Skip to content

chore: sync the foundation patch queue - #268

Merged
spalladino merged 10 commits into
mainfrom
spl/sync-foundation-patches
Sep 18, 2026
Merged

spalladino merged 10 commits into
mainfrom
spl/sync-foundation-patches

Conversation

@spalladino

@spalladino spalladino commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Drains the foundation's labs-patches queue from aztec-packages next (labs gitlink 703af8fbdc184f229944b807b51d463e3d630dc2), one commit per patch under the original author, plus the toolchain pin bump the series needs.

Rebased on 07ae594689. An earlier revision of this PR carried a one-line archiver fix, because main did not typecheck at the time: 3c101d08d5 (#264) made inboxPrefixRef required on DataStoreUpdater.addProposedBlock while bfc6b2c1e8 (in #243) added a single-argument call site. #267 has since landed the identical fix on main, so the commit dropped out of the rebase as empty and nothing outside the patch queue remains here.

Patches applied

  • 0009 feat(world-state)!: seed protocol contract registration nullifiers at genesis
  • 0010 feat(world-state): expose the canonical genesis measurement
  • 0016 test: refresh compile_failure snapshots for the rc.2 associated-item diagnostic
  • 0017 feat(stdlib)!: size the fee model's L1 gas constants for Glamsterdam
  • 0017 feat: support attester-signed provider exits
  • 0018 test: check provider entry points on the rollup ABI
  • 0018 test: derive stale fee snapshot from padding ceiling
  • 0019 refactor: name attester-initiated withdrawals consistently
  • 0020 feat: add batched attester exit CLI

Patches dropped as already landed

0004, 0005 and 0008 reverse-applied cleanly against main, so their content is already here verbatim.

0001, 0002, 0003, 0006 and 0007 conflicted only because main carries them in a superseding form. Each was audited hunk by hunk against current source before being dropped, and each resolution left an empty index — nothing from the patch remained unaccounted for:

  • 0001 fix: link epoch proof library when deploying rollup — main has the EpochProofExtLib import and libraries entry, and additionally validates library bytecode through asBytecode() with its own tests.
  • 0002 feat: submit compact fees for proven checkpoints — main has provenPrefixLength threaded through validateEpochProofSubmission and the provenCheckpointFees encoding, and additionally short-circuits on getHasSubmittedProof and takes a kind: 'full' | 'partial' argument.
  • 0003 feat: introduce a protocol fee margin (AZIP-23) — main has protocolFeeMarginBps end to end; it also refactored FeePredictor to computeState(blockNumber) so the margin is read at the pinned snapshot block, and moved the state-caching tests to fee_provider.test.ts.
  • 0006 feat(ethereum): wrap inbox endpoint resolution and checkpoint preflight — main has the wrapping, plus messageSentSearchWindow with MESSAGE_SENT_SEARCH_WINDOW_BLOCKS and a { stateOverride } options object on getManaMinFeeAt.
  • 0007 fix(ethereum): drop the dead ignoreSignatures header validation flag — main already dropped the flag and moved the preflight to the typed CheckpointPreflightArgs object.

No patch was disabled, and none re-pins the standard contracts — noir-projects/noir-contracts/pinned-standard-contracts.tar.gz and standard_addresses.nr are untouched, and the noir build produced no bytecode drift.

Conflicts resolved

Every conflict in this sync was of one kind: the patch's change is already on main in a form main has since extended, so the resolution kept main's side in full and the patch contributed nothing. One line each:

  • 0001 / yarn-project/ethereum/src/l1_artifacts.ts — kept main's asBytecode('EpochProofExtLib', …) over the patch's raw as Hex cast; the validation is strictly stronger.
  • 0001 / yarn-project/ethereum/src/l1_artifacts.test.ts — kept main's file, which is the patch's test plus the asBytecode suite.
  • 0002 / yarn-project/prover-node/src/prover-node-publisher.ts — kept main's getHasSubmittedProof guard and kind destructuring; the patch side was the same code without them.
  • 0002 / yarn-project/prover-node/src/prover-node-publisher.test.ts — kept main's already-submitted test; the compact-header tests the patch adds were already common to both sides.
  • 0003 / yarn-project/ethereum/src/contracts/rollup.ts — kept main's getProtocolFeeMargin(options) with checkBlockTag, over the patch's argument-less read.
  • 0003 / yarn-project/sequencer-client/src/global_variable_builder/fee_predictor.ts — kept main's getProtocolFeeMargin(opts) so the margin is pinned to the snapshot block.
  • 0003 / yarn-project/sequencer-client/src/global_variable_builder/fee_predictor.test.ts — kept main's predictMinFees helper and its pinned-snapshot-block test; the patch's refreshState/getState caching tests describe an API that no longer exists on FeePredictor, having moved to fee_provider.ts.
  • 0003 / yarn-project/aztec-node/src/aztec-node/node_public_calls_simulator.test.ts — kept main's deletion of the unused makeFeeHeader/makeProposedCheckpointData/makeInvalidStatus helpers; the patch only renamed congestionCost to protocolFee inside them, and that rename is already reflected everywhere the field is still used.
  • 0006 / yarn-project/ethereum/src/contracts/inbox.ts — kept main's fetchLogsBisectingRange import alongside L1EventLog.
  • 0006 / yarn-project/ethereum/src/contracts/inbox.test.ts — kept main's file, which adds the messageSentSearchWindow suite the patch does not have.
  • 0006 / yarn-project/ethereum/src/contracts/rollup.test.ts — kept main's { stateOverride: stateOverrides } options-object call over the patch's positional argument.
  • 0007 / yarn-project/sequencer-client/src/publisher/sequencer-publisher.ts — kept main's typed CheckpointPreflightArgs object, which already omits ignoreSignatures and additionally carries expectedTotal and expectedParentCheckpointNumber.

No three-way base blobs had to be fetched from a fork: the three preimage blobs the series names that this repo lacks are intermediate postimages produced by earlier patches in the same chain, which the sequential replay reconstructs.

Pin bump

6.0.0-nightly.20260916 to 6.0.0-nightly.20260918.a, with NOIR_VERSION moving 1.0.0-rc.1 to 1.0.0-rc.2 — the noir release that nightly's noir/noir-repo submodule (0ecc97a242ed37c0d1567e25747ed8d4c59cae49) points at. The bump is required rather than opportunistic: patch 0016 refreshes the compile_failure snapshots for the rc.2 associated-item diagnostic, so the series does not compile against rc.1. Release completeness was checked before pinning — all 23 pinned @aztec-foundation/* resolutions and all six per-platform bb tarballs are published at that version.

set-pins rewrote the pins in labs-aztec-toolchain/bootstrap.sh, yarn-project/package.json, docs/package.json, noir-projects/aztec-nr/aztec/Nargo.toml, docs/examples/contracts/recursive_verification_contract/Nargo.toml and docs/examples/ts/recursive_verification/config.yaml. Both lockfiles were refreshed with a plain yarn, and every changed entry in them is an @aztec-foundation/* resolution.

After this merges

These patches leave the foundation's series on their own. Once this lands and the foundation bumps its labs pin past these commits, they drop out of the next labs-patches export — nothing needs deleting on the aztec-packages side.

Verification

Compile checks only; the suite is CI's job and starts when this leaves draft.

  • ./labs-aztec-toolchain/bootstrap.sh — provisioned bb and bb-avm 6.0.0-nightly.20260918.a and nargo 1.0.0-rc.2, drift check clean
  • noir-projects/bootstrap.sh — all contracts compiled, no tracked bytecode drift
  • yarn-project/bootstrap.sh — code generation plus tsgo -b, format --check and the dynamic-load dependency check all clean

@spalladino spalladino added ci-no-fail-fast Do not cancel remaining jobs on first failure ci-full Run the extended CI labels Sep 18, 2026
@socket-security

socket-security Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​aztec-foundation/​noir-types@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a81 +21006697 +1100
Updatednpm/​@​aztec-foundation/​noir-noir_js@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a77 +11006897 +1100
Updatednpm/​@​aztec-foundation/​l1-artifacts@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a84 -210074 -596 +170
Updatednpm/​@​aztec-foundation/​noir-noir_codegen@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a80 +11007197 +1100
Updatednpm/​@​aztec-foundation/​noir-noirc_abi@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a82 +210071 +197 +1100
Updatednpm/​@​aztec-foundation/​ipc-runtime@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a82 +11007296 +1100
Updatednpm/​@​aztec-foundation/​mock-protocol-circuits-artifacts@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a81 +11007696 +1100
Updatednpm/​@​aztec-foundation/​noir-acvm_js@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a82 +11007796 +1100
Updatednpm/​@​aztec-foundation/​cdb@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a80 +11007796 +1100
Updatednpm/​@​aztec-foundation/​bb-avm-sim@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a79 +11007796 +1100
Updatednpm/​@​aztec-foundation/​constants-codegen@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a77 +11008496 +1100
Updatednpm/​@​aztec-foundation/​protocol-contracts-artifacts@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a82 +11007996 +1100
Updatednpm/​@​aztec-foundation/​protocol-circuits-artifacts@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a81 -410083 +196 +1100
Updatednpm/​@​aztec-foundation/​wsdb@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a82 +11008196 +1100
Updatednpm/​@​aztec-foundation/​bb.js@​6.0.0-nightly.20260916 ⏵ 6.0.0-nightly.20260918.a86 +11009896 +1100

View full report

@socket-security

socket-security Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@spalladino
spalladino marked this pull request as ready for review September 18, 2026 20:53
@spalladino
spalladino enabled auto-merge (squash) September 18, 2026 20:55
@greptile-apps

greptile-apps Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

This PR is not safe to merge until existing mainnet and testnet nodes can select their historical genesis, and the explicit same-package duplication requirement is satisfied.

Fix All in CodexFindings

  1. P1 Historical genesis becomes unreachable ▶
  2. P2 Historical helper is duplicated ▶
Summary

This PR synchronizes the foundation patch queue, updates the pinned BB/Noir toolchain, seeds protocol-contract registration nullifiers into new genesis state, adds attester-initiated exit wrappers and CLI commands, and updates fee constants and affected tests.

  • The canonical genesis measurement and registration-nullifier baseline are now exposed through protocol-contract and world-state packages.
  • Rollup integration gains direct, signed, and batched attester-exit operations.
  • BB packages move to 6.0.0-nightly.20260918.a and Noir moves to 1.0.0-rc.2.
  • Existing mainnet and testnet startup need a historical-genesis selection path before this can merge.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  Config[Node genesis configuration] --> G[getGenesisValues]
  G --> N[Always add protocol registration nullifiers]
  N --> NewRoot[New canonical genesis root]
  Mainnet[Existing mainnet root<br/>empty genesis nullifier tree] --> Compare[Startup compatibility check]
  Testnet[Existing testnet root<br/>empty genesis nullifier tree] --> Compare
  NewRoot --> Compare
  Compare -->|Mismatch| Standby[Node remains in standby / startup rejects]
  Config -. required fix .-> Select{Select genesis generation}
  Select -->|Existing network| Historical[Historical empty-nullifier genesis]
  Select -->|New deployment| Canonical[Canonical seeded genesis]
Loading

Reviews (1) · Last reviewed commit: "fix(archiver): pass the Inbox prefix ref..."

Comment on lines +81 to +83
const prefilledNullifiers = [...DEFAULT_GENESIS_DATA.prefilledNullifiers, ...additionalNullifiers].sort((a, b) =>
a.toBigInt() < b.toBigInt() ? -1 : 1,
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Historical genesis becomes unreachable

Existing mainnet and testnet were created with empty genesis nullifier trees, but node startup calls getGenesisValues, which now always adds the protocol-contract nullifiers. This produces a root that cannot match either deployed rollup, so upgraded nodes will remain in standby and the later compatibility check would reject them. Preserve a way for network configuration to select the historical genesis instead of applying the new baseline to every network.

Knowledge Base Used:

Fix in Codex Fix in Claude Code

Comment on lines +38 to +55
async function historicalGenesisArchiveRoot(fundedAccounts: AztecAddress[], initialAccountFeeJuice: Fr) {
const prefilledPublicData = await Promise.all(
fundedAccounts.map(
async address => new PublicDataTreeLeaf(await computeFeePayerBalanceLeafSlot(address), initialAccountFeeJuice),
),
);
prefilledPublicData.sort((a, b) => (b.slot.lt(a.slot) ? 1 : -1));

const ws = await NativeWorldStateService.ephemeral({
prefilledPublicData,
prefilledNullifiers: [],
genesisTimestamp: 0n,
});
try {
return new Fr((await ws.getCommitted().getTreeInfo(MerkleTreeId.ARCHIVE)).root);
} finally {
await ws.close();
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Historical helper is duplicated

The new historicalGenesisArchiveRoot implementation is repeated verbatim in the mainnet and testnet compatibility suites. The repository requires duplicated logic within the same package to be moved to a shared free function in a dedicated helper file. This requirement must be satisfied before merging, and sharing the helper will prevent the two historical-root calculations from drifting independently.

Context Used: AGENTS.md (source)

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Codex Fix in Claude Code

@spalladino
spalladino force-pushed the spl/sync-foundation-patches branch from b521bbf to e4cc22f Compare September 18, 2026 21:35
spalladino and others added 10 commits September 18, 2026 19:14
… genesis

Generate the siloed class-registration and magic-instance nullifiers for every
bundled protocol contract and seed them into the genesis nullifier tree by
default (DEFAULT_GENESIS_DATA in @aztec-labs/protocol-contracts), so that an
on-chain re-publish of a bundled protocol class is rejected as a duplicate
nullifier instead of reaching the archiver.

GenesisData.prefilledNullifiers becomes required, so every explicit genesis
literal has to choose between the canonical default and a deliberately empty
tree. getGenesisValues' fifth argument now means *additional* nullifiers on top
of the protocol baseline, and duplicates are rejected rather than discarded.

This moves the genesis nullifier-tree root, block-header hash and archive root,
so it only applies to a network initialized from the new genesis.
`measureCanonicalGenesis` returns the seeded nullifiers, the genesis
nullifier-tree root, the block-header hash and the archive root from one
ephemeral world state, so the foundation's regeneration script and the
`compute-genesis-values` CLI read the same numbers rather than each
deriving their own.

The l2_block genesis test now reads GENESIS_NULLIFIER_TREE_ROOT from the
generated constants instead of repeating the literal, so a regeneration
no longer has to reach into the patch series to update it.
…diagnostic

noir-lang/noir#13666 replaces "Could not resolve 'X' in path" with
"no associated item named \`X\` found for \`T\`" plus a secondary label on
the path segment. Six compile_failure stderr snapshots capture that
diagnostic; the assertions themselves are unchanged.
`L1_GAS_PER_CHECKPOINT_PROPOSED` and `L1_GAS_PER_EPOCH_VERIFIED` are the
TypeScript port of the constants in `FeeLib.sol`, used to predict the minimum
fee per mana a few slots ahead. Follow the L1 change that resizes them for the
Glamsterdam gas schedule (EIP-8037 state gas, EIP-8038 state access repricing):
300k -> 500k and 3.6M -> 4M. A stale port would predict fees that no longer
match what the rollup charges.

Both values are placeholders on the L1 side too: they come from the
`BenchmarkRollupTest` gas report run under `forge --evm-version amsterdam`,
which uses a mock proof verifier and an empty proof, and will be replaced once
the fork is live and the costs can be measured on testnet.
@spalladino
spalladino force-pushed the spl/sync-foundation-patches branch from e4cc22f to 86f1a2b Compare September 18, 2026 22:16
@spalladino
spalladino merged commit a488630 into main Sep 18, 2026
7 checks passed
@spalladino
spalladino deleted the spl/sync-foundation-patches branch September 18, 2026 22:51
spalladino added a commit to AztecProtocol/aztec-packages that referenced this pull request Sep 19, 2026
aztec-node merged the whole foundation patch series in
[aztec-labs-eng/aztec-node#268](aztec-labs-eng/aztec-node#268),
so the pin moves past it and the series drops to empty.

- `labs` gitlink `703af8fbdc` → `a488630bd4` (the sync merge commit on
`main`)
- all 17 `labs-patches/*.patch` files deleted — every one is now
upstream, either applied verbatim or superseded by a form `main` already
carries

Done with `./labs-patches/bootstrap.sh bump a488630bd4`, which stages
the gitlink and re-applies; with no patches left it just checks out the
new base.

## Verification

- `./labs-patches/bootstrap.sh status` — series empty, applied on
`a488630bd4`
- `./labs-patches/bootstrap.sh check` — clean against the new gitlink
- `./labs-patches/bootstrap.sh test` — 14/14 lifecycle checks pass
- spot-checked the drained content in the new base: `EpochProofExtLib`,
`provenCheckpointFees`, `protocolFeeMarginBps`,
`messageSentSearchWindow`, `InboxParity`, the genesis seeding, the
attester-exit CLI and artifacts are all there, and `ignoreSignatures` is
gone as patch `0007` intended

The labs build against this tree is CI's job here; nothing was built
locally.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-full Run the extended CI ci-no-fail-fast Do not cancel remaining jobs on first failure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants