Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unlimited dry running of the transactions #1970

Closed
xgreenx opened this issue Jun 14, 2024 · 0 comments · Fixed by #2151
Closed

Unlimited dry running of the transactions #1970

xgreenx opened this issue Jun 14, 2024 · 0 comments · Fixed by #2151
Assignees
Labels
bug Something isn't working good first issue Good for newcomers

Comments

@xgreenx
Copy link
Collaborator

xgreenx commented Jun 14, 2024

Problem overview

The executor ignores the block gas limit during the dry running of transactions. It allows the attacker to submit a lot of transactions to dry run in one request, consuming the endpoint entirely.

Solution

  1. Update the executor's dry run logic to respect the block gas limit.
  2. And upgrade the dry_run endpoint to deserialize transactions one by one and check that cumulative gas less than block gas limit.
image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working good first issue Good for newcomers
Projects
None yet
3 participants