spec(eip8025): contain invalid proof gossip - #5502
Draft
exocognosis wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
EIP-8025 allows any active validator to sign an execution proof. Existing gossip validation rejects invalid proofs and can penalize the forwarding peer, but a malicious validator can rotate inexpensive peer identities while continuing to sign proofs that require expensive proof-engine verification.
This change adds authenticated validator-level containment for unsolicited execution-proof gossip without reintroducing proof re-signing.
Proposed solution
execution_proofgossip signed by a validator that has already authenticated an invalid execution proof.ExecutionProofsByRangeandExecutionProofsByRootrequests.Rationale
Peer scoring remains useful because a gossip rejection penalizes the peer that forwarded the invalid message. It is not sufficient by itself when peer identities can be rotated independently of validator keys.
The authenticated signer record makes the validator key the durable accountability anchor. Each client performs at most one expensive unsolicited invalid-proof verification per validator before suppressing later gossip from that signer.
Applying suppression only to gossip addresses the selective-availability concern raised in the issue. A node that ignored later gossip from a signer can still recover a valid proof through the existing bounded request and response protocols. This removes the need for validators to re-sign every valid proof and avoids the resulting protocol complexity and network amplification.
The mechanism is transitional and does not alter proof containers, signatures, topic encodings, or request limits.
Validation
make lintmake test fork=eip8025Fixes #5145.