evstack / evstack/ev-node

p2p: allowed_peers list propagated network-wide instead of being local to the node

未關閉
#3,254 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
C:p2p
主要語言
Go
星號
361
分支
280
平均合併
2 天 14 小時
30 天內合併 PR
10

描述

Sequencer version : `v1.1.0-rc.1`

## Description

When running a sequencer node with `--allowed_peers=fullnode-1,fullnode-2`, the allowed peers list appears to be propagated to the rest of the network. As a result, other fullnodes that try to connect via P2P to `fullnode-1` or `fullnode-2` are rejected, even though those fullnodes never set `allowed_peers` themselves.

## Expected Behavior

The `allowed_peers` configuration should be **local** to the node that runs the argument. It should only restrict which peers *that specific node* accepts connections from. It must not be advertised or enforced on other nodes in the network.

## Actual Behavior

The `allowed_peers` list set on the sequencer is propagated across the network. Nodes that did not set `allowed_peers` still refuse connections from nodes not on the sequencer's list.

## Network Topology

The following diagram illustrates the affected network and the expected isolation of the `allowed_peers` constraint:

```
Eden Testnet Network
┌─────────────────────────────────────────────────────────────────────┐
│ │
│ ┌───────────────────────────────┐ │
│ │ Sequencer │ │
│ │ allowed_peers=fullnode-1, │ │
│ │ fullnode-2 │ │
│ └──────────────┬────────────────┘ │
│ │ P2P │
│ ┌────────┴────────┐ │
│ │ │ │
│ ┌─────▼──────┐ ┌──────▼─────┐ │
│ │ fullnode-1 │ │ fullnode-2 │ │
│ └─────┬──────┘ └──────┬─────┘ │
│ │ │ │
│ │ P2P (EXPECTED) │ P2P (EXPECTED) │
│ │ │ │
│ ┌─────▼─────────────────▼─────┐ │
│ │ new-fullnode-N ... │ │
│ │ (unable to connect — BUG) │ │
│ └─────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────────────────┘

Legend:
──► P2P connection (established / expected)
BUG: new-fullnode-N cannot connect to fullnode-1 or fullnode-2
because the sequencer's allowed_peers list is enforced there
```

### Intended behavior (allowed_peers should be local)

```
Sequencer ←──(only accepts fullnode-1, fullnode-2)──► fullnode-1
──► fullnode-2

fullnode-1 ←──(no restriction; accepts any peer)──► new-fullnode-N
fullnode-2 ←──(no restriction; accepts any peer)──► new-fullnode-N
```

## Steps to Reproduce

1. Start a network with: sequencer, fullnode-1, fullnode-2.
2. Run the sequencer with `--allowed_peers=fullnode-1,fullnode-2`.
3. Attempt to join a new fullnode that connects via P2P to fullnode-1 or fullnode-2.
4. Observe: the new fullnode is rejected by fullnode-1/fullnode-2 despite them not having `allowed_peers` set.

## Environment

- Network: eden-testnet
- Observed: week of 2026-04-14

## Impact

Any new node attempting to sync via fullnode-1 or fullnode-2 is silently blocked, making fullnode only syncing through DA unless modifying the sequencer's `allowed_peers` list.

貢獻指南

開啟貢獻指南

研究方向

首先,沿著 P2P peer 廣播和連線處理路徑追蹤 --allowed_peers CLI 設定。重現 issue 中描述的 sequencer/fullnode 拓撲,然後驗證該限制僅由設定它的 node 強制執行,且不受限制的 fullnode 接受新的 peer。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
go
領域
networking
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。