kaiax/gov: validate the governing node successor - #1056
Open
hyunsooda wants to merge 1 commit into
Open
Conversation
hyunsooda
force-pushed
the
fix/validate-governing-node-successor
branch
from
September 1, 2026 09:08
ab0b0fe to
3d5848d
Compare
The consistency check for a governing-node vote compares the current governing node against the council and never inspects the proposed value, which only has to be a well-formed address. After Permissionless only the governing node may vote, and voting requires council membership, so a successor that is the zero address or outside the council leaves header governance with no way back. Constraint: VerifyVote also runs on pre-fork headers, so the check is gated on Permissionless rather than applied unconditionally Rejected: Fail at the fork block when the existing governing node is ineligible | that halts every node on a chain already holding a bad value, which is worse than a frozen parameter Rejected: Require the successor to be in the committee rather than the council | a briefly paused validator is a legitimate successor Confidence: high Scope-risk: narrow Not-tested: A successor that is in the council at vote time but leaves it afterwards through the node lifecycle Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
hyunsooda
force-pushed
the
fix/validate-governing-node-successor
branch
from
September 1, 2026 09:08
3d5848d to
fccfde7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed changes
The consistency check for a governing-node vote compares the current governing node against the council and never inspects the proposed value, which only has to be a well-formed address. After Permissionless only the governing node may vote, and voting requires council membership, so a successor that is the zero address or outside the council leaves header governance with no way back. Validate the proposed value where that rule applies.
Types of changes
Checklist
I have read the CLA Document and I hereby sign the CLAin first time contribute after having read CLA$ make test)Related issues
Further comments
The check is gated on Permissionless because
VerifyVotealso runs on pre-fork headers, and tightening it unconditionally could reject a header that was accepted before.