Skip to content

p2p, blocksync: add native peer observation hooks - #46

Draft
0xrukimedo wants to merge 1 commit into
developfrom
vbhattac/peer-observation
Draft

0xrukimedo wants to merge 1 commit into
developfrom
vbhattac/peer-observation

Conversation

@0xrukimedo

@0xrukimedo 0xrukimedo commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

Expose thin native peer observation hooks so Heimdall can score repeated bulk requests and existing validation outcomes without a sidecar or a second P2P stack. An application installs Config.P2P.PeerObserver before node construction; the field is excluded from serialized config and defaults to nil.

Both connection directions report decoded messages and their existing envelope sizes, successful local send-queue acceptance, and existing decode/unwrap failures. Blocksync/statesync report basic validation failures before their existing disconnect paths. Local MaxSnapshotChunks policy rejection is excluded from correctness evidence. Hooks borrow messages; they perform no extra serialization, hashing, validation, scoring or admission themselves.

Heimdall owns bounded scoring and metrics through this interface. Existing protocol validation, disconnects, bans, snapshot exclusions and serving behavior remain unchanged. Queue acceptance is explicitly not delivery/acknowledgement. Deferred validation needs supplier provenance before adding more evidence hooks. See p2p/observation/README.md for the callback contract.

Executed tests

  • go test -race ./p2p/... ./blocksync ./statesync ./config passed, including real transport tests for both directions, malformed messages, send outcomes and reactor validation. An initial non-race run failed TestBadBlockStopsPeer; the later complete race-enabled package run passed.
  • golangci-lint 2.11.4 on changed packages against origin/develop passed.
  • Diffguard against origin/develop passed: 16/16 mutations killed, T1 3/3; structure/size/dependency checks passed. Existing-function churn warnings remain informational.
  • go mod verify and diff whitespace checks passed.
  • With Go 1.26.8, standalone govulncheck ./... reports 18 reachable dependency advisories across six modules. Clean origin/develop reports the identical 18 advisories; no new advisory IDs. This is not a clean standalone security scan. Dependency/security review is required before release. Heimdall's composed dependency graph is scanned separately.

Rollout notes

Draft only. This is the native companion for Heimdall peer reputation observation: 0xPolygon/heimdall-v2#651. No observer means no new telemetry/policy state. Application callbacks must use bounded memory/work, perform no I/O, retain no message and never call networking recursively. Runtime observer replacement is unsupported.

No enforcement, new listener, IPC, sidecar, SDK change or identity mapping. No deployments, live sentry calibration, full CometBFT repository test run, Kurtosis run or live dashboard installation were performed. CI/security gates remain required before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant