Skip to content

Track: legacy TokenStaking delegation grants permanent peer admission via beacon.go regardless of current authorization #4335

Description

@piotr-roslaniec

Split out from PR #4288 (fixes #4287).

PR #4288 fixes the tBTC branch of the peer-admission firewall to gate on WalletRegistry.eligibleStake instead of a frozen legacy TokenStaking delegation. The beacon branch (pkg/chain/ethereum/beacon.go) deliberately keeps the legacy RolesOf check, because RandomBeacon.eligibleStake is zero for every registered provider (TokenStaking.authorizedStake only recognizes the TACo application).

This leaves an acknowledged, disclosed gap: any staking provider holding a pre-TIP-092 legacy delegation retains full P2P peer admission forever via the beacon branch, regardless of its current authorization. An operator could decrease authorization to zero after any pending-decrease delay finalizes and remain a permanently-connected peer through this path alone.

PR #4288's own description calls this "the security half of the incident" and states it "is tracked separately" - this issue is that tracking artifact.

Not a regression introduced by #4288; a pre-existing condition the beacon-branch asymmetry documents but does not close. See pkg/chain/ethereum/beacon.go (asymmetry comment) and the legacy_revoked test case in internal/ethtest/admission.go, which pins this exact behavior as current, unchanged production behavior.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions