Skip to content

Backport release/v6.7: Bound block reference parsing depth - #4035

Merged
masih merged 1 commit into
release/v6.7from
backport-4030-to-release/v6.7
Aug 27, 2026
Merged

masih merged 1 commit into
release/v6.7from
backport-4030-to-release/v6.7

Conversation

@seidroid

@seidroid seidroid Bot commented Aug 27, 2026

Copy link
Copy Markdown

Backport of #4030 to release/v6.7.

Limit nested EIP-1898 block references to 16 levels to prevent quadratic
parsing time on deeply nested inputs. Add boundary coverage.

Fixes PLT-1083

(cherry picked from commit bafdcf3)
@github-actions

github-actions Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedAug 27, 2026, 2:57 PM

@codecov

codecov Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.00000% with 9 lines in your changes missing coverage. Please review.
✅ Project coverage is 60.34%. Comparing base (b117536) to head (6ce2194).

Files with missing lines Patch % Lines
cmd/frozen-rpc-router/router.go 80.48% 4 Missing and 4 partials ⚠️
cmd/frozen-rpc-router/main.go 0.00% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@               Coverage Diff                @@
##           release/v6.7    #4035      +/-   ##
================================================
- Coverage         61.34%   60.34%   -1.01%     
================================================
  Files              2163     2064      -99     
  Lines            188757   177173   -11584     
================================================
- Hits             115792   106912    -8880     
+ Misses            62256    60491    -1765     
+ Partials          10709     9770     -939     
Flag Coverage Δ
sei-chain-pr 60.63% <80.00%> (?)
sei-db 69.80% <ø> (ø)
sei-db-state-db ?

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
cmd/frozen-rpc-router/config.go 80.95% <100.00%> (+1.46%) ⬆️
cmd/frozen-rpc-router/main.go 0.00% <0.00%> (ø)
cmd/frozen-rpc-router/router.go 64.21% <80.48%> (+0.44%) ⬆️

... and 99 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@cursor

cursor Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Small, localized hardening of RPC request parsing with a safe default; routing behavior only changes for abnormally deep nested block references.

Overview
Adds a configurable cap on how deeply the frozen RPC router unwraps nested EIP-1898-style {"blockNumber": ...} block parameters when choosing live vs frozen upstreams.

--max-block-reference-depth (default 16) is wired through config into the router; non-positive values are rejected at startup. parseBlockReference is now a router method that iterates up to that limit instead of recursing without bound; references nested one level beyond the limit resolve as unknown (empty reference), which keeps routing on the live node rather than spinning on pathological JSON.

Tests cover flag parsing, rejection of zero depth, and behavior at exactly the limit vs one level over.

Reviewed by Cursor Bugbot for commit 6ce2194. Bugbot is set up for automated code reviews on this repo. Configure here.

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The automated review did not complete; see the failing AI Review check for details.

@alexander-sei
alexander-sei self-requested a review August 27, 2026 14:57
@masih
masih merged commit e93e56c into release/v6.7 Aug 27, 2026
108 of 115 checks passed
@masih
masih deleted the backport-4030-to-release/v6.7 branch August 27, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants