<oembed><type>rich</type><version>1.0</version><author_name>npub12478zv0dxzfgepyn9m3v8vl8sn5yy8vhxpxump6lnfw84rslr0wqwxpaq3</author_name><author_url>https://nostr.ae/npub12478zv0dxzfgepyn9m3v8vl8sn5yy8vhxpxump6lnfw84rslr0wqwxpaq3</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-05-11&#xA;📝 Original message:Hi,&#xA;&#xA;not sure if headergolf was mentioned yet. It&#39;s about very similar ideas: https://github.com/alecalve/headergolf&#xA;&#xA;&#xA;&#xA;&#xA;&#xA;&#xA;&#xA;&#xA;&#xA;‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐&#xA;On Friday, May 8, 2020 2:31 PM, Will Clark via bitcoin-dev &lt;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; Hello list,&#xA;&gt;&#xA;&gt; I would like to propose a compressed block header scheme for IBD and block announcements. This proposal is derivative of previous proposals found on this list (see links in spec below) with some modifications and clarifications.&#xA;&gt;&#xA;&gt; The below specification (also found at https://github.com/willcl-ark/compressed-block-headers/blob/v1.0/compressed-block-headers.adoc ) details the compression recommended along with the generated bandwidth savings in the best-case scenario.&#xA;&gt;&#xA;&gt; I look forward to any feedback anyone has to offer on the specification itself, as well as any additions or objections to the motivation.&#xA;&gt;&#xA;&gt; Cheers,&#xA;&gt; Will&#xA;&gt;&#xA;&gt; = Compressed block headers&#xA;&gt; Will Clark will8clark at gmail.com&#xA;&gt; v1.0, May 2020:&#xA;&gt; :toc: preamble&#xA;&gt; :toclevels: 4&#xA;&gt;&#xA;&gt; This work is a derivation of these mailing list posts:&#xA;&gt;&#xA;&gt; 1.  https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-August/014876.html[bitcoin-dev: &#34;Compressed&#34; headers stream - 2017] (with resurrection https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-December/015385.html[here])&#xA;&gt; 2.  https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-March/015851.html[bitcoin-dev: Optimized Header Sync]&#xA;&gt;&#xA;&gt;     &#39;&#39;&#39;&#xA;&gt;&#xA;&gt;     == Motivation&#xA;&gt;&#xA;&gt;     Block headers as exchanged by nodes over the p2p network are currently 81 bytes each.&#xA;&gt;&#xA;&gt;     For low bandwidth nodes who are doing a headers-only sync, reducing the size of the headers can provide a significant bandwidth saving. Also, nodes can support more header-only peers for IBD and protection against eclipse attacks if header bandwidth is reduced.&#xA;&gt;&#xA;&gt;     === Background&#xA;&gt;&#xA;&gt;     Currently headers are sent over the p2p network as a vector of `block_headers`, which are composed of the following sized fields:&#xA;&gt;&#xA;&gt;     [cols=&#34;&lt;,&gt;&#34;]&#xA;&gt;&#xA;&gt;&#xA;&gt; |===&#xA;&gt; |Field |Size&#xA;&gt;&#xA;&gt; |Version |4 bytes&#xA;&gt; |Previous block hash |32 bytes&#xA;&gt; |Merkle root hash |32 bytes&#xA;&gt; |Time |4 bytes&#xA;&gt; |nBits |4 bytes&#xA;&gt; |nonce |4 bytes&#xA;&gt; |txn_count |1 byte&#xA;&gt; |Total |81 bytes&#xA;&gt; |===&#xA;&gt;&#xA;&gt; Some fields can be removed completely, others can be compressed under certain conditions.&#xA;&gt;&#xA;&gt; == Proposed specification&#xA;&gt;&#xA;&gt; === block_header2 data type&#xA;&gt;&#xA;&gt; The following table illustrates the proposed `block_header2` data type specification.&#xA;&gt;&#xA;&gt; [cols=&#34;&lt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Field |Size |Compressed&#xA;&gt;&#xA;&gt; |Bitfield |1 byte | 1 byte&#xA;&gt; |Version |4 bytes |0 \| 4 bytes&#xA;&gt; |Previous block hash |32 bytes |0 \| 32 bytes&#xA;&gt; |Merkle root hash |32 bytes |32 bytes&#xA;&gt; |Time |4 bytes |2 \| 4 bytes&#xA;&gt; |nBits |4 bytes |0 \| 4 bytes&#xA;&gt; |nonce |4 bytes |4 bytes&#xA;&gt; |Total |81 bytes |range: 39 - 81 bytes&#xA;&gt; |===&#xA;&gt;&#xA;&gt; This compression results in a maximum reduction from an 81 byte header to best-case 39 byte header. With 629,474 blocks in the current blockchain, a continuous header sync from genesis (requiring a single full 81 byte header followed by only compressed `block_header2`) has been tested to have its required bandwidth reduced from 50.98MB down to 25.86MB, a saving of 49%.&#xA;&gt;&#xA;&gt; ==== Bitfield&#xA;&gt;&#xA;&gt; To make parsing of header messages easier and further increase header compression, a single byte bitfield was suggested by gmaxwell footnote:[https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-December/015397.html]. We propose the following amended bitfield meanings (bits re-ordered to match `headers2` field order):&#xA;&gt;&#xA;&gt; [cols=&#34;&lt;,&lt;&#34;]&#xA;&gt; |===&#xA;&gt; |Bit |Meaning + field size to read&#xA;&gt;&#xA;&gt; |0 +&#xA;&gt; 1 +&#xA;&gt; 2 |version: same as the last distinct value 1st ... 7th (0 byte field) or a new 32bit distinct value (4 byte field).&#xA;&gt; |3 |prev_block_hash: is omitted (0 byte field) or included (32 byte field)&#xA;&gt; |4 |timestamp: as small offset (2 byte field) or full (4 byte field).&#xA;&gt; |5 |nbits: same as last header (0 byte field) or new (4 byte field).&#xA;&gt; |6 |possibly to signal &#34;more headers follow&#34; to make the encoding self-delimiting.&#xA;&gt; |7 |currently undefined&#xA;&gt; |===&#xA;&gt;&#xA;&gt; This bitfield adds 1 byte for every block in the chain, for a current total increase of 629,474B.&#xA;&gt;&#xA;&gt; ==== Version&#xA;&gt;&#xA;&gt; In most cases the Version field will be identical to one referenced in one of the previous 7 unique versions, as indicated by bits 0,1,2 of the Bitfield.&#xA;&gt;&#xA;&gt; To block 629,474 there were 616,137 blocks whose version was in the previous 7 distinct versions, and only 13,338 blocks whose version was not, this includes any version bit manipulation done via overt ASIC boost.&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&gt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Genesis to block |Current (B) |Compressed (B) |Saving (%)&#xA;&gt;&#xA;&gt; |629,474 |2,517,896 |53,352 |98&#xA;&gt; |===&#xA;&gt;&#xA;&gt; ==== Previous block hash&#xA;&gt;&#xA;&gt; The previous block hash will always be the&#xA;&gt; `SHA256(SHA256(&lt;previous_header&gt;))` so is redundant, presuming you have the previous header in the chain.&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&gt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Genesis to block |Current (B) |Compressed (B) |Saving (%)&#xA;&gt;&#xA;&gt; |629,474 |20,143,168 |0 |100&#xA;&gt; |===&#xA;&gt;&#xA;&gt; ==== Time&#xA;&gt;&#xA;&gt; The timestamp (in seconds) is consensus bound, based both on the time in the previous&#xA;&gt; header: `MAX_FUTURE_BLOCK_TIME = 2 * 60 * 60 = 7200`, and being greater than the `MedianTimePast` of the previous 11 blocks. Therefore this can be safely represented as an offset from the previous headers&#39; timestamp using a 2 byte `signed short int`.&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&gt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Genesis to block |Current (B) |Compressed (B) |Saving (%)&#xA;&gt;&#xA;&gt; |629,474 |2,517,896 |1,258,952 |50&#xA;&gt; |===&#xA;&gt;&#xA;&gt; ==== nBits&#xA;&gt;&#xA;&gt; nBits currently changes once every 2016 blocks. It could be entirely calculated by the client from the timestamps of the previous 2015 blocks footnote:[2015 blocks are used in the adjustment calculation due to an off-by-one error: https://bitcointalk.org/index.php?topic=43692.msg521772#msg521772&#34;].&#xA;&gt;&#xA;&gt; To simplify &#39;light&#39; client implementations which would otherwise require consensus-valid calculation of the adjustments, we propose to transmit this according to the &lt;&lt;Bitfield&gt;&gt; specification above.&#xA;&gt;&#xA;&gt; To block 629,474 there have been 298 nBits adjustments (vs an expected 311 -- there was none before block 32,256).&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&gt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Genesis to block |Current (B) |Compressed (B) |Saving (%)&#xA;&gt;&#xA;&gt; |629,474 |2,517,896 |1,196 |99.6&#xA;&gt; |===&#xA;&gt;&#xA;&gt; ==== txn_count&#xA;&gt;&#xA;&gt; txn_count is included to make parsing of these messages compatible with parsing of `block` messages footnote:[https://bitcoin.stackexchange.com/questions/2104/why-is-the-block-header-txn-count-field-always-zero]. Therefore this field and its associated byte can be removed for transmission of compact headers.&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&gt;,&gt;,&gt;&#34;]&#xA;&gt; |===&#xA;&gt; |Genesis to block |Current (B) |Compressed (B) |Saving (%)&#xA;&gt;&#xA;&gt; |629,474 |629,474 |0 |100&#xA;&gt; |===&#xA;&gt;&#xA;&gt; === Service Bit&#xA;&gt;&#xA;&gt; A new service bit would be required so that the nodes can advertise their ability to supply compact headers.&#xA;&gt;&#xA;&gt; === P2P Messages&#xA;&gt;&#xA;&gt; Three new messages would be used by nodes that enable compact block header support, two query messages: `getheaders2` and `sendheaders2` and one response: `headers2`.&#xA;&gt;&#xA;&gt; ==== `getheaders2` -- Requesting compact headers&#xA;&gt;&#xA;&gt; The new p2p message required to request compact block headers would require the same fields as the current `getheaders` message:&#xA;&gt;&#xA;&gt; [cols=&#34;&gt;,&lt;,&lt;,&lt;&#34;]&#xA;&gt; |===&#xA;&gt; |Field Size |Description |Data type |Comments&#xA;&gt;&#xA;&gt; |4 |version |uint32_t |the protocol version&#xA;&gt; |1+ |hash count |var_int |number of block locator hash entries&#xA;&gt; |32+ |block locator hashes |char[32] |block locator object; newest back to genesis block (dense to start, but then sparse)&#xA;&gt; |32 |hash_stop |char[32] |hash of the last desired block header; set to zero to get as many blocks as possible (2000)&#xA;&gt; |===&#xA;&gt;&#xA;&gt; ==== `sendheaders2` -- Request compact header announcements&#xA;&gt;&#xA;&gt; Since https://github.com/bitcoin/bips/blob/master/bip-0130.mediawiki[BIP-130], nodes have been able to request to receive new headers directly in `headers` messages, rather than via an `inv` of the new block hash and subsequent `getheader` request and `headers` response (followed by a final `getdata` to get the tip block itself, if desired). This is requested by transmitting an empty `sendheaders` message after the version handshake is complete.]&#xA;&gt;&#xA;&gt; Upon receipt of this message, the node is permitted, but not required, to preemptively announce new headers with the `headers2` message (instead of `inv`). Preemptive header announcement is supported by the protocol version ≥ 70012 | Bitcoin Core version ≥ 0.12.0.&#xA;&gt;&#xA;&gt; For the motivational use-case it makes sense to also update this mechanism to support sending header updates using compact headers using a new message.&#xA;&gt;&#xA;&gt; ==== `headers2` -- Receiving compact headers&#xA;&gt;&#xA;&gt; A `headers2` message is returned in response to `getheaders2` or at new header announcement following a `sendheaders2` request. It contains both `length` and `headers` fields. The `headers` field contains a variable length vector of `block_header2`:&#xA;&gt;&#xA;&gt; |===&#xA;&gt; |Field Size |Description |Data type |Comments&#xA;&gt;&#xA;&gt; |1+ |length |var_int |Length of `headers`&#xA;&gt; |39-81x? |headers |block_header2[] |Compressed block headers in &lt;&lt;block_header2 data type&gt;&gt; format&#xA;&gt; |===&#xA;&gt;&#xA;&gt; === Implementation&#xA;&gt;&#xA;&gt; -   The first header in the first `block_header2[]` vector to a newly-connected client MUST contain the full nBits`,`timestamp`,`version`and`prev_block_hash`fields, along with a correctly populated`bitfield` byte.&#xA;&gt;&#xA;&gt; -   Subsequent headers in a contiguous vector SHOULD follow the compressed &lt;&lt;block_header2 data type&gt;&gt; format.&#xA;&gt;&#xA;&gt; -   Subsequent compressed headers supplied to an already-connected client (requesting compressed headers), SHOULD follow the compressed &lt;&lt;block_header2 data type&gt;&gt; format.&#xA;&gt;&#xA;&gt;&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev</html></oembed>