Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
37 commits
Select commit Hold shift + click to select a range
0102df7
feat(protocol): Proposal0024 raises the inbox basefee sharing percent…
davidtaikocha Sep 12, 2026
9deb5b5
chore(protocol): drop the comment on ZK_REQUIRED_VERIFIER
davidtaikocha Sep 12, 2026
4dc19c4
feat(protocol): Proposal0024 points at the deployed MainnetInbox impl…
davidtaikocha Sep 12, 2026
d1d8823
docs(protocol): drop the status block from the Proposal0024 runbook
davidtaikocha Sep 12, 2026
1514d5c
docs(protocol): shorten the Proposal0024 rationale TODO
davidtaikocha Sep 12, 2026
4919198
docs(protocol): drop the Current State section from the Proposal0024 …
davidtaikocha Sep 12, 2026
c399fea
Update protocol generated artifacts
davidtaikocha Sep 12, 2026
fd6b3d3
docs(protocol): point the Proposal0024 preconfer note at the Catalyst…
davidtaikocha Sep 12, 2026
617802a
docs(protocol): keep the Proposal0024 preconfer note free of PR refer…
davidtaikocha Sep 12, 2026
08aedfc
fix(protocol): keep the Proposal0024 fork rehearsal within the via-IR…
davidtaikocha Sep 12, 2026
c4bde77
Apply suggestion from @dantaik
dantaik Sep 16, 2026
993c55d
Update packages/protocol/script/layer1/mainnet/DeployInboxUpgradeL1.s…
dantaik Sep 16, 2026
a691e7d
docs(protocol): write the Proposal0024 rationale
claude Sep 16, 2026
bdc9206
feat(protocol): raise the devnet inbox basefee sharing percentage to …
claude Sep 16, 2026
24dbb79
fix(protocol): finish the ZKEVM_VERIFIER rename
claude Sep 16, 2026
9e580cc
revert(protocol): keep the verifier constant named ZK_REQUIRED_VERIFIER
claude Sep 16, 2026
e319834
fix(protocol): pin the live basefee sharing percentage in DeployInbox…
claude Sep 16, 2026
a1a7bda
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
dantaik Sep 16, 2026
8e6942d
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
davidtaikocha Sep 21, 2026
2447a95
refactor(protocol): renumber Proposal0023/0024 to match the DAO propo…
dantaik Sep 21, 2026
91b7711
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
dantaik Sep 21, 2026
8bd58ad
refactor(protocol): renumber Proposal0023 to match the DAO proposal ID
dantaik Sep 21, 2026
9e32a29
Revert "refactor(protocol): renumber Proposal0023/0024 to match the D…
dantaik Sep 21, 2026
36b8a96
Merge branch 'refactor/proposal0023-to-0024' into claude/proposal0024…
dantaik Sep 21, 2026
44e45e0
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
dantaik Sep 21, 2026
492d140
refactor(protocol): renumber Proposal0025 to Proposal0026
claude Sep 22, 2026
dee6446
Merge origin/main into Proposal0026 branch
davidtaikocha Sep 24, 2026
efe2619
docs(protocol): pin Proposal0026 bytecode verification to deployment
davidtaikocha Sep 24, 2026
8070ec3
test(protocol): pin Proposal0026 fork rehearsal block
Sep 24, 2026
dd70fb0
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
davidtaikocha Sep 24, 2026
1d155df
feat(protocol): rotate raiko2 artifacts to v0.9.0-rc1 (Proposal0026) …
smtmfft Sep 28, 2026
d4bec46
refactor(protocol): move the Proposal0026 SGX MRENCLAVEs into LibSGXC…
davidtaikocha Sep 29, 2026
1e6a874
docs(protocol): correct the MainnetInbox layout entry count in Propos…
claude Sep 29, 2026
0f9e64b
Merge branch 'main' into claude/proposal0024-basefee-sharing-100
dantaik Sep 29, 2026
6b1adef
feat(protocol): rotate Proposal0026 artifacts to raiko2 v0.9.0 (#22178)
smtmfft Sep 30, 2026
a3d4cdc
chore(protocol): drop the unused raiko2 v0.9.0-rc1 constants
davidtaikocha Sep 30, 2026
4559c11
docs(protocol): add Proposal0026 artifact verification (#22182)
smtmfft Sep 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ contract DevnetInbox is Inbox {
permissionlessProvingDelay: 5 days,
maxProofSubmissionDelay: 3 minutes,
ringBufferSize: _RING_BUFFER_SIZE,
basefeeSharingPctg: 75,
basefeeSharingPctg: 100,
forcedInclusionDelay: 0 seconds, // Devnet: immediate forced inclusion for faster testing
forcedInclusionFeeInGwei: 1_000_000,
forcedInclusionFeeDoubleThreshold: 50,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ library LibL1Addrs {
address public constant BRIDGED_ERC1155 = 0x35001aB6f53CF9fE583653Ca3F56cae75E8C385e;

// Proof system verifiers and attesters
address public constant ZK_REQUIRED_VERIFIER = 0x7284aaC05555Ae6559bdAd8B4221eC9584254Eec;
address public constant RISC0_RETH_VERIFIER = 0x059dAF31F571da48Ab4e74Ae12F64f907681Cd8b;
// Deployed by Proposal0017 (hack recovery); replaces 0x96337327648dcFA22b014009cf10A2D5E2F305f6
address public constant SP1_RETH_VERIFIER = 0x73A0Db393ef87ce781ac7957bE10D6628432100F;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@ contract MainnetInbox is Inbox {
permissionlessProvingDelay: 5 days,
maxProofSubmissionDelay: 3 minutes, // We want this to be lower than the expected cadence
ringBufferSize: _RING_BUFFER_SIZE,
basefeeSharingPctg: 75,
// Raised from 75 by Proposal0026: the whole basefee goes to the block's coinbase.
basefeeSharingPctg: 100,
// 1.5 epochs. Makes sure the proposer is not surprised by a forced inclusion landing on their window.
forcedInclusionDelay: 576 seconds,
forcedInclusionFeeInGwei: 1_000_000, // 0.001 ETH base fee.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,9 @@ library LibRisc0Constants {
0xd6ab71c22201c23ef512b706f2e2d720f6da1b559fb76834aa9d4e35276f6e10;
bytes32 internal constant V0_8_0_RC1_AGGREGATION_IMAGE_ID =
0xdd9b8abff96c409ae2418edfb51d893ea2bd10f4873a0226f17a6998c1afc1b7;

bytes32 internal constant V0_9_0_PROPOSAL_IMAGE_ID =
0x88712dad7dc78126ee7bb592282d3102569c706f1b9db80580a582e5ffd1dfb0;
bytes32 internal constant V0_9_0_AGGREGATION_IMAGE_ID =
0x04480b22e244d60165f3d0898bc61ea084d9c76221464a8a3c3343c74889040a;
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.24;

/// @title LibSGXConstants
/// @custom:security-contact security@taiko.xyz
library LibSGXConstants {
bytes32 internal constant V0_8_0_RC1_SGXGETH_MR_ENCLAVE =
0x5f7da556f3b75dcc71465030e1b7274e82df9e9120c0b3eaf5bb76246a514005;
bytes32 internal constant V0_8_0_RC1_SGXRETH_NON_EDMM_MR_ENCLAVE =
0x3564b6a30089fcb3e2f69c19b22d23f84ce148387cd7a15f5c1df165b2ae5847;
bytes32 internal constant V0_8_0_RC1_SGXRETH_EDMM_MR_ENCLAVE =
0xae2c7b92b2a71238226cb624ecd1171b66bf943cc372314affca0e6748ccecdf;

bytes32 internal constant V0_9_0_SGXGETH_MR_ENCLAVE =
0x8c23c79045b9b6bb827eab208e0fe58d7446a57a55f3dfc825c90e904953105b;
bytes32 internal constant V0_9_0_SGXRETH_NON_EDMM_MR_ENCLAVE =
0xfeabd725eb5bb621b5c6a5071d1702bcbe06a643b42a0db8f381d5bc07dd81bf;
bytes32 internal constant V0_9_0_SGXRETH_EDMM_MR_ENCLAVE =
0x6f3c8c55ec62fe48b83e57463e8717aa9f8594418203c9520f0f80e6f4fc4d87;
}
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,13 @@ library LibSP1Constants {
0x0051ac1d9e8cfd4196e37f9cfefd08e9b0f7ce653bad4634cd1ee84b71ca3be6;
bytes32 internal constant V0_8_0_RC1_AGGREGATION_PROGRAM_VKEY_HASH_BYTES =
0x28d60ecf233f50655c6ff39f6fd08e9b07be73296eb518d31a3dd09671ca3be6;

bytes32 internal constant V0_9_0_PROPOSAL_PROGRAM_VKEY_BN254 =
0x0012b97234e59f2319d44202c7b093fed9c9a51b2068e38d26625c139d668c97;
bytes32 internal constant V0_9_0_PROPOSAL_PROGRAM_VKEY_HASH_BYTES =
0x095cb91a3967c8c63a8840587b093fed4e4d28d901a38e344cc4b8271d668c97;
bytes32 internal constant V0_9_0_AGGREGATION_PROGRAM_VKEY_BN254 =
0x0017912dfd72308e2e2cd4211b05ed73a97eb7f576816adec2606a37507de51e;
bytes32 internal constant V0_9_0_AGGREGATION_PROGRAM_VKEY_HASH_BYTES =
0x0bc896fe5c8c238b459a8423305ed73a4bf5bfab5a05ab7b04c0d46e507de51e;
}
8 changes: 8 additions & 0 deletions packages/protocol/gas-reports/layer1-contracts.txt
Original file line number Diff line number Diff line change
Expand Up @@ -240,6 +240,14 @@ Proposal0025Test:test_buildL1Actions_UsesDeployedImplementations() (gas: 42126)
Proposal0025Test:test_buildL2Actions_RequiresProposal0024ThenUpgradesWithTheBridgeLast() (gas: 55524)
Proposal0025Test:test_buildL2Actions_RevertsWhileAnAddressIsMissing() (gas: 44264)
Proposal0025Test:test_buildL2Actions_UsesDeployedImplementations() (gas: 63219)
Proposal0026ForkTest:test_l1_dryrunSucceeds() (gas: 0)
Proposal0026ForkTest:test_l1_upgradesAgainstLiveState() (gas: 0)
Proposal0026Test:test_actionFileMatchesTheBuiltCalldata() (gas: 113803)
Proposal0026Test:test_buildL1Actions_EncodesInboxUpgradeAndVerifierRotation() (gas: 91345)
Proposal0026Test:test_buildL1Actions_RevertsWhileTheImplementationIsMissing() (gas: 10675)
Proposal0026Test:test_buildL1Actions_UsesDeployedImplementation() (gas: 55917)
Proposal0026Test:test_buildL2Actions_HasNoL2Leg() (gas: 10322)
Proposal0026Test:test_mainnetInbox_MatchesTheLiveConfigExceptForBasefeeSharing() (gas: 4703403)
ProverWhitelistTest:test_init_setsOwner() (gas: 15531)
ProverWhitelistTest:test_init_startsWithZeroProverCount() (gas: 15386)
ProverWhitelistTest:test_isProverWhitelisted_returnsCorrectCount() (gas: 102391)
Expand Down
108 changes: 108 additions & 0 deletions packages/protocol/script/layer1/mainnet/DeployInboxUpgradeL1.s.sol
Original file line number Diff line number Diff line change
@@ -0,0 +1,108 @@
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.24;

import { Script, console2 } from "forge-std/src/Script.sol";
import { IInbox } from "src/layer1/core/iface/IInbox.sol";
import { LibL1Addrs } from "src/layer1/mainnet/LibL1Addrs.sol";
import { MainnetInbox } from "src/layer1/mainnet/MainnetInbox.sol";

/// @title DeployInboxUpgradeL1
/// @notice Deploys the `MainnetInbox` implementation that Proposal0026 upgrades the mainnet inbox
/// proxy to: the live configuration with `basefeeSharingPctg` raised from 75 to 100.
/// @dev Deploys a new implementation only. It does not upgrade the proxy and does not call any
/// initializer.
///
/// The five constructor arguments reproduce the address immutables the live implementation
/// (`0x5253D4C91e80b880DdB54B78E74082Abe066F6b9`, deployed for Proposal0019) carries, and the
/// script reads them back from the live proxy before broadcasting so a drifted `LibL1Addrs`
/// constant aborts the run instead of baking into the new immutables. The numeric configuration is
/// hardcoded in `MainnetInbox`, so after deploying, the script compares the new implementation's
/// `getConfig()` with the live proxy's and aborts unless the basefee sharing percentage is the
/// only difference.
///
/// Diffing the implementation's dependency tree from the commit the live implementation was built
/// from (`9078278909a43a83fc5bb2664f30b81eb5c967f6`) to `main` leaves `MainnetInbox.sol` and
/// `EssentialContract.sol`: #22058 folded the transient-storage reentry lock `MainnetInbox`
/// already used through `LibFasterReentryLock` into the base contract at the same slot constant.
/// So the only behavioural change this implementation ships is the sharing percentage.
///
/// `MainnetInbox` links `LibForcedInclusion` and `LibInboxSetup` (both have `public` functions),
/// so the broadcast is three creates: the two libraries through CREATE2, then the implementation.
/// Verify all three landed before writing the logged address anywhere.
/// @custom:security-contact security@taiko.xyz
contract DeployInboxUpgradeL1 is Script {
/// @notice The basefee sharing percentage the new implementation must carry.
uint8 public constant NEW_BASEFEE_SHARING_PCTG = 100;

/// @notice The basefee sharing percentage the live proxy must still carry. `_checkConfig`
/// normalises this field away before comparing the new implementation with the live one, so
/// this constant is the only thing pinning what the upgrade moves away from.
uint8 public constant OLD_BASEFEE_SHARING_PCTG = 75;

error AlreadyUpgraded();
error ConfigMismatch();
error LiveProxyMismatch();

/// @notice Deploys the implementation and logs the address Proposal0026 needs.
function run() external {
uint256 privateKey = vm.envUint("PRIVATE_KEY");
require(privateKey != 0, "PRIVATE_KEY not set");

IInbox.Config memory live = IInbox(LibL1Addrs.INBOX).getConfig();
_checkLiveProxy(live);

vm.startBroadcast(privateKey);
MainnetInbox inboxImpl = new MainnetInbox(
LibL1Addrs.ZK_REQUIRED_VERIFIER,
LibL1Addrs.PRECONF_WHITELIST,
LibL1Addrs.PROVER_WHITELIST,
LibL1Addrs.SIGNAL_SERVICE,
LibL1Addrs.TAIKO_TOKEN
);
vm.stopBroadcast();

_checkConfig(inboxImpl.getConfig(), live);

console2.log("MAINNET_INBOX_NEW_IMPL:", address(inboxImpl));
}

/// @dev Aborts unless the live proxy answers the five addresses this script is about to
/// compile into the new implementation — all five are reproduced from `LibL1Addrs`, and the
/// whole point of the upgrade is to keep them — and still shares exactly the old percentage,
/// so the script cannot be re-run to any effect once the proposal has executed.
/// @param _live The live proxy's configuration.
function _checkLiveProxy(IInbox.Config memory _live) private pure {
require(
_live.proofVerifier == LibL1Addrs.ZK_REQUIRED_VERIFIER
&& _live.proposerChecker == LibL1Addrs.PRECONF_WHITELIST
&& _live.proverWhitelist == LibL1Addrs.PROVER_WHITELIST
&& _live.signalService == LibL1Addrs.SIGNAL_SERVICE
&& _live.bondToken == LibL1Addrs.TAIKO_TOKEN,
LiveProxyMismatch()
);
// The re-run case first, so it reports itself rather than as a generic mismatch.
require(_live.basefeeSharingPctg != NEW_BASEFEE_SHARING_PCTG, AlreadyUpgraded());
require(_live.basefeeSharingPctg == OLD_BASEFEE_SHARING_PCTG, LiveProxyMismatch());
}

/// @dev Aborts unless the new implementation's configuration equals the live one in every
/// field but the basefee sharing percentage, which must be the new value. Catches a
/// transposed constructor argument (all five are addresses, so a swapped pair compiles
/// cleanly) and any numeric constant in `MainnetInbox` that drifted from the live value.
/// @param _new The freshly deployed implementation's configuration.
/// @param _live The live proxy's configuration.
function _checkConfig(
IInbox.Config memory _new,
IInbox.Config memory _live
)
private
pure
{
require(_new.basefeeSharingPctg == NEW_BASEFEE_SHARING_PCTG, ConfigMismatch());

// Normalise the one field that is meant to differ, then compare the rest in one go. `_new`
// is the caller's own copy, so overwriting it here is local to this check.
_new.basefeeSharingPctg = _live.basefeeSharingPctg;
require(keccak256(abi.encode(_new)) == keccak256(abi.encode(_live)), ConfigMismatch());
}
}
Loading
Loading