eth/gasprice: add query limit for FeeHistory to defend DDOS attack

This commit is contained in:
Eric 2024-04-25 14:05:12 +08:00 committed by NathanBSC
parent 243cde0f54
commit 4408ba2d7e

View file

@ -44,6 +44,7 @@ const (
// maxBlockFetchers is the max number of goroutines to spin up to pull blocks // maxBlockFetchers is the max number of goroutines to spin up to pull blocks
// for the fee history calculation (mostly relevant for LES). // for the fee history calculation (mostly relevant for LES).
maxBlockFetchers = 4 maxBlockFetchers = 4
maxQueryLimit = 100
) )
// blockFees represents a single block for processing // blockFees represents a single block for processing
@ -240,6 +241,9 @@ func (oracle *Oracle) FeeHistory(ctx context.Context, blocks uint64, unresolvedL
if len(rewardPercentiles) != 0 { if len(rewardPercentiles) != 0 {
maxFeeHistory = oracle.maxBlockHistory maxFeeHistory = oracle.maxBlockHistory
} }
if len(rewardPercentiles) > maxQueryLimit {
return common.Big0, nil, nil, nil, fmt.Errorf("%w: over the query limit %d", errInvalidPercentile, maxQueryLimit)
}
if blocks > maxFeeHistory { if blocks > maxFeeHistory {
log.Warn("Sanitizing fee history length", "requested", blocks, "truncated", maxFeeHistory) log.Warn("Sanitizing fee history length", "requested", blocks, "truncated", maxFeeHistory)
blocks = maxFeeHistory blocks = maxFeeHistory