Skip to content

docs(protocol): add Proposal0026 artifact verification - #22182

Merged
dantaik merged 1 commit into
claude/proposal0024-basefee-sharing-100from
docs/proposal0026-v090-verification
Sep 30, 2026
Merged

dantaik merged 1 commit into
claude/proposal0024-basefee-sharing-100from
docs/proposal0026-v090-verification

Conversation

@smtmfft

@smtmfft smtmfft commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • follow up on merged feat(protocol): rotate Proposal0026 artifacts to raiko2 v0.9.0 #22178 with the artifact-verification material requested in the Proposal0026 review
  • link the final raiko2 v0.9.0 release page and its release manifest, guest digest summary, and TEE attestation manifest with verified SHA-256 hashes
  • document source reproduction for ZK identifiers and TEE measurements, registry inspection for all four published images, and live verifier preflight checks
  • quote the RPC placeholders so every documented Bash block is syntactically valid

The stacked base already contains a3d4cdc1 (chore(protocol): drop the unused raiko2 v0.9.0-rc1 constants), so this PR does not duplicate that removal. This is documentation-only and does not change Proposal0026 calldata or runtime behavior.

Verification

  • pnpm exec prettier --check packages/protocol/script/layer1/proposals/Proposal0026.md
  • FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026Test -vv (6 passed)
  • FOUNDRY_PROFILE=layer1 forge build
  • P=0026 pnpm proposal
  • L1_FORK_URL=https://eth.drpc.org FOUNDRY_PROFILE=layer1 forge test --match-contract Proposal0026ForkTest -vv (2 passed)
  • all eight Bash blocks pass bash -n
  • downloaded release assets match the documented SHA-256 hashes
  • the four registry tags resolve to the documented immutable image digests
  • live mainnet preconditions pass for legacy trust, new identifiers being untrusted, SGX nextInstanceId, and instance 2 providers
  • independent reviewer and tester found no remaining material issues

The expensive full guest and SGX image rebuilds were not rerun for this documentation follow-up; the documented commands were checked against the final v0.9.0 release instructions and the published artifacts, registry objects, live state, unit tests, and fork rehearsal were verified directly.


Note

Low Risk
Markdown-only updates to the Proposal0026 runbook; no contract, script, or governance calldata changes.

Overview
Proposal0026 runbook gains end-to-end raiko2 v0.9.0 artifact verification: links to the release page, a table of release assets with SHA-256 hashes, and copy-paste steps to reproduce ZK guest digests and TEE attestation metadata from source (including stripping mr_signer for local SGX builds), plus docker buildx imagetools inspect for the four published image tags.

The Verification section adds live mainnet preflight checks (legacy trust on, v0.9.0 identifiers off, SGX nextInstanceId and instance 2) and splits inbox/fork rehearsal under its own heading. Documented Bash blocks now quote L1_RPC='<l1 rpc>' so they pass bash -n.

Documentation only; no proposal calldata or on-chain behavior changes.

Reviewed by Cursor Bugbot for commit bd3056a. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bd3056ac98

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +170 to +171
git fetch --tags origin "${TAG}"
git checkout "${TAG}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bind the reproduction workflow to the documented artifacts

The workflow resolves TAG to whatever v0.9.0 currently points at, but never asserts HEAD is the documented dcbf... commit or checks either downloaded blob against the SHA-256 values in the new table. If the tag is force-moved and the corresponding release assets are replaced, both source-vs-release diffs can succeed against the altered release, so this procedure no longer verifies the artifacts that Proposal0026 documents. Check the checkout commit and run SHA-256 verification immediately after each download.

Useful? React with 👍 / 👎.

@github-actions

Copy link
Copy Markdown
Contributor

🐋 DeepSeek Code Review

🔴 Critical Issues

None.

🟡 Warnings

  • Verification blocks can silently pass on stale artifacts.
    The ZK/TEE reproduction and registry inspection bash blocks do not include set -euo pipefail. If a cargo run, gh release download, or just build-guest command fails, the script continues and may use stale files from a previous run, producing a false-positive diff. Add set -euo pipefail to each non-preflight block, and preferably rm -f the generated from-source.json before regeneration.

  • The documented SHA-256 hashes are not enforced in the runbook.
    The table lists hashes for guest-digests-summary.json and tee-attestation-manifest-v0.9.0.json, but the repro commands download and use those files without checking their hashes. Add a sha256sum -c step immediately after download so tampered/corrupted release assets fail closed instead of being used in the comparison.

🔵 Suggestions

  • Quote $L1_RPC in all command usages, e.g. --rpc-url "$L1_RPC", not just at assignment. The new blocks fix the assignment but still use the variable unquoted in several cast commands.

  • For the registry inspection block, use --format '{{.Manifest.Digest}}' and compare against the expected digests programmatically rather than relying on manual visual inspection of docker buildx imagetools inspect.

  • In the live preflight block, consider using cast call --json plus jq -r '.[0]' instead of sed -n '1p' for parsing tuple return values; it is more robust against output formatting changes.

  • Set umask 077 before generating the local Gramine signing key in the TEE repro block — the key is disposable, but the instruction currently creates it with default permissions.

🟢 What Looks Good

  • Quoting the L1_RPC placeholder assignment is a clear fix.
  • The live preflight block correctly uses set -euo pipefail, has a reusable check_trust helper, and checks legacy/new trust state, nextInstanceId, and instance 2 provider presence.
  • The TEE repro correctly strips mr_signer for local builds and sorts for deterministic comparison.

Automatically triggered on PR update • model: deepseek-v4-pro

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot completed successfully with no findings that need human review, and no approval policy required extra review. No additional reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router

@dantaik
dantaik merged commit 4559c11 into claude/proposal0024-basefee-sharing-100 Sep 30, 2026
13 of 15 checks passed
@dantaik
dantaik deleted the docs/proposal0026-v090-verification branch September 30, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants