Skip to content

fix: retain initialized DKG sessions during inventory reads - #7824

Open
PastaPastaPasta wants to merge 1 commit into
dashpay:developfrom
PastaPastaPasta:codex/security-dkg-session-lifetime
Open

PastaPastaPasta wants to merge 1 commit into
dashpay:developfrom
PastaPastaPasta:codex/security-dkg-session-lifetime

Conversation

@PastaPastaPasta

@PastaPastaPasta PastaPastaPasta commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Issue being fixed or feature implemented

DKG round initialization replaces the current session on a phase thread while inventory getters read it from peer processing. The unsynchronized owner can be destroyed during a getter, and the replacement was visible before initialization completed. This fixes that object lifetime race; reliable crashes and stronger exploitation have not been demonstrated.

What was done?

Protect publication and acquisition with one handler mutex, initialize the next session privately, and return shared ownership to inventory and phase callers. Release the publication mutex before session work or retirement destruction. Failed initialization retires prior-round inventory.

How Has This Been Tested?

No new test is added: the race needs a getter running concurrently with a session replacement, which a deterministic unit test cannot reproduce. Verification was code review plus the existing tests:

  • On macOS arm64 with the configured depends build: ./src/test/test_dash --run_test=llmq_dkg_tests passed, and test/functional/test_runner.py -j1 feature_llmq_connections.py passed, including normal DKG, quorum connections, probes and restarts.
  • The existing feature_llmq_* functional tests pass in CI under TSan (linux64_tsan-test) and ASan (linux64_asan-test), which exercise the session lifetime path.

No baseline mutation or runtime race reproduction is claimed.

Breaking Changes

None. No wire, consensus, activation or persisted-format changes.

Checklist:

  • I have performed a self-review of my own code
  • I have made corresponding changes to the documentation
  • I have assigned this pull request to a milestone

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 22 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 4 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fdabd8c5-ce83-4d3d-adc5-698ed60f11cd
📥 Commits

Reviewing files that changed from the base of the PR and between f35a24c and 1f33db3.

📒 Files selected for processing (3)
  • src/active/dkgsessionhandler.cpp
  • src/active/dkgsessionhandler.h
  • src/llmq/net_dkg.cpp
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thepastaclaw

thepastaclaw commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — no blockers (commit 1f33db3) · triage: normal · Phase 2 only (queue backlog)

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final validation — Phase 2 only (queue backlog)

Verified the supplied Phase-2 assessment against the complete diff at 8637d68 and the surrounding initialization, inventory, phase-thread, and shutdown paths; no in-scope findings were identified. Session ownership is acquired under the publication mutex, replacements are published only after successful initialization, and retained ownership protects inventory reads without holding that mutex during session work or retirement destruction. Verification was static only: the added test exercises sequential ownership and failed initialization, not the race itself; the supplied CI snapshot shows successful formatting and container preparation, queued manifest jobs, and no completed project build/test results.

Review provenance

Source: reviewer 1: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: normal by gpt-6.1-sol (effort low) — The change requires reasoning about concurrent session publication, shared ownership, lock scope and failed initialization, but does not itself alter consensus, cryptography, signatures, deserialization or another qualifying critical surface.
  • Phase 1 reviewers: not run (skipped for throughput: 13 PRs queued, above the 10 limit)
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort high); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort high); agent phase2-reviewer

@thepastaclaw thepastaclaw added the pastaclaw:approved thepastaclaw's latest review approved this PR label Oct 7, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@PastaPastaPasta
PastaPastaPasta force-pushed the codex/security-dkg-session-lifetime branch from 8637d68 to 1f33db3 Compare October 7, 2026 16:35
@thepastaclaw thepastaclaw removed the pastaclaw:approved thepastaclaw's latest review approved this PR label Oct 7, 2026

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — Final validation — Phase 2 only (queue backlog)

Independently reviewed the complete diff at head 1f33db3 and verified the supplied Phase-2 claims against session initialization, inventory getters, phase-thread ownership, and shutdown paths; no actionable in-scope defects were found. Session acquisition and publication use the same mutex, shared ownership retains sessions during reads and phase work, and initialization and retirement destruction occur outside that mutex. This was a static review: the supplied CI snapshot shows successful formatting and preliminary checks, but build-container jobs remain queued and sanitizer/test success for this exact head is not established.

🔴 0 blocking | 🟡 0 suggestion(s) | 💬 0 nitpick(s)

Review provenance

Source: reviewer 1: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: normal by gpt-6.1-sol (effort low) — The change requires reasoning about cross-thread session ownership, initialization visibility, and destruction outside locks, but does not directly change a qualifying critical surface.
  • Phase 1 reviewers: not run (skipped for throughput: 16 PRs queued, above the 10 limit)
  • Fresh final gate: an independent Phase-2 review ran after iterative findings were reconciled
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort high); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort high); agent phase2-reviewer, gpt-6.1-sol — general (completed, effort high); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort high); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify the current code and confirm that no unresolved issues remain.

No unresolved findings remain from the prior review on this head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants