Repository navigation
Backport release/v6.7: Fix FlatKV state sync bad-hash scenario. - #4377
Conversation
|
Please cherry-pick the changes locally and resolve any conflicts. git fetch origin backport-4370-to-release/v6.7
git worktree add --checkout .worktree/backport-4370-to-release/v6.7 backport-4370-to-release/v6.7
cd .worktree/backport-4370-to-release/v6.7
git reset --hard HEAD^
git cherry-pick -x 712fa98e10eb7dd3c245df4d155c4f6cbbd7a7bb
git push --force-with-lease |
|
The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release/v6.7 #4377 +/- ##
================================================
- Coverage 61.37% 60.55% -0.82%
================================================
Files 2163 2081 -82
Lines 189080 179949 -9131
================================================
- Hits 116051 108976 -7075
+ Misses 62295 60942 -1353
+ Partials 10734 10031 -703
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
|
@seidroid review |
PR SummaryHigh Risk Overview
New tests cover duplicate-key rejection (LtHash wrap attack), descending-key rejection, and trusted import behavior; existing import tests feed nodes via Reviewed by Cursor Bugbot for commit c9dc93d. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
This is a clean backport of #4370. CommitStore.Importer, which handles untrusted state-sync data, now rejects the import unless physical keys arrive in strictly ascending order. That closes the gap where a peer could repeat a forged pair until its LtHash limbs wrapped to zero, so it no longer changes the root hash. The offline memiavl→FlatKV migration switches to the new TrustedImporter, which accepts keys in any order. The check sits in the single dispatch loop that every node passes through. KVExporter already emits keys in that order through RawGlobalIterator, and the tests that fed keys out of order now sort them first. I found nothing blocking.
Findings: 0 blocking | 0 non-blocking | 0 posted inline
Blockers
- None at the file/PR level.
Non-blocking
- None at the file/PR level.
Adds the `release/v6.7` entries merged since the rc2 changelog (#4293), in prep to cut **v6.7.0-rc4**. The rc3 update (#4335) was closed without merging, so its entries are included here: - [#4411](#4411) — Log a pinned node's skipped migration kick-off once per batch size - [#4410](#4410) — Apply compiled KV repair files at a fixed height and generate them from digest inspect lists - [#4409](#4409) — feat: add migration pause handler - [#4397](#4397) — fix(evmrpc): release eth_getLogs DB-read slots when a block read panics - [#4378](#4378) — Raise goreleaser timeout to 2h - [#4377](#4377) — Fix FlatKV state sync bad-hash scenario - [#4371](#4371) — fix(seidb): keep writes in the old DB until the migration boundary first moves - [#4348](#4348) — fix(seidb): report only the current migration boundary on the snapshot gauge - [#4347](#4347) — fix(flatkv): keep 10 old checkpoints instead of mirroring memIAVL's count - [#4339](#4339) — rc3 version bump - [#4334](#4334) — Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call - [#4315](#4315) — Pin the Go builder image per architecture in build-static.sh - [#4313](#4313) — fix(memiavl): hold a snapshot reference for an iterator's lifetime - [#4295](#4295) — rc2 version bump - [#4294](#4294) — rc2 changelog backport Also returns `## v6.7` to the format used through v6.6: the version heading, `sei-chain`, and the generated PR list. The hand-written `### Improvements` and `### Upgrade guide` sections are removed; every PR they described is already a line in the generated list. Regenerated with `./scripts/generate-changelog.sh release/v6.6 release/v6.7`; only the `## v6.7` section changes. Docs-only; no code change. **Backport note:** the #4347 backport added its own line to the top of the `## v6.7` list on `release/v6.7`, and `main` doesn't have it, so the `backport release/v6.7` cherry-pick of this PR conflicts at that one spot (simulated with `git merge-tree`). Resolve it by taking this PR's side: its fifteen lines already include #4347. --------- Co-authored-by: Cursor <cursoragent@cursor.com>
## Summary - Bump `version.json` from `v6.7.0-rc3` to `v6.7.0-rc4` to cut the fourth `v6.7` release candidate. Contents since rc3: #4411, #4410, #4409, #4397, #4378, #4377, #4371, plus the rc4 changelog update (#4415, with the conflict-marker fix #4416). The changelog has already landed, so the `v6.7.0-rc4` tag will include it. - All seven are labeled `non-app-hash-breaking`. #4371 changes the AppHash only for nodes pinned to a `migrate_*` write mode while the migration hasn't started (see #4369), and the hard-fork handlers added by #4409 and #4410 are not registered for any chain in this release. Unlike rc3, moving from rc3 to rc4 should not need a coordinated validator switch. - Push `v6.7.0-rc4` by hand on this PR's merge commit once it has merged; the tagging ruleset stops `uci-release-publish` from creating it. The rc3 tag was pushed before #4339 merged and sits on `0d56aaeef`, where `version.json` still reads `v6.7.0-rc2`. - #4378 raises GoReleaser's timeout to 2h. The rc3 tag push hit the 1h limit during the emulated arm64 build and attached nothing, so rc4 is the first `v6.7` release candidate that should get binaries. ## Test plan - [x] `git diff --check` Made with [Cursor](https://cursor.com) Co-authored-by: Cursor <cursoragent@cursor.com>
Backport of #4370 to
release/v6.7.