Skip to content

fix(slasher): do not file data-withholding offenses while peerless - #25179

Closed
spalladino wants to merge 1 commit into
spl/p2p-connectivity-signalfrom
spl/slasher-no-peers-gate
Closed

spalladino wants to merge 1 commit into
spl/p2p-connectivity-signalfrom
spl/slasher-no-peers-gate

Conversation

@spalladino

@spalladino spalladino commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

The data-withholding watcher infers an offense from the absence of a
checkpoint's txs in the local pool. That is only valid evidence if the node
could have received those txs in the first place: a node whose p2p stack is
down sees every checkpoint's txs as missing and accuses entire committees of
withholding data.

The watcher now checks p2p connectivity once per tick, and while p2p is
enabled with zero connected peers it skips the slots that would otherwise be
probed. The skip is permanent — those slots are marked as checked and never
backfilled — because after peers return, txs from those checkpoints may
already have been evicted from the pool as mined, so a late probe would still
report them missing. An unknown must not become an offense.

The gate is vacuous when p2p is disabled by configuration (sandbox and
single-node setups report enabled: false), so behavior there is unchanged.
The degraded-state warning is logged only on the transition into and out of
the state, since the watcher ticks several times per slot.

Part of A-1701.


Part of a stacked-PR chain (bottom → top) hardening the node against running with a dead p2p stack; each PR targets the branch below it and the bottom targets merge-train/spartan-v5:

  1. fix(p2p): fail node startup when p2p service fails to start #25177 — fail node startup when the p2p service fails to start
  2. feat(p2p): expose p2p connectivity (enabled + connected peer count) #25178 — expose p2p connectivity (enabled + connected peer count)
  3. fix(slasher): do not file data-withholding offenses while peerless #25179 — do not file data-withholding offenses while peerless
  4. fix(sequencer): skip proposing when node has no connected peers #25180 — skip proposing when the node has no connected peers
  5. feat(node): report per-component health with p2p peer count on GET /status #25181 — report per-component health with p2p peer count on GET /status
  6. fix(node): reject sendTx when node has no peers to propagate the tx #25182 — reject sendTx when the node has no peers to propagate the tx
  7. feat(p2p): warn periodically while node has zero connected peers #25183 — warn periodically while the node has zero connected peers

The data-withholding watcher infers an offense from the absence of a
checkpoint's txs in the local pool. That is only valid evidence if the node
could have received those txs in the first place: a node whose p2p stack is
down sees every checkpoint's txs as missing and accuses entire committees of
withholding data.

The watcher now checks p2p connectivity once per tick, and while p2p is
enabled with zero connected peers it skips the slots that would otherwise be
probed. The skip is permanent — those slots are marked as checked and never
backfilled — because after peers return, txs from those checkpoints may
already have been evicted from the pool as mined, so a late probe would still
report them missing. An unknown must not become an offense.

The gate is vacuous when p2p is disabled by configuration (sandbox and
single-node setups report `enabled: false`), so behavior there is unchanged.
The degraded-state warning is logged only on the transition into and out of
the state, since the watcher ticks several times per slot.

Part of A-1701.
@spalladino

Copy link
Copy Markdown
Contributor Author

Superseded by #25185, which groups this stack's dependent layers (connectivity signal + slasher/proposer/health/sendTx gates) into one PR with a commit per concern, targeting merge-train/spartan-v5 directly. The independent fixes remain as #25177 and #25183.

@spalladino spalladino closed this Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant