From 1e39f322aace6026c5013be9495d5822b8c14330 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Oliveira?= Date: Mon, 14 Sep 2026 17:04:13 +0100 Subject: [PATCH 1/4] fix(gossipsub): reject `key` field in anonymous validation mode `ValidationMode::Anonymous` (the StrictNoSign policy) requires the `signature`, `key`, `from` and `seqno` envelope fields to be absent, but the decoder only checked three of them. A message carrying a non-empty `key` was accepted at ingress and re-emitted verbatim to mesh peers on forward, causing conformant peers to penalise the relaying node for traffic it did not author. Add `ValidationError::KeyPresent` and reject a non-empty `key` in the `Anonymous` validation arm, aligning with the libp2p pubsub spec. --- Cargo.lock | 2 +- Cargo.toml | 2 +- protocols/gossipsub/CHANGELOG.md | 5 +++++ protocols/gossipsub/Cargo.toml | 2 +- protocols/gossipsub/src/config.rs | 4 ++-- protocols/gossipsub/src/error.rs | 3 +++ protocols/gossipsub/src/protocol.rs | 5 +++++ 7 files changed, 18 insertions(+), 5 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 33dc54adb89..7686062e8f2 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -3044,7 +3044,7 @@ dependencies = [ [[package]] name = "libp2p-gossipsub" -version = "0.50.0" +version = "0.51.0" dependencies = [ "async-channel", "asynchronous-codec", diff --git a/Cargo.toml b/Cargo.toml index 092e759eed0..1093b41c884 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -83,7 +83,7 @@ libp2p-core = { version = "0.44.0", path = "core" } libp2p-dcutr = { version = "0.15.0", path = "protocols/dcutr" } libp2p-dns = { version = "0.45.0", path = "transports/dns" } libp2p-floodsub = { version = "0.48.0", path = "protocols/floodsub" } -libp2p-gossipsub = { version = "0.50.0", path = "protocols/gossipsub" } +libp2p-gossipsub = { version = "0.51.0", path = "protocols/gossipsub" } libp2p-identify = { version = "0.48.0", path = "protocols/identify" } libp2p-identity = { version = "0.3.0" } libp2p-kad = { version = "0.49.0", path = "protocols/kad" } diff --git a/protocols/gossipsub/CHANGELOG.md b/protocols/gossipsub/CHANGELOG.md index e8f86b6d8ae..977934f9488 100644 --- a/protocols/gossipsub/CHANGELOG.md +++ b/protocols/gossipsub/CHANGELOG.md @@ -1,3 +1,8 @@ +## 0.51.0 +- Reject messages carrying a `key` field in `ValidationMode::Anonymous`, aligning with the + `StrictNoSign` policy which forbids `from`, `seqno`, `signature` and `key` on the envelope. + See [PR #6620](https://github.com/libp2p/rust-libp2p/pull/6621). + ## 0.50.0 - Fix unbounded growth of per-peer `connected_peer.topics` from GRAFT control messages ([GHSA-g3g5-x568-qvqx](https://github.com/libp2p/rust-libp2p/security/advisories/GHSA-g3g5-x568-qvqx)). diff --git a/protocols/gossipsub/Cargo.toml b/protocols/gossipsub/Cargo.toml index aa7bb6c452e..580ae8b427a 100644 --- a/protocols/gossipsub/Cargo.toml +++ b/protocols/gossipsub/Cargo.toml @@ -3,7 +3,7 @@ name = "libp2p-gossipsub" edition.workspace = true rust-version = { workspace = true } description = "Gossipsub protocol for libp2p" -version = "0.50.0" +version = "0.51.0" authors = ["Age Manning "] license = "MIT" repository = "https://github.com/libp2p/rust-libp2p" diff --git a/protocols/gossipsub/src/config.rs b/protocols/gossipsub/src/config.rs index 0fd32b12c64..84a915eb372 100644 --- a/protocols/gossipsub/src/config.rs +++ b/protocols/gossipsub/src/config.rs @@ -43,8 +43,8 @@ pub enum ValidationMode { /// This setting permits messages that have no author, sequence number or signature. If any of /// these fields exist in the message these are validated. Permissive, - /// This setting requires the author, sequence number and signature fields of a message to be - /// empty. Any message that contains these fields is considered invalid. + /// This setting requires the author, key, sequence number and signature fields of a message to + /// be empty. Any message that contains these fields is considered invalid. Anonymous, /// This setting does not check the author, sequence number or signature fields of incoming /// messages. If these fields contain data, they are simply ignored. diff --git a/protocols/gossipsub/src/error.rs b/protocols/gossipsub/src/error.rs index b3c7e5ea8ea..8f3a83cee18 100644 --- a/protocols/gossipsub/src/error.rs +++ b/protocols/gossipsub/src/error.rs @@ -111,6 +111,9 @@ pub enum ValidationError { /// Message source existed when validation has been sent to /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. MessageSourcePresent, + /// Message key existed when validation has been sent to + /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + KeyPresent, /// The data transformation failed. TransformFailed, /// Message size was too large for topic diff --git a/protocols/gossipsub/src/protocol.rs b/protocols/gossipsub/src/protocol.rs index 1950abc6c8d..2053b475167 100644 --- a/protocols/gossipsub/src/protocol.rs +++ b/protocols/gossipsub/src/protocol.rs @@ -434,6 +434,11 @@ impl Decoder for GossipsubCodec { "Message dropped. Message source was non-empty and anonymous validation mode is set" ); invalid_kind = Some(ValidationError::MessageSourcePresent); + } else if message.key.is_some() { + tracing::warn!( + "Message dropped. Message key was non-empty and anonymous validation mode is set" + ); + invalid_kind = Some(ValidationError::KeyPresent); } } ValidationMode::None => {} From 15844e93acd4870f3a05eea3c7858d6bdd44bc9a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Oliveira?= Date: Wed, 16 Sep 2026 14:02:38 +0100 Subject: [PATCH 2/4] Apply suggestion from @jxs --- protocols/gossipsub/CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/protocols/gossipsub/CHANGELOG.md b/protocols/gossipsub/CHANGELOG.md index 977934f9488..cb9cfc8bdf7 100644 --- a/protocols/gossipsub/CHANGELOG.md +++ b/protocols/gossipsub/CHANGELOG.md @@ -1,7 +1,7 @@ ## 0.51.0 - Reject messages carrying a `key` field in `ValidationMode::Anonymous`, aligning with the `StrictNoSign` policy which forbids `from`, `seqno`, `signature` and `key` on the envelope. - See [PR #6620](https://github.com/libp2p/rust-libp2p/pull/6621). + See [PR 6621](https://github.com/libp2p/rust-libp2p/pull/6621). ## 0.50.0 - Fix unbounded growth of per-peer `connected_peer.topics` from GRAFT control messages From 5afe906db52d4e9c9423203efb0d01f6a14c6742 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Oliveira?= Date: Wed, 16 Sep 2026 14:05:49 +0100 Subject: [PATCH 3/4] Apply suggestion from @jxs --- protocols/gossipsub/src/error.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/protocols/gossipsub/src/error.rs b/protocols/gossipsub/src/error.rs index 8f3a83cee18..40310262635 100644 --- a/protocols/gossipsub/src/error.rs +++ b/protocols/gossipsub/src/error.rs @@ -112,7 +112,7 @@ pub enum ValidationError { /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. MessageSourcePresent, /// Message key existed when validation has been sent to - /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + /// [`crate::behaviour::ValidationMode::Anonymous`]. KeyPresent, /// The data transformation failed. TransformFailed, From fe9b87d97bf6d8f904a0f24accbcc638525853e6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Oliveira?= Date: Thu, 17 Sep 2026 08:57:42 +0100 Subject: [PATCH 4/4] fix doc --- protocols/gossipsub/src/error.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/protocols/gossipsub/src/error.rs b/protocols/gossipsub/src/error.rs index 8f3a83cee18..e61301da827 100644 --- a/protocols/gossipsub/src/error.rs +++ b/protocols/gossipsub/src/error.rs @@ -103,16 +103,16 @@ pub enum ValidationError { /// The PeerId was invalid InvalidPeerId, /// Signature existed when validation has been sent to - /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + /// [`crate::ValidationMode::Anonymous`]. SignaturePresent, /// Sequence number existed when validation has been sent to - /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + /// [`crate::ValidationMode::Anonymous`]. SequenceNumberPresent, /// Message source existed when validation has been sent to - /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + /// [`crate::ValidationMode::Anonymous`]. MessageSourcePresent, /// Message key existed when validation has been sent to - /// [`crate::behaviour::MessageAuthenticity::Anonymous`]. + /// [`crate::ValidationMode::Anonymous`]. KeyPresent, /// The data transformation failed. TransformFailed,