Repository navigation
Multi-Ledger 2-Phase Commit Protocol Implementation - #439
Closed
NhoxxKienn wants to merge 20 commits into
Closed
NhoxxKienn wants to merge 20 commits into
NhoxxKienn wants to merge 20 commits into
Conversation
Sync v0.14.1
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
…ding Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
…erage and backend event-driven coordination Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
NhoxxKienn
force-pushed
the
2pc-multi-ledger
branch
from
April 7, 2026 11:23
e08e9b9 to
a6298b8
Compare
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Count coordinated readiness against distinct participating ledgers by using per-ledger adjudicator subscriptions in settlement. - add ledger-aware deduplicated notifications in CoordinationRegistry - configure expected coordinated event threshold from participating ledgers - consume coordination events per ledger when available - stop pre-counting coordinated events during registration scans - add regression tests for distinct-ledger counting and coordinated event handling Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Multi-ledger Perun channels are vulnerable to a stale-state cross-ledger settlement attack, where diverging locally-finalised state versions across chains can be exploited during withdrawal. This PR introduces a Two-Phase Commit (2PC) coordination step via a Trusted Third Party (TTP) to ensure all linked chains settle on the same canonical state before any withdrawal is permitted.
Single-ledger channels are not affected by any of these changes.
What's New
New
Coordinatedphase — inserted betweenRegistered/ProgressedandWithdrawingin the multi-ledger dispute lifecycle:Registering → Registered → [Progressing → Progressed]* → Coordinated → WithdrawingOnly the TTP coordinator
W(identified bypkWagreed at channel opening) can trigger entry intoCoordinatedby submitting a signedCommitCert = σ_W(cid, σ*, Coordinated)to each chain. Withdrawal from a multi-ledger channel is blocked until this phase is reached.Commits
da17666feat(channel): AddCoordinatedEventtypec001efbfeat(channel, client): Add coordinated settlement bridge for multiledger4baee51feat(channel/multi): AddCoordinationRegistry(RequestCoordination,AwaitCoordinated,NotifyCoordinated)b2c1fc3feat(channel, client): Make coordinator optional in multi-ledger params; fallback to direct withdrawal whenpkWabsentb16db44feat(client): Insert coordination wait inSettle()path:ensureRegistered → RequestCoordination → AwaitCoordinated → Withdrawa3cb01efeat(client): ConsumeCoordinatedEventfrom adjudicator subscription4b0bde8feat(client): Forward coordinated events during settle coordination waitdf151ecfeat(wire/protobuf): Preserve coordinator identity in proposal and params encoding49cdb7ftest(client, multiledger): Add coordinated settle blocking/cancel coverage and event-driven backend coordinationKey Design Decisions
pkWis optional — when absent, channels fall back to the original Perun withdrawal path for backward compatibilityCommitCertsubmission) is out of scopeCoordinatedEventflows through the existingAdjudicatorSubscriptionmechanismTests
Final → Registered, no coordinator involvementRegistering → Registered/Progressed → Coordinated → WithdrawingAwaitCoordinatedinSettle()