Skip to content

api: return errors instead of panicking on malformed web3 requests - #5037

Open
guo wants to merge 1 commit into
masterfrom
guo/web3-malformed-params
Open

guo wants to merge 1 commit into
masterfrom
guo/web3-malformed-params

Conversation

@guo

@guo guo commented Oct 2, 2026

Copy link
Copy Markdown
Member
  • require the request method to be a string when parsing requests
  • check the block lookup error before reading the block in
    eth_getTransactionByBlock{Hash,Number}AndIndex
  • reject a SetCode call value that does not fit in 256 bits instead of
    calling uint256.MustFromBig

Test: api/web3server_test.go covers the change and fails without it. go test -gcflags=all=-N -l -short passes for the touched packages.

- require the request method to be a string when parsing requests
- check the block lookup error before reading the block in
  eth_getTransactionByBlock{Hash,Number}AndIndex
- reject a SetCode call value that does not fit in 256 bits instead of
  calling uint256.MustFromBig
@guo
guo requested a review from a team as a code owner October 2, 2026 17:42
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant