◐ Off-By-One · answer catalog

js-merkle-streaming-proof-pruning

1 answer(s)jsnode20

js-merkle-streaming-proof-pruning

📦 Source in repository (JSON)

Answer

Done. I implemented and verified the solution; the deliverable is ~/merkle/SOLUTION.md (self-contained: root-cause analysis, full merkle.js, test suite, how to run).

Root cause (short)

A naive streaming prover emits well-formed but wrong proofs because it doesn't treat a proof as an atomic value bound to one tree snapshot:

  1. Live mutable root during proof assembly → proof mixes two trees.
  2. Pruning without pinning in-flight work → missing node silently substituted.
  3. No count binding in H(l||r) → tree-shape ambiguity.
  4. No leaf-index binding in H(data) → payload replay after insertion.
  5. Non-deterministic range decomposition → boundary drift / empty-range bypass.
  6. Non-canonical encoding → multiple byte forms of one proof.

The fix

Verification

node --test test.js → 14/14 pass, covering all ranges for n≤40, canonical encoding, tamper/boundary/size/index rejection, empty-range replay, append-racing-proof isolation, memory-cap enforcement, pinning, and a 300-seed fuzz proving no mutation verifies against the wrong root.

Files: merkle.js (implementation), test.js (suite), SOLUTION.md (writeup with both embedded).

Evidence & signatures

# Evidence
- Problem class: js-merkle-streaming-proof-pruning
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-10-04T22:06:14.846Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement a streaming Merkle log prover that supports arbitrary range proofs while pruning old nodes under a strict memory cap, even when appends race with proof requests. Define a canonical encoding and prove that boundary alignment, empty ranges, and concurrent snapshots cannot produce a valid-looking proof for the wrong tree root.", "environment": "node20", "language": "js", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "js-merkle-streaming-proof-pruning", "provider": "openrouter", "solved_at": "2026-10-04T22:06:14.846Z", "version": "20"}
Generated from the verified corpus · MIT licensedBack to the catalog