feat: switch LMD-GHOST + 3SF-mini for Goldfish + RLMD-GHOST + BFT - #434
Draft
MegaRedHand wants to merge 14 commits into
Draft
feat: switch LMD-GHOST + 3SF-mini for Goldfish + RLMD-GHOST + BFT#434MegaRedHand wants to merge 14 commits into
MegaRedHand wants to merge 14 commits into
Conversation
main (#447/#449/#450) merged cleanly textually, but the simple BFT finality condition removed slot_is_justifiable_after, which main's block_builder and store still called. Reconciled those call sites to the new model (every slot justifiable; finalize only on consecutive source+1 == target): - store::get_attestation_target_with_checkpoints: drop the justifiability walk-back (now a no-op); finalized arg unused, kept as _finalized. - block_builder: drop the target_not_justifiable rejection; the finalizes predicate now checks source.slot + 1 == target.slot.
Resolve conflicts in block_builder.rs and store.rs: keep this branch's simple BFT finality (source.slot + 1 == target.slot) and RLMD safe-target (last-period votes, voter-count threshold), while adopting main's Result-returning store read API and the ProjectedState scoring refactor. Drop the justifiability filter and slot_is_justifiable_after, which this branch removed under the simple BFT model (every slot is justifiable).
Split `SignedBlock.proof` into `BlockProof { proposer_signature,
attestation_proof }`. The proposer's raw XMSS signature is now carried as
a standalone field and verified directly with the hash-based XMSS verifier,
while `attestation_proof` is a lean-multisig Type-2 over the block body's
attestations only.
Previously the proposer signature was wrapped as a singleton Type-1 and
merged into a single block Type-2 alongside every attestation, so even a
block with zero attestations needed a prover call. Decoupling the proposer
lets the attestation aggregate be built independently of the block root (a
prerequisite for proposer prebuild) and removes prover work from the
empty-attestation case.
before: block-proof = aggregate([prop-sig, att0, att1])
after: block-proof = (prop-sig, aggregate([att0, att1]))
before (no atts): aggregate([prop-sig])
after (no atts): (prop-sig, empty-proof)
Verification now checks the raw proposer signature against the proposer's
proposal pubkey, then verifies the attestation Type-2 over attestation
components only (and rejects a stray aggregate on an attestation-less block).
Reaggregation drops the proposer component from the split layout.
NOTE: this diverges from the leanSpec #799 single-merged-proof wire format,
so the signature/SSZ spec tests fail against the current cross-client
fixtures until those are regenerated for the new layout. Draft PR.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🗒️ Description / Motivation
What Changed
Correctness / Behavior Guarantees
Tests Added / Run
Related Issues / PRs
✅ Verification Checklist
make fmt— cleanmake lint(clippy with-D warnings) — cleancargo test --workspace --release— all passing