Skip to content

Multi-Ledger 2-Phase Commit Protocol Implementation - #439

Closed
NhoxxKienn wants to merge 20 commits into
hyperledger-labs:mainfrom
perun-network:2pc-multi-ledger
Closed

NhoxxKienn wants to merge 20 commits into
hyperledger-labs:mainfrom
perun-network:2pc-multi-ledger

Conversation

@NhoxxKienn

Copy link
Copy Markdown
Contributor

Problem

Multi-ledger Perun channels are vulnerable to a stale-state cross-ledger settlement attack, where diverging locally-finalised state versions across chains can be exploited during withdrawal. This PR introduces a Two-Phase Commit (2PC) coordination step via a Trusted Third Party (TTP) to ensure all linked chains settle on the same canonical state before any withdrawal is permitted.

Single-ledger channels are not affected by any of these changes.

What's New

New Coordinated phase — inserted between Registered/Progressed and Withdrawing in the multi-ledger dispute lifecycle:

Registering → Registered → [Progressing → Progressed]* → Coordinated → Withdrawing

Only the TTP coordinator W (identified by pkW agreed at channel opening) can trigger entry into Coordinated by submitting a signed CommitCert = σ_W(cid, σ*, Coordinated) to each chain. Withdrawal from a multi-ledger channel is blocked until this phase is reached.


Commits

Commit Change
da17666 feat(channel): Add CoordinatedEvent type
c001efb feat(channel, client): Add coordinated settlement bridge for multiledger
4baee51 feat(channel/multi): Add CoordinationRegistry (RequestCoordination, AwaitCoordinated, NotifyCoordinated)
b2c1fc3 feat(channel, client): Make coordinator optional in multi-ledger params; fallback to direct withdrawal when pkW absent
b16db44 feat(client): Insert coordination wait in Settle() path: ensureRegistered → RequestCoordination → AwaitCoordinated → Withdraw
a3cb01e feat(client): Consume CoordinatedEvent from adjudicator subscription
4b0bde8 feat(client): Forward coordinated events during settle coordination wait
df151ec feat(wire/protobuf): Preserve coordinator identity in proposal and params encoding
49cdb7f test(client, multiledger): Add coordinated settle blocking/cancel coverage and event-driven backend coordination

Key Design Decisions

  • pkW is optional — when absent, channels fall back to the original Perun withdrawal path for backward compatibility
  • go-perun core defines the reception boundary only — the external TTP coordinator service (cross-chain monitoring, canonical state selection, CommitCert submission) is out of scope
  • No new inter-component paths — CoordinatedEvent flows through the existing AdjudicatorSubscription mechanism

Tests

  • Happy path: Final → Registered, no coordinator involvement
  • Dispute path: Registering → Registered/Progressed → Coordinated → Withdrawing
  • Blocking/cancel coverage for AwaitCoordinated in Settle()
  • Event-driven backend coordination in mock backend

NhoxxKienn and others added 13 commits November 11, 2025 10:48
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
…ding

Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
…erage and backend event-driven coordination

Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
@NhoxxKienn
NhoxxKienn requested a review from iljabvh April 7, 2026 13:17
Signed-off-by: Minh Huy Tran <huy@perun.network>
Count coordinated readiness against distinct participating ledgers by
using per-ledger adjudicator subscriptions in settlement.

- add ledger-aware deduplicated notifications in CoordinationRegistry
- configure expected coordinated event threshold from participating ledgers
- consume coordination events per ledger when available
- stop pre-counting coordinated events during registration scans
- add regression tests for distinct-ledger counting and coordinated event handling

Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
Signed-off-by: Minh Huy Tran <huy@perun.network>
@NhoxxKienn NhoxxKienn closed this Jul 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant