Skip to content

Security: GPU Escrow Concurrency Fix#2943

Closed
MichaelSovereign wants to merge 82 commits intoScottcjn:mainfrom
MichaelSovereign:security-fix/gpu-escrow-atomicity
Closed

Security: GPU Escrow Concurrency Fix#2943
MichaelSovereign wants to merge 82 commits intoScottcjn:mainfrom
MichaelSovereign:security-fix/gpu-escrow-atomicity

Conversation

@MichaelSovereign
Copy link
Copy Markdown
Contributor

Summary

This PR fixes a critical race condition in the GPU escrow creation logic that could allow users to lock more funds than they actually possess.

Changes

  1. Atomic Escrow Initiation: Wrapped the entire escrow creation process (balance check, balance deduction, and escrow record insertion) within a SQLite transaction. This ensures that concurrent requests from the same wallet are processed serially, preventing 'over-escrowing' where the balance check passes for multiple requests before the first deduction is committed.
  2. Robust Rollbacks: Added explicit rollbacks on balance check failures to ensure database integrity.

Closes #6460

…es to prevent MitM via certificate tampering
@MichaelSovereign MichaelSovereign requested a review from Scottcjn as a code owner May 2, 2026 06:03
@github-actions github-actions Bot added BCOS-L1 Beacon Certified Open Source tier BCOS-L1 (required for non-doc PRs) BCOS-L2 Beacon Certified Open Source tier BCOS-L2 (required for non-doc PRs) consensus Consensus/RIP-200 related node Node server related tests Test suite changes size/XL PR: 500+ lines labels May 2, 2026
@Scottcjn
Copy link
Copy Markdown
Owner

Scottcjn commented May 3, 2026

Closing as part of Tier 0 hard-ban cleanup — see #3074 / #3104 / #3169 for the documented incident chain. All MichaelSovereign PRs are closed unread per the Tier 0 contract. No review path; no future PRs from this account will be processed. (See feedback_michaelsovereign_tier0_2026-05-02.md.)

@Scottcjn Scottcjn closed this May 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

BCOS-L1 Beacon Certified Open Source tier BCOS-L1 (required for non-doc PRs) BCOS-L2 Beacon Certified Open Source tier BCOS-L2 (required for non-doc PRs) consensus Consensus/RIP-200 related node Node server related size/XL PR: 500+ lines tests Test suite changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants