fix(api): fail closed on registerValidator signature verify errors - #793
Open
SashaMIT wants to merge 1 commit into
Open
fix(api): fail closed on registerValidator signature verify errors#793SashaMIT wants to merge 1 commit into
SashaMIT wants to merge 1 commit into
Conversation
VerifySignature errors (e.g. invalid BLS point encoding) previously logged and broke the loop, then still returned HTTP 200. Return 400 instead, matching submitNewBlock. Also return (not break) on invalid signatures when continue-on-invalid-sig is off. Fix GetEnvDurationSec inverted strconv error check so valid integer env values are honored instead of always falling back to the default.
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
registerValidatorcalledssz.VerifySignatureand onerr != nil(e.g. invalid BLS point encoding) logged andbreakd, then still returned HTTP 200. Malformed signatures were treated as success. Invalid signatures (!ok) alsobreakd after writing 400, then fell through toWriteHeader(200).Return 400 on verify errors (parity with
submitNewBlock) andreturninstead ofbreakwhen invalid signatures are rejected.Also fixes
GetEnvDurationSec: thestrconv.Atoierror check was inverted, so valid integer env values were ignored and the default was always used.Test plan
go test ./services/api/ -run TestRegisterValidatorgo test ./common/ -run TestGetEnvDurationSecMade with Cursor