Skip to content

[guardian-proxy] Limit each member's committee updates - #1395

Draft
0xsiddharthks wants to merge 1 commit into
mainfrom
siddharth/proxy-committee-update-limit
Draft

0xsiddharthks wants to merge 1 commit into
mainfrom
siddharth/proxy-committee-update-limit

Conversation

@0xsiddharthks

Copy link
Copy Markdown
Contributor

Summary

A committee member can resend committee updates without limit, each costing the proxy up to two Sui reads and the enclave a chain to parse. The proxy now takes one committee update per member every 5 seconds (follow-up to #1365).

Changes

  • HandoffGate::admit takes the calling member and refuses a second update within UPDATE_INTERVAL.
  • member_auth sets the admitted member's MemberKey on the request, and Forwarding passes it to the gate.
  • guardian_proxy_handoff_refused_total gains the rate_limited reason.

Nodes need no change. A leader retries a refused push every checkpoint, so the limit delays a handoff by at most 5 seconds.

Hops at or below the guardian's epoch are still forwarded. With this limit a resent chain reaches the enclave once per interval per member.

A member could resend committee updates without limit. One naming an
epoch with no stored handoff costs the proxy two Sui reads each time,
on the provider its allowlist refresh uses, and the enclave parses
every chain it is sent.

HandoffGate now takes one committee update per member every 5 seconds,
whatever its outcome. The member gate sets the admitted member's TLS
key on the request, and the forwarder passes it to the handoff gate.
A leader retries a refused push every checkpoint, so the limit delays
a handoff by at most that interval.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant