mirror of
https://github.com/ethereum/go-ethereum.git
synced 2026-08-19 18:32:23 +00:00
eth/gasprice: add query limit for FeeHistory to defend DDOS attack
This commit is contained in:
parent
243cde0f54
commit
4408ba2d7e
1 changed files with 4 additions and 0 deletions
|
|
@ -44,6 +44,7 @@ const (
|
|||
// maxBlockFetchers is the max number of goroutines to spin up to pull blocks
|
||||
// for the fee history calculation (mostly relevant for LES).
|
||||
maxBlockFetchers = 4
|
||||
maxQueryLimit = 100
|
||||
)
|
||||
|
||||
// blockFees represents a single block for processing
|
||||
|
|
@ -240,6 +241,9 @@ func (oracle *Oracle) FeeHistory(ctx context.Context, blocks uint64, unresolvedL
|
|||
if len(rewardPercentiles) != 0 {
|
||||
maxFeeHistory = oracle.maxBlockHistory
|
||||
}
|
||||
if len(rewardPercentiles) > maxQueryLimit {
|
||||
return common.Big0, nil, nil, nil, fmt.Errorf("%w: over the query limit %d", errInvalidPercentile, maxQueryLimit)
|
||||
}
|
||||
if blocks > maxFeeHistory {
|
||||
log.Warn("Sanitizing fee history length", "requested", blocks, "truncated", maxFeeHistory)
|
||||
blocks = maxFeeHistory
|
||||
|
|
|
|||
Loading…
Reference in a new issue