc7730-compiled-format.md b/docs/erc7730-compiled-format.md index 434374a3..2c0b5aaa 100644 --- a/docs/erc7730-compiled-format.md +++ b/docs/erc7730-compiled-format.md @@ -43,6 +43,14 @@ the exact canonical program. The delegate certificate binds that signature to one chain and the compiled-in KeepKey root; the purpose prefix prevents replay as v1-v4 ClearSign metadata. +On-demand offsets address this complete envelope, with offset zero at `K773`. +The definition id is SHA-256 of the complete envelope and does not make +individual ranges independently authentic. Firmware rereads an accepted +definition as a contiguous offset-zero stream, hashes and validates the full +envelope again, and stages bounded interpreter results until that replay has +matched the accepted definition id. No display result derived from replayed +bytes becomes authoritative before the final match. + ## Canonical program header The format-1 header is exactly 179 bytes. diff --git a/messages-ethereum.proto b/messages-ethereum.proto index 5c211509..a700b157 100644 --- a/messages-ethereum.proto +++ b/messages-ethereum.proto @@ -420,7 +420,10 @@ message EthereumClearSignDefinitionAck { * The lookup tuple is authenticated again from the returned definition; these * fields select an entry but never grant trust. selector_or_type_hash is four * bytes for calldata, 32 bytes for EIP-712, and omitted for token/network - * lookups. + * lookups. Offsets address the complete signed envelope, beginning at K773. + * A definition_id commits to the entire envelope, not independently + * authenticated ranges, so firmware verifies a contiguous offset-zero replay + * before consuming its program bytes for display. * @next EthereumClearSignDefinitionChunk * @next Failure */ @@ -435,7 +438,12 @@ message EthereumClearSignDefinitionRequest { optional uint32 recursion_depth = 8; } -/** Host response to an on-demand definition request. */ +/** + * Host response to an on-demand definition request. Chunks are contiguous and + * offset is relative to the complete signed envelope. Program bytes remain + * untrusted until the complete replay hashes to definition_id and its catalog + * authentication verifies. + */ message EthereumClearSignDefinitionChunk { required bytes definition_id = 1; required uint32 offset = 2;