Skip to content

LLMQ: Bound pending signature shares - #1930

Open
navidR wants to merge 1 commit into
firoorg:masterfrom
navidR:dev/navidr/bounded-pending-sig-shares
Open

LLMQ: Bound pending signature shares#1930
navidR wants to merge 1 commit into
firoorg:masterfrom
navidR:dev/navidr/bounded-pending-sig-shares

Conversation

@navidR

@navidR navidR commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Bound unverified pending signature shares per peer and globally with constant-time accounting. Add boundary and cleanup coverage for all counted-map mutation paths.

Upstream: Dash PR #7415.

Limit unverified pending shares per peer and globally. Keep signature-share size accounting constant-time.
@codeant-ai

codeant-ai Bot commented Aug 30, 2026

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR a7c392a Aug 30, 2026 · 14:55 14:59

@codeant-ai

codeant-ai Bot commented Aug 30, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 59 minutes.

View limit details

Limit details: You’ve used all 4 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0c7c1719-427a-4812-b112-4c5a70b7b5e2

📥 Commits

Reviewing files that changed from the base of the PR and between 4f0c771 and a7c392a.

📒 Files selected for processing (4)
  • src/llmq/quorums_signing_shares.cpp
  • src/llmq/quorums_signing_shares.h
  • src/test/CMakeLists.txt
  • src/test/quorums_signing_pending_tests.cpp

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 30, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-30T14:57:47.705241Z a7c392a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Aug 30, 2026
@codeant-ai

codeant-ai Bot commented Aug 30, 2026

Copy link
Copy Markdown

User description

Bound unverified pending signature shares per peer and globally with constant-time accounting. Add boundary and cleanup coverage for all counted-map mutation paths.


CodeAnt-AI Description

Limit pending signature shares per peer and globally

What Changed

  • Unverified pending signature shares are rejected after reaching 1,000 shares from one peer or 10,000 shares across all peers
  • Pending shares are removed from the limits when processed, deleted, or when a peer is banned
  • Share counts remain accurate after individual, session-based, filtered, and bulk removals
  • Added coverage for per-peer limits, global limits, cleanup, and duplicate entries

Impact

✅ Bounded memory use from pending signature shares
✅ Reduced exposure to signature-share flooding
✅ Accurate capacity after pending-share cleanup

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

auto& nodeState = it->second;
for (auto& s : sigShares) {
nodeState.pendingIncomingSigShares.Add(s.GetKey(), s);
TryAddPendingIncomingSigShare(pfrom->id, nodeState, s);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: The return value is ignored, so a cap-rejected share is permanently dropped after its request was cleared and its announcement bit was consumed. [incomplete implementation]

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** src/llmq/quorums_signing_shares.cpp
**Line:** 541:541
**Comment:**
	*Incomplete Implementation: The return value is ignored, so a cap-rejected share is permanently dropped after its request was cleared and its announcement bit was consumed.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Comment on lines +559 to +562
size_t total{0};
for (const auto& p : nodeStates) {
total += p.second.pendingIncomingSigShares.Size();
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: Each share scans every node while holding cs; a peer can send repeated batches and cause expensive lock-held work that delays other signing messages. [performance]

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** src/llmq/quorums_signing_shares.cpp
**Line:** 559:562
**Comment:**
	*Performance: Each share scans every node while holding `cs`; a peer can send repeated batches and cause expensive lock-held work that delays other signing messages.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

@navidR

navidR commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

This is not from upstream, but something I think we should address:

  diff --git a/src/llmq/quorums_signing_shares.cpp b/src/llmq/quorums_signing_shares.cpp
  @@ -505,18 +505,19 @@
           for (size_t i = 0; i < batchedSigShares.sigShares.size(); i++) {
               CSigShare sigShare = RebuildSigShare(sessionInfo, batchedSigShares, i);
  -            nodeState.requestedSigShares.Erase(sigShare.GetKey());

               if (this->sigShares.Has(sigShare.GetKey())) {
  +                nodeState.requestedSigShares.Erase(sigShare.GetKey());
                   continue;
               }

               if (quorumSigningManager->HasRecoveredSigForId(
                       (Consensus::LLMQType)sigShare.llmqType, sigShare.id)) {
  +                nodeState.requestedSigShares.Erase(sigShare.GetKey());
                   continue;
               }

  @@ -538,6 +539,11 @@
       }
       auto& nodeState = it->second;
       for (auto& s : sigShares) {
  +        if (this->sigShares.Has(s.GetKey()) ||
  +            quorumSigningManager->HasRecoveredSigForId(
  +                (Consensus::LLMQType)s.llmqType, s.id)) {
  +            nodeState.requestedSigShares.Erase(s.GetKey());
  +            continue;
  +        }
           TryAddPendingIncomingSigShare(pfrom->id, nodeState, s);
       }
       return true;
  @@ -550,9 +556,27 @@
       if (nodeState.banned) {
           return false;
       }
  +    const auto& key = sigShare.GetKey();
  +    if (nodeState.pendingIncomingSigShares.Has(key)) {
  +        nodeState.requestedSigShares.Erase(key);
  +        return false;
  +    }
  +
  +    const auto rearmRequest = [&]() {
  +        if (!nodeState.requestedSigShares.Has(key)) {
  +            return;
  +        }
  +        if (auto session = nodeState.GetSessionBySignHash(key.first)) {
  +            session->announced.Set(key.second, true);
  +        }
  +        nodeState.requestedSigShares.Erase(key);
  +        sigSharesRequested.Erase(key);
  +    };
  +
       if (nodeState.pendingIncomingSigShares.Size() >= MAX_PENDING_SIG_SHARES_PER_NODE) {
           LogPrint("llmq-sigs", "CSigSharesManager::%s -- per-node pending sig shares cap reached (%d), dropping sigShare. node=%d\n",
               __func__, MAX_PENDING_SIG_SHARES_PER_NODE, nodeId);
  +        rearmRequest();
           return false;
       }

  @@ -563,10 +587,15 @@
       if (total >= MAX_PENDING_SIG_SHARES_TOTAL) {
           LogPrint("llmq-sigs", "CSigSharesManager::%s -- global pending sig shares cap reached (%d), dropping sigShare. node=%d\n",
               __func__, MAX_PENDING_SIG_SHARES_TOTAL, nodeId);
  +        rearmRequest();
           return false;
       }

  -    return nodeState.pendingIncomingSigShares.Add(sigShare.GetKey(), sigShare);
  +    const bool added = nodeState.pendingIncomingSigShares.Add(key, sigShare);
  +    if (added) {
  +        nodeState.requestedSigShares.Erase(key);
  +    }
  +    return added;
   }



@reubenyap reubenyap left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed the pending-share admission path, every counted-map mutation path (single, bucket, predicate, and full clear), the per-peer/global boundaries, and ban/session cleanup. I also traced the request bookkeeping and the existing discussion; I found no additional actionable defect beyond the issues already raised on this PR. The focused regression coverage and full CI matrix are green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants