Skip to content

fix: unbounded memory in calldataRetriever#22004

Merged
PhilWindle merged 1 commit intomerge-train/spartanfrom
mr/fix-unbounded-trace-failure-set
Mar 25, 2026
Merged

fix: unbounded memory in calldataRetriever#22004
PhilWindle merged 1 commit intomerge-train/spartanfrom
mr/fix-unbounded-trace-failure-set

Conversation

@mrzeszutko
Copy link
Copy Markdown
Contributor

Summary

  • Fix unbounded memory leak in CalldataRetriever.traceFailureWarnedTxHashes (audit finding A-685). The static Set<string> tracking L1 tx hashes that failed trace/debug RPC decoding grew without bound in long-running archiver nodes.
  • Introduce a new LruSet<T> utility in foundation/src/collection/ — a bounded set with LRU eviction using a doubly-linked list + Map for O(1) operations. Both has() and add() refresh recency, so actively-checked hashes stay cached while stale ones get evicted.
  • Replace the unbounded Set<string> with LruSet<string>(1000) in the archiver. No new npm dependencies, no logic changes to the call site — the LruSet API is a drop-in replacement.

Test plan

  • 11 new unit tests for LruSet covering basic operations, eviction, LRU refresh semantics, edge cases (maxSize=1), and clear/re-add behavior
  • All 55 existing calldata_retriever.test.ts tests pass unchanged, including the "warn once per tx hash" test
  • Build, lint, and format verified

Fixes A-685

@PhilWindle PhilWindle merged commit 5817d8c into merge-train/spartan Mar 25, 2026
11 checks passed
@PhilWindle PhilWindle deleted the mr/fix-unbounded-trace-failure-set branch March 25, 2026 16:43
github-merge-queue Bot pushed a commit that referenced this pull request Mar 27, 2026
BEGIN_COMMIT_OVERRIDE
fix: only clear provenBlockNumber when it exceeds prune point (#21946)
chore: (A-779) load all accounts before calling
LogService.#getSecretsForSenders (#21923)
fix: align staging-public mana target with testnet/mainnet (#21983)
chore: (A-777) add warn logs for regressive path in block synchronizer
(#21925)
fix: fully validate txs retrieved from tx file store (#21988)
refactor: extract checkpoint proposal handling to ProposalHandler
(#21999)
fix: unbounded memory in calldataRetriever (#22004)
fix(p2p): check peer rate limit before global to prevent quota
starvation (#21997)
fix(p2p): evict expired failed-auth-handshake entries on heartbeat
(#21992)
chore: defensively handle skipPushProposedBlocksToArchiver (#22017)
chore: bump testnet prover resource profile to prod-hi-tps (#22019)
chore: (A-835) remove unused serializer (#22037)
fix(p2p): remove disconnected peers from scoring maps (#22009)
fix(e2e): set anvilSlotsInAnEpoch in slashing tests (#21869)
fix(ethereum): Audit fixes A-810, A-812 (nonce race, isEscapeHatchOpen
logging) (#21948)
chore: remove old TxPool implementation (#22028)
fix: Fix blob encoding when uploaded from proposals (#22045)
chore: Adds /cycle and /fix skills. Also configures linear mcp server
(#22043)
chore: remove validatorReexecute config option (#22024)
fix(sequencer): use last L1 slot of L2 slot as eth_simulateV1 timestamp
(#22023)
docs(simulator): clarify teardown gas billing is intentional (#22057)
chore: revert account loading optimization in log service (#22062)
fix: use DateProvider in PeerScoring (#22070)
fix(aztec.js): preserve extraHashedArgs in DeployMethod.with() (#22053)
fix(p2p): replace process.exit() with graceful shutdown in worker
cleanup (#22046)
chore: merge next (#22089)
fix(stdlib): correct NoteDao size (#22068)
feat: improve blob download from filestores (#22096)
fix: remove stale tx_pool v1 benchmark reference (#22104)
END_COMMIT_OVERRIDE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants