0xMiden / 0xMiden/protocol

Batch kernel: apply the 1024 note limit to post-erasure counts

未关闭
#3,184 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
kernels
主要语言
Rust
星标
132
派生
167
平均合并
1 天 23 小时
30 天内合并 PR
110

描述

Follow-up from the PR #2905 review (thread on `asm/kernels/batch/lib/prologue.masm`).

## Problem

`ProposedBatch` enforces `MAX_INPUT_NOTES_PER_BATCH` / `MAX_OUTPUT_NOTES_PER_BATCH` (= 1024) on the **post-erasure** note sets. The batch kernel instead stores the **pre-erasure** union of every transaction's notes in fixed 1024-entry regions, and asserts the pre-erasure length ≤ 1024 before writing.

So a batch with >1024 pre-erasure notes that erases down to ≤ 1024 passes `ProposedBatch` but is rejected by the kernel. It is memory-safe, but some valid batches cannot be proven.

## Temporary mitigation (landed in #2905)

`BatchExecutor::execute` rejects a batch whose pre-erasure input/output union exceeds `MAX_*_NOTES_PER_BATCH`.

## Proper fix

The 1024 limit should stay a **post-erasure** limit

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。