Add ML-DSA-65 cold signing support and NEAR integration - #171
Conversation
- Cold wallet QR signing now accepts ML-DSA-65 responses (scheme detected by response length: 7219 bytes = ML-DSA-87, 5261 = ML-DSA-65), and cold-sign-sim can sign with either scheme. - New 'quantus near' commands (show-key, create-account, keys, send) let a Quantus ML-DSA-65 wallet solely control a NEAR sub-account, using NEAR protocol v85+ post-quantum access keys (borsh tag 2, sha3-256 key handle). - Minimal hand-rolled NEAR borsh wire types, JSON-RPC client, and tx signing with golden-vector tests. Co-authored-by: Cursor <cursoragent@cursor.com>
n13
left a comment
There was a problem hiding this comment.
Reviewer model: GPT-6 Sol
Verdict: Request changes. The NEAR wire layout and ML-DSA-65 signing path match the protocol reference, but the transfer command can report success without a successful transaction outcome.
- P2 — Reject missing or non-successful
send_txoutcomes (src/near/rpc.rs:81,208-215;src/cli/near.rs:409-411).call()converts an absent JSON-RPCresulttonull, andsend_tx()only rejectsstatus.Failure. A 200 response with noresult, or a result with missing/unfinishedstatus, therefore returnsOk;near sendthen prints “Transfer finalized” even though no finalized transfer was confirmed. Require a present result and an explicit successful final execution status before returningOk; reject unknown/unfinished shapes and cover those cases in an RPC test.
Validation: git diff --check and pinned cargo +nightly-2026-08-31 fmt --all -- --check passed. Eight focused NEAR tests and the ML-DSA-65 cold-signing test passed. The local library suite passed 372/373 tests; the unrelated batch-verifier test requires generated circuit binaries excluded by SKIP_CIRCUIT_BUILD=1. On GitHub, format, security, analysis, and macOS build/test passed; Ubuntu build/test and examples were pending at review time.
A 200 response with a missing result, missing/unfinished status, or a non-FINAL execution status no longer counts as success; near send and create-account only report success on an explicit finalized SuccessValue. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed the review: |
n13
left a comment
There was a problem hiding this comment.
Reviewer model: GPT-6 Sol
Verdict: Approve. The previous send_tx false-success finding is resolved. The current head rejects missing, failed, unfinished, and non-final execution outcomes before near send or create-account can report success. I found no blocking issues in the current diff.
Validation: git diff --check, cargo +nightly-2026-08-31 fmt --all -- --check, and SKIP_CIRCUIT_BUILD=1 cargo clippy --all-targets --locked -- -D warnings passed. All 15 focused NEAR tests and both cold-signature response tests passed. The NEAR key sizes, handle derivation, and wire tags were checked against NEP-645 and nearcore. A funded live account-creation test was not available. At posting time, GitHub format, security, and analysis checks had passed; macOS, Ubuntu, and examples were still running.
Summary
Part 1: ML-DSA-65 cold wallet signing
quantus cold-sign-simsigns with whichever scheme the wallet uses.verify_ml_dsa_65alongside the existing 87 verification insrc/chain/signing.rs(shared via macro).Part 2: NEAR integration (
quantus near)NEAR protocol v85 added ML-DSA-65 access keys, so a Quantus ML-DSA-65 wallet can directly control a NEAR account. New subcommands:
show-key— print the wallet's NEAR public key (ml-dsa-65:<bs58>) and its on-chain handle (ml-dsa-65-hash:<bs58>).create-account— create a NEAR sub-account whose only access key is the Quantus wallet's ML-DSA-65 key, funded/signed by a parent account's ed25519 credentials (near-cli JSON format). After creation it verifies viaview_access_key_listthat exactly one full-access key exists and it matches the wallet.keys— list an account's access keys.send— transfer NEAR, signed with the wallet's ML-DSA-65 key (pure FIPS 204, empty context, over sha256 of the borsh-encoded TransactionV0).Implementation uses minimal hand-rolled borsh wire types pinned to nearcore's layout (validated with hand-built byte goldens plus independently computed sha256/sha3 golden vectors) and a small JSON-RPC client with a protocol-version preflight — no heavy
near-*crate dependencies.Part 3: NEAR multisig from cold wallets
Roadmap only (no code) — documented in the planning doc; will build on the cold-signing scheme detection from Part 1.
Testing
ml_dsa_65verifier), and cold-signing scheme-detection tests../clippy.shclean.quantus near --helpsmoke-tested. Live testnet account creation not yet exercised (needs a funded parent account).Made with Cursor