[SharovBot] execution/rlp: revert stale listLimit re-read causing wrong trie root regression - #21867
Merged
Merged
Conversation
…ng trie root regression The listLimit re-read introduced in cecf3ad was intended to fix a FuzzRLP round-trip failure, but it caused "invalid block: wrong trie root" errors in stage-exec-test CI jobs on all 3 variants (from-0 serial, from-0 parallel, resume-nonchaintip serial) as well as eth_call diff mismatches in RPC integration tests against nethermind. Root cause of regression: after readKind() calls willRead() for the type byte, listLimit drops by 1 (the header byte). For a list element, the re-read listLimit is now (original - 1 byte), making the size check s.size > listLimit fire spuriously for elements that exactly fill the remaining space, triggering ErrElemTooLarge and aborting block execution with a corrupted state. Revert the re-read. The original code read listLimit before readKind(), which is correct: the ErrElemTooLarge guard is comparing the *declared* element size against the *available* list space before any consumption — that's the right semantic. The fuzz corpus entry (29859ba08ac1b7a2) is intentionally kept so future fuzz runs can revisit this edge case with a proper fix. Fixes CI regressions from #21839. Co-authored-by: Giulio Rebuffo <giulio.rebuffo@gmail.com>
AskAlexSharov
approved these changes
Jun 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[SharovBot]
Summary
Reverts the
listLimitre-read introduced in #21839 (cecf3ad) which causedinvalid block: wrong trie rootregressions across all CI stage-exec-test jobs.Root cause of regression
After
readKind()callswillRead()to consume the 1-byte type header,listLimitdrops by 1. The re-read then compares the declared elements.sizeagainst(original - 1 byte), causing theErrElemTooLargeguard to fire spuriously for elements that exactly fill the remaining list space. This aborted block execution with corrupted state and produced wrong trie roots.Failing CI jobs (commit cecf3ad)
stage-exec-test (from-0, serial)—invalid block: wrong trie root, block=513814stage-exec-test (from-0, parallel)—invalid block: wrong trie root, block=263641stage-exec-test (resume-nonchaintip, serial)—invalid block: wrong trie root, block=25314648RPC Integration Tests - nethermind—eth_calldiff mismatches on all test casesFix
Revert
decode.goto readlistLimitbeforereadKind()(original behaviour). The pre-readKind()read is correct: theErrElemTooLargeguard compares the declared element size against the available space before any consumption.The fuzz corpus entry (
29859ba08ac1b7a2) is kept so the edge case is preserved for future investigation.Test plan
go build ./...passesgo test -count=3 -race ./execution/rlp/... ./execution/types/...passes all 3 runsCloses regression introduced by #21839.