Alchemy - Code Fix - #11714
Conversation
|
@stdevMac needs to be cherry picked in 1.38.0 |
|
Claude finished @svlachakis's task in 6m 30s —— View job Code Review
SummaryThe root-cause analysis is accurate and the fix is well-targeted. The bug was a lifetime mismatch: the persisted-code hint cache lived on the long-lived Verdict: Approve with minor comments. No correctness regressions found. The three findings below are low-to-medium; none block merge. FindingsMedium —
|
| Scenario | Before | After |
|---|---|---|
debug_traceCall deploys code → overlay reset → second call same code |
Throws Code 0x… missing |
✓ Returns code |
| Production block processing: same factory bytecode deployed many blocks | Skips DB write (cross-block hint) ✓ | Same — _persistedHint on the durable codeDb ✓ |
| Same code deployed twice in same block | Skips second _codeBatch insert ✓ |
Same — _blockCodeInsertFilter ✓ |
WorldStateManager.CreateResettableWorldState() (read-only) |
N/A | codeDbIsPersistent: false default → no hint cache ✓ |
HealingWorldStateScopeProvider |
Was using old single filter | codeDbIsPersistent: true passed explicitly ✓ |
Thread safety: AssociativeKeyCache uses lock-free seqlock reads and Volatile.Write for mutations — it is safe for concurrent access from the main thread (ContainsCode) and the Task.Run background thread (MarkCodePersisted).
_codeDb null guard in InsertCode: _codeDb?.ContainsCode(codeHash) ?? false is fail-open (false-negative), so code is redundantly re-inserted rather than silently skipped if _codeDb is null — correct direction.
Regression tests: Both KeyValueWithBatchingBackedCodeDb_ContainsCode_respects_isPersistent_flag (unit) and Same_code_can_be_redeployed_across_overlay_resets (integration) directly exercise the failure path. The integration test correctly relies on worldState.BeginScope dispose calling Reset() (which clears _blockCodeInsertFilter) between the two overlay passes.
|
@claude review again |
|
Claude finished @svlachakis's task in 3m 24s —— View job Code Review
SummaryThis is a re-review after the previous round of feedback. All three findings from the first review have been addressed:
Correctness analysis
Thread safety:
Remaining findingLow — Session-specific test comment
Verdict: Approve. The bug fix is correct and well-targeted. The interface change is non-breaking. All call sites have the right |
|
Claude finished @svlachakis's task in 4m 56s —— View job Code Review
SummaryThis is a complete re-review. All findings from both prior review rounds have been addressed. The implementation is correct, well-tested, and safe. Previously flagged findings — all resolved
Unmodified
|
| Site | Code db | Why false is correct |
|---|---|---|
WorldStateManager.CreateResettableWorldState() |
_readaOnlyCodeCb — ReadOnlyDb(…, true) overlay |
Temp-overlay writes are discarded on reset; true would re-introduce the same lifetime bug for block producers |
FlatOverridableWorldScope |
new ReadOnlyDb(codeDb, true) overlay |
Same overlay semantics |
StatelessBlockProcessingEnv |
witness.CreateCodeDb() — witness-backed, not RocksDB |
No persistent store to cache against |
WitnessGeneratingBlockProcessingEnvFactory |
readOnlyDbProvider.CodeDb — ReadOnlyDb overlay |
Temp overlay; writes discarded |
Correctness analysis
| Scenario | Result |
|---|---|
debug_traceCall deploys code → overlay reset → second call same code |
✓ Fixed: _persistedHint is null on overlay codeDb; ContainsCode always false |
| Production block sync: same factory bytecode across many blocks | ✓ _persistedHint (1 024-entry) on durable codeDb still short-circuits redundant writes |
| Same code deployed twice in the same block | ✓ _blockCodeInsertFilter (256-entry, intra-block, cleared on Reset) prevents duplicate inserts |
OverridableWorldStateManager (debug/call overlays) |
✓ codeDbIsPersistent: false explicit |
HealingWorldStateScopeProvider (production) |
✓ codeDbIsPersistent: true hardcoded in constructor |
Non-healing production path (PruningTrieStateFactory) |
✓ codeDbIsPersistent: true explicit |
FlatScopeProvider |
✓ isPersistent: !isReadOnly — write paths durable, read-only paths overlay |
Thread safety: MarkCodePersisted runs in Task.Run(PersistCodeBatch). The main thread blocks via codeFlushTask.GetAwaiter().GetResult() before the next block's InsertCode can run — no race on _persistedHint. AssociativeKeyCache seqlock reads and Volatile.Write mutations are safe for this access pattern.
_codeDb null guard in InsertCode: _codeDb?.ContainsCode(codeHash) ?? false is fail-open (false-negative direction) — code is re-inserted rather than silently skipped when _codeDb is null. Correct.
MarkCodePersisted ordering: Called after the using (ICodeSetter batch = codeDb.BeginCodeWrite()) block completes — code is durably written before the hint is set. Correct.
Regression tests: KeyValueWithBatchingBackedCodeDb_ContainsCode_respects_isPersistent_flag (parameterized unit) and Same_code_can_be_redeployed_across_overlay_resets (integration, both trie and flat backends) directly exercise the failure path. The integration test correctly disposes the scope (triggering Reset() which clears _blockCodeInsertFilter) and calls ResetOverrides() between the two overlay passes.
Verdict: Approve. No outstanding findings. The fix is minimal, correct, and well-tested.
|
@claude review my regression tests we should have one unit, one in state module and one full end to end on rpc layer |
|
Claude finished @svlachakis's task in 4m 24s —— View job Regression Test Review
Coverage mapAll three layers are present:
FindingsMedium — Unit test runs 4× instead of 2×
Low — RPC test has no content assertion
What each test exercisesUnit ( State module ( RPC end-to-end ( |
|
@claude review again |
|
Claude finished @svlachakis's task in 4m 38s —— View job Code Review
SummaryThis is a full re-review of the current branch state. All findings from the three prior review rounds have been resolved. The implementation is correct, well-tested, and safe. Previously flagged findings — all resolved
Correctness analysis
Thread safety:
Remaining notes (pre-existing, unmodified files — not blocking)Two call sites in unmodified files still use the implicit
These are harmless and pre-date this PR; worth a follow-up pass to make intent explicit, but do not block merge. Verdict: Approve. No outstanding findings. The fix is minimal, correct, and well-tested across all three layers (unit, state module, RPC end-to-end). |
| public bool ContainsCode(in ValueHash256 codeHash) => false; | ||
|
|
||
| public void MarkCodePersisted(in ValueHash256 codeHash) { } |
There was a problem hiding this comment.
not needed as there is default implementation in interface?
| public bool ContainsCode(in ValueHash256 codeHash) => false; | ||
|
|
||
| public void MarkCodePersisted(in ValueHash256 codeHash) { } |
| // code is used by multiple deployments. Either from factory contracts (e.g. LPs) | ||
| // or people copy and pasting popular contracts | ||
| if (!_blockCodeInsertFilter.Get(codeHash) && !_persistedCodeInsertFilter.Get(codeHash)) | ||
| if (!_blockCodeInsertFilter.Get(codeHash) && !(_codeDb?.ContainsCode(codeHash) ?? false)) |
There was a problem hiding this comment.
IMO more readable:
| if (!_blockCodeInsertFilter.Get(codeHash) && !(_codeDb?.ContainsCode(codeHash) ?? false)) | |
| if (!_blockCodeInsertFilter.Get(codeHash) && !(_codeDb?.ContainsCode(codeHash) == true)) |
|
Does this supersede #11712? Should we close that one? |
|
@LukaszRozmej I've left #11712 in case we wanted to release 1.37.3 because it's based of from release and for the customer image diff, looks like not so I'm closing it |
* RLP tx decoding fixes (#11496) * Handle null txs * PR feedback * Revert `BlobTxStorage.TryDecodeFullTx` changes Silent `false` may be worse that NRE on DB corruption --------- Co-authored-by: Alexey Osipov <me@flcl.me> * eth/71 (#10844) * Improve eth/70 checks (#11456) * Improve eth/70 verification * Comments * Gas remake * Fix full sync * fix: prevent negative RequestSize crash when beacon pivot destination advances mid-sync (#11478) * fix: prevent negative RequestSize crash when beacon pivot destination advances mid-sync `HeadersSyncFeed.ShouldBuildANewBatch` checked `_lowestRequestedHeaderNumber == HeadersDestinationNumber`. For beacon headers, `HeadersDestinationNumber` is `BeaconPivot.PivotDestinationNumber`, which tracks `Head.Number - Reorganization.MaxDepth + 1` and so advances upward as the chain head progresses. When it stepped above `_lowestRequestedHeaderNumber` mid-sync, the `==` check missed it, `BuildNewBatch` produced a negative `RequestSize`, and `HeaderStore.FindReversedHeaders` crashed with `ArgumentOutOfRangeException` on `new Dictionary<>(negativeCount)`. Widen the guard to `<=` and add a regression test that reproduces the scenario via mocked `IBeaconPivot`. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: shorten inline comments per review Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Add new default for gnosis and gnosis archive config (#11269) feat: add Db.SkipCheckingSstFileSizesOnDbOpen=true default for gnosis and gnosis archive * Alchemy - Code Fix (#11714) * feat: add SkipMetricsTracking property to DbSettings (#11515) * feat: add SkipMetricsTracking property to DbSettings - Introduced SkipMetricsTracking property in DbSettings to control metrics tracking for specific databases. - Updated FullPruningInnerDbFactory to set SkipMetricsTracking to true for inner databases to prevent stale references after pruning. - Added unit tests to verify the behavior of metrics tracking based on the new property. - Enhanced DbMonitoringModule to respect the SkipMetricsTracking setting when adding databases to the tracker. * fix: address PR feedback for db metrics tracking - Add XML doc to DbSettings.SkipMetricsTracking property - Clarify WorldStateModule comment for both FullPruningInnerDbFactory and MemDbFactory branches - DbMonitoringModule: clear stale dictionary entries on GatherMetric failure and log only once per failure streak (with recovery info log) - DbTrackerTests: add [TearDown] to reset shared static metrics keys, collapse double enumeration in TestSkipMetricsTracking, and add FullPruningDbTrackedWrapper_SurvivesPruningCycle integration test Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor: dedupe DbTrackerTests container setup and metric-map iteration Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: Initialize _failingDbs with an empty HashSet --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Co-authored-by: lukasz.rozmej <lukasz.rozmej@gmail.com> * Fix DbTracker repeatedly logging ObjectDisposedException after disposal (#11720) * Fix DbTracker repeatedly logging ObjectDisposedException after disposal When the Autofac LifetimeScope (or the shared cache SafeHandle) is disposed while MonitoringService's timer is still scheduled, `_sharedBlockCache.Value` in `UpdateDbMetrics` throws `ObjectDisposedException` via Autofac's LazyRegistrationSource. The generic catch logs it at Error and the callback stays registered, so the same exception re-fires on every metric interval — producing dozens of identical errors per minute on affected nodes. Catch `ObjectDisposedException` explicitly and short-circuit subsequent ticks via a `_stopped` flag. Adds a regression test that disposes the container and asserts the callback neither throws nor logs on repeated invocations. Fixes #11719 * Address review: debug-log first stop, drop redundant CreateDb in test - Log at Debug level in the new `ObjectDisposedException` branch so there is a (no-cost on production) signal that DbTracker has stopped updating metrics, rather than only inferring it from the absence of further Error logs. - Remove the duplicate `CreateDb` call in the regression test — the helper `ConfigureMetricUpdater` already registers the test DB. - Disable `TestLogger.IsDebug` in the regression test so the new Debug message does not trip the `LogList.Should().BeEmpty()` assertion; the test still asserts no Error-level spam, which was the bug. * Address review: make DbTracker IDisposable, drop redundant comment - Implement IDisposable on DbTracker so Autofac proactively sets _stopped during scope teardown, short-circuiting subsequent monitoring ticks before they touch disposed resources. The catch (ObjectDisposedException) remains as a backstop for the race where a tick is already executing when Dispose runs. - Mark _stopped as volatile since it is now written from the disposing thread and read from the monitoring timer thread. - Drop the inline comment in the catch block; the Debug log message already conveys the same information. * Fix Eth69/Eth70 receipt tests for null-means-unknown contract After dropping the FindHeader pre-check, the response loop relies solely on GetReceipts returning null to detect an unknown block. The two "unknown block hash" tests still mocked the old contract (FindHeader returns null + GetReceipts returns []), so the loop saw [] as a legitimate zero-tx block and kept going instead of breaking. Update the mocks to return null for unknown hashes, matching the ISyncServer.GetReceipts contract (null = unknown, [] = exists w/ 0 txs). * Make EraE tests visible and green (#11727) * fix(eth/70): reject null receipt payloads (#11615) * fix(eth/70): reject null receipt payloads * fix(eth/70): validate receipt payloads while decoding * refactor(eth): move null receipt validation into base serializer Apply the validation in V63 ReceiptsMessageSerializer so eth/63, eth/66, eth/69 and eth/70 all reject null receipt payloads at decode time. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: lukasz.rozmej <lukasz.rozmej@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> (cherry picked from commit fd2fd25) * fix(eth/70): stop response early when block has txs but no receipts FulfillReceiptsRequest used to emit `txReceipts.Add([])` for any block where SyncServer.GetReceipts(hash) returned empty, regardless of whether the block actually had zero transactions. The eth/70 receiver validates segment-complete responses against its own transaction count and throws SubprotocolException ("Receipt count mismatch with block transactions count") + disconnects the peer when an [] arrives for a block that locally has transactions. That made a node that is briefly without receipts (e.g. still syncing receipts, or its receipt store is pruned for the requested block) appear malicious to the requester. We observed this disconnect-storm pattern materially starving receipt-sync on small networks. Distinguish the two cases at the sender by looking up the block: - block is null or body is missing → we can't safely claim anything; break the response and let the requester ask another peer - block.Transactions.Length > 0 → same: we don't actually have the receipts even though we have the body; break - block.Transactions.Length == 0 → block is legitimately empty; emit [] as before Update Should_return_empty_receipts_block_when_local_block_has_no_receipts → ..._has_no_transactions to reflect the new precondition, and stub SyncServer.Find on two pre-existing empty-receipts-in-the-middle tests so they still represent the legitimate empty case. Add new regression test Should_stop_response_when_local_block_has_transactions_but_no_receipts covering the bug. Closes #11752. (cherry picked from commit f0f6ea2) * refactor(eth/70): disambiguate "unknown" vs "legit empty" in ISyncServer.GetReceipts Following @LukaszRozmej's review suggestion on #11752: rather than have the protocol handler do a second SyncServer.Find lookup to figure out whether an empty receipts array means "block has zero transactions" or "I don't have the receipts yet", push the disambiguation down to where the data lives. ISyncServer.GetReceipts now returns TxReceipt[]?: null → receipts are not known locally (block missing, body missing, or receipts not stored). Callers MUST NOT emit [] on the wire. empty [] → block is known and legitimately has zero transactions. non-empty → receipts for an executed block. SyncServer.GetReceipts implements the three cases directly: - blockHash is null OR block not found OR block body missing → null - block.Transactions.Length == 0 → [] - block has txs, receipts not stored → null - block has txs and receipts → receipts Eth70ProtocolHandler.FulfillReceiptsRequest is now a single null-check instead of the previous Find-then-classify dance. SyncPeerProtocolHandlerBase.Fulfill (eth/63-69 path) gets the same fix for free — same bug, same one-line guard. Tests: replace the Find-based stubs with GetReceipts-returning-null stubs and update OldStyleFullSynchronizerTests.Can_retrieve_empty_receipts to assert the new contract (genesis → BeEmpty; unknown blocks → BeNull). Closes #11752. (cherry picked from commit 1d880be) * Apply suggestions from code review Co-authored-by: Lukasz Rozmej <lukasz.rozmej@gmail.com> (cherry picked from commit c01295b) * Apply suggestion from @LukaszRozmej (cherry picked from commit 27258b9) * Drop redundant FindHeader pre-check in receipt response loop GetReceipts now returns null for unknown blocks (block missing, body missing, or receipts not stored), so the up-front FindHeader call before GetReceipts is redundant — the `if (receipts is null) break;` below it already handles the unknown case. Per @flcl42 review on #11754. (cherry picked from commit 742cb1a) * Fix shutdown race in SnapProvider PLINQ (closes #11806) (#11807) * Unwrap AggregateException(ObjectDisposedException) from snap PLINQ on shutdown When the node is stopped during snap sync, SnapProvider.AddAccountRange's parallel code-existence check (codeHashes.AsParallel().Where(_codeDb.KeyExists)) races RocksDB disposal in the DI container teardown. The resulting ObjectDisposedException is wrapped by PLINQ in an AggregateException, which falls past the snap dispatcher's existing `catch (ObjectDisposedException) → Info("Ignoring sync response as the DB has already closed.")` guard and lands on `catch (Exception) → Error("Error when handling response", e)`. The node recovers correctly on restart — this is purely a noisy shutdown log line — but the post-merge fuzz tests' StabilityVerification watchdog scans for non-allowlisted exception lines and fails the test on it, blocking the 1.38 release smoke run. Unwrap the AggregateException at the point of throw so the dispatcher's existing benign guard handles it uniformly. No new log path; reuses the already-tested "Ignoring sync response..." Info message. Race introduced 2024-03-28 by PR #6873 "Perf/dont redownload downloaded code" (commit 7059b45), latent until the fuzz watchdog started catching it. * Tidy unwrap: single Flatten, preserve stack via ExceptionDispatchInfo Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Guard against empty InnerExceptions in unwrap filter Enumerable.All() returns true vacuously on an empty sequence, which would let the filter pass and then InnerExceptions[0] throw ArgumentOutOfRangeException instead of re-throwing the original. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: lukasz.rozmej <lukasz.rozmej@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Default Discovery to V4 (#11614) * Default Discovery to V4 * Update tests * Activate BAL only when needed (#11795) * Activate BAL only when needed * Guard ChangeState against same-state transitions Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Align IsFinished with ShouldFinish; short-circuit cheap checks first Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: lukasz.rozmej <lukasz.rozmej@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: update Directory.Build.props for 1.38.0 --------- Co-authored-by: Alex <alexb5dh@gmail.com> Co-authored-by: Alexey Osipov <me@flcl.me> Co-authored-by: Amirul Ashraf <asdacap@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Co-authored-by: Stavros Vlachakis <89769224+svlachakis@users.noreply.github.com> Co-authored-by: Carlos Bermudez Porto <43155355+cbermudez97@users.noreply.github.com> Co-authored-by: lukasz.rozmej <lukasz.rozmej@gmail.com> Co-authored-by: DeFi Junkie <deffie.jnkiee@gmail.com> Co-authored-by: Ben {chmark} Adams <thundercat@illyriad.co.uk>
Name / Identifier Stavros Vlachakis Team / Project Nethermind Start date of relevant projects July 2025 (part-time) February 2026 (full-time) Proposed weight Full (1.0) Summary of work / eligibility Stavros joined Nethermind in March 2025. Since July 2025, he has contributed part-time to the Nethermind Ethereum Execution Client (Core team) alongside other responsibilities. Since February 2026, he has worked full-time on Nethermind Client, with 100+ merged PRs in total. He owns the JSON-RPC for Nethermind Client. He is also expected to contribute extensively to Frame Transactions on Hegota. Representative work: - EIP-4444 history expiry (EraE): implemented the EraE archive format end-to-end — era export/import and remote download with SHA-256 verification. (#10812 (NethermindEth/nethermind#10812)) - JSON-RPC (owner): broad spec-compliance and Geth-parity work plus new endpoints — e.g. Geth-compatible error codes (#11335 (NethermindEth/nethermind#11335)) and eth_signTransaction / raw-transaction methods (#11517 (NethermindEth/nethermind#11517), #11521 (NethermindEth/nethermind#11521)). - Streaming for large RPC responses: streaming approach for trace_* and debug_* results, avoiding buffering huge responses in memory. (#11755 (NethermindEth/nethermind#11755), #11693 (NethermindEth/nethermind#11693)). - EVM & execution performance: eth_call interpreter/dispatch optimizations (#11965 (NethermindEth/nethermind#11965)), EVM memory pooling and SLOAD / flat-state read caching (#11991 (NethermindEth/nethermind#11991), #12043 (NethermindEth/nethermind#12043)). - State & consensus reliability: correct persisted-code tracking in the code DB (#11714 (NethermindEth/nethermind#11714)), forkchoice canonical-chain corruption healing after beacon sync (#10876 (NethermindEth/nethermind#10876)). All merged PRs: https://github.com/NethermindEth/nethermind/pulls?q=is%3Apr+author%3Asvlachakis+is%3Aclosed (edited)
Moved the persisted-code hint cache from StateProvider onto the ICodeDb itself, where the underlying storage actually lives.
Before: StateProvider._persistedCodeInsertFilter was a single long-lived in-memory cache that recorded "this code hash has been flushed to disk". It was set after every CommitCodeAsync, regardless of whether that commit went to durable production storage or a transient overlay storage.
After: the hint cache lives on the codeDb instance via ICodeDb.ContainsCode / MarkCodePersisted. Two implementations:
The bug:
The root issue was a lifetime mismatch: the hint cache's lifetime (long-lived on StateProvider) didn't match the lifetime of the storage it claimed to describe (short-lived overlay).
Types of changes
What types of changes does your code introduce?
Testing
Requires testing
If yes, did you write tests?
Notes on testing
Added regression test which fails on master.