Repository navigation
Conversation
This was referenced Sep 24, 2026
This was referenced Sep 29, 2026
3for
reviewed
Sep 30, 2026
3for
reviewed
Sep 30, 2026
3for
reviewed
Sep 30, 2026
3for
reviewed
Oct 3, 2026
3for
reviewed
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Require a validated application-layer HELLO before processing peer traffic, enforce a handshake deadline, and validate untrusted HELLO fields before formatting logs.
BAD_PROTOCOLbefore parsing or PBFT dispatch, and reject null or empty frames safely.TIME_OUTdisconnect, while retaining synchronization and request timeout checks. MakehelloMessageReceivevolatile for visibility to the status-check thread.validEndPoint()to validate the raw protobuf endpoint: port 1–65535, at least one IP address, a 200-byte limit per address field, and valid IPv4/IPv6 literals for every nonempty field. Run validation beforetoString()constructs aNode; preserve the log format for valid HELLO messages.endpointValidflag instead of full hashes. Read diagnostic lengths withByteString.size()to avoid copying untrusted fields for logging.Why are these changes required?
Peers could reach business handlers, including PBFT, before completing the application handshake, while handshake timeout depended indirectly on synchronization state. Malformed endpoint fields could also reach address formatting before validation, and oversized hashes could produce excessive warning output.
Handshake admission retains the existing version, genesis, and solid-block compatibility checks without adding a main-chain membership requirement for the peer's unfinalized head. This avoids rejecting otherwise compatible peers during a temporary fork, including reconnection after a disconnect or restart. Subsequent fork handling remains with the existing synchronization and broadcast logic.
This PR has been tested by:
HandShakeServiceTest; HELLO timeout scenarios consolidated intoPeerStatusCheckMockTest. The latest timeout consolidation passed 24 related tests.HelloMessageTest.testValidAddressLogFormatverified on an actual Java 8 runtime after fixing its JDK-dependent IPv6 formatting expectation../gradlew checkstyleMain checkstyleTestandgit diff --checkpassed locally.The full repository test suite and manual multi-node network testing were not run locally.
Follow up
The planned libp2p v2.3.0 fixes will be integrated into java-tron separately. This PR covers java-tron's application-layer HELLO handling and does not update the libp2p dependency.
Extra details