mirror of
https://github.com/luxfi/node.git
synced 2026-07-27 03:39:39 +00:00
Red adversarial review of the PQ-finality gate. Dormant default verified a true no-op; these harden the ACTIVATED path before any forward-dated activation: H1 (HIGH) — bindCheck now binds cert.Epoch == cp.Epoch (and cert.Round). The gate resolves verification keys from the cert's epoch; an unbound epoch let a cert signed under a DIFFERENT validator-set era (e.g. a compromised RETIRED committee key) certify the current block, nullifying KeyEra rotation as a blast-radius bound. Honest certs match (producer signs Subject.Epoch==cp.Epoch). + wrong-epoch / wrong-round anti-replay test cases. M2 (MED) — activation is now HEIGHT-ONLY, deterministic. Removed time.Now() (and the ActivationConfig.Time field) from the accept path: wall-clock gating split finalization across validators with skewed clocks (some halting on a missing cert, others finalizing without one). A height is consensus-agreed; timestamp forward-dating is expressed by choosing the activation height. L5 (LOW) — an activated gate with a nil store/validator provider now fails closed with ErrGateMisconfigured instead of panicking in the accept hook (a panic would halt the chain uncontrollably). Off the dormant path. + test. M3 (doc) — made the StateRoot=0 transitive-through-BlockHash contract explicit in bindCheck (non-zero cert StateRoot already rejected + tested) so the producer follow-on cannot silently ship state-committing certs that self-halt. proposervm: verifyQuasarFinality short-circuits on nil gate BEFORE building the Checkpoint, so the default path makes zero block-accessor calls. 13 gate tests green under -race; full proposervm suite green; go build ./... exit 0. Deferred to follow-ons (gate is dormant + unwired in production): M4 cert- unavailability halt runbook + grace window, L6 MemCertStore eviction (no ingest caller yet), proposervm Accept-path integration test, positive valid-cert test (needs consensus to export cert encoders).