Skip to content

test(verify_signatures): reject out-of-range proposer_index via tamper#664

Merged
tcoratger merged 1 commit intoleanEthereum:mainfrom
tcoratger:test/verify-signatures-proposer-bounds
Apr 21, 2026
Merged

test(verify_signatures): reject out-of-range proposer_index via tamper#664
tcoratger merged 1 commit intoleanEthereum:mainfrom
tcoratger:test/verify-signatures-proposer-bounds

Conversation

@tcoratger
Copy link
Copy Markdown
Collaborator

🗒️ Description

Adds the rejection vector for `block.py:277` Proposer index out of range. The builder's round-robin proposer selection never produces an out-of-range index, so this rejection only fires for blocks received from a malicious peer.

Uses the `verify_signatures` tamper hook to set `proposer_index` to 99 on a block built normally against a 4-validator state. The fixture pins the `AssertionError` clients must raise.

Tamper extension

Extends the dispatcher in #663 with a `set_proposer_index` operation. Preserves the same contract: tamper runs after the valid build, before verification.

⚠️ Depends on #663

Stacked on `framework/verify-signatures-tamper`. Please review and merge #663 first; after that lands I'll rebase this on `main` and the diff will shrink to just the new operation + test.

🔗 Related Issues or PRs

Stacked on #663.

✅ Checklist

  • Ran `tox` checks to avoid unnecessary CI fails:
    ```console
    uvx tox -e all-checks
    ```
  • Considered adding appropriate tests for the changes.
  • N/A for docs — test-vector-only PR.

🤖 Generated with Claude Code

Adds the rejection vector for block.py:277 Proposer index out of range.
The builder's round-robin proposer selection never produces an
out-of-range index, so this rejection only fires for blocks received
from a malicious peer.

Uses the verify_signatures tamper hook to set proposer_index to 99 on
a block built normally against a 4-validator state. The fixture pins
the AssertionError clients must raise.

Extends the tamper dispatcher with a set_proposer_index operation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@tcoratger tcoratger force-pushed the test/verify-signatures-proposer-bounds branch from e989b6a to a174974 Compare April 21, 2026 21:02
@tcoratger tcoratger merged commit d56e332 into leanEthereum:main Apr 21, 2026
13 checks passed
tcoratger added a commit to tcoratger/leanSpec that referenced this pull request Apr 22, 2026
Integrates the metrics→observability split (leanEthereum#667) with the multi-fork layout:

- fork code (forks/devnet4/store.py, forks/devnet4/containers/state/state.py)
  imports only the vendor-neutral observe_on_attestation / observe_on_block /
  observe_state_transition hooks; no Prometheus-specific metrics land inside
  forks/, keeping the fork folder consensus-critical by construction
- BlockLookup is now the plain dict[Bytes32, Block] alias from leanEthereum#667, so the
  former dict-subclass imports (Iterator, GetCoreSchemaHandler, ZERO_HASH)
  and the node's BlockLookup({...}) wrap are dropped
- reorg-depth telemetry moves to sync/service.py's default_block_processor
  and stays off the spec side
- consensus tests and fixture builders added in leanEthereum#663, leanEthereum#664, leanEthereum#665, leanEthereum#666 retarget
  lean_spec.subspecs.containers.* → lean_spec.forks.devnet4.containers.*; the
  verify_signatures tamper hook's in-function imports are pulled up to the top
- drops tests/lean_spec/subspecs/containers/block/test_block_lookup.py
  (BlockLookup no longer has ancestors / reorg_depth methods to test)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant