chore: sync the foundation patch queue - #268
Conversation
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
|
| const prefilledNullifiers = [...DEFAULT_GENESIS_DATA.prefilledNullifiers, ...additionalNullifiers].sort((a, b) => | ||
| a.toBigInt() < b.toBigInt() ? -1 : 1, | ||
| ); |
There was a problem hiding this comment.
Historical genesis becomes unreachable
Existing mainnet and testnet were created with empty genesis nullifier trees, but node startup calls getGenesisValues, which now always adds the protocol-contract nullifiers. This produces a root that cannot match either deployed rollup, so upgraded nodes will remain in standby and the later compatibility check would reject them. Preserve a way for network configuration to select the historical genesis instead of applying the new baseline to every network.
Knowledge Base Used:
| async function historicalGenesisArchiveRoot(fundedAccounts: AztecAddress[], initialAccountFeeJuice: Fr) { | ||
| const prefilledPublicData = await Promise.all( | ||
| fundedAccounts.map( | ||
| async address => new PublicDataTreeLeaf(await computeFeePayerBalanceLeafSlot(address), initialAccountFeeJuice), | ||
| ), | ||
| ); | ||
| prefilledPublicData.sort((a, b) => (b.slot.lt(a.slot) ? 1 : -1)); | ||
|
|
||
| const ws = await NativeWorldStateService.ephemeral({ | ||
| prefilledPublicData, | ||
| prefilledNullifiers: [], | ||
| genesisTimestamp: 0n, | ||
| }); | ||
| try { | ||
| return new Fr((await ws.getCommitted().getTreeInfo(MerkleTreeId.ARCHIVE)).root); | ||
| } finally { | ||
| await ws.close(); | ||
| } |
There was a problem hiding this comment.
Historical helper is duplicated
The new historicalGenesisArchiveRoot implementation is repeated verbatim in the mainnet and testnet compatibility suites. The repository requires duplicated logic within the same package to be moved to a shared free function in a dedicated helper file. This requirement must be satisfied before merging, and sharing the helper will prevent the two historical-root calculations from drifting independently.
Context Used: AGENTS.md (source)
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
b521bbf to
e4cc22f
Compare
… genesis Generate the siloed class-registration and magic-instance nullifiers for every bundled protocol contract and seed them into the genesis nullifier tree by default (DEFAULT_GENESIS_DATA in @aztec-labs/protocol-contracts), so that an on-chain re-publish of a bundled protocol class is rejected as a duplicate nullifier instead of reaching the archiver. GenesisData.prefilledNullifiers becomes required, so every explicit genesis literal has to choose between the canonical default and a deliberately empty tree. getGenesisValues' fifth argument now means *additional* nullifiers on top of the protocol baseline, and duplicates are rejected rather than discarded. This moves the genesis nullifier-tree root, block-header hash and archive root, so it only applies to a network initialized from the new genesis.
`measureCanonicalGenesis` returns the seeded nullifiers, the genesis nullifier-tree root, the block-header hash and the archive root from one ephemeral world state, so the foundation's regeneration script and the `compute-genesis-values` CLI read the same numbers rather than each deriving their own. The l2_block genesis test now reads GENESIS_NULLIFIER_TREE_ROOT from the generated constants instead of repeating the literal, so a regeneration no longer has to reach into the patch series to update it.
…diagnostic noir-lang/noir#13666 replaces "Could not resolve 'X' in path" with "no associated item named \`X\` found for \`T\`" plus a secondary label on the path segment. Six compile_failure stderr snapshots capture that diagnostic; the assertions themselves are unchanged.
`L1_GAS_PER_CHECKPOINT_PROPOSED` and `L1_GAS_PER_EPOCH_VERIFIED` are the TypeScript port of the constants in `FeeLib.sol`, used to predict the minimum fee per mana a few slots ahead. Follow the L1 change that resizes them for the Glamsterdam gas schedule (EIP-8037 state gas, EIP-8038 state access repricing): 300k -> 500k and 3.6M -> 4M. A stale port would predict fees that no longer match what the rollup charges. Both values are placeholders on the L1 side too: they come from the `BenchmarkRollupTest` gas report run under `forge --evm-version amsterdam`, which uses a mock proof verifier and an empty proof, and will be replaced once the fork is live and the costs can be measured on testnet.
e4cc22f to
86f1a2b
Compare
aztec-node merged the whole foundation patch series in [aztec-labs-eng/aztec-node#268](aztec-labs-eng/aztec-node#268), so the pin moves past it and the series drops to empty. - `labs` gitlink `703af8fbdc` → `a488630bd4` (the sync merge commit on `main`) - all 17 `labs-patches/*.patch` files deleted — every one is now upstream, either applied verbatim or superseded by a form `main` already carries Done with `./labs-patches/bootstrap.sh bump a488630bd4`, which stages the gitlink and re-applies; with no patches left it just checks out the new base. ## Verification - `./labs-patches/bootstrap.sh status` — series empty, applied on `a488630bd4` - `./labs-patches/bootstrap.sh check` — clean against the new gitlink - `./labs-patches/bootstrap.sh test` — 14/14 lifecycle checks pass - spot-checked the drained content in the new base: `EpochProofExtLib`, `provenCheckpointFees`, `protocolFeeMarginBps`, `messageSentSearchWindow`, `InboxParity`, the genesis seeding, the attester-exit CLI and artifacts are all there, and `ignoreSignatures` is gone as patch `0007` intended The labs build against this tree is CI's job here; nothing was built locally.
Drains the foundation's
labs-patchesqueue from aztec-packagesnext(labs gitlink703af8fbdc184f229944b807b51d463e3d630dc2), one commit per patch under the original author, plus the toolchain pin bump the series needs.Rebased on
07ae594689. An earlier revision of this PR carried a one-line archiver fix, becausemaindid not typecheck at the time:3c101d08d5(#264) madeinboxPrefixRefrequired onDataStoreUpdater.addProposedBlockwhilebfc6b2c1e8(in #243) added a single-argument call site. #267 has since landed the identical fix onmain, so the commit dropped out of the rebase as empty and nothing outside the patch queue remains here.Patches applied
0009feat(world-state)!: seed protocol contract registration nullifiers at genesis0010feat(world-state): expose the canonical genesis measurement0016test: refresh compile_failure snapshots for the rc.2 associated-item diagnostic0017feat(stdlib)!: size the fee model's L1 gas constants for Glamsterdam0017feat: support attester-signed provider exits0018test: check provider entry points on the rollup ABI0018test: derive stale fee snapshot from padding ceiling0019refactor: name attester-initiated withdrawals consistently0020feat: add batched attester exit CLIPatches dropped as already landed
0004,0005and0008reverse-applied cleanly againstmain, so their content is already here verbatim.0001,0002,0003,0006and0007conflicted only becausemaincarries them in a superseding form. Each was audited hunk by hunk against current source before being dropped, and each resolution left an empty index — nothing from the patch remained unaccounted for:0001fix: link epoch proof library when deploying rollup —mainhas theEpochProofExtLibimport andlibrariesentry, and additionally validates library bytecode throughasBytecode()with its own tests.0002feat: submit compact fees for proven checkpoints —mainhasprovenPrefixLengththreaded throughvalidateEpochProofSubmissionand theprovenCheckpointFeesencoding, and additionally short-circuits ongetHasSubmittedProofand takes akind: 'full' | 'partial'argument.0003feat: introduce a protocol fee margin (AZIP-23) —mainhasprotocolFeeMarginBpsend to end; it also refactoredFeePredictortocomputeState(blockNumber)so the margin is read at the pinned snapshot block, and moved the state-caching tests tofee_provider.test.ts.0006feat(ethereum): wrap inbox endpoint resolution and checkpoint preflight —mainhas the wrapping, plusmessageSentSearchWindowwithMESSAGE_SENT_SEARCH_WINDOW_BLOCKSand a{ stateOverride }options object ongetManaMinFeeAt.0007fix(ethereum): drop the dead ignoreSignatures header validation flag —mainalready dropped the flag and moved the preflight to the typedCheckpointPreflightArgsobject.No patch was disabled, and none re-pins the standard contracts —
noir-projects/noir-contracts/pinned-standard-contracts.tar.gzandstandard_addresses.nrare untouched, and the noir build produced no bytecode drift.Conflicts resolved
Every conflict in this sync was of one kind: the patch's change is already on
mainin a formmainhas since extended, so the resolution keptmain's side in full and the patch contributed nothing. One line each:0001/yarn-project/ethereum/src/l1_artifacts.ts— keptmain'sasBytecode('EpochProofExtLib', …)over the patch's rawas Hexcast; the validation is strictly stronger.0001/yarn-project/ethereum/src/l1_artifacts.test.ts— keptmain's file, which is the patch's test plus theasBytecodesuite.0002/yarn-project/prover-node/src/prover-node-publisher.ts— keptmain'sgetHasSubmittedProofguard andkinddestructuring; the patch side was the same code without them.0002/yarn-project/prover-node/src/prover-node-publisher.test.ts— keptmain'salready-submittedtest; the compact-header tests the patch adds were already common to both sides.0003/yarn-project/ethereum/src/contracts/rollup.ts— keptmain'sgetProtocolFeeMargin(options)withcheckBlockTag, over the patch's argument-less read.0003/yarn-project/sequencer-client/src/global_variable_builder/fee_predictor.ts— keptmain'sgetProtocolFeeMargin(opts)so the margin is pinned to the snapshot block.0003/yarn-project/sequencer-client/src/global_variable_builder/fee_predictor.test.ts— keptmain'spredictMinFeeshelper and its pinned-snapshot-block test; the patch'srefreshState/getStatecaching tests describe an API that no longer exists onFeePredictor, having moved tofee_provider.ts.0003/yarn-project/aztec-node/src/aztec-node/node_public_calls_simulator.test.ts— keptmain's deletion of the unusedmakeFeeHeader/makeProposedCheckpointData/makeInvalidStatushelpers; the patch only renamedcongestionCosttoprotocolFeeinside them, and that rename is already reflected everywhere the field is still used.0006/yarn-project/ethereum/src/contracts/inbox.ts— keptmain'sfetchLogsBisectingRangeimport alongsideL1EventLog.0006/yarn-project/ethereum/src/contracts/inbox.test.ts— keptmain's file, which adds themessageSentSearchWindowsuite the patch does not have.0006/yarn-project/ethereum/src/contracts/rollup.test.ts— keptmain's{ stateOverride: stateOverrides }options-object call over the patch's positional argument.0007/yarn-project/sequencer-client/src/publisher/sequencer-publisher.ts— keptmain's typedCheckpointPreflightArgsobject, which already omitsignoreSignaturesand additionally carriesexpectedTotalandexpectedParentCheckpointNumber.No three-way base blobs had to be fetched from a fork: the three preimage blobs the series names that this repo lacks are intermediate postimages produced by earlier patches in the same chain, which the sequential replay reconstructs.
Pin bump
6.0.0-nightly.20260916to6.0.0-nightly.20260918.a, withNOIR_VERSIONmoving1.0.0-rc.1to1.0.0-rc.2— the noir release that nightly'snoir/noir-reposubmodule (0ecc97a242ed37c0d1567e25747ed8d4c59cae49) points at. The bump is required rather than opportunistic: patch0016refreshes thecompile_failuresnapshots for the rc.2 associated-item diagnostic, so the series does not compile against rc.1. Release completeness was checked before pinning — all 23 pinned@aztec-foundation/*resolutions and all six per-platform bb tarballs are published at that version.set-pinsrewrote the pins inlabs-aztec-toolchain/bootstrap.sh,yarn-project/package.json,docs/package.json,noir-projects/aztec-nr/aztec/Nargo.toml,docs/examples/contracts/recursive_verification_contract/Nargo.tomlanddocs/examples/ts/recursive_verification/config.yaml. Both lockfiles were refreshed with a plainyarn, and every changed entry in them is an@aztec-foundation/*resolution.After this merges
These patches leave the foundation's series on their own. Once this lands and the foundation bumps its labs pin past these commits, they drop out of the next
labs-patchesexport — nothing needs deleting on the aztec-packages side.Verification
Compile checks only; the suite is CI's job and starts when this leaves draft.
./labs-aztec-toolchain/bootstrap.sh— provisioned bb and bb-avm6.0.0-nightly.20260918.aand nargo1.0.0-rc.2, drift check cleannoir-projects/bootstrap.sh— all contracts compiled, no tracked bytecode driftyarn-project/bootstrap.sh— code generation plustsgo -b,format --checkand the dynamic-load dependency check all clean