Skip to content

Reject MagicRoot targets in scheduled tasks #1674

Description

@bmuddha

Problem

The post-Hydra validate_cranks_instructions still accepts MagicRoot targets because program-specific restrictions apply only to the Magic Program.

Engine #137 will enforce privileged-call authorization. MBV should also reject these invalid tasks at admission, before queuing a scheduling request or creating a sponsored Hydra crank.

Reproduction

Source-inspected at PR #1369 head 3f3be050; no end-to-end exploit run:

  1. Supply a scheduled instruction targeting MagicRoot with otherwise permitted account metas.
  2. validate_cranks_instructions skips program-specific validation.
  3. ScheduleTask queues the accepted request.

This demonstrates the admission gap, not successful exploitation through Hydra.

Expected

Implement on top of #1369 after Engine #137 is available:

  • Consume the Engine fix; reuse an existing dependency update if already present.
  • Add a direct MagicRoot program-ID rejection in validate_cranks_instructions, before the non-Magic-Program skip.
  • Return UnsupportedProgramId with a clear diagnostic.
  • Adapt legitimate builtin MagicRoot calls to Engine’s explicit invocation API only where required. Never use that API for forwarded task payloads.

Keep the change local: no new validation framework, recursive payload decoder, scheduler redesign, or restoration of the removed crank executor.

Completion criteria:

  • MagicRoot tasks fail before the scheduling request is queued.
  • Ordinary permitted tasks remain accepted.
  • Existing internal account creation still works with the hardened Engine.
  • Focused regression coverage verifies rejection and permitted scheduling.

Context

Post-Hydra validation source.

Engine fix: magicblock-labs/magicblock-engine#137.
Implementation base: #1369; no dependency on #1554.

There are no dev deployments, and deployment will wait for Hydra. No separate pre-Hydra fix is needed.

Queue the new task-target restriction for docs/task-scheduler.md in the weekly documentation update.

Activity

  1. self-assigned this
    on Sep 15, 2026
  2. added theissue type on Sep 15, 2026
  3. bmuddha commented on Sep 16, 2026

    @bmuddha
    CollaboratorAuthor

    Closing as superseded by Engine 0.7.0 (resolved revision c77877d67335a48fefc1df9b9cbc314663334b18), which includes magicblock-labs/magicblock-engine#138.

    MagicRoot CPI now requires the trusted builtin-only native_invoke_magic_root entrypoint. Ordinary native_invoke_as / native_invoke_signed forwarding does not grant authorization, even in validator-signed transactions. Authorization is bound to the exact child instruction-trace index, not stack depth: it does not propagate to descendants, later siblings, or PostFinalize actions, and the previous scope is restored on success and failure. Top-level authority-signed MagicRoot operations remain intentionally permitted.

    The additional task-target rejection proposed here would only provide early admission failure, not close a remaining CPI authorization gap. We are intentionally not adding that redundant policy check. Trusted builtins must never forward arbitrary task/callback payloads through the privileged entrypoint.

    The redundant MagicRoot callback-destination ban from 3dcc014 has also been removed locally (not yet committed/pushed). Callback signer/account restrictions and the independent source-to-destination provenance checks from 8329c539 remain unchanged; Engine does not replace those provenance checks.

    Validation: all seven existing Engine MagicRoot tests passed at the resolved revision, covering ordinary forwarding rejection, exact-child/nested/sibling/PostFinalize scope, failure cleanup, and legitimate internal account creation. MBV formatting and cargo check -p magicblock-program --tests passed. No end-to-end Hydra exploit test was run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions