Polkadot Technical Fellowship Application: Hillary Chima

14d ago
3

Background

I'm an open-source developer and regular contributor to the polkadot-sdk. Most of my work is on the runtime: storage invariants, migrations, transaction validity, asset id allocation and parachain onboarding.

I came to this through security. At Web3Bridge I did penetration testing and code review of dApps, non-custodial wallets and EVM contracts, and most of what I found were rules people relied on that the code didn't actually enforce: signature replay, EIP-712 payload tampering, authentication bypass in SIWE and WalletConnect flows, and state-synchronisation flaws in multi-step transactions. For the runtime itself, I learned from the polkadot-sdk docs, Substrate Stack Exchange and the Runtime Developer Guide, whose live sessions I joined for a while, and most of all from reading other people's pull requests and the reviews on them.

Motivations

I've started reviewing runtime changes, and as a member of the Fellowship I'd like to take on more of that work, help move RFCs forward, and learn from people who have been doing this much longer than I have.

Outside that work, my ongoing engineering practice PSYKYODAI works where coordination fails. It currently focuses on supply chain, where the carrier writes the only record of where goods are, and the plan is to anchor both the carrier's readings and the shipper's own on Polkadot.

Area(s) of interest in relation to the Polkadot ecosystem

  • FRAME/Runtime
  • JAM

Contribution(s) to Polkadot SDK

Merged

#13031 frame-support: fix CountedStorageMap and CountedStorageNMap counter drift

Reported in #12782 by the Runtime Whitebox Fuzzer as medium severity: pallets that bound, migrate or bill by a map's count saw more keys than were stored, and the error never cleared. Appending to an existing key raised the counter even though no key was added. I added the same contains_key guard that append uses, with a test on count().

#12378 pallet-assets: force_create with an arbitrary asset id under auto-increment

Raised in #12302: governance could be front-run when creating an asset. With auto-increment on, a forced creation had to use the next id in the sequence, so anyone creating an asset first took that id and made the governance call fail. The same rule kept Asset Hub from reserving id ranges for system assets below its 50,000,000 start. I let ForceOrigin create at any unused id while the sequence keeps running.

#12369 pallet-asset-conversion: per-pair swap fee

Requested in #12301: every pool paid the same swap fee, 0.3% on Asset Hub, though stable pairs and volatile pairs warrant different fees. I added an optional per-pool fee that falls back to the global one, with no migration and no change for existing pools. It is set through a separate create_pool_with_fee call, so create_pool keeps its encoding.

#12288 binary-merkle-tree: preallocate the proof vector

Raised in #9106: building a merkle proof reallocated its vector as it grew, though its final length, ⌈log2 n⌉, is known before the first step. The crate backs BEEFY MMR proofs and the bridges' BEEFY primitives. I allocate the proof at that length from the start.

#9107 pallet-proxy: creation block in PureCreated

Reported by Nova Wallet in #9066: after the Asset Hub migration, wallets and indexers could not easily find the relay-chain block a pure proxy was created in, and killing the proxy requires it. I added that block to the creation event, taken from the pallet's BlockNumberProvider.

Open

#12452 pallet-whitelist: permissionless authorized dispatch, implementing RFC #12224

Asset Hub governance can whitelist a relay-chain call by hash in a small XCM message, but someone still has to dispatch the full call on the relay chain, and the RFC lets anyone do it unsigned and fee-free. I added #[pallet::authorize] to both dispatch calls and moved to pool admission every check the dispatch would otherwise fail with nobody charged: runtime opt-in, the hash, a decodable preimage, and weight within the witness.

#12690 paras: remove the validation-code sentinel from UpcomingParasGenesis

Follows an inline note left from polkadot#4457: parachain onboarding overwrote the stored validation code with an empty vector and read that emptiness as "code already inserted". I replaced it with a dedicated UpcomingParaGenesis holding only the genesis head and para kind, plus a versioned migration from 0 to 1 for Westend and Rococo that links the code hash of any legacy entry, as enactment did.

All pull requests: paritytech/polkadot-sdk, author PSYKYODAI

Reviews

polkadot-fellows/runtimes#1233 Integrate Individuality into People and Asset Hub Polkadot (merged)

The upgrade's migration creates the PGAS asset at a fixed id, which Asset Hub's auto-increment ids reject without #12378 above. That fix was not in the 2604 release the runtimes build on, so the upgrade would have shipped with no PGAS asset and every PGAS flow dead. A backport or workaround was requested as urgent.

I proposed a runtime-side migration instead of a backport: take NextAssetId, create PGAS, restore the counter, with a try-runtime check that the asset exists. I also noted what it leaves open. The two id ranges are then separated only by distance, so create stalls if the sequence reaches 2,000,000,000, and once #12378 is pinned its default allocator would move later permissionless ids into the reserved range. For that I proposed a ReservedFloorAllocator bounded by a floor governance can raise through pallet-parameters. The migration was adopted in 2e987a5 and the PR merged.

Link to the GitHub profile of the applicant

https://github.com/PSYKYODAI

Polkadot address with a verified on-chain identity

14miiyFptygSQMQUoeU8QJXHPYnb5JXSTDHMTiWNnwcxHYU1

Applicant
Reply
Up
Share
Comments