Skip to content

Bound block reference parsing depth - #4030

Merged
masih merged 2 commits into
mainfrom
masih/freeze-bound-block-ref-recu
Aug 27, 2026
Merged

masih merged 2 commits into
mainfrom
masih/freeze-bound-block-ref-recu

Conversation

@masih

@masih masih commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

Limit nested EIP-1898 block references to 16 levels to prevent quadratic parsing time on deeply nested inputs. Add boundary coverage.

Fixes PLT-1083

Limit nested EIP-1898 block references to 16 levels to prevent
quadratic parsing time on deeply nested inputs. Add boundary coverage.
@masih
masih marked this pull request as ready for review August 27, 2026 10:43
@masih masih added backport release/v6.6 Backport to release v6.6 backport release/v6.7 Backport to release v6.7 labels Aug 27, 2026
@codecov

codecov Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.00000% with 9 lines in your changes missing coverage. Please review.
✅ Project coverage is 60.34%. Comparing base (b117536) to head (b684c55).
⚠️ Report is 6 commits behind head on main.

Files with missing lines Patch % Lines
cmd/frozen-rpc-router/router.go 80.48% 4 Missing and 4 partials ⚠️
cmd/frozen-rpc-router/main.go 0.00% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #4030      +/-   ##
==========================================
- Coverage   61.34%   60.34%   -1.01%     
==========================================
  Files        2163     2064      -99     
  Lines      188757   177173   -11584     
==========================================
- Hits       115792   106912    -8880     
+ Misses      62256    60491    -1765     
+ Partials    10709     9770     -939     
Flag Coverage Δ
sei-chain-pr 60.63% <80.00%> (?)
sei-db 69.80% <ø> (ø)
sei-db-state-db ?

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
cmd/frozen-rpc-router/config.go 80.95% <100.00%> (+1.46%) ⬆️
cmd/frozen-rpc-router/main.go 0.00% <0.00%> (ø)
cmd/frozen-rpc-router/router.go 64.21% <80.48%> (+0.44%) ⬆️

... and 99 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@masih
masih requested a review from codchen August 27, 2026 10:44
@cursor

cursor Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes request parsing on the RPC routing hot path; mis-tuning depth could alter routing for unusually nested block refs, but the change is primarily DoS hardening with a conservative default.

Overview
Adds a configurable cap on how deeply the router unwraps nested EIP-1898 {"blockNumber": ...} objects when parsing block parameters for routing (eth_getLogs, eth_feeHistory, and block-tagged methods).

parseBlockReference is now a router method that iterates with a maxBlockReferenceDepth limit (default 16, flag --max-block-reference-depth) instead of unbounded recursion. References deeper than the limit resolve to an empty reference, which affects upstream selection the same as an unparseable block. Config and newRouter validate that the depth is positive; tests cover flag parsing and the depth boundary.

Reviewed by Cursor Bugbot for commit b684c55. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

github-actions Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedAug 27, 2026, 11:12 AM

@masih
masih requested a review from sei-will August 27, 2026 10:45

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Converts the recursive EIP-1898 block-reference parser into a loop bounded at 16 nesting levels, removing the quadratic parse cost and stack-depth exposure while keeping over-depth inputs on the existing "unparseable reference routes live" path. The boundary is off-by-one correct and the new test pins both the accepted (16) and rejected (17) cases.

Findings: 0 blocking | 0 non-blocking | 0 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • None at the file/PR level.

Comment thread cmd/frozen-rpc-router/router.go Outdated
@masih
masih requested a review from codchen August 27, 2026 11:11
@masih

masih commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator Author

@seidroid review

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bounds EIP-1898 block-reference parsing to a configurable nesting depth (default 16), replacing unbounded recursion with a loop; the boundary arithmetic, fallback routing, and validation at both the flag and router construction paths all check out, with test coverage on each. No findings.

Findings: 0 blocking | 0 non-blocking | 0 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • None at the file/PR level.

@masih
masih added this pull request to the merge queue Aug 27, 2026
Merged via the queue into main with commit bafdcf3 Aug 27, 2026
72 checks passed
@masih
masih deleted the masih/freeze-bound-block-ref-recu branch August 27, 2026 14:29
@seidroid

seidroid Bot commented Aug 27, 2026

Copy link
Copy Markdown

Successfully created backport PR for release/v6.6:

@seidroid

seidroid Bot commented Aug 27, 2026

Copy link
Copy Markdown

Successfully created backport PR for release/v6.7:

masih added a commit that referenced this pull request Aug 27, 2026
Backport of #4030 to `release/v6.6`.

Co-authored-by: Masih H. Derkani <m@derkani.org>
masih added a commit that referenced this pull request Aug 27, 2026
Backport of #4030 to `release/v6.7`.

Co-authored-by: Masih H. Derkani <m@derkani.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport release/v6.6 Backport to release v6.6 backport release/v6.7 Backport to release v6.7 non-app-hash-breaking

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants