Problem
The post-Hydra validate_cranks_instructions still accepts MagicRoot targets because program-specific restrictions apply only to the Magic Program.
Engine #137 will enforce privileged-call authorization. MBV should also reject these invalid tasks at admission, before queuing a scheduling request or creating a sponsored Hydra crank.
Reproduction
Source-inspected at PR #1369 head 3f3be050; no end-to-end exploit run:
- Supply a scheduled instruction targeting MagicRoot with otherwise permitted account metas.
validate_cranks_instructions skips program-specific validation.
ScheduleTask queues the accepted request.
This demonstrates the admission gap, not successful exploitation through Hydra.
Expected
Implement on top of #1369 after Engine #137 is available:
- Consume the Engine fix; reuse an existing dependency update if already present.
- Add a direct MagicRoot program-ID rejection in
validate_cranks_instructions, before the non-Magic-Program skip.
- Return
UnsupportedProgramId with a clear diagnostic.
- Adapt legitimate builtin MagicRoot calls to Engine’s explicit invocation API only where required. Never use that API for forwarded task payloads.
Keep the change local: no new validation framework, recursive payload decoder, scheduler redesign, or restoration of the removed crank executor.
Completion criteria:
- MagicRoot tasks fail before the scheduling request is queued.
- Ordinary permitted tasks remain accepted.
- Existing internal account creation still works with the hardened Engine.
- Focused regression coverage verifies rejection and permitted scheduling.
Context
Post-Hydra validation source.
Engine fix: magicblock-labs/magicblock-engine#137.
Implementation base: #1369; no dependency on #1554.
There are no dev deployments, and deployment will wait for Hydra. No separate pre-Hydra fix is needed.
Queue the new task-target restriction for docs/task-scheduler.md in the weekly documentation update.
Problem
The post-Hydra
validate_cranks_instructionsstill accepts MagicRoot targets because program-specific restrictions apply only to the Magic Program.Engine #137 will enforce privileged-call authorization. MBV should also reject these invalid tasks at admission, before queuing a scheduling request or creating a sponsored Hydra crank.
Reproduction
Source-inspected at PR #1369 head
3f3be050; no end-to-end exploit run:validate_cranks_instructionsskips program-specific validation.ScheduleTaskqueues the accepted request.This demonstrates the admission gap, not successful exploitation through Hydra.
Expected
Implement on top of #1369 after Engine #137 is available:
validate_cranks_instructions, before the non-Magic-Program skip.UnsupportedProgramIdwith a clear diagnostic.Keep the change local: no new validation framework, recursive payload decoder, scheduler redesign, or restoration of the removed crank executor.
Completion criteria:
Context
Post-Hydra validation source.
Engine fix: magicblock-labs/magicblock-engine#137.
Implementation base: #1369; no dependency on #1554.
There are no
devdeployments, and deployment will wait for Hydra. No separate pre-Hydra fix is needed.Queue the new task-target restriction for
docs/task-scheduler.mdin the weekly documentation update.