Author(s)
Satyawan Singh (GitHub: ss1738)
Experiences and qualifications
Background in Rust distributed systems and protocol correctness, with experience in property-based testing, fuzzing, and formal verification using Kani.
My directly relevant public work is ss1738/cargo-vouch on GitHub, which generates bounded Kani proof harnesses for Rust functions and reports BUG, UNGUARDED, VERIFIED, or INCONCLUSIVE rather than treating an incomplete analysis as a pass.
I’ve already built and previously run a working local prototype of this: a services-side generator using production OrderData::{hash_struct, uid}, signature::hashed_eip712_message, and EcdsaSignature::{sign, recover}, together with a cow-rs-side consumer that independently reproduces every value using cow-rs’s own functions. It currently has 57 cases. I also mutation-tested it by corrupting one expected value and confirming that the test failed on the correct case.
The prototype currently reconstructs the EthSign digest because services’ hashed_ethsign_message is private and cannot be reached from an external test. Milestone 1 includes resolving this duplicated logic, either by removing it or by adding an explicit equivalence check against the production implementation. I can provide the current prototype diff for technical review on request.
Grant Description
cow-rs’s currently committed test suite checks its OrderData hashing, EIP-712/EthSign signing digests, ECDSA recovery, and OrderUid packing against ethers.js fixtures, but it has no equivalent corpus generated by cowprotocol/services. mfw78 pointed me in this direction earlier in this thread: “the cow-rs properties/testing would be done against services, as that is ultimately where the data goes.”
This grant will add that missing conformance layer. A services-side generator will produce deterministic, versioned fixtures from the canonical implementation. A cow-rs integration test will consume those fixtures and verify the struct hash, signing digests, recovered owner, and OrderUid. Any future divergence will produce a CI failure tied to the exact vector.
The work is preventative compatibility hardening. The prototype has not found a current mismatch, but it demonstrates that the cross-repository check is practical and can be made reproducible.
Scope is narrow on purpose: EIP-712 and EthSign ECDSA signing only. EIP-1271, on-chain presign, and full orderbook acceptance are out of scope for this.
Type of Grant
Milestone-based.
Milestones
| Milestone | Title | Due date | Funding request |
|---|---|---|---|
| 1 | services-side fixture generator, scaled and accepted upstream | 3 weeks after maintainer greenlight | $3,000 |
| 2 | cow-rs consumer test, source-lock update, CI and documentation, accepted upstream | 2 weeks after Milestone 1 | $2,500 |
Specifics: Milestone 1
Scale the existing 57-case prototype to 64-128 vectors and address the remaining gaps: explicit v ∈ {0,1,27,28} recovery-ID normalisation (the prototype currently exercises only 27/28), the EthSign duplication described above, and a versioned schema with deterministic regeneration. I will first open the tracking issue required by services’ CONTRIBUTING.md. The milestone timeline will begin only after that issue receives maintainer approval.
Specifics: Milestone 2
Wire the generated fixture into a cow-rs integration test, update the stale services SHA pin in parity/source-lock.toml (currently 47af30fe..., from 2026-05-13, four months old at the time of writing), document how to regenerate the fixture, and add the test to CI so that future drift produces a visible test failure.
Length
Work will start after both successful Snapshot approval and the required repository approval, whichever happens later. Expected implementation time is 5 weeks from that point. Upstream review time outside my control may extend final acceptance.
Funding Request
$5,500 total, milestone-based as above, in xDAI. No COW tokens requested. The funding covers a maintainer-approved fixture design in services, recovery-ID coverage, removal or explicit validation of the duplicated EthSign path, deterministic schema and regeneration tooling, the cow-rs consumer, CI integration, documentation, and review revisions across both repositories.
Gnosis Chain Address
0xAda6BB4C99bc5A20479bbb790bfb84Edd7C41e20
Terms and Conditions
By submitting this grant application, I acknowledge and agree to be bound by the CoW DAO Participation Agreement (https://gateway.pinata.cloud/ipfs/Qmf9MYhcG2pFrDoVy13p6FWeVF4nG9HbJvRfYYbhazTCFe) and the CoW DAO Grant Agreement Terms (https://bafkreifcftgaleyxkekkic36beyveiomqmlwyduyfh3s25zj3uyngr6ht4.ipfs.dweb.link/).
Please notify the Grantee of their reviewer and their steward in the thread and latest upon successful approval of the Grant on Snapshot.