Skip to content

Guard ticket signing against observed epoch changes - #7

Merged
tuhalf merged 2 commits into
mainfrom
fix/ticket-usage-epoch
Sep 24, 2026
Merged

tuhalf merged 2 commits into
mainfrom
fix/ticket-usage-epoch

Conversation

@tuhalf

@tuhalf tuhalf commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

A relay usage report can be measured in epoch N while ticket creation later reads epoch N+1. Previously, the old byte total could be signed as a new-epoch ticket.

Bind each validated usage report to the observed ticket epoch and report sequence. Reject and retry when either changes before or during signing, including during a too_low repair. Normal reconnect and cold-start behavior remains. Bump diodejs to 0.5.10.

The relay's v1001 report contains no usage epoch, so this guards observable changes but cannot prove the epoch of every report. Complete protection needs an epoch-tagged relay response.

Validation: full Node 20 and Node 22 suites passed (292 tests each) on the final commit; npm pack dry-run passed.

@tuhalf
tuhalf merged commit 349cc0b into main Sep 24, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant