Skip to content

Reject negative block IDs in channel participation fetch - #5608

Open
hmdsefi wants to merge 1 commit into
hyperledger:mainfrom
hmdsefi:fix/reject-negative-block-id
Open

hmdsefi wants to merge 1 commit into
hyperledger:mainfrom
hmdsefi:fix/reject-negative-block-id

Conversation

@hmdsefi

@hmdsefi hmdsefi commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Type of change

  • Bug fix

Description

ValidateFetchBlockID and osnadmin channel fetch accept a block ID when strconv.Atoi succeeds. Atoi("-1") succeeds, and FetchBlock then passes uint64(-1) to the block store, which treats that value as the newest block. A fetch of -1 returns the latest block. +1 is accepted the same way.

Both checks now use strconv.ParseUint. newest, oldest, config, 0, and 99 still pass. -1 and +1 are rejected before any block is read.

Additional details

FetchBlock uses the same parse, so a direct call cannot wrap either.

Tests:

  • TestValidateFetchBlockID covers -1 and +1.
  • TestFetchRejectsNonCanonicalBlockID checks osnadmin channel fetch rejects both before it dials the orderer.

go test ./orderer/common/channelparticipation/ ./cmd/osnadmin/ -run 'TestValidateFetchBlockID|TestFetchRejectsNonCanonicalBlockID' passes.

Related issues

Fixes #5605

Atoi accepts "-1", and the block store treats that bit pattern as the newest block.

Signed-off-by: Hamed Yousefi <hdyousefi@gmail.com>
@hmdsefi
hmdsefi requested a review from a team as a code owner October 8, 2026 19:15
pfi79
pfi79 previously approved these changes Oct 8, 2026
@pfi79
pfi79 self-requested a review October 8, 2026 20:26
@pfi79
pfi79 dismissed their stale review October 8, 2026 20:27

unit tests failed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Negative block IDs fetch the newest block

2 participants