Commit 2f8d257
authored
fix(network): cap attester set size to prevent DoS and uint16 overflow (#361)
* security: cap attester set size to prevent DoS and uint16 overflow
The attester set was unbounded, allowing an attacker to register thousands
of sybil identities. This caused:
- EndBlocker stalling via O(n) iteration in BuildValidatorIndexMap
- Silent uint16 index overflow when >65,535 attesters joined
This commit:
- Adds MaxAttesters=10,000 variable to cap the attester set size
- Enforces the cap in JoinAttesterSet, rejecting new joins at capacity
- Adds uint16 overflow guard in BuildValidatorIndexMap as defense-in-depth
Adds 2 table-driven tests for cap enforcement.
* fix: make MaxAttesters a const, refactor test to not override
- Changed MaxAttesters from var to const per review: protocol limits
should be immutable
- Refactored TestJoinAttesterSetMaxCap to verify the constant value
fits in uint16 and test the happy path without overriding the const1 parent ba94ff1 commit 2f8d257
3 files changed
Lines changed: 55 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
188 | 193 | | |
189 | 194 | | |
190 | 195 | | |
| |||
193 | 198 | | |
194 | 199 | | |
195 | 200 | | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
196 | 207 | | |
197 | 208 | | |
198 | 209 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
160 | 169 | | |
161 | 170 | | |
162 | 171 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
124 | 124 | | |
125 | 125 | | |
126 | 126 | | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
127 | 162 | | |
128 | 163 | | |
129 | 164 | | |
| |||
0 commit comments