Skip to content
This repository has been archived by the owner on Jan 22, 2025. It is now read-only.

Validate the genesis config downloaded over RPC before accepting it #8474

Merged
merged 2 commits into from
Feb 26, 2020

Conversation

mvines
Copy link
Contributor

@mvines mvines commented Feb 26, 2020

This PR replaces #8467, and additionally adds verification of a downloaded genesis.tar.bz2 before accepting it. If an RPC node serves a bad genesis, that node gets blacklisted and the validator tries another.

This should be sufficient to prevent the Chorus One poisoned genesis attack during SLP2 boot from reoccurring. However note that the Certus One bzip2 bomb as described by #8427 is not fixed here.

@codecov
Copy link

codecov bot commented Feb 26, 2020

Codecov Report

❗ No coverage uploaded for pull request base (master@407d058). Click here to learn what that means.
The diff coverage is 33.3%.

@@           Coverage Diff            @@
##             master   #8474   +/-   ##
========================================
  Coverage          ?   80.3%           
========================================
  Files             ?     256           
  Lines             ?   56447           
  Branches          ?       0           
========================================
  Hits              ?   45344           
  Misses            ?   11103           
  Partials          ?       0

# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant