Skip to content

feat(protocol): rotate Proposal0026 artifacts to raiko2 v0.9.0 - #22178

Merged
davidtaikocha merged 1 commit into
claude/proposal0024-basefee-sharing-100from
feat/proposal0026-raiko2-v090
Sep 30, 2026
Merged

davidtaikocha merged 1 commit into
claude/proposal0024-basefee-sharing-100from
feat/proposal0026-raiko2-v090

Conversation

@smtmfft

@smtmfft smtmfft commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • retarget Proposal0026's proving identifiers from raiko2 v0.9.0-rc1 to final v0.9.0
  • keep the existing 21-action batch and Inbox upgrade unchanged
  • rotate the live v0.8.0-rc1 identifiers directly to final v0.9.0; the rc1 proposal was never executed, so there is no rc1-to-final on-chain leg
  • regenerate the committed calldata and update unit/fork expectations and release provenance

This PR is stacked on #22127 and supersedes the rc1 identifiers merged into that branch by #22176.

Release provenance

  • raiko2 release: v0.9.0
  • source commit: dcbfdec7396c7e25a53ee26b43c55d58f63e0b81
  • release manifest SHA-256: e0fe8f2283fa4112206fe6d6686e81121e083251b2a7a3722b30818933dedd06
  • guest summary SHA-256: 376225618b838bbe1e93be5ff1670eec1a4fb101bf69e52acbe2176761ed5ed2
  • TEE attestation manifest SHA-256: de75ce83550809ca4a495abfec34e6a177e12ab73a2a75716e68a95c827b812c
  • runtime image: us-docker.pkg.dev/evmchain/images/raiko2@sha256:615c8ca72b7d657adc56ec73ea7fb4f871a2492ad9f4f49c2e98c91be2e89018

All 2 RISC0 image IDs, 4 SP1 vkeys, and 3 SGX MRENCLAVEs were cross-checked against the official release assets. Compared with the stacked base, only the nine trusted=true identifiers in actions 3, 4, 9-12, and 16-18 change; action 0, the old v0.8.0-rc1 removals, and SGX instance deletions remain byte-identical.

Verification

  • FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026Test -vv — 6 passed
  • L1_FORK_URL=https://eth.drpc.org FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026ForkTest -vv — 2 passed at L1 block 26,075,649
  • FOUNDRY_PROFILE=layer1 forge build — passed (pre-existing lint warnings only)
  • forge fmt --check — passed
  • pnpm solhint 'contracts/**/*.sol' — passed
  • P=0026 pnpm proposal — regenerated byte-identically
  • git diff --check — passed

Independent adversarial review found no P0-P3 issues. Independent behavioral verification decoded the base and updated batches, checked all nine release values, and reran the historical fork rehearsal.

Rollout boundary

This PR does not execute the proposal, register SGX instances, or deploy providers. All nine final identifiers differ from rc1, so before governance execution the final v0.9.0 artifacts still need Hoodi/canary proof validation and final signed SGX registration quotes must be prepared.


Note

High Risk
Governance calldata changes which RISC0, SP1, and SGX trust roots mainnet accepts after execution; wrong digests would reject valid proofs or accept invalid ones until corrected.

Overview
Proposal0026 still runs the same 21-action batch (inbox basefeeSharingPctg → 100 plus v0.8.0-rc1 teardown); this PR retargets the nine “enable” verifier actions from raiko2 v0.9.0-rc1 digests to final v0.9.0.

New V0_9_0_* constants are added in LibRisc0Constants, LibSP1Constants, and LibSGXConstants (RC1 entries stay for history). Proposal0026.s.sol, regenerated Proposal0026.action.md, proposal docs, and unit/fork tests now reference those finals. Because the rc1 proposal was never executed on mainnet, the batch still goes v0.8.0-rc1 off → v0.9.0 on with no extra rc1-disable steps.

Reviewed by Cursor Bugbot for commit 7b94930. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Repo admins can enable using credits for code reviews in their settings.

@github-actions

Copy link
Copy Markdown
Contributor

🐋 DeepSeek Code Review

🔵 Suggestions

  • Add release provenance/NatSpec comments to the new V0_9_0_* constants in LibRisc0Constants, LibSP1Constants, and LibSGXConstants. These are trust roots for mainnet; linking the source commit/manifest hashes directly in the code makes audits easier.
  • In Proposal0026Test.t.sol and Proposal0026Fork.t.sol, reference the library constants instead of redeclaring local copies. Local duplication can silently diverge from the library and weaken the test’s coverage.
  • Keep abi.encodeCall formatting consistent in Proposal0026.s.sol; action 3 now puts the selector and tuple on one line while the other actions keep them on separate lines.
  • Consider adding uniqueness checks in _validateIdentifiers between the new proposal and aggregation identifiers (e.g. V0_9_0_PROPOSAL_IMAGE_ID != V0_9_0_AGGREGATION_IMAGE_ID). This would catch copy/paste errors in future rotations.

🟢 What Looks Good

  • The nine trusted=true identifiers are updated consistently across library constants, proposal script, tests, docs, and generated action.md calldata.
  • The validation logic still enforces non-zero values and old-vs-new rotation for each identifier class.
  • The rc1 proposal was never executed, so dropping rc1 disarm actions and rotating directly from v0.8.0-rc1 to final is correct.
  • Generated calldata regeneration, fork tests, and unit tests were all run and cover the changed trust roots.

Automatically triggered on PR update • model: deepseek-v4-pro

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved: Cursor Bugbot completed successfully and there are no findings that require human review. Reviewers were not assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 41.75%. Comparing base (0f9e64b) to head (7b94930).
⚠️ Report is 1 commits behind head on claude/proposal0024-basefee-sharing-100.

Additional details and impacted files

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 0f9e64b...7b94930. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@davidtaikocha
davidtaikocha merged commit 6b1adef into claude/proposal0024-basefee-sharing-100 Sep 30, 2026
19 of 22 checks passed
@davidtaikocha
davidtaikocha deleted the feat/proposal0026-raiko2-v090 branch September 30, 2026 02:56
davidtaikocha added a commit that referenced this pull request Sep 30, 2026
#22178 moved Proposal0026 to the final raiko2 v0.9.0 identifiers but left
the nine v0.9.0-rc1 constants in LibRisc0Constants, LibSP1Constants and
LibSGXConstants. Nothing references them, and none was ever trusted on
mainnet, so the libraries keep only the versions the proposal uses. The
calldata in Proposal0026.action.md is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants