• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

tari-project / tari / 36590992162
71%

Build:
DEFAULT BRANCH: development
Ran 29 Sep 2026 04:28PM UTC
Jobs 1
Files 792
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

29 Sep 2026 03:32PM UTC coverage: 69.91% (+5.0%) from 64.886%
36590992162

push

github

web-flow
fix(jellyfish)!: domain-separate leaf and internal node hashes (#8060)

Description
---
Domain-separates JMT leaf and internal node hashes by using distinct
`"Leaf"` and `"Internal"` hasher labels, where both previously used
`"Node"`.

Replaces the ootle-generated eviction proof fixture with synthetic
tests. Ootle no longer produces the eviction command, and the fixture's
inclusion proof was built with the old hashing. The base layer still
validates eviction proofs, so `tests/eviction_proof.rs` now builds a
command JMT locally (`key == value == command_hash`). It checks that a
valid inclusion proof passes, and that a proof for another command, a
command not in the tree, or the wrong root is rejected. The
unknown-validator QC rejection moved to `commit_proof.rs`.

`jmt_node_hash`, `jmt_node_hash2` and the `JmtHashDomain` version are
unchanged, so leaf key mapping in consumers (e.g. `key_mapper` in ootle)
is not affected.

Motivation and Context
---
Leaf and internal nodes were hashed with the same hasher over the same
64-byte layout (`H(key, value_hash)` vs `H(left, right)`). Because of
this, a real internal node could be presented as a leaf with `key = left
child hash` and `value = right child hash`:
- **Forged inclusion:** this succeeds when the fake key's prefix matches
the node's path, which has probability ~2^-depth, so ~50% at depth 1.
- **Forged non-inclusion:** `verify_exclusion` accepts the same fake
leaf for any key in that subtree, so it can "prove" that existing keys
are absent.

The current base layer caller (`key == value == command_hash`) was not
exploitable. Other consumers of `verify_exclusion`, or of inclusion with
an arbitrary key and value, were.

How Has This Been Tested?
---
Added `it_rejects_an_internal_node_presented_as_a_leaf`, which builds a
two-leaf tree and forges a proof from the root's children. The test
fails on the old hashing, where the forged proof verifies, and passes
with this change. `cargo test -p tari_jellyfish -p... (continued)

45 of 45 new or added lines in 2 files covered. (100.0%)

1437 existing lines in 33 files now uncovered.

102373 of 146436 relevant lines covered (69.91%)

398594.29 hits per line

Coverage Regressions

Lines Coverage ∆ File
312
44.03
41.69% base_layer/wallet/src/output_manager_service/service.rs
179
7.8
7.8% base_layer/wallet/src/utxo_scanner_service/utxo_scanner_task.rs
118
0.0
0.0% base_layer/wallet/src/wallet.rs
95
63.33
-1.79% base_layer/core/src/chain_storage/blockchain_database.rs
90
23.88
15.5% clients/rust/base_node_wallet_client/src/client/http.rs
86
29.82
29.82% base_layer/wallet/src/transaction_service/service.rs
79
84.23
-0.23% comms/core/src/protocol/rpc/client/mod.rs
65
25.94
25.94% base_layer/wallet/src/transaction_service/protocols/transaction_validation_protocol.rs
59
73.03
0.0% comms/core/src/protocol/messaging/protocol.rs
59
0.0
0.0% comms/core/src/tor/hidden_service/controller.rs
51
33.15
-0.19% base_layer/p2p/src/initialization.rs
51
0.0
0.0% base_layer/wallet/src/transaction_service/protocols/fetch_claim_burn_merkle_proofs.rs
38
80.92
0.0% comms/core/src/connection_manager/manager.rs
23
55.66
-0.56% base_layer/core/src/chain_storage/lmdb_db/lmdb_db.rs
18
0.0
0.0% comms/core/src/tor/hidden_service/builder.rs
16
40.0
40.0% base_layer/wallet/src/base_node_service/monitor.rs
16
71.28
-1.1% comms/core/src/connectivity/manager.rs
11
89.91
0.8% base_layer/service_framework/src/context/handles.rs
11
67.47
67.47% base_layer/wallet/src/utxo_scanner_service/service.rs
10
89.13
4.38% base_layer/service_framework/src/stack.rs
10
96.32
29.96% infrastructure/shutdown/src/lib.rs
8
92.45
2.45% infrastructure/shutdown/src/oneshot_trigger.rs
6
75.49
-0.73% base_layer/core/src/test_helpers/blockchain.rs
5
90.41
0.0% comms/core/src/pipeline/inbound.rs
4
63.82
-1.14% base_layer/core/src/chain_storage/db_transaction.rs
4
61.03
-0.98% base_layer/core/src/validation/helpers.rs
3
82.34
-0.6% base_layer/transaction_components/src/validation/aggregate_body/aggregate_body_internal_validator.rs
3
73.8
3.61% infrastructure/jellyfish/src/types.rs
2
88.86
0.0% base_layer/core/src/validation/block_body/test.rs
2
87.57
0.37% comms/core/src/connection_manager/peer_connection.rs
1
98.24
-0.15% base_layer/core/src/proof_of_work/monero_rx/merkle_tree.rs
1
78.72
-0.13% base_layer/wallet/src/storage/sqlite_db/wallet.rs
1
69.41
-0.16% comms/dht/src/connectivity/mod.rs
Jobs
ID Job ID Ran Files Coverage
1 36590992162.1 29 Sep 2026 04:28PM UTC 792
69.91
GitHub Action Run
Source Files on build 36590992162
  • Tree
  • List 792
  • Changed 119
  • Source Changed 35
  • Coverage Changed 110
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36590992162
  • bcf9ea96 on github
  • Prev Build on development (#36580513241)
  • Next Build on development (#36681473458)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc