Skip to content

fix(vara.eth): reject post-quarantine-delay above 1000 - #5648

Open
neelsatyavolu wants to merge 1 commit into
gear-tech:masterfrom
neelsatyavolu:ns/limit-post-quarantine-delay
Open

neelsatyavolu wants to merge 1 commit into
gear-tech:masterfrom
neelsatyavolu:ns/limit-post-quarantine-delay

Conversation

@neelsatyavolu

Copy link
Copy Markdown

Closes #5478

Summary

Root cause: post_quarantine_delay was accepted at any u32 value. The producer walks canonical_quarantine + post_quarantine_delay parents through the database on every wait_for_proposable_content call. A typo such as --post-quarantine-delay 4294967295 therefore turned each call into millions of RocksDB reads, and nothing told the operator.

Fix: follows the plan in the issue.

  • Add MalachiteServiceConfig::MAX_POST_QUARANTINE_DELAY = 1000 and drop the TODO: #5478 comment it replaces.
  • NodeParams::into_config now fails with `post-quarantine-delay` must be at most 1000, got N. The check runs on the effective value, so it covers both the CLI flag and the TOML key.
  • The --post-quarantine-delay help text now mentions the maximum.

How to test

cargo test -p ethexe-cli --lib params::node::tests
  • post_quarantine_delay_above_max_is_rejected checks that 1001 is rejected with an error naming the option. I wrote it before the fix and confirmed it failed on master: into_config() returned a NodeConfig with post_quarantine_delay: 4294967295.
  • post_quarantine_delay_at_max_is_accepted checks that 1000 is still accepted.

Also ran locally on macOS (arm64):

  • cargo test -p ethexe-cli -p ethexe-malachite: all pass.
  • cargo clippy -p ethexe-cli -p ethexe-malachite --all-targets -- -D warnings: clean.
  • cargo fmt --all -- --check: clean.

Notes

  • I didn't run make typos locally because typos-cli isn't installed here.
  • Unrelated to this change: on macOS 27 with Apple clang 21, sha1-asm 0.5.3 (pulled in through gear-workspace-hack) fails to build. The Xcode clang crashes on its #:lo12: relocation syntax in aarch64_apple.S. To run the checks above I passed a local [patch] through cargo --config. That workaround is not part of this PR.
  • This PR was written with the help of an AI agent (Claude Code, claude-opus-5-5). Per CONTRIBUTING.md, it probably qualifies for the ai-generated label, but I can't set labels on this repository.

Checklist

  • PR title follows Conventional Commits (type(scope): description)
  • Single logical change
  • Tests added or updated (if logic changed)
  • Docs updated (if needed)

`post_quarantine_delay` was accepted at any `u32` value. The producer
walks `canonical_quarantine + post_quarantine_delay` parents through the
database on every `wait_for_proposable_content` call, so a typo such as
`u32::MAX` turned each call into millions of RocksDB reads.

Add `MalachiteServiceConfig::MAX_POST_QUARANTINE_DELAY` (1000) and make
`NodeParams::into_config` fail with a clear error above it.

Closes gear-tech#5478
@neelsatyavolu
neelsatyavolu marked this pull request as ready for review September 25, 2026 22:16

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ethexe-malachite: add upper-bound validation for post_quarantine_delay config

1 participant