Skip to content

fix(net): harden sync message resource controls - #20

Closed
xxo1shine wants to merge 1 commit into
base-codefrom
fix/net-sync-message-validation
Closed

xxo1shine wants to merge 1 commit into
base-codefrom
fix/net-sync-message-validation

Conversation

@xxo1shine

Copy link
Copy Markdown
Owner

Peer-derived sync state could bypass height validation, request rate limiting, and block-fetch deduplication at boundary conditions.

Reject invalid remain counts and overflowed heights, apply sync-chain rate limiting to every request, and size the block ID cache to cover the full valid fetch window.

What does this PR do?

Why are these changes required?

This PR has been tested by:

  • Unit Tests
  • Manual Testing

Follow up

Extra details

Peer-derived sync state could bypass height validation, request rate limiting, and block-fetch deduplication at boundary conditions.

Reject invalid remain counts and overflowed heights, apply sync-chain rate limiting to every request, and size the block ID cache to cover the full valid fetch window.
@xxo1shine xxo1shine closed this Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant