Skip to content

deps: update reth from main (2026-08-25) - #7142

Merged
shekhirin merged 46 commits into
mainfrom
reth-auto-bump
Aug 25, 2026
Merged

shekhirin merged 46 commits into
mainfrom
reth-auto-bump

Conversation

@decofe

@decofe decofe commented Aug 11, 2026 •

Copy link
Copy Markdown
Member

Automated nightly update of reth dependencies from paradigmxyz/reth main branch.

Upstream reth changes

10aa6a5...00ff650

🔗 Amp thread: https://ampcode.com/threads/T-01a036f1-9f58-7640-b789-4e3dd9778ebe

  • Engine

    • Improved payload building across canonical ancestors, finality, persistence handoffs, pending resolution, and responsive cancellation (#26559, #26567, #26580, #26708, #26759).
    • Added Bogota Engine API support and fork-time validation, plus FOCIL inclusion-list construction and stubs (#26682, #26706, #26711, #26737).
    • Tightened payload and block-access-list validation, including state-gas admission and malformed BAL rejection (#26651, #26694, #26719).
    • Fixed little-endian cell bitvectors, Osaka getBlobsV4, and prewarm-worker shutdown (#26650, #26703, #26768).
    • Reused scratch buffers for faster BAL hash encoding (#26701).
  • RPC

    • Added debug_traceChain, Alloy trace-chain result types, block-level EVM reuse, and raw block transactions on the auth server (#26582, #26614, #26669, #26760).
    • Added configurable response compression and request decompression (#26668, #20277).
    • Added Bogota Engine API stubs and Amsterdam system contracts to eth_config (#26691, #26705).
    • Fixed cancellation of payload-hash and blocking-I/O work (#26569, #26776).
    • Corrected execution-witness block identifiers, optional receipt conversion/caching, and access-list environment preparation (#26572, #26596, #26599, #26598).
    • Fixed testing block gas limits, transaction gas-limit preservation, timestamp overflow, and chain-ID validation (#26632, #26743, #26767, #26782).
    • Added network-specific log responses and generic testing RPC handlers (#26491, #26547).
  • Networking

    • Added ingress limits, configurable no-op client versions, and outbound GetCells support (#26660, #26652, #26673).
    • Improved handshake and protocol safety through ECIES identity checks, message-ID validation, negotiated-protocol assertions, and bad-message handling (#26639, #26654, #26659, #26671).
    • Fixed ping/pong validation and pacing (#26698, #26702).
    • Made eth/72 blob-cell announcements interoperable with geth while preserving availability masks (#26573, #26670).
    • Shared the snap/2 slim-account codec between client and server (#26587).
  • Txpool

    • Added blob-cell availability tracking and exposure on pooled transactions (#25463, #26642).
    • Included blob-pool transactions in queued counts and listings (#26677, #26679).
    • Allowed senders with empty code hashes, added consensus encoding, and converted sender accessors to iterators (#26644, #26739, #26681).
  • Trie & State

    • Added partial trie unwind and persistence support, including changeset-cache handling (#26543, #26612).
    • Corrected witness construction to use depth-first node order (#26707).
    • Simplified HashedPostState wipe handling and added trie-data reference collectors (#26524, #26752).
  • Storage & Providers

    • Removed ConsistentDbView, relocated OverlayStateProvider, and simplified provider bounds (#26581, #26611, #26591).
    • Fixed storage-wipe handling during batched persistence (#26750).
    • Made RocksDB tolerate unknown column families (#26647).
    • Updated static-file consistency checks to respect prune checkpoints (#26565).
  • Chainspec & Consensus

    • Added Bogota hardfork support and validated block-access-list hashes during import (#26686, #26696).
    • Honored the genesis slotNumber instead of hardcoding zero (#26680).
    • Defaulted unspecified payload attributes (#26684).
  • DNS

    • Fixed EIP-1459 discovery records by rejoining long TXT character strings and ignoring unrelated TXT records (#26602, #26603).
  • Snapshots & CLI

    • Added base-URL resolution and exposed prepared snapshot context (#26576, #26777).
    • Fixed history downloads when the final snapshot chunk is partial (#26607).
    • Added bootnode configuration to reth.toml (#26551).
  • Testing & Development

    • Improved engine reorg tests with explicit finality management and expanded execute-blob Hive coverage (#26584, #26606).
    • Added a persistent-datadir testing node and made dev-mined blocks canonical immediately (#26774, #26761).
  • Bench

    • Restored metrics visibility in benchmark run configurations (#26461).
  • Dependencies & Releases

Migrations

🔗 Amp thread: https://ampcode.com/threads/T-01a036f2-23b2-77c0-8959-5c3f0f9df6c5

  • Upgraded Reth to 00ff650, Alloy to 2.4.1, and related dependencies to match their latest APIs.
  • Renamed workspace lint keys from kebab-case to snake_case for updated Cargo lint syntax.
  • Removed the no-longer-needed crate recursion limit.
  • Migrated hashed storage construction from the removed from_iter API to direct struct initialization.
  • Reused Reth’s prepared snapshot manifest, base URL, and data directory, removing Tempo’s duplicate manifest discovery, fetching, parsing, and path-resolution logic.
  • Updated snapshot planning to handle Reth’s new (plan, prepared) return value and execution’s optional prepared manifest.
  • Updated HashedPostStateProvider implementations and callers for its new fallible ProviderResult return type.
  • Added the required RPC log associated type and identity convert_log implementation for the updated receipt converter trait.
  • Updated pooled transaction construction for the reordered transaction field and new blob_cell_availability field.

GitHub Workflow

@decofe decofe added the A-dependencies Related to dependency updates label Aug 11, 2026
@decofe

decofe commented Aug 11, 2026

Copy link
Copy Markdown
Member Author

derek bench preset=tip20

@decofe decofe changed the title deps: update reth from main (2026-08-11) deps: update reth from main (2026-08-12) Aug 12, 2026
@decofe decofe changed the title deps: update reth from main (2026-08-12) deps: update reth from main (2026-08-13) Aug 13, 2026
@pepyakin pepyakin closed this Aug 13, 2026
@pepyakin pepyakin reopened this Aug 13, 2026
@decofe decofe changed the title deps: update reth from main (2026-08-13) deps: update reth from main (2026-08-14) Aug 14, 2026
shekhirin
shekhirin previously approved these changes Aug 14, 2026
@shekhirin

Copy link
Copy Markdown
Member

cyclops audit fast

@shekhirin

Copy link
Copy Markdown
Member

derek bench

@tempoxyz-bot tempoxyz-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👁️ Cyclops Review — No actionable findings on current head.

The audited issue in crates/consensus/src/validators.rs is stale: current head restores the header-only provider lookup at lines 46–50.

Reviewer Callouts
  • ⚡ Canonical-ancestor payload builds (bin/tempo/src/defaults.rs:199-215): Tempo's setting currently bypasses Reth's new too-deep-reorg rejection for canonical ancestors below finality. Re-check fatal FCU error handling before changing it.
  • ⚡ Pre-execution gas-limit guard (Reth commit f3e49cc6): reconfirm Tempo's block gas-limit policy against Reth's new gas_limit > 2 * parent.gas_limit guard.
  • ⚡ Devp2p behavior changes (Reth commits dd637cef, ae81966b, 20fab813, 3a83ccc5, and 1c6945c5): the new unconditional ping pacing merits a soak test.

@shekhirin

Copy link
Copy Markdown
Member

derek bench

@shekhirin

Copy link
Copy Markdown
Member

cyclops audit fast

@tempo-github-sts

tempo-github-sts Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

cc @shekhirin

❌ Benchmark failed. View logs

@decofe decofe changed the title deps: update reth from main (2026-08-24) deps: update reth from main (2026-08-25) Aug 25, 2026
@decofe

decofe commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

cyclops audit note="Review every upstream reth commit included in the revision diff."

@tempoxyz-bot tempoxyz-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👁️ Cyclops Review

Summary

This dependency update imports two verified denial-of-service risks from Reth: tempo/1 does not register its intended 1 KiB pre-decompression ingress cap, and opt-in HTTP decompression lets stalled request bodies exhaust every decompression permit. The Tempo-local compatibility changes otherwise preserve the reviewed state, snapshot, receipt, and transaction-pool invariants. The deferred persistence-handoff risk was already identified in a preserved prior review and is not repeated here.

Findings

🚨 [SECURITY] tempo/1 does not register its 1 KiB transport ingress limit

Severity: Medium
File: crates/node/src/gossip/transport.rs:460
Summary: Reth's new defaulted ConnectionHandler::inbound_limits() returns no frame-size cap, and GossipProtocolHandler does not override it. An unauthenticated peer that negotiates tempo/1 can therefore make Reth allocate and Snappy-decompress frames up to the generic 16 MiB ceiling before Tempo's downstream 1 KiB check runs. The downstream rejection is treated as a graceful disconnect, so the peer also avoids the reputation penalty attached to Reth's transport-level oversized-message error.
Recommended Fix: Override GossipProtocolHandler::inbound_limits() with ProtocolIngressLimits::new(wire::MAX_FRAME_BYTES) and suitable bounded message/byte limits. Keep the downstream size check as defense in depth.

🚨 [SECURITY] Stalled compressed HTTP bodies exhaust all decompression permits

Severity: Low
File: reth@00ff650:crates/rpc/rpc-layer/src/decompression_layer.rs:138
Summary: When --http.decompression is enabled, Reth acquires one of eight shared semaphore permits before awaiting the client-controlled request body, with no body-completion or idle deadline. Eight incomplete compressed bodies can retain every permit indefinitely and block all later compressed RPC requests. A verifier reproduced this with eight incomplete chunked gzip requests followed by a complete request.
Recommended Fix: Apply a body read/idle timeout and release the permit on timeout, or collect the body under an independently bounded network-body policy before acquiring the decompression permit. Add a regression test covering eight stalled bodies followed by a valid compressed request.

Reviewer Callouts

Reviewer Callouts
  • ⚡ Cooperative payload finalization (crates/payload/builder/src/lib.rs:386): Reth's new FINALIZATION_REQUESTED state is distinct from cancellation, but Tempo only checks is_cancelled(). Confirm whether Tempo should seal the partial payload when finalization is requested instead of continuing until its proposal budget expires.
  • ⚡ Bounded RLPx satellite queues (crates/node/src/gossip/transport.rs:585): Tempo currently drains eagerly, but future backpressure in this path can turn a tempo/1 queue overflow into teardown of the entire RLPx session, including the eth primary.

@mattsse
mattsse enabled auto-merge August 25, 2026 09:55
@mattsse
mattsse added this pull request to the merge queue Aug 25, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Aug 25, 2026
@shekhirin
shekhirin added this pull request to the merge queue Aug 25, 2026
Merged via the queue into main with commit b110f4e Aug 25, 2026
67 checks passed
@shekhirin
shekhirin deleted the reth-auto-bump branch August 25, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-dependencies Related to dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants