Conversation
Aliemeka
marked this pull request as draft
October 3, 2026 23:41
Aliemeka
force-pushed
the
fix/verify-blocks-before-storing-as-pending
branch
from
October 3, 2026 23:45
c7220cd to
18df6b2
Compare
Aliemeka
marked this pull request as ready for review
October 3, 2026 23:46
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🗒️ Description / Motivation
When a block arrives and its parent state is missing, the BlockChain actor writes it to the DB as pending (header, body, and proof, with no
LiveChainentry) so the cascade can import it once the parent lands. The P2P actor serves anything in those tables overBlocksByRoot.Before this PR, the only checks ahead of that write were that the slot is above finalized and not too far in the future. That had three consequences:
discard_pending_subtreeonly cleared the in-memory maps, so discarded pending blocks stayed on disk and kept being served.This PR validates a block before storing it as pending, deletes the rows of pending blocks that are discarded, and rejects children of blocks that failed the state transition.
What Changed
crates/blockchain/src/store.rsvalidate_pending_block, which runs every check that needs no parent state, cheapest first:AttestationData, and at mostMAX_ATTESTATIONS_DATAdistinct entries.proposer_indexis the slot's proposer.verify_block_signatures, so a forged block never reaches the SNARK verifier.validate_block_attestationsandvalidate_validator_indices, now shared byon_block_core,verify_block_signatures, and the pending path.StoreErrorvariants:InvalidParentRoot,ParentSlotNotBefore,ParentConflictsWithFinalized.crates/blockchain/src/lib.rsprocess_or_pend_blockvalidates beforeinsert_pending_block. A rejected block is logged and its waiting subtree is discarded.invalid_blocks: HashMap<H256, u64>field holding roots that failed the state transition. A block whose parent is in it is rejected before validation. Entries at or below the finalized slot are pruned after each block cascade.on_import_failure: on aStateTransitionFailederror it records the root and discards the block and its waiting children. Other failures are ignored.discard_pending_subtreenow deletes the stored rows of every block it discards.crates/blockchain/src/spec_test_runner.rscrates/storage/src/store.rsStore::delete_pending_block, which removes theBlockHeaders,BlockBodies, andBlockProofrows of a block that was never imported.docs/architecture.md,docs/data_storage.mdCorrectness / Behavior Guarantees
on_block_coreruns the same checks in the same order; the extraction is behavior-preserving.delete_pending_blockreturns early for any root with a state, and never touchesLiveChainorBlockRoots. This matters becausediscard_pending_subtreealso runs on blocks at or below the finalized slot, which can be canonical.invalid_blocksstays small. An entry requires a block that passed signature verification, so only a misbehaving validator can add one, and entries are pruned at finality.Out of Scope / Follow-ups
prune_old_block_proofsremoves its proof row after about a day, so it stops being served, but its header and body stay.BlocksByRangeblocks with a missing parent. Range sync starts at our head slot plus one, so an honest peer on a fork that split below our head sends exactly that. Dropping them would stop the node reorging onto that fork.Tests Added / Run
crates/storage: 3 tests fordelete_pending_blockcovering a pending block, an imported block, and an unknown root.crates/blockchain/src/store.rs:on_block_rejects_too_many_attestation_data, since the cap was only covered by the currently skipped spec fixtures.validate_pending_block_*tests: two acceptance cases, one rejection per check, and an invalid-proof rejection.crates/blockchain/src/lib.rs: 9 actor tests:validate_pending_block_core(.., verify: false), mirroringon_block_without_verification. Actor tests that need a block already pending set that state up directly. A real proof needs the leanVM prover.on_import_failureis tested directly, because reaching a real state transition failure needs a validly signed block. Its one-line call in the import failure arm is not covered.cargo test --profile release-fast -p ethlambda-blockchain -p ethlambda-storage --lib: all passingcargo clippy --profile release-fast -p ethlambda-blockchain -p ethlambda-storage --all-targets -- -D warnings: cleancargo check --profile release-fast --workspace --all-targets: cleanRelated Issues / PRs
crates/storage/src/store.rs, so whichever lands second may need a rebase.✅ Verification Checklist
make fmtmake lint(clippy with-D warnings)make test