Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport #101: fix find_ancestor. #105

Merged
merged 1 commit into from
Jan 17, 2020
Merged

Conversation

andresilva
Copy link
Contributor

@andresilva andresilva commented Jan 14, 2020

Dropped the fuzzing changes as the v0.10 branch doesn't include the fuzzing setup.

  * Some cleanup for the fuzzing code with a few more assertions.
  * In order for the round fuzzing to check the eventual completability
    of the round, all remaining prevotes must be imported. This is a
	good illustration of the fact that in the general case a single
	receive omission (of a prevote or precommit) may lead to a
	voter being "stuck" in a round due not seeing the estimate at
	the right spot in the block tree (i.e. missed prevotes can cause the
	estimate to not move "down" far enough and missed precommits can
	cause it to not move "up" far enough, in a block tree that grows
	downwards).
  * The graph fuzzing was always returning early when starting to
    record precommit weights, thus not checking much.
  * The (generalised) graph fuzzing showed a problem with
    find_ancestor whereby it may not return the highest block
	in the chain satisfying the condition due to a (hidden)
	assumption that the condition must only be true of at most
	one child of each vote-node on the chain whose head is the
	given starting block (this assumption comes from ghost_find_merge_point).
	In the context of a Round, where this function is used to
	determine the estimate, this assumption seems satisfied only
	because the estimate is not computed before a supermajority of
	precommits have been observed.  Since all (honest) precommit
	weight must be somewhere downwards from the prevote-ghost any
	voter sees, it is impossible for a chain not descending from
	the prevote-ghost to have supermajority, thus satisfying the
	assumption that find_ancestor needs to work correctly. However,
	since this is very subtle and not documented, the implementation of
	find_ancestor is instead changed here to a simpler version
	in which this assumption is not necessary and is arguably
	easier to see correct.
  * Regression tests for the previous point have been added.
@andresilva andresilva merged commit 7abe9e0 into v0.10 Jan 17, 2020
@andresilva andresilva deleted the andre/backport-vote-graph-fix branch June 13, 2022 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants