Skip to content

feat(protocol): rotate raiko2 artifacts to v0.9.0-rc1 (Proposal0026) - #22176

Merged
davidtaikocha merged 2 commits into
claude/proposal0024-basefee-sharing-100from
feat/proposal0026-raiko2-v090rc1
Sep 28, 2026
Merged

davidtaikocha merged 2 commits into
claude/proposal0024-basefee-sharing-100from
feat/proposal0026-raiko2-v090rc1

Conversation

@smtmfft

@smtmfft smtmfft commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR is intentionally stacked on #22127 so the raiko2 v0.9.0-rc1 verifier rotation can be reviewed separately from the existing Proposal0026 basefee-sharing change.

It extends Proposal0026 from 1 to 21 atomic L1 actions:

  • preserve the Inbox upgrade as action 0;
  • disable the active raiko2 v0.8.0-rc1 RISC0 IDs, SP1 vkeys, and SGX MRENCLAVEs;
  • enable the corresponding v0.9.0-rc1 values;
  • delete active SGX instance ID 2 from both SGX verifier registries.

The proposal does not touch the already-disabled v0.6 values, MRSIGNER trust, SGX attribute policies, or register replacement SGX instances. New v0.9.0-rc1 SGX instances must be registered separately after execution and are expected to receive ID 3.

Source artifacts

Release asset SHA-256 metadata and every embedded identifier were independently cross-checked. The generated Proposal0026 calldata is reproducible byte-for-byte.

Validation

  • FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026Test -vv — 6/6 passed
  • L1_FORK_URL=<archive mainnet RPC> FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026ForkTest -vv at block 26,075,649 — 2/2 passed
  • FOUNDRY_PROFILE=layer1 forge build — passed
  • focused forge fmt --check for all changed Solidity files — passed
  • focused pnpm solhint ... for all changed Solidity files — passed
  • P=0026 pnpm proposal — regenerated the exact committed action file
  • git diff --check — passed

The fork tests verify all 21 actions, live preconditions, resulting verifier state, Inbox invariants, and atomic dry-run rollback. An independent adversarial review found no material issues.

The v0.9.0-rc1 SP1 runtime was also exercised on Hoodi with two proposal proofs (79948 and 79949) and one aggregate proof; all completed successfully.

Operational boundary

This PR does not deploy contracts, execute Proposal0026, register SGX instances, or perform any other on-chain action. A public-RPC proposal:dryrun:l1 was not run; the historical mainnet fork covers controller execution and rollback locally.


Note

High Risk
The batch changes L1 proof and TEE trust roots and removes active SGX instance 2, so a mistaken identifier or ordering could halt proving until operators register v0.9.0-rc1 SGX instances.

Overview
Proposal0026 grows from a single inbox upgradeTo to 21 atomic L1 actions: action 0 is unchanged (raise basefeeSharingPctg to 100); actions 1–20 rotate mainnet proving from raiko2 v0.8.0-rc1 to v0.9.0-rc1.

The PR adds v0.9.0-rc1 RISC0 image IDs and SP1 program vkeys in LibRisc0Constants / LibSP1Constants, wires Proposal0026.s.sol to disable the v0.8.0-rc1 trust entries and enable the new ones on the RISC0 and SP1 verifiers, flip three SGX MRENCLAVE allowlists on the geth/reth attesters, and deleteInstances([2]) on both SGX verifiers (new SGX instance registration stays out of band). Committed DAO calldata in Proposal0026.action.md and the proposal doc are updated accordingly.

Unit tests now assert all 21 encoded actions; the mainnet fork rehearsal (block 26,075,649) executes the full batch and checks verifier rotation plus inbox invariants, with dry-run rollback coverage for the rotation leg.

Reviewed by Cursor Bugbot for commit 0fae8c7. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0fae8c7424

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +40 to +44
error Risc0ImageIdNotSet();
error Risc0ImageIdNotRotated();
error SP1ProgramVKeyNotSet();
error SP1ProgramVKeyNotRotated();
error SgxMrEnclaveNotSet();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Move custom errors to the end of the implementation

Place these newly added custom errors in the implementation's final custom-error section rather than before the functions. The protocol's Solidity organization rule explicitly requires implementation errors at the end, so leaving this batch here makes this proposal diverge from the required structure.

AGENTS.md reference: packages/protocol/AGENTS.md:L41-L45

Useful? React with 👍 / 👎.

});
}

function _checkRisc0Constants() private pure {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Complete NatSpec for new helpers and interface methods

Add the required @dev NatSpec to the three new private validation helpers, and complete the @dev documentation on the two newly introduced interface methods. Repository guidance requires NatSpec for every Solidity function, with private helpers using @dev and interfaces carrying full documentation; the current additions leave the validation and governance-call ABI under-documented.

AGENTS.md reference: AGENTS.md:L103-L107

Useful? React with 👍 / 👎.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: Cursor Bugbot completed successfully with no findings that need human review. No reviewers were assigned by this automation.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router

@github-actions

Copy link
Copy Markdown
Contributor

🐋 DeepSeek Code Review

🟡 Warnings

Duplicated SGX constants without a shared source
Proposal0026.s.sol, Proposal0026.t.sol, and Proposal0026Fork.t.sol each hardcode the same SGX MRENCLAVE values. This is partly intentional for independent test assertions, but there is no shared LibSgxConstants unlike RISC0/SP1. If a bad MRENCLAVE is copied into all three files, unit and fork tests will still pass. For a rotation this high-risk, the SGX values should be centralized or generated from the release manifest.

Checks only test old != new per role/lane
_checkRisc0Constants, _checkSP1Constants, and _checkSgxConstants verify old vs new values, but do not check proposal vs aggregation, geth vs reth, EDMM vs non-EDMM, etc. A copy-paste error swapping aggregation with proposal or reth with geth would pass these checks and still produce a plausible-looking batch that disables/enables the wrong trust root.

Fork test does not assert nextInstanceId() == 3
The docs and operational plan depend on the next SGX registration receiving instance ID 3. The fork test checks that instance 2 is deleted but never asserts nextInstanceId() before or after. If the verifier implementation changed behavior (or the fork state shifts), the expected ID could be wrong without failing CI.

SGX interfaces duplicated in script/tests
IProposal0026Attestation / IProposal0026SgxVerifier etc. are redefined in both the script and tests rather than using the actual source interfaces. Local ABI drift could otherwise be caught; fork tests reduce this risk, but importing the real interfaces is safer for a governance proposal.

🔵 Suggestions

  • Add explicit fork assertions that already-disabled v0.6 trust entries, MRSIGNER trust, and SGX attribute policies remain unchanged, since the PR states they are untouched.
  • Add tests for _check* reverting on zero or non-rotated constants; these checks currently have no unit coverage.
  • Consider centralizing SGX MRENCLAVE constants into LibSgxConstants.sol, matching the pattern used for RISC0/SP1.
  • Add NatSpec provenance comments to the new constants/interfaces (release URL, manifest file, digest).

🟢 What Looks Good

  • All 21 actions are covered by unit tests and a historical-mainnet fork test, including atomic dry-run rollback.
  • Proposal0026.action.md is pinned and regenerated byte-for-byte; action count and calldata match.
  • Disable/enable ordering is correct: old trust roots are removed and new ones enabled without a partial-state risk.
  • Fork assertions verify the pre/post rotation state of RISC0, SP1, SGX MRENCLAVEs, and SGX instance deletion.
  • Target addresses, selectors, and embedded identifiers in the committed calldata line up with the Solidity constants.

Automatically triggered on PR update • model: deepseek-v4-pro

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 41.56%. Comparing base (dd70fb0) to head (d332dd6).

Additional details and impacted files

see 1 file with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update dd70fb0...d332dd6. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@davidtaikocha
davidtaikocha merged commit 1d155df into claude/proposal0024-basefee-sharing-100 Sep 28, 2026
14 of 18 checks passed
@davidtaikocha
davidtaikocha deleted the feat/proposal0026-raiko2-v090rc1 branch September 28, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants