Skip to content

fix(tip-money): allow tip receiver validation - #1532

Draft
lizhang-jito wants to merge 4 commits into
masterfrom
lizhang/tip-receiver-validation
Draft

fix(tip-money): allow tip receiver validation#1532
lizhang-jito wants to merge 4 commits into
masterfrom
lizhang/tip-receiver-validation

Conversation

@lizhang-jito

Copy link
Copy Markdown

Problem

Current tip-money doesn't verify the new tip receiver is validator's TDA account.
This causes a security issue.

Summary of Changes

This is validator side change.

  • Passing the validator's vote account in change tip receiver TX. This allows the on-chain part to do the verification.

Testing

Minor changes.

Fixes #

0xEdgar and others added 4 commits July 17, 2026 12:17
only reroute if relayer connected (#123)
feat: add client tls config (#121)
remove extra val (#129)
fix clippy (#130)
copy all binaries to docker-output (#131)
Ledger tool halts at slot passed to create-snapshot (#118)
update program submodule (#133)
quick fix for tips and clearing old bundles (#135)
update submodule to new program (#136)
Improve stake-meta-generator usability (#134)
pinning submodule head (#140)
Use BundleAccountLocker when handling tip txs (#147)
Add metrics for relayer + block engine proxy (#149)
Build claim-mev in docker (#141)
Rework bundle receiving and add metrics (#152) (#154)
update submodule + dev files (#158)
Deterministically find tip amounts, add meta to stake info, and cleanup pubkey/strings in MEV tips (#159)
update jito-programs submodule (#160)
Separate MEV tip related workflow (#161)
Add block builder fee protos (#162)
fix jito programs (#163)
update submodule so autosnapshot exits out of ledger tool early (#164)
Pipe through block builder fee (#167)
pull in new snapshot code (#171)
block builder bug (#172)

Pull in new slack autosnapshot submodule (#174)

sort stake meta json and use int math (#176)

add accountsdb conn submod (#169)

Update tip distribution parameters (#177)

new submodules (#180)

Add buildkite link for jito CI (#183)

Fixed broken links to repositories (#184)

Changed from ssh to https transfer for clone

Seg/update submods (#187)

fix tests (#190)

rm geyser submod (#192)

rm dangling geyser references (#193)

fix syntax err (#195)

use deterministic req ids in batch calls (#199)

update jito-programs

revert cargo

update Cargo lock

update with path fix

fix cargo

update autosnapshot with block lookback (#201)

[JIT-460] When claiming mev tips, skip accounts that won't have min rent exempt amount after claiming (#203)

Add logging for sol balance desired (#205)

* add logging

* add logging

* update msg

* tweak vars

update submodule (#204)

use efficient data structures when calling batch_simulate_bundles (#206)

[JIT-504] Add low balance check in uploading merkle roots (#209)

add config to simulate on top of working bank (#211)

rm frozen bank check

simulate_bundle rpc bugfixes (#214)

rm frozen bank check in simulate_bundle rpc method

[JIT-519] Store ClaimStatus address in merkle-root-json (#210)

* add files

* switch to include bump

update submodule (#217)

add amount filter (#218)

update autosnapshot (#222)

Print TX error in Bundles (#223)

add new args to support single relayer and block-engine endpoints (#224)

point to new jito-programs submod and invoke updated init tda instruction (#228)

fix clippy errors (#230)

fix validator start scripts (#232)

Point README to gitbook (#237)

use packaged cargo bin to build (#239)

Add validator identity pubkey to StakeMeta (#226)

The vote account associated with a validator is not a permanent link, so log the validator identity as well.

bugfix: conditionally compile with debug flags (#240)

Seg/tip distributor master (#242)

* validate tree nodes

* fix unit tests

* pr feedback

* bump jito-programs submod

Simplify bootstrapping (#241)

* startup without precompile

* update spacing

* use release mode

* spacing

fix validation

rm validation skip

Account for block builder fee when generating excess tip balance (#247)

Improve docker caching

delay constructing claim mev txs (#253)

fix stake meta tests from bb fee (#254)

fix tests

Buffer bundles that exceed cost model (#225)

* buffer bundles that exceed cost model

clear qos failed bundles buffer if not leader soon (#260)

update Cargo.lock to correct solana versions in jito-programs submodule (#265)

fix simulate_bundle client and better error handling (#267)

update submod (#272)

Preallocate Bundle Cost (#238)

fix Dockerfile (#278)

Fix Tests (#279)

Fix Tests (#281)

* fix tests

update jito-programs submod (#282)

add reclaim rent workflow (#283)

update jito-programs submod

fix clippy errs

rm wrong assertion and swap out file write fn call (#292)

Remove security.md (#293)

demote frequent relayer_stage-stream_error to warn (#275)

account for case where TDA exists but not allocated (#295)

implement better retries for tip-distributor workflows (#297)

limit number of concurrent rpc calls (#298)

Discard Empty Packet Batches (#299)

Identity Hotswap (#290)

small fixes (#305)

Set backend config from admin rpc (#304)

Admin Shred Receiver Change (#306)

Seg/rm bundle UUID (#309)

Fix github workflow to recursively clone (#327)

Add recursive checkout for downstream-project-spl.yaml (#341)

Use cluster info functions for tpu (#345)

Use git rev-parse for git sha

Remove blacklisted tx from message_hash_to_transaction (#374)

Updates bootstrap and start scripts needed for local dev. (#384)

Remove Deprecated Cli Args (#387)

Master Rebase

improve simulate_bundle errors and response (#404)

derive Clone on accountoverrides (#416)

Add upsert to AccountOverrides (#419)

update jito-programs (#430)

[JIT-1661] Faster Autosnapshot (#436)

Reverts simulate_transaction result calls to upstream (#446)

Don't unlock accounts in TransactionBatches used during simulation (#449)

first pass at wiring up jito-plugin (#428)

[JIT-1713] Fix bundle's blockspace preallocation (#489)

[JIT-1708] Fix TOC TOU condition for relayer and block engine config (#491)

[JIT-1710] - Optimize Bundle Consumer Checks (#490)

Add Blockhash Metrics to Bundle Committer (#500)

add priority fee ix to mev-claim (#520)

Update Autosnapshot (#548)

Run MEV claims + reclaiming rent-exempt amounts in parallel. (#582)

Update CI (#584)
- Add recursive submodule checkouts.
- Re-add solana-secondary step

Add more release fixes (#585)

Fix more release urls (#588)

[JIT-1812] Fix blocking mutexs (#495)

 [JIT-1711] Compare the unprocessed transaction storage BundleStorage against a constant instead of VecDeque::capacity() (#587)

Automatically rebase Jito-Solana on a periodic basis. Send message on slack during any failures or success.

Fix periodic rebase #594

Fixes the following bugs in the periodic rebase:
Sends multiple messages on failure instead of one
Cancels entire job if one branch fails

Ignore buildkite curl errors for rebasing and try to keep curling until job times out (#597)

Sleep longer waiting for buildkite to start (#598)

correctly initialize account overrides (#595)

Fix: Ensure set contact info to UDP port instead of QUIC (#603)

Add fast replay branch to daily rebase (#607)

take a snapshot of all bundle accounts before sim (#13) (#615)

update jito-programs submodule

Add 2.0 to daily rebase (#626)

Export agave binaries during docker build (#627)

Buffer bundles that exceed processing time and make the allowed processing time longer (#611)

Publish releases to S3 and GCS (#633)

Rebase from different repos (#637)

Point SECURITY.md to immunefi (#671)

Loosen requirements on tip accounts touchable in BankingStage (#683)

Separate out broadcast + retransmit shredstream (#703)

Add packet flag for staked node (#705)

Add auto-rebase to v2.1 (#739)

Fix release github (#745)

Move block_cost_limit tracking to BankingStage in preparation for SIMD-0207 (#753)

Add precompile checks in BundleStage (#787)

Add auto-rebase to v2.2 (#818)

Add better error handling around missing transaction signatures for bundle id generation (#860)

Remove unwrap from authentication (#861)

Revert Jito-Solana WorkingBankEntry changes (#873)

Add libclang to Dockerfile (#885)

Remove the tip distributor code (#888)

Rebase: Update anchor to not use deprecated crates

Add TLS webpki roots back in (#933)

Remove trusted relayer packets (#952)

Fix shred retransmit (#954)

Add daily v3.0 rebase (#972)

[Master] Automatically use optimal Block Engine region (#974)

Disable autoconfig (#995)

Make shredstream optional (#997)

Fix flaky test (#1027)
Remove bundle reservation (#1025)

Ensure execution-based failures are dropped (#1072)

Update programs to newest tip distribution + tip payment code (#1063)

Remove commented out code (#1074)

Remove unused bundle committer (#1091)

Fix bundle account locker TOCTOU (time of check time of use) bug (#1093)

fix unstaked xdp retransmit to block engine (#1090)

Bam Patch

This commit contains the contents migrated from the bam repository here: https://github.com/jito-labs/bam-client

Add BAM Connectivity Management Integration Tests (#1127)

[Master] Shoot down block engine connection if BAM enabled (#1139)

Fix priority graph TOCTOU (#1128)

Dynamic Client Id (#1138)

Set ClientId based on if it is actively connected to the BAM Node; with Jito-Solana being the default until a bam_connection exists.

Simple ping pong response implementation (#1145)

Problem

Implement pong response from the validator

Summary of Changes

This PR implements a simple ping-pong response mechanism for the BAM (Block Auction Market) connection system. The changes add handling for incoming ping messages by responding with pong messages, along with corresponding metrics tracking.

Changes:

Added ping message handling in the outbound message processing loop
Introduced three new metrics to track ping-related activity (ping_sent, outbound_ping_sent, outbound_ping_fail)
Updated the bam-protos subproject commit reference

Fix dockerfile warnings (#1174)

[master] Reduce BAM Scheduler allocs, remove lock contention in consume_work (#1161)

chore: fix cargo audit (#1184)

Propagate RUST_LOG to bam-local-cluster & use a valid merkle root upload authority (#1196)

Disconnect BAM when url is cleared (#1199)

feat: add support for multiple shred receivers (#1200)

Add documentation (#1214)

Fix insert_new_batch slab-capacity check (#1215)

Add a tag to scheduler metrics to distinguish between schedulers (#1198)

Clean up bam connection handling (#1213)

Reduce verbosity of slot logging  (#1234)

Stat improvement (#1225)

GRPC latency measurement (#1192)

Co-authored-by: haoranjito <haoran@jito.wtf>

Log new bam url (#1239)

Use better error codes for BAM connection (#1164)

fix ci secondary build  (#1240)

fix fetch stage manager (#1172)

Fix BAM fee-payer validation regression for bundled transactions. (#1236)

Proxy stage metric fix (#1244)

Small cleanups (#1268)

Use size hint (#1272)

skip secondary build for CI (#1273)

Bundle Lifecycle Management Cleanup (#1098)

Changes
- Remove unused solana-bundle-sdk
- Simplify insert_bundle callsite by removing method and chaining the recv_timeout with a try_recv
- Simplify BundleAccountLocker/BundleStorage management when processing bundles
- Simplify bundle result aggregation
- Cache static_instruction_limit
- Remove unused data structures

Some cleanup in FetchManager (#1281)

Bugfix: Fix tpu socket bug considering the offsetting math has changed in v4.X (#1261)

fix: suppress WARN log when --relayer-url is not configured (#1232)

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

Small cleanups (#1285)

Fix BAM enabled flag in update_tpu_config

Set ExecutionFlags values to revert_on_error

Disable incremental re-check inside BAM (#1334)

Multicast: send to DZ (#1355)

* Add MulticastShredCheckService

- Monitors /proc/net/route every 60s for multicast routes
- Mainnet: 233.84.178.1:7733, Testnet: 233.84.178.10:7733
- Automatically adds multicast address to shred receivers when route appears
- Automatically removes multicast address from shred receivers when route disappears
- Enabled on MainnetBeta and Testnet (controlled by disable_multicast_shred_check flag)
- Logs state changes once, no repeated messages while state is stable

* add

---------

Co-authored-by: Juan Olveira <juan@malbeclabs.com>

Bugfix - External Scheduler Account Checks (#1356)

* pipe blacklisted account into the external consume worker

* extract blacklist check logic to contains_blacklisted_account for use in both internal/external schduler

* add happy path test

* use arc for cloning the blisted accounts and minor cleaning

* format and sort

* update for cargo audit

* add quick little unit test

Update team references in .mergify.yml (#1363)

[Master] Support remote hosts connecting to local cluster (#1366)

add

[master] Defer BAM post-auth tasks until stream acceptance (#1368)

* add

* fmt

ci: Disable Dependabot version update PRs (#1393)

remove dependabot

feat: Add backport automation with GPG signing (#1386)

Fix: Adding SIGTERM handling for local cluster manager (#1396)

Adding SIGTERM handling for local cluster

Dynamically pinned PoH core in local cluster (#1397)

add

[improvement] adding --limit-ledger-size to cluster manager to limit RocksDB size i… (#1407)

Adding --limit-ledger-size to cluster manager to limit RocksDB size in local cluster mode

Fix race condition in admin RPC BAM URL updater registration (#1418)

* Register BAM identity updater before spawning manager

* fix test

[master] turbine: use a dedicated 0.0.0.0-bound socket for ShredReceiverAddresses (#1420)

add

Update shred receiver documentation (#1422)

* add

* fix

refactor (#1410)

[Master] Poh Core ordering (#1427)

add

[Master] Shred rework (#1431)

* Forward BAM shreds near leader windows

* dz fix

* shred cleanups

---------

Co-authored-by: haoranjito <haoran@jito.wtf>

[Master] More efficient retransmit for BAM (#1434)

gate BAM receivers to leader window start

Add program cache test (#1439)

add

feat: Add simulateTransaction extra fields to simulateBundle (#1443)

* feat: Add simulateTransaction extra fields to simulateBundle

* add replacementBlockhash

[master] Shred multicast update order (#1447)

feat(turbine): prioritize multicast receiver address in shred broadcast order

Move multicast_receiver_address to the front of external_receiver_addrs
so multicast shreds are sent before shred_receiver_addresses entries.

Co-authored-by: Juan Olveira <juan@malbeclabs.com>

- Increase BAM shred retransmit lookahead (#1455)
- fix(bundle): Don't unwrap priority fee cache for BundleStage (#1460)
- Fix client id to JitoLabs (#1461)
- [Master] Fix prio graph (#1464)
- [master] Allow local cluster startup (#1466)
- fix(ci): adding v4.1 to autorebase CI (#1458)
- Enable TLS Connections to BAM Node (#1467)
- [master] Add Multicast root receiver (#1469)
- ci(backport): Add v4.1 target branch (#1482)
- Ignore quinn-proto RustSec advisory (#1484)
- [codex] Run cargo audit at the end of CI (#1483)
- Clean up priority handling (#1479)
- Polling cleanup (#1480)
- Zercopy bam (#1481)
- BAM URL switch cleanups (#1487)
- Target slot adjustment (#1491)
- Add 4.2 to gh workflows (#1495)
- Use native CA roots (#1493)
- fix(bam-local-cluster): Enable dev utilities
- test(rpc): Use unique validator ports
- Refactor build pipeline to drive upstream tooling under BuildKit (#1441)
- Centralize Tonic Endpoint Creation (#1499)
- Local cluster no XDP (#1507)
- Configurable faucet mint sol for local cluster (#1508)
- fix(build): Clean up tagging mechanics (#1509)
- Cleanup BAM Connection (#1504)
- Simplify URL parsing (#1514)
- fix(bam): Fix flakey CI tests by signaling parsing thread shutdown (#1520)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants