fix(bifrost): S14 - bound attestation state synchronization

Add limits to Bifrost state synchronization so peers cannot start too many transfers or send oversized batches. Keep large valid snapshots exportable by splitting their attestations into smaller items.

Series context

This is S14 in the focused MR series replacing !4983 (closed). The full series plan is tracked there.

  • Scope: State-sync request limits, message validation and complete snapshot export for all chains. This applies beyond XMR.
  • Depends on: Current develop directly - no RDY dependency.
  • Follow-up: S15(!5108) - stopping state processing, lock waits and THORNode queries when a transfer is cancelled.
  • Included tests: Uneven-category and zero-transaction snapshot tests.

This MR targets develop. S15(!5108) builds on it. The changes affect Bifrost only. They do not change THORNode consensus or protobuf schemas.

Changes

  • Check that a peer is active before reading its request. Allow one incoming state request per peer, ten in total, and only one exported snapshot at a time.
  • Check message lengths, batch order and declared counts. Limit each transfer to 1,000 batches and 10,000 items, with up to 128 attestations per item.
  • Validate each decoded batch before processing it. Reset failed or timed-out streams, and keep their request slots occupied until the handlers finish.
  • Split stored items with more than 128 uncommitted attestations into smaller transfer items. Keep all signatures and unrelated state, and continue packing batches by byte size. Reject snapshots that exceed the overall limits before starting the transfer.
  • Add bifrost.attestation_gossip.state_sync_timeout, with a 30-minute default. State transfers get their own time budget, separate from the ordinary peer timeout. Existing per-message read and write deadlines remain.
  • Report export-limit failures at Warn level, with useful item details and at most one warning per minute.

These rules cover transactions, network fees, solvencies, errata and price feeds.

Known limitations and follow-ups

  • A timeout resets the connection, but processing or queries already running may continue. S15(!5108) handles cancellation of that work.
  • Retrying incomplete startup sync is deferred to S26. Protection against peers that stall acknowledgements is tracked under P15.
  • Protobuf decoding still allocates memory before item counts are checked. P16 covers limits on those allocations.
  • The 30-minute default allows more time for large transfers. It does not guarantee completion on every machine or under every workload.

Verification

  • Focused normal and mocknet tests passed three times.
  • Tests cover request limits, malformed transfers, large-bucket import/export/reimport, all five categories, timeouts, warnings and uneven snapshots.
  • Relevant race tests passed three times.
  • Configuration checks, repository formatting, diff checks and configured lint passed.

No full cluster simulation was run.

Edited by ZlyDevMaya

Merge request reports

Loading
Loading