Skip to content

consensus: define remote genesis application policy #992

Description

@hackobi

Decision required

The current verifier special-cases block number 0 and accepts it without normal signature/hash checks. The synced-block follow-up review found that direct sync/batch callers could theoretically apply a remote genesis block unless callers guarantee this is unreachable.

Required decision

Choose and document one fail-closed policy:

  1. Reject remote genesis application and require the configured local genesis; or
  2. Validate the remote genesis against a canonical genesis hash/configuration.

Acceptance criteria

  • Policy is explicit in the consensus code/documentation.
  • A regression test covers direct sync/batch ingress.
  • No arbitrary remote genesis can be persisted.

This is separate from signer-membership filtering and vote domain binding (#987).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions