Skip to content

[SharovBot] execution/rlp: revert stale listLimit re-read causing wrong trie root regression - #21867

Merged
AskAlexSharov merged 1 commit into
mainfrom
agent-fix/rlp-revert-listlimit-regression
Jun 17, 2026
Merged

AskAlexSharov merged 1 commit into
mainfrom
agent-fix/rlp-revert-listlimit-regression

Conversation

@erigon-copilot

Copy link
Copy Markdown
Contributor

[SharovBot]

Summary

Reverts the listLimit re-read introduced in #21839 (cecf3ad) which caused invalid block: wrong trie root regressions across all CI stage-exec-test jobs.

Root cause of regression

After readKind() calls willRead() to consume the 1-byte type header, listLimit drops by 1. The re-read then compares the declared element s.size against (original - 1 byte), causing the ErrElemTooLarge guard to fire spuriously for elements that exactly fill the remaining list space. This aborted block execution with corrupted state and produced wrong trie roots.

Failing CI jobs (commit cecf3ad)

  • stage-exec-test (from-0, serial) — invalid block: wrong trie root, block=513814
  • stage-exec-test (from-0, parallel) — invalid block: wrong trie root, block=263641
  • stage-exec-test (resume-nonchaintip, serial) — invalid block: wrong trie root, block=25314648
  • RPC Integration Tests - nethermind — eth_call diff mismatches on all test cases

Fix

Revert decode.go to read listLimit before readKind() (original behaviour). The pre-readKind() read is correct: the ErrElemTooLarge guard compares the declared element size against the available space before any consumption.

The fuzz corpus entry (29859ba08ac1b7a2) is kept so the edge case is preserved for future investigation.

Test plan

  • go build ./... passes
  • go test -count=3 -race ./execution/rlp/... ./execution/types/... passes all 3 runs
  • No test files modified

Closes regression introduced by #21839.

…ng trie root regression

The listLimit re-read introduced in cecf3ad was intended to fix a FuzzRLP
round-trip failure, but it caused "invalid block: wrong trie root" errors
in stage-exec-test CI jobs on all 3 variants (from-0 serial, from-0 parallel,
resume-nonchaintip serial) as well as eth_call diff mismatches in RPC
integration tests against nethermind.

Root cause of regression: after readKind() calls willRead() for the type byte,
listLimit drops by 1 (the header byte). For a list element, the re-read
listLimit is now (original - 1 byte), making the size check
  s.size > listLimit
fire spuriously for elements that exactly fill the remaining space, triggering
ErrElemTooLarge and aborting block execution with a corrupted state.

Revert the re-read. The original code read listLimit before readKind(), which
is correct: the ErrElemTooLarge guard is comparing the *declared* element size
against the *available* list space before any consumption — that's the right
semantic.

The fuzz corpus entry (29859ba08ac1b7a2) is intentionally kept so future fuzz
runs can revisit this edge case with a proper fix.

Fixes CI regressions from #21839.

Co-authored-by: Giulio Rebuffo <giulio.rebuffo@gmail.com>
@erigon-copilot
erigon-copilot Bot requested review from mh0lt and yperbasis as code owners June 17, 2026 14:41
@AskAlexSharov
AskAlexSharov enabled auto-merge June 17, 2026 15:11
@AskAlexSharov
AskAlexSharov added this pull request to the merge queue Jun 17, 2026
Merged via the queue into main with commit e72f961 Jun 17, 2026
92 checks passed
@AskAlexSharov
AskAlexSharov deleted the agent-fix/rlp-revert-listlimit-regression branch June 17, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant