Skip to content

feat: switch LMD-GHOST + 3SF-mini for Goldfish + RLMD-GHOST + BFT - #434

Draft
MegaRedHand wants to merge 14 commits into
mainfrom
goldfish-rlmd-finality
Draft

feat: switch LMD-GHOST + 3SF-mini for Goldfish + RLMD-GHOST + BFT#434
MegaRedHand wants to merge 14 commits into
mainfrom
goldfish-rlmd-finality

Conversation

@MegaRedHand

Copy link
Copy Markdown
Collaborator

🗒️ Description / Motivation

  • What does this PR change?
  • Why is this change needed?
  • What problem does it solve?

What Changed

  • List the files or areas touched
  • Brief summary of each change

Correctness / Behavior Guarantees

  • What invariants are preserved or updated?
  • Are there any behavior changes reviewers should know about?

Tests Added / Run

  • What tests were added or updated?
  • What commands did you run to verify this change?

Related Issues / PRs

  • Closes #
  • Related to #

✅ Verification Checklist

  • Ran make fmt — clean
  • Ran make lint (clippy with -D warnings) — clean
  • Ran cargo test --workspace --release — all passing

main (#447/#449/#450) merged cleanly textually, but the simple BFT finality
condition removed slot_is_justifiable_after, which main's block_builder and
store still called. Reconciled those call sites to the new model (every slot
justifiable; finalize only on consecutive source+1 == target):

- store::get_attestation_target_with_checkpoints: drop the justifiability
  walk-back (now a no-op); finalized arg unused, kept as _finalized.
- block_builder: drop the target_not_justifiable rejection; the finalizes
  predicate now checks source.slot + 1 == target.slot.
Resolve conflicts in block_builder.rs and store.rs: keep this branch's simple
BFT finality (source.slot + 1 == target.slot) and RLMD safe-target
(last-period votes, voter-count threshold), while adopting main's
Result-returning store read API and the ProjectedState scoring refactor.

Drop the justifiability filter and slot_is_justifiable_after, which this
branch removed under the simple BFT model (every slot is justifiable).
Split `SignedBlock.proof` into `BlockProof { proposer_signature,
attestation_proof }`. The proposer's raw XMSS signature is now carried as
a standalone field and verified directly with the hash-based XMSS verifier,
while `attestation_proof` is a lean-multisig Type-2 over the block body's
attestations only.

Previously the proposer signature was wrapped as a singleton Type-1 and
merged into a single block Type-2 alongside every attestation, so even a
block with zero attestations needed a prover call. Decoupling the proposer
lets the attestation aggregate be built independently of the block root (a
prerequisite for proposer prebuild) and removes prover work from the
empty-attestation case.

  before:  block-proof = aggregate([prop-sig, att0, att1])
  after:   block-proof = (prop-sig, aggregate([att0, att1]))

  before (no atts): aggregate([prop-sig])
  after  (no atts): (prop-sig, empty-proof)

Verification now checks the raw proposer signature against the proposer's
proposal pubkey, then verifies the attestation Type-2 over attestation
components only (and rejects a stray aggregate on an attestation-less block).
Reaggregation drops the proposer component from the split layout.

NOTE: this diverges from the leanSpec #799 single-merged-proof wire format,
so the signature/SSZ spec tests fail against the current cross-client
fixtures until those are regenerated for the new layout. Draft PR.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant