Repository navigation
feat(protocol): rotate raiko2 artifacts to v0.9.0-rc1 (Proposal0026) - #22176
davidtaikocha merged 2 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0fae8c7424
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| error Risc0ImageIdNotSet(); | ||
| error Risc0ImageIdNotRotated(); | ||
| error SP1ProgramVKeyNotSet(); | ||
| error SP1ProgramVKeyNotRotated(); | ||
| error SgxMrEnclaveNotSet(); |
There was a problem hiding this comment.
Move custom errors to the end of the implementation
Place these newly added custom errors in the implementation's final custom-error section rather than before the functions. The protocol's Solidity organization rule explicitly requires implementation errors at the end, so leaving this batch here makes this proposal diverge from the required structure.
AGENTS.md reference: packages/protocol/AGENTS.md:L41-L45
Useful? React with 👍 / 👎.
| }); | ||
| } | ||
|
|
||
| function _checkRisc0Constants() private pure { |
There was a problem hiding this comment.
Complete NatSpec for new helpers and interface methods
Add the required @dev NatSpec to the three new private validation helpers, and complete the @dev documentation on the two newly introduced interface methods. Repository guidance requires NatSpec for every Solidity function, with private helpers using @dev and interfaces carrying full documentation; the current additions leave the validation and governance-call ABI under-documented.
AGENTS.md reference: AGENTS.md:L103-L107
Useful? React with 👍 / 👎.
🐋 DeepSeek Code Review🟡 WarningsDuplicated SGX constants without a shared source Checks only test old != new per role/lane Fork test does not assert SGX interfaces duplicated in script/tests 🔵 Suggestions
🟢 What Looks Good
Automatically triggered on PR update • model: |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted filessee 1 file with indirect coverage changes Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
1d155df
into
claude/proposal0024-basefee-sharing-100


Summary
This PR is intentionally stacked on #22127 so the raiko2 v0.9.0-rc1 verifier rotation can be reviewed separately from the existing Proposal0026 basefee-sharing change.
It extends Proposal0026 from 1 to 21 atomic L1 actions:
The proposal does not touch the already-disabled v0.6 values, MRSIGNER trust, SGX attribute policies, or register replacement SGX instances. New v0.9.0-rc1 SGX instances must be registered separately after execution and are expected to receive ID 3.
Source artifacts
guest-digests-summary.jsontee-attestation-manifest-v0.9.0-rc1.jsonRelease asset SHA-256 metadata and every embedded identifier were independently cross-checked. The generated Proposal0026 calldata is reproducible byte-for-byte.
Validation
FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026Test -vv— 6/6 passedL1_FORK_URL=<archive mainnet RPC> FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026ForkTest -vvat block 26,075,649 — 2/2 passedFOUNDRY_PROFILE=layer1 forge build— passedforge fmt --checkfor all changed Solidity files — passedpnpm solhint ...for all changed Solidity files — passedP=0026 pnpm proposal— regenerated the exact committed action filegit diff --check— passedThe fork tests verify all 21 actions, live preconditions, resulting verifier state, Inbox invariants, and atomic dry-run rollback. An independent adversarial review found no material issues.
The v0.9.0-rc1 SP1 runtime was also exercised on Hoodi with two proposal proofs (79948 and 79949) and one aggregate proof; all completed successfully.
Operational boundary
This PR does not deploy contracts, execute Proposal0026, register SGX instances, or perform any other on-chain action. A public-RPC
proposal:dryrun:l1was not run; the historical mainnet fork covers controller execution and rollback locally.Note
High Risk
The batch changes L1 proof and TEE trust roots and removes active SGX instance 2, so a mistaken identifier or ordering could halt proving until operators register v0.9.0-rc1 SGX instances.
Overview
Proposal0026 grows from a single inbox
upgradeToto 21 atomic L1 actions: action 0 is unchanged (raisebasefeeSharingPctgto 100); actions 1–20 rotate mainnet proving from raiko2 v0.8.0-rc1 to v0.9.0-rc1.The PR adds v0.9.0-rc1 RISC0 image IDs and SP1 program vkeys in
LibRisc0Constants/LibSP1Constants, wiresProposal0026.s.solto disable the v0.8.0-rc1 trust entries and enable the new ones on the RISC0 and SP1 verifiers, flip three SGX MRENCLAVE allowlists on the geth/reth attesters, anddeleteInstances([2])on both SGX verifiers (new SGX instance registration stays out of band). Committed DAO calldata inProposal0026.action.mdand the proposal doc are updated accordingly.Unit tests now assert all 21 encoded actions; the mainnet fork rehearsal (block 26,075,649) executes the full batch and checks verifier rotation plus inbox invariants, with dry-run rollback coverage for the rotation leg.
Reviewed by Cursor Bugbot for commit 0fae8c7. Bugbot is set up for automated code reviews on this repo. Configure here.