Batch kernel: apply the 1024 note limit to post-erasure counts
- 主要语言
- Rust
- 星标
- 132
- 派生
- 167
- 平均合并
- 1 天 23 小时
- 30 天内合并 PR
- 110
描述
Follow-up from the PR #2905 review (thread on `asm/kernels/batch/lib/prologue.masm`).
## Problem
`ProposedBatch` enforces `MAX_INPUT_NOTES_PER_BATCH` / `MAX_OUTPUT_NOTES_PER_BATCH` (= 1024) on the **post-erasure** note sets. The batch kernel instead stores the **pre-erasure** union of every transaction's notes in fixed 1024-entry regions, and asserts the pre-erasure length ≤ 1024 before writing.
So a batch with >1024 pre-erasure notes that erases down to ≤ 1024 passes `ProposedBatch` but is rejected by the kernel. It is memory-safe, but some valid batches cannot be proven.
## Temporary mitigation (landed in #2905)
`BatchExecutor::execute` rejects a batch whose pre-erasure input/output union exceeds `MAX_*_NOTES_PER_BATCH`.
## Proper fix
The 1024 limit should stay a **post-erasure** limit
贡献指南
评估
这个 Issue 还没有评估数据。