Verifying Bytecode
Overview
bake prove verifies that the on-chain binary matches what the Recipe Book says was deployed. This is cryptographic proof, not just "is the account executable."
The verification process
- Fetch ProgramData โ get the account's data bytes
- Skip header โ the ProgramData account has a header that's not part of the binary
- Parse ELF64 header โ determine the exact binary length from the ELF header
- Hash โ compute SHA-256 of the binary portion
- Compare โ match against the recorded build hash in the Recipe Book
Why this is hard
The naive approach ("hash all the bytes") fails because:
- ProgramData accounts have headers that aren't part of the binary
- ELF64 binaries have variable-length headers
- Trailing zeros can't be stripped heuristically
The correct approach:
- Skip the fixed-size ProgramData header
- Parse the ELF64
e_phoffande_phnumfields to find the program header table - Use
e_entry+ program headers to determine exact binary length - Hash only the binary bytes
Implementation
The exact computation is in the CLI's src/lib/deployPipeline.ts (fetchOnChainBytecodeHash). This went through two real bugs during development:
- Wrong header byte count โ initially skipped too few bytes
- Flawed trailing-zero stripping โ tried to strip trailing zeros, which broke on legitimate zero-padded sections
The current approach is verified against real deployments.
Dashboard verification
The bakeacookie dashboard performs the same verification for the "live status strip" on program pages. It uses the exact same logic as the CLI โ ported, not reimplemented.
Level 2: Full reproducibility
bash
bake prove --rebuild
Goes further by:
- Checking out the exact commit from the Recipe Book
- Rebuilding from source
- Comparing the rebuilt binary against the on-chain binary
This proves source โ binary โ on-chain integrity.