Skip to content

miner: support builder-proposed block with validator blind signing - #3691

Merged
allformless merged 104 commits into
bnb-chain:developfrom
flywukong:bep-675
Jun 17, 2026
Merged

allformless merged 104 commits into
bnb-chain:developfrom
flywukong:bep-675

Conversation

@flywukong

@flywukong flywukong commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR adds validator-side support for Builder-Proposed Block with Validator Blind Signin mev flow (bep-675)

It adds the full BidBlock path: builder submission, validator admission, pre-seal validation, bind-signing of unsigned system transactions, BidBlock selection, post-insert GasFee validation, and local permission revoke on dishonest or malformed BidBlocks.

Main Changes

  • Add BidBlock RPC admission, permission control, and local revoke/fallback behavior.
  • Add validator-side BidBlock selection and candidate retry alongside local block and legacy SendBid.
  • Add Parlia support for builder-produced unsigned system transactions and validator bind-signing.
  • Add builder-facing helpers for BidBlock header preparation and unsigned block assembly.

Rationale

tell us why we need these changes...

Example

[Eth.Miner.Mev]
Enabled = true
BidBlockEnabled = true

Validator need to add config BidBlockEnabled to support new bid path

Changes

Notable changes:

  • add each change in a bullet point here
  • ...
@flywukong
flywukong marked this pull request as draft May 13, 2026 10:56
@flywukong
flywukong force-pushed the bep-675 branch 3 times, most recently from b7c3533 to f18a70a Compare May 14, 2026 03:06
@flywukong flywukong changed the title miner: add BidBlock zero-simulate path May 14, 2026
@flywukong flywukong changed the title miner: support bidblock mev path in bep-675 May 14, 2026
@flywukong flywukong changed the title feat: support builder-proposed block with validator blind signing May 14, 2026
Comment thread consensus/parlia/feynmanfork.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
Comment thread consensus/parlia/parlia.go
Comment thread consensus/parlia/ramanujanfork.go Outdated
@hashdit-bot

This comment was marked as resolved.

@hashdit-bot

This comment was marked as resolved.

@hashdit-bot

This comment was marked as resolved.

@allformless allformless added this to the v1.7.4 milestone May 18, 2026
Comment thread consensus/parlia/bid_block.go Outdated
Comment thread consensus/parlia/bid_block.go Outdated
Comment thread miner/bid_simulator.go Outdated
Comment thread consensus/parlia/feynmanfork.go Outdated
Comment thread consensus/parlia/parlia.go Outdated
@hashdit-bot

This comment was marked as resolved.

@hashdit-bot

This comment was marked as resolved.

@hashdit-bot

hashdit-bot Bot commented May 18, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces a new BidBlock (builder-proposed block) flow for Parlia/MEV, including RPC admission (mev_sendBidBlock), deterministic pre-seal checks, validator bind-signing of unsigned system transactions, candidate selection, and post-insert verification. It refactors system transaction handling into explicit modes (importing/mining/packing), adds permission revocation mechanics for misbehaving builders, and integrates these paths through miner, worker, API backend, and ethclient layers. It also adds comprehensive tests for unsigned system-tx assembly, deterministic BidBlock timing, permission lifecycle, and commit behavior.

Sensitive Content

No sensitive content detected.

Security Issues

🟠 [HIGH] BidBlock is broadcast before full verification, enabling potential invalid block propagation

File: miner/worker.go
In handleBidBlockResult, the code posts core.NewMinedBlockEvent (broadcast path) before running InsertChain verification and GasFee validation. This means a malformed or invalid BidBlock can be propagated to peers before local full validation fails, which can be abused for network-level spam/amplification and trust degradation.
Recommendation: Perform full local verification (InsertChain + BidBlock-specific post checks) before emitting mined block events to the network, or gate broadcasting behind a successful verification result.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

@hashdit-bot

This comment was marked as resolved.

@hashdit-bot

hashdit-bot Bot commented Jun 4, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces validator-side support for BEP-675 builder-proposed BidBlocks with blind-signing flow, including new RPCs (mev_sendBidBlock, permission/status APIs), BidBlock decoding/validation, system-tx whitelist/order checks, and miner-side bidblock selection plus fallback to legacy SendBid. It also refactors Parlia block preparation/finalization paths to support unsigned system transaction packing and later bind-signing, while adding MEV block source tagging (v1/v2) in block metadata and tooling visibility (eth_getBlockMevInfo, jsutils updates). Additionally, it adds in-memory per-builder BidBlock permission revocation management with admin override endpoints and extensive unit tests around permissions, blob validation, and BidBlock assembly behavior.

Sensitive Content

No sensitive content detected.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

@hashdit-bot

hashdit-bot Bot commented Jun 4, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces comprehensive validator-side support for BEP-675 BidBlock flow, including new mev_sendBidBlock handling, pre-seal validation, blind-signing of unsigned system transactions, bid selection logic, post-insert verification, and per-builder permission revocation controls. It also refactors Parlia block preparation/finalization paths to support packing unsigned system txs for builder-proposed blocks while preserving deterministic header construction and adds block-level MEV source tagging (v1 legacy bid vs v2 bidblock). In addition, it expands RPC/admin/client surfaces and status tooling to expose BidBlock submission, permission state, and block MEV attribution.

Sensitive Content

No sensitive content detected.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

allformless
allformless previously approved these changes Jun 4, 2026
@hashdit-bot

hashdit-bot Bot commented Jun 8, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces validator-side support for BEP-675 SendBidBlock (builder-proposed block + validator blind signing), adding new bid-block data structures, RPC endpoints, admission/pre-seal verification, system-tx bind-signing flow, and miner-side block selection/fallback logic. It also adds a per-builder BidBlock permission/revocation manager with admin controls and public query APIs, plus MEV path attribution/tagging (v1 vs v2) exposed via new RPCs and client helpers. Additionally, the PR refactors Parlia system transaction handling with explicit modes (importing/mining/packing), improves header preparation for BidBlock flow, and extends tests/metrics around the new pipeline.

Sensitive Content

Blockchain Address:

  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 in cmd/jsutils/getchainstatus.js — hardcoded builder mapping entry
  • 0x2000000000000000000000000000000000000000 in consensus/parlia/parlia_test.go — validator address literal in test code (test file; ignored per policy)
  • 0x0000000000000000000000000000000000001000 in consensus/parlia/parlia_test.go — system contract address in expected trace (test file; ignored per policy)

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

@hashdit-bot

hashdit-bot Bot commented Jun 8, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces validator-side support for BEP-675 Builder-Proposed Blocks with blind signing, including new mev_sendBidBlock flow, bidblock pre-seal validation, unsigned system transaction handling, and post-seal verification/revocation logic. It adds new MEV APIs and types for bidblock submission, permission status, block-source attribution (v1 vs v2), and admin controls for builder bidblock permissions. It also refactors Parlia block preparation/finalization paths to support separate system transaction modes (importing/mining/packing) and extends tooling/tests to track and validate the new path.

Sensitive Content

Blockchain Address:

  • 0x2000000000000000000000000000000000000000 in consensus/parlia/parlia_test.go — hardcoded test validator address (in test file, ignored per policy)
  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 in cmd/jsutils/getchainstatus.js — builder mapping address

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

allformless
allformless previously approved these changes Jun 8, 2026
@hashdit-bot

hashdit-bot Bot commented Jun 16, 2026

Copy link
Copy Markdown

Pull Request Review

This PR adds full validator-side support for BEP-675 BidBlock flow, including new mev_sendBidBlock handling, BidBlock pre-seal validation, unsigned system-tx bind-signing, block-source tagging (v1/v2), and builder permission/revocation controls. It also refactors Parlia block preparation/finalization paths to support packing unsigned system transactions for builder-proposed blocks while preserving normal mining/import behavior through explicit system transaction modes. Additional RPC/admin/client APIs and metrics were introduced for BidBlock permission management and MEV attribution/observability.

Sensitive Content

Blockchain Address:

  • 0x317aB60A0815F8Db2e6cb3f302C152d2A5ef4854 (Ethereum address) in core/types/block_mev_info_test.go — test round-trip builder address
  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 (Ethereum address) in cmd/jsutils/getchainstatus.js — builder map entry

No private keys, mnemonic phrases, or social accounts detected in newly added non-test files.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

@hashdit-bot

hashdit-bot Bot commented Jun 16, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces BEP-675 BidBlock support end-to-end in a Go-based Ethereum client/miner stack (Parlia/BSC context), including new RPCs (mev_sendBidBlock, permission/status APIs), BidBlock admission/pre-seal checks, unsigned system-tx handling with validator bind-signing, and selection/fallback logic between local blocks, legacy SendBid, and BidBlock. It also adds block MEV attribution tagging/decoding via header.RequestsHash and expands miner/worker flows to verify selected BidBlocks post-seal with automatic builder permission revocation on malformed/dishonest submissions. Additional tooling and tests were added across consensus, miner, ethapi, and client layers, plus status reporting updates in getchainstatus.js.

Sensitive Content

Blockchain Address:

  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 (Ethereum address) in cmd/jsutils/getchainstatus.js — builder mapping entry (blockroute)

No private keys, mnemonic phrases, or secret key material newly added in non-test files.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

allformless
allformless previously approved these changes Jun 16, 2026
@hashdit-bot

hashdit-bot Bot commented Jun 17, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces validator-side support for BEP-675 BidBlock flow, including new RPCs (mev_sendBidBlock, permission query/admin controls), BidBlock decoding/signature recovery, pre-seal validation, system transaction bind-signing, and miner-side BidBlock selection/fallback behavior. It also refactors Parlia block preparation/finalization paths to support unsigned system tx packing for builder-proposed blocks and adds MEV path tagging (v1/v2) into block metadata plus related status/reporting APIs. A broad set of tests was added for BidBlock validation, permission manager behavior, transaction mode handling, and MEV info encoding/decoding.

Sensitive Content

Blockchain Address:

  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 (Ethereum address) in cmd/jsutils/getchainstatus.js — builder mapping entry.
  • 0x317aB60A0815F8Db2e6cb3f302C152d2A5ef4854 (Ethereum address) in core/types/block_mev_info_test.go — test data.
  • 0x3000000000000000000000000000000000000003 (Ethereum address) in consensus/parlia/parlia_test.go — test data.
  • 0x1000000000000000000000000000000000000001 (Ethereum address) in consensus/parlia/parlia_test.go — test data.
  • 0x2000000000000000000000000000000000000002 (Ethereum address) in consensus/parlia/parlia_test.go — test data.
  • 0x2000000000000000000000000000000000000000 (Ethereum address) in consensus/parlia/parlia_test.go — test data.

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

@hashdit-bot

hashdit-bot Bot commented Jun 17, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces full validator-side support for BEP-675 BidBlock flow in a Go-based blockchain client (Parlia/BNB chain stack), including new mev_sendBidBlock admission, pre-seal validation, unsigned system-tx bind-signing, selection/commit logic, and post-insert verification with builder revocation controls. It also adds MEV path attribution (v1 vs v2) encoded in block headers and new RPC/client/admin surfaces to query block MEV info and manage per-builder BidBlock permissions. In addition, miner internals were refactored to support system transaction modes (importing/mining/packing), with broad test coverage for BidBlock processing, permission windows, and blob validation behavior.

Sensitive Content

Blockchain Address:

  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 in cmd/jsutils/getchainstatus.js — builder map entry
  • 0x317aB60A0815F8Db2e6cb3f302C152d2A5ef4854 in core/types/block_mev_info_test.go — test address (not a finding if treated strictly as test-only file)
  • Multiple fixed addresses in non-test code paths (e.g., 0x1000...0001, 0x2000...0002) appear in test files only and are excluded per rules.

Private Key / Seed Phrase / Mnemonic / Secret Material:

  • b71c...f291 (Private Key) in consensus/parlia/parlia_test.go — hardcoded test key material (in test file; excluded per rules, listed for awareness only)

Security Issues

🟡 [MEDIUM] Unauthenticated admin RPC method can change builder permissions (confirm RPC exposure/auth is enforced)

File: eth/api_admin.go, internal/web3ext/web3ext.go
A new admin API admin_setBidBlockPermission(builder, allowed) is introduced without an explicit in-method auth check. In go-ethereum this is typically protected by RPC namespace exposure and transport-level controls, but if admin namespace is accidentally exposed over untrusted interfaces, an attacker could revoke/restore builders and affect MEV flow availability.
Recommendation: Confirm admin namespace is restricted to trusted local/admin channels only, and consider adding explicit operator-auth guardrails or audit logs around permission mutation calls.

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

Comment thread miner/miner_mev.go Outdated
@hashdit-bot

hashdit-bot Bot commented Jun 17, 2026

Copy link
Copy Markdown

Pull Request Review

This PR introduces validator-side BEP-675 BidBlock support across the miner, Parlia consensus, RPC/API surface, and client bindings, including admission checks, system-tx bind-signing flow, BidBlock selection, and permission revoke/restore mechanics for misbehaving builders. It also adds block-level MEV attribution tagging (v1 SendBid vs v2 SendBidBlock), new MEV RPC methods (mev_sendBidBlock, mev_getBidBlockPermission, eth_getBlockMevInfo), and admin controls for builder permissions. A substantial set of tests was added to cover BidBlock system-tx shape verification, signing modes, permission lifecycle behavior, and gas-price/blob validation paths.

Sensitive Content

Blockchain Address:

  • 0xA8caEc0D68a90Ac971EA1aDEFA1747447e1f9871 in cmd/jsutils/getchainstatus.js — builder mapping entry
  • 0x3000000000000000000000000000000000000003 in consensus/parlia/parlia_test.go — hardcoded address in new test case (not reported as sensitive finding if strictly test-only)
  • 0x1000000000000000000000000000000000000001 in consensus/parlia/parlia_test.go — hardcoded address in new test case (test-only)
  • 0x2000000000000000000000000000000000000002 in consensus/parlia/parlia_test.go — hardcoded address in new test case (test-only)
  • 0x2000000000000000000000000000000000000000 in consensus/parlia/parlia_test.go — hardcoded address in new test case (test-only)

Security Issues

No serious security issues detected.


Generated by Hashdit Bot. This tool can absolutely NOT replace manual audits.

) {
m.mu.Lock()
defer m.mu.Unlock()
m.revoked[builder] = BidBlockRevokeRecord{

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need prune this map every day?

Comment thread miner/bid_block.go
// - Tx precheck failures (nonce, balance, signature, intrinsic gas, ...)
// - System tx value / params (e.g. deposit value vs. SystemAddress balance)
// - Blob sidecar checks (KZG proofs, blob hashes)
if _, err := w.chain.InsertChain(types.Blocks{block}); err != nil {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need check the err if it cause by bid?

Comment thread miner/bid_block.go Outdated
}

bidBlockFee := uint256.MustFromBig(bidBlock.GasFee)
bidBlockValidatorReward := new(uint256.Int).Mul(bidBlockFee, uint256.NewInt(*w.config.Mev.ValidatorCommission))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

validatorCommission could be nil?

Comment thread ethclient/ethclient.go
BlockHash *common.Hash `json:"blockHash,omitempty"`
BlockNumber *hexutil.Uint64 `json:"blockNumber,omitempty"`
RevokedAt *time.Time `json:"revokedAt,omitempty"`
ResetAt time.Time `json:"resetAt"`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not same as 'BidBlockPermissionResult' in api_mev.go'

Comment thread miner/bid_simulator.go
case b.newBidBlockCh <- newBidBlockPackage{bidBlock: block, feedback: replyCh}:
b.AddPending(block.BlockNumber(), block.Builder, block.Hash())
case <-timer.C:
return types.ErrMevBusy

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
return types.ErrMevBusy
return types.ErrMevBusy
case <-ctx.Done():
return ctx.Err()
Comment thread miner/bid_simulator.go

// sendBidBlock queues a decoded BidBlock for selection.
func (b *bidSimulator) sendBidBlock(_ context.Context, block *types.DecodedBidBlock) error {
timer := time.NewTimer(1 * time.Second)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use a const value?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4 participants