Skip to content

Promoted system tx may consume its nonce on a REX5 gas-validation rejection #345

Description

@wayzeek

Summary

Suspected: needs confirmation against op-revm's deposit catch_error.

A legacy transaction from the system address is promoted to deposit-style in before_run (sets deposit.source_hash, gas_price = 0) before validate runs. If the REX5 final initial/floor-gas validation then rejects it, the error is caught by op.catch_error, which for a deposit-typed tx converts it into Halt(FailedDeposit) and persists the caller nonce. That contradicts the code's own comment that "fees and nonce stay untouched" when a tx cannot fit its final intrinsic+storage gas.

Reachability

Low. System transactions are sequencer-produced with controlled gas limits, so this requires a system tx whose final Mega-adjusted intrinsic+storage gas exceeds its gas limit (a sequencer misconfiguration, not attacker-controlled). Not a security hole, but it breaks a documented invariant.

Code pointers

crates/mega-evm/src/evm/execution.rs: before_run promotion (~L82-153), the REX5 final gas check in validate (~L638), and the deposit-path handling in execution_result (~L793).

Next steps

  1. Confirm whether op.catch_error on a promoted (deposit-typed) system tx actually persists the nonce for a validate-stage rejection.
  2. If confirmed: track the legacy-system promotion separately so its pre-execution validation errors bypass the failed-deposit conversion, while genuine deposits keep it. This changes REX5 behavior, so it would require a new spec.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions