Skip to content

Backport release/v6.7: Fix FlatKV state sync bad-hash scenario. - #4377

Merged
masih merged 3 commits into
release/v6.7from
backport-4370-to-release/v6.7
Sep 29, 2026
Merged

masih merged 3 commits into
release/v6.7from
backport-4370-to-release/v6.7

Conversation

@seidroid

@seidroid seidroid Bot commented Sep 29, 2026

Copy link
Copy Markdown

Backport of #4370 to release/v6.7.

@seidroid

seidroid Bot commented Sep 29, 2026

Copy link
Copy Markdown
Author

Please cherry-pick the changes locally and resolve any conflicts.

git fetch origin backport-4370-to-release/v6.7
git worktree add --checkout .worktree/backport-4370-to-release/v6.7 backport-4370-to-release/v6.7
cd .worktree/backport-4370-to-release/v6.7
git reset --hard HEAD^
git cherry-pick -x 712fa98e10eb7dd3c245df4d155c4f6cbbd7a7bb
git push --force-with-lease

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedSep 29, 2026, 6:02 PM

@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.55%. Comparing base (3558509) to head (c9dc93d).

Additional details and impacted files

Impacted file tree graph

@@               Coverage Diff                @@
##           release/v6.7    #4377      +/-   ##
================================================
- Coverage         61.37%   60.55%   -0.82%     
================================================
  Files              2163     2081      -82     
  Lines            189080   179949    -9131     
================================================
- Hits             116051   108976    -7075     
+ Misses            62295    60942    -1353     
+ Partials          10734    10031     -703     
Flag Coverage Δ
sei-chain-pr 33.18% <100.00%> (?)
sei-db 69.80% <ø> (ø)
sei-db-state-db ?
sei-db-state-db-pr 76.49% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
sei-db/state_db/sc/flatkv/exporter.go 81.08% <ø> (ø)
sei-db/state_db/sc/flatkv/importer.go 92.03% <100.00%> (+0.78%) ⬆️
sei-db/state_db/sc/flatkv/store.go 79.28% <100.00%> (+0.19%) ⬆️
...cmd/seidb/operations/import_flatkv_from_memiavl.go 41.42% <100.00%> (ø)

... and 111 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@cody-littley

Copy link
Copy Markdown
Contributor

@seidroid review

@cody-littley
cody-littley marked this pull request as ready for review September 29, 2026 15:49
@cursor

cursor Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

PR Summary

High Risk
Changes state-sync import validation and LtHash integrity boundaries; incorrect ordering or caller choice between Importer vs TrustedImporter could break restores or leave a bad hash undetected on trusted paths.

Overview
Hardens FlatKV state sync by treating strictly ascending physical key order as part of the snapshot contract and rejecting imports that violate it.

CommitStore.Importer (untrusted peers / state sync) now wires KVImporter with ascending-key checks in dispatch: duplicate keys and out-of-order keys fail the import and do not finalize the store. TrustedImporter skips that check for offline migrations (e.g. memiavl → FlatKV), which may emit keys in arbitrary order. Exporter comments document the required global lexicographic order.

New tests cover duplicate-key rejection (LtHash wrap attack), descending-key rejection, and trusted import behavior; existing import tests feed nodes via addNodesInKeyOrder.

Reviewed by Cursor Bugbot for commit c9dc93d. Bugbot is set up for automated code reviews on this repo. Configure here.

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a clean backport of #4370. CommitStore.Importer, which handles untrusted state-sync data, now rejects the import unless physical keys arrive in strictly ascending order. That closes the gap where a peer could repeat a forged pair until its LtHash limbs wrapped to zero, so it no longer changes the root hash. The offline memiavl→FlatKV migration switches to the new TrustedImporter, which accepts keys in any order. The check sits in the single dispatch loop that every node passes through. KVExporter already emits keys in that order through RawGlobalIterator, and the tests that fed keys out of order now sort them first. I found nothing blocking.

Findings: 0 blocking | 0 non-blocking | 0 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • None at the file/PR level.

@masih
masih enabled auto-merge (squash) September 29, 2026 18:00
@masih
masih merged commit 8a4dff3 into release/v6.7 Sep 29, 2026
72 checks passed
@masih
masih deleted the backport-4370-to-release/v6.7 branch September 29, 2026 18:21
masih pushed a commit that referenced this pull request Oct 1, 2026
Adds the `release/v6.7` entries merged since the rc2 changelog (#4293),
in prep to cut **v6.7.0-rc4**. The rc3 update (#4335) was closed without
merging, so its entries are included here:

- [#4411](#4411) — Log a
pinned node's skipped migration kick-off once per batch size
- [#4410](#4410) — Apply
compiled KV repair files at a fixed height and generate them from digest
inspect lists
- [#4409](#4409) — feat:
add migration pause handler
- [#4397](#4397) —
fix(evmrpc): release eth_getLogs DB-read slots when a block read panics
- [#4378](#4378) — Raise
goreleaser timeout to 2h
- [#4377](#4377) — Fix
FlatKV state sync bad-hash scenario
- [#4371](#4371) —
fix(seidb): keep writes in the old DB until the migration boundary first
moves
- [#4348](#4348) —
fix(seidb): report only the current migration boundary on the snapshot
gauge
- [#4347](#4347) —
fix(flatkv): keep 10 old checkpoints instead of mirroring memIAVL's
count
- [#4339](#4339) — rc3
version bump
- [#4334](#4334) — Fail
dynamic-gas precompile out-of-gas as an EVM out-of-gas call
- [#4315](#4315) — Pin the
Go builder image per architecture in build-static.sh
- [#4313](#4313) —
fix(memiavl): hold a snapshot reference for an iterator's lifetime
- [#4295](#4295) — rc2
version bump
- [#4294](#4294) — rc2
changelog backport

Also returns `## v6.7` to the format used through v6.6: the version
heading, `sei-chain`, and the generated PR list. The hand-written `###
Improvements` and `### Upgrade guide` sections are removed; every PR
they described is already a line in the generated list.

Regenerated with `./scripts/generate-changelog.sh release/v6.6
release/v6.7`; only the `## v6.7` section changes. Docs-only; no code
change.

**Backport note:** the #4347 backport added its own line to the top of
the `## v6.7` list on `release/v6.7`, and `main` doesn't have it, so the
`backport release/v6.7` cherry-pick of this PR conflicts at that one
spot (simulated with `git merge-tree`). Resolve it by taking this PR's
side: its fifteen lines already include #4347.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
masih pushed a commit that referenced this pull request Oct 1, 2026
## Summary
- Bump `version.json` from `v6.7.0-rc3` to `v6.7.0-rc4` to cut the
fourth `v6.7` release candidate.

Contents since rc3: #4411, #4410, #4409, #4397, #4378, #4377, #4371,
plus the rc4 changelog update (#4415, with the conflict-marker fix
#4416). The changelog has already landed, so the `v6.7.0-rc4` tag will
include it.

- All seven are labeled `non-app-hash-breaking`. #4371 changes the
AppHash only for nodes pinned to a `migrate_*` write mode while the
migration hasn't started (see #4369), and the hard-fork handlers added
by #4409 and #4410 are not registered for any chain in this release.
Unlike rc3, moving from rc3 to rc4 should not need a coordinated
validator switch.
- Push `v6.7.0-rc4` by hand on this PR's merge commit once it has
merged; the tagging ruleset stops `uci-release-publish` from creating
it. The rc3 tag was pushed before #4339 merged and sits on `0d56aaeef`,
where `version.json` still reads `v6.7.0-rc2`.
- #4378 raises GoReleaser's timeout to 2h. The rc3 tag push hit the 1h
limit during the emulated arm64 build and attached nothing, so rc4 is
the first `v6.7` release candidate that should get binaries.

## Test plan
- [x] `git diff --check`

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants