Impact
The RequestTrieProof request handler validates only the upper bound (<= MAX_KEYS = 255) on self.keys and forwards the list unchanged to MerkleRadixTrie::get_proof. Inside that function, duplicate keys that are not present in the current accounts trie each reach the _ arm of match pointer_node.child_key(..) and attempt to insert into the missing_proven_by BTreeMap. On the second insertion, BTreeMap::insert returns Some(_), violating the assert!(... .is_none())
Patches
#3754
Workarounds
No Workaround
Impact
The RequestTrieProof request handler validates only the upper bound (<= MAX_KEYS = 255) on self.keys and forwards the list unchanged to MerkleRadixTrie::get_proof. Inside that function, duplicate keys that are not present in the current accounts trie each reach the _ arm of match pointer_node.child_key(..) and attempt to insert into the missing_proven_by BTreeMap. On the second insertion, BTreeMap::insert returns Some(_), violating the assert!(... .is_none())
Patches
#3754
Workarounds
No Workaround