Split out from PR #4288 (fixes #4287).
PR #4288 fixes the tBTC branch of the peer-admission firewall to gate on WalletRegistry.eligibleStake instead of a frozen legacy TokenStaking delegation. The beacon branch (pkg/chain/ethereum/beacon.go) deliberately keeps the legacy RolesOf check, because RandomBeacon.eligibleStake is zero for every registered provider (TokenStaking.authorizedStake only recognizes the TACo application).
This leaves an acknowledged, disclosed gap: any staking provider holding a pre-TIP-092 legacy delegation retains full P2P peer admission forever via the beacon branch, regardless of its current authorization. An operator could decrease authorization to zero after any pending-decrease delay finalizes and remain a permanently-connected peer through this path alone.
PR #4288's own description calls this "the security half of the incident" and states it "is tracked separately" - this issue is that tracking artifact.
Not a regression introduced by #4288; a pre-existing condition the beacon-branch asymmetry documents but does not close. See pkg/chain/ethereum/beacon.go (asymmetry comment) and the legacy_revoked test case in internal/ethtest/admission.go, which pins this exact behavior as current, unchanged production behavior.
Split out from PR #4288 (fixes #4287).
PR #4288 fixes the tBTC branch of the peer-admission firewall to gate on WalletRegistry.eligibleStake instead of a frozen legacy TokenStaking delegation. The beacon branch (pkg/chain/ethereum/beacon.go) deliberately keeps the legacy RolesOf check, because RandomBeacon.eligibleStake is zero for every registered provider (TokenStaking.authorizedStake only recognizes the TACo application).
This leaves an acknowledged, disclosed gap: any staking provider holding a pre-TIP-092 legacy delegation retains full P2P peer admission forever via the beacon branch, regardless of its current authorization. An operator could decrease authorization to zero after any pending-decrease delay finalizes and remain a permanently-connected peer through this path alone.
PR #4288's own description calls this "the security half of the incident" and states it "is tracked separately" - this issue is that tracking artifact.
Not a regression introduced by #4288; a pre-existing condition the beacon-branch asymmetry documents but does not close. See pkg/chain/ethereum/beacon.go (asymmetry comment) and the legacy_revoked test case in internal/ethtest/admission.go, which pins this exact behavior as current, unchanged production behavior.