deps: update reth from main (2026-08-25) - #7142
Conversation
|
derek bench preset=tip20 |
|
cyclops audit fast |
|
derek bench |
tempoxyz-bot
left a comment
There was a problem hiding this comment.
👁️ Cyclops Review — No actionable findings on current head.
The audited issue in crates/consensus/src/validators.rs is stale: current head restores the header-only provider lookup at lines 46–50.
Reviewer Callouts
- ⚡ Canonical-ancestor payload builds (
bin/tempo/src/defaults.rs:199-215): Tempo's setting currently bypasses Reth's new too-deep-reorg rejection for canonical ancestors below finality. Re-check fatal FCU error handling before changing it. - ⚡ Pre-execution gas-limit guard (Reth commit
f3e49cc6): reconfirm Tempo's block gas-limit policy against Reth's newgas_limit > 2 * parent.gas_limitguard. - ⚡ Devp2p behavior changes (Reth commits
dd637cef,ae81966b,20fab813,3a83ccc5, and1c6945c5): the new unconditional ping pacing merits a soak test.
4a5264b to
4d07541
Compare
|
derek bench |
|
cyclops audit fast |
|
cc @shekhirin ❌ Benchmark failed. View logs |
|
cyclops audit note="Review every upstream reth commit included in the revision diff." |
tempoxyz-bot
left a comment
There was a problem hiding this comment.
👁️ Cyclops Review
Summary
This dependency update imports two verified denial-of-service risks from Reth: tempo/1 does not register its intended 1 KiB pre-decompression ingress cap, and opt-in HTTP decompression lets stalled request bodies exhaust every decompression permit. The Tempo-local compatibility changes otherwise preserve the reviewed state, snapshot, receipt, and transaction-pool invariants. The deferred persistence-handoff risk was already identified in a preserved prior review and is not repeated here.
Findings
🚨 [SECURITY] tempo/1 does not register its 1 KiB transport ingress limit
Severity: Medium
File: crates/node/src/gossip/transport.rs:460
Summary: Reth's new defaulted ConnectionHandler::inbound_limits() returns no frame-size cap, and GossipProtocolHandler does not override it. An unauthenticated peer that negotiates tempo/1 can therefore make Reth allocate and Snappy-decompress frames up to the generic 16 MiB ceiling before Tempo's downstream 1 KiB check runs. The downstream rejection is treated as a graceful disconnect, so the peer also avoids the reputation penalty attached to Reth's transport-level oversized-message error.
Recommended Fix: Override GossipProtocolHandler::inbound_limits() with ProtocolIngressLimits::new(wire::MAX_FRAME_BYTES) and suitable bounded message/byte limits. Keep the downstream size check as defense in depth.
🚨 [SECURITY] Stalled compressed HTTP bodies exhaust all decompression permits
Severity: Low
File: reth@00ff650:crates/rpc/rpc-layer/src/decompression_layer.rs:138
Summary: When --http.decompression is enabled, Reth acquires one of eight shared semaphore permits before awaiting the client-controlled request body, with no body-completion or idle deadline. Eight incomplete compressed bodies can retain every permit indefinitely and block all later compressed RPC requests. A verifier reproduced this with eight incomplete chunked gzip requests followed by a complete request.
Recommended Fix: Apply a body read/idle timeout and release the permit on timeout, or collect the body under an independently bounded network-body policy before acquiring the decompression permit. Add a regression test covering eight stalled bodies followed by a valid compressed request.
Reviewer Callouts
Reviewer Callouts
- ⚡ Cooperative payload finalization (
crates/payload/builder/src/lib.rs:386): Reth's newFINALIZATION_REQUESTEDstate is distinct from cancellation, but Tempo only checksis_cancelled(). Confirm whether Tempo should seal the partial payload when finalization is requested instead of continuing until its proposal budget expires. - ⚡ Bounded RLPx satellite queues (
crates/node/src/gossip/transport.rs:585): Tempo currently drains eagerly, but future backpressure in this path can turn atempo/1queue overflow into teardown of the entire RLPx session, including theethprimary.
Automated nightly update of reth dependencies from
paradigmxyz/rethmain branch.Upstream reth changes
10aa6a5...00ff650🔗 Amp thread: https://ampcode.com/threads/T-01a036f1-9f58-7640-b789-4e3dd9778ebe
Engine
getBlobsV4, and prewarm-worker shutdown (#26650, #26703, #26768).RPC
debug_traceChain, Alloy trace-chain result types, block-level EVM reuse, and raw block transactions on the auth server (#26582, #26614, #26669, #26760).eth_config(#26691, #26705).Networking
GetCellssupport (#26660, #26652, #26673).Txpool
Trie & State
HashedPostStatewipe handling and added trie-data reference collectors (#26524, #26752).Storage & Providers
ConsistentDbView, relocatedOverlayStateProvider, and simplified provider bounds (#26581, #26611, #26591).Chainspec & Consensus
slotNumberinstead of hardcoding zero (#26680).DNS
Snapshots & CLI
reth.toml(#26551).Testing & Development
Bench
Dependencies & Releases
alloy-hardforks/alloy-eip7928to 0.4.8, and released Reth 2.5.0–2.5.1 (#26663, #26666, #26685, #26687, #26700, #26771).Migrations
🔗 Amp thread: https://ampcode.com/threads/T-01a036f2-23b2-77c0-8959-5c3f0f9df6c5
00ff650, Alloy to2.4.1, and related dependencies to match their latest APIs.from_iterAPI to direct struct initialization.(plan, prepared)return value and execution’s optional prepared manifest.HashedPostStateProviderimplementations and callers for its new fallibleProviderResultreturn type.convert_logimplementation for the updated receipt converter trait.blob_cell_availabilityfield.GitHub Workflow