Skip to content

Gloas: verifiers - #1940

Open
madlabman wants to merge 31 commits into
developfrom
gloas-verifier
Open

madlabman wants to merge 31 commits into
developfrom
gloas-verifier

Conversation

@madlabman

@madlabman madlabman commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Add Gloas support:

  • primitives for verifiers

@madlabman
madlabman requested a review from a team as a code owner August 7, 2026 19:10
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

badge

Hardhat Unit Tests Coverage Summary

Details
Filename                                                                Stmts    Miss  Cover    Missing
--------------------------------------------------------------------  -------  ------  -------  ------------------------------------------------------------------------------------------------------------
contracts/0.4.24/Lido.sol                                                 310      11  96.45%   1038-1057, 1165-1177
contracts/0.4.24/StETH.sol                                                 80       0  100.00%
contracts/0.4.24/StETHPermit.sol                                           15       0  100.00%
contracts/0.4.24/lib/Packed64x4.sol                                         5       0  100.00%
contracts/0.4.24/lib/SigningKeys.sol                                       36       0  100.00%
contracts/0.4.24/lib/StakeLimitUtils.sol                                   41       0  100.00%
contracts/0.4.24/nos/NodeOperatorsRegistry.sol                            435       0  100.00%
contracts/0.4.24/utils/Pausable.sol                                         9       0  100.00%
contracts/0.4.24/utils/UnstructuredStorageExt.sol                          14       0  100.00%
contracts/0.4.24/utils/Versioned.sol                                        5       0  100.00%
contracts/0.6.12/WstETH.sol                                                17       0  100.00%
contracts/0.8.25/CLProofVerifier.sol                                       15       0  100.00%
contracts/0.8.25/CLValidatorVerifier.sol                                   33       1  96.97%   96
contracts/0.8.25/TopUpGateway.sol                                         102       2  98.04%   269, 317
contracts/0.8.25/ValidatorExitDelayVerifier.sol                            66       0  100.00%
contracts/0.8.25/consolidation/ConsolidationBus.sol                        73       0  100.00%
contracts/0.8.25/consolidation/ConsolidationGateway.sol                    75       0  100.00%
contracts/0.8.25/consolidation/ConsolidationMigrator.sol                   65       0  100.00%
contracts/0.8.25/lib/BeaconChainDepositor.sol                              42       4  90.48%   44, 47, 83, 98
contracts/0.8.25/sr/ISRBase.sol                                             0       0  100.00%
contracts/0.8.25/sr/SRLib.sol                                             290      15  94.83%   99-148, 313
contracts/0.8.25/sr/SRStorage.sol                                          13       0  100.00%
contracts/0.8.25/sr/SRTypes.sol                                             0       0  100.00%
contracts/0.8.25/sr/SRUtils.sol                                            13       1  92.31%   87
contracts/0.8.25/sr/StakingRouter.sol                                     273      11  95.97%   70, 384-393, 640-641, 725, 779, 877-882
contracts/0.8.25/utils/AccessControlConfirmable.sol                         2       0  100.00%
contracts/0.8.25/utils/Confirmable2Addresses.sol                            5       0  100.00%
contracts/0.8.25/utils/Confirmations.sol                                   37       0  100.00%
contracts/0.8.25/utils/PausableUntilWithRoles.sol                           3       0  100.00%
contracts/0.8.25/vaults/LazyOracle.sol                                    134      18  86.57%   203-209, 248, 276-279, 436, 449, 465, 513, 554-556, 648, 656
contracts/0.8.25/vaults/OperatorGrid.sol                                  196       1  99.49%   203
contracts/0.8.25/vaults/PinnedBeaconProxy.sol                               6       0  100.00%
contracts/0.8.25/vaults/StakingVault.sol                                  111      14  87.39%   307-341
contracts/0.8.25/vaults/ValidatorConsolidationRequests.sol                 48       3  93.75%   183, 187, 199
contracts/0.8.25/vaults/VaultFactory.sol                                   34       0  100.00%
contracts/0.8.25/vaults/VaultHub.sol                                      427      76  82.20%   257-266, 281-287, 342-366, 383, 552-553, 595-688, 998-1000, 1088-1092, 1150, 1205-1212, 1498-1499, 1514-1524
contracts/0.8.25/vaults/dashboard/Dashboard.sol                           137       8  94.16%   183-201, 327, 636-649
contracts/0.8.25/vaults/dashboard/NodeOperatorFee.sol                      70       0  100.00%
contracts/0.8.25/vaults/dashboard/Permissions.sol                          47       2  95.74%   321-330
contracts/0.8.25/vaults/interfaces/IPinnedBeaconProxy.sol                   0       0  100.00%
contracts/0.8.25/vaults/interfaces/IPredepositGuarantee.sol                 0       0  100.00%
contracts/0.8.25/vaults/interfaces/IStakingVault.sol                        0       0  100.00%
contracts/0.8.25/vaults/interfaces/IVaultFactory.sol                        0       0  100.00%
contracts/0.8.25/vaults/lib/PinnedBeaconUtils.sol                           5       0  100.00%
contracts/0.8.25/vaults/lib/RecoverTokens.sol                               5       0  100.00%
contracts/0.8.25/vaults/lib/RefSlotCache.sol                               36       0  100.00%
contracts/0.8.25/vaults/predeposit_guarantee/MeIfNobodyElse.sol             3       0  100.00%
contracts/0.8.25/vaults/predeposit_guarantee/PredepositGuarantee.sol      213      12  94.37%   477-497, 526, 665, 672, 694
contracts/0.8.9/Accounting.sol                                             98       2  97.96%   384-385
contracts/0.8.9/Burner.sol                                                 92       0  100.00%
contracts/0.8.9/DepositSecurityModule.sol                                 119       0  100.00%
contracts/0.8.9/EIP712StETH.sol                                            16       0  100.00%
contracts/0.8.9/LidoExecutionLayerRewardsVault.sol                         16       0  100.00%
contracts/0.8.9/LidoLocator.sol                                            28       0  100.00%
contracts/0.8.9/OracleDaemonConfig.sol                                     28       0  100.00%
contracts/0.8.9/TokenRateNotifier.sol                                      45       0  100.00%
contracts/0.8.9/TriggerableWithdrawalsGateway.sol                          54       1  98.15%   271
contracts/0.8.9/WithdrawalQueue.sol                                        88       0  100.00%
contracts/0.8.9/WithdrawalQueueBase.sol                                   146       0  100.00%
contracts/0.8.9/WithdrawalQueueERC721.sol                                  89       0  100.00%
contracts/0.8.9/WithdrawalVault.sol                                        37       0  100.00%
contracts/0.8.9/WithdrawalVaultEIP7685.sol                                 45       0  100.00%
contracts/0.8.9/lib/ExitLimitUtils.sol                                     35       0  100.00%
contracts/0.8.9/lib/Math.sol                                                4       0  100.00%
contracts/0.8.9/lib/PositiveTokenRebaseLimiter.sol                         22       0  100.00%
contracts/0.8.9/lib/UnstructuredRefStorage.sol                              2       0  100.00%
contracts/0.8.9/oracle/AccountingOracle.sol                               197       3  98.48%   440-441, 615
contracts/0.8.9/oracle/BaseOracle.sol                                      89       1  98.88%   401
contracts/0.8.9/oracle/HashConsensus.sol                                  263       1  99.62%   1005
contracts/0.8.9/oracle/ValidatorsExitBus.sol                              243       2  99.18%   1037, 1102
contracts/0.8.9/oracle/ValidatorsExitBusOracle.sol                         58       1  98.28%   218
contracts/0.8.9/proxy/OssifiableProxy.sol                                  17       0  100.00%
contracts/0.8.9/proxy/WithdrawalsManagerProxy.sol                          60       0  100.00%
contracts/0.8.9/sanity_checks/OracleReportSanityChecker.sol               382       2  99.48%   1300, 1312
contracts/0.8.9/utils/DummyEmptyContract.sol                                0       0  100.00%
contracts/0.8.9/utils/PausableUntil.sol                                    31       0  100.00%
contracts/0.8.9/utils/Versioned.sol                                        11       0  100.00%
contracts/0.8.9/utils/access/AccessControl.sol                             23       0  100.00%
contracts/0.8.9/utils/access/AccessControlEnumerable.sol                    9       0  100.00%
contracts/common/utils/PausableUntil.sol                                   29       0  100.00%
contracts/tooling/AlertingHarness.sol                                      54       1  98.15%   97
contracts/tooling/sepolia/SepoliaDepositAdapter.sol                        21      21  0.00%    55-106
TOTAL                                                                    5997     214  96.43%

Diff against master

Filename                                           Stmts    Miss  Cover
-----------------------------------------------  -------  ------  --------
contracts/0.8.25/CLProofVerifier.sol                 +15       0  +100.00%
contracts/0.8.25/CLValidatorVerifier.sol              -1       0  -0.09%
contracts/0.8.25/ValidatorExitDelayVerifier.sol       -9       0  +100.00%
contracts/0.8.9/DepositSecurityModule.sol             -1       0  +100.00%
TOTAL                                                 +4       0  -0.01%

Results for commit: 2f4a21d

Minimum allowed coverage is 95%

♻️ This comment has been updated with latest results

hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Aug 11, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.
hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Aug 11, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.
@tamtamchik
tamtamchik requested a balanced review from Copilot August 13, 2026 11:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Gloas-compatible generalized-index handling across validator proof verifiers and deployment tooling.

Changes:

  • Adds ProgressiveList GIndex calculation and fork-aware validator proofs.
  • Extends exit-delay verification with block_roots proofs.
  • Updates configuration, deployment helpers, and tests for new constructor parameters.

Reviewed changes

Copilot reviewed 44 out of 44 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
test/integration/vaults/scenario/pdg-specific-validator.integration.ts Uses fork-aware validator GIndex.
test/integration/vaults/scenario/pdg-paused-happy-path.integration.ts Updates PDG proof setup.
test/integration/vaults/scenario/node-operator.happy-path.integration.ts Updates validator tree setup.
test/integration/vaults/scenario/happy-path.integration.ts Uses fork-aware PDG proofs.
test/integration/vaults/obligations.integration.ts Accounts for existing owner shares.
test/integration/vaults/dashboard.integration.ts Updates PDG proof setup.
test/integration/report-validator-exit-delay.ts Supplies block-roots witnesses.
test/integration/core/happy-path.integration.ts Checks balance increases by delta.
test/integration/core/burn-shares.integration.ts Preserves pre-existing shares in assertions.
test/common/lib/GIndex.t.sol Tests ProgressiveList GIndices.
test/common/contracts/GIndex__Harness.sol Exposes ProgressiveList helper.
test/0.8.9/lib/GIndex.test.ts Adds TypeScript GIndex tests.
test/0.8.25/vaults/predepositGuarantee/predepositGuarantee.test.ts Updates PDG constructor fixtures.
test/0.8.25/vaults/predepositGuarantee/contracts/CLProofVerifier__harness.sol Updates verifier constructor.
test/0.8.25/vaults/predepositGuarantee/clProofVerifyer.test.ts Tests Gloas validator proofs.
test/0.8.25/vaults/contracts/PredepositGuarantee__HarnessForFactory.sol Forwards new PDG parameters.
test/0.8.25/validatorExitDelayVerifierHelpers.ts Builds synthetic block-roots proofs.
test/0.8.25/validatorExitDelayVerifier.test.ts Covers updated exit verifier.
test/0.8.25/srv3/contracts/CLValidatorVerifier__Harness.sol Updates validator harness.
test/0.8.25/srv3/clValidatorProofVerifier.test.ts Tests fork-aware validator GIndices.
test/0.8.25/contracts/ValidatorExitDelayVerifier__Harness.sol Exposes new GIndex helpers.
test/0.8.25/contracts/TopUpGateway__Harness.sol Updates gateway constructor.
test/0.8.25/consolidationGateway/consolidationGateway.rateLimit.test.ts Updates consolidation fixture.
test/0.8.25/consolidationGateway/consolidationGateway.pausable.test.ts Updates consolidation fixture.
test/0.8.25/consolidationGateway/consolidationGateway.addConsolidationRequests.test.ts Updates consolidation fixture.
test/0.8.25/consolidation-helpers.ts Adds null GIndex fixture.
scripts/upgrade/upgrade-params-mainnet.toml Adds mainnet Gloas parameters.
scripts/upgrade/upgrade-params-hoodi.toml Adds Hoodi Gloas parameters.
scripts/upgrade/steps/0100-deploy-base-contracts.ts Passes new gateway parameters.
scripts/scratch/steps/0085-deploy-vaults.ts Passes new PDG parameters.
scripts/scratch/steps/0083-deploy-core.ts Passes new verifier parameters.
scripts/scratch/deploy-params-testnet.toml Adds testnet Gloas configuration.
scripts/defaults/local-devnet-defaults.json Updates local PDG defaults.
lib/protocol/helpers/vaults.ts Selects proof GIndex by slot.
lib/protocol/helpers/topup.ts Builds pre-Gloas top-up fixtures.
lib/protocol/helpers/consolidation.ts Builds pre-Gloas consolidation fixtures.
lib/config-schemas.ts Validates new configuration fields.
contracts/common/lib/GIndex.sol Implements ProgressiveList GIndices.
contracts/0.8.25/vaults/predeposit_guarantee/PredepositGuarantee.sol Accepts Gloas verifier parameters.
contracts/0.8.25/vaults/predeposit_guarantee/CLProofVerifier.sol Supports ProgressiveList validators.
contracts/0.8.25/ValidatorExitDelayVerifier.sol Adds Gloas and block-roots verification.
contracts/0.8.25/TopUpGateway.sol Forwards Gloas validator parameters.
contracts/0.8.25/consolidation/ConsolidationGateway.sol Forwards Gloas validator parameters.
contracts/0.8.25/CLValidatorVerifier.sol Supports ProgressiveList validators.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread contracts/0.8.25/ValidatorExitDelayVerifier.sol Outdated
Comment thread contracts/0.8.25/vaults/predeposit_guarantee/PredepositGuarantee.sol Outdated
Comment thread test/0.8.25/validatorExitDelayVerifierHelpers.ts Outdated
Comment thread scripts/scratch/deploy-params-testnet.toml Outdated
hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Aug 17, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.
hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Aug 17, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.
hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Aug 17, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.

@dry914 dry914 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Contract changes look right, but upgrade flow doesn't ship new ValidatorExitDelayVerifier and PDG implementation.

Comment thread contracts/0.8.25/ValidatorExitDelayVerifier.sol Outdated
Comment thread contracts/0.8.25/vaults/predeposit_guarantee/CLProofVerifier.sol Outdated
Comment thread test/0.8.25/validatorExitDelayVerifier.test.ts Outdated
Comment thread test/0.8.25/validatorExitDelayVerifier.test.ts Outdated
Comment thread contracts/common/lib/GIndex.sol
Comment thread contracts/0.8.25/ValidatorExitDelayVerifier.sol Outdated
Comment thread scripts/upgrade/steps/0100-deploy-base-contracts.ts Outdated
Comment thread scripts/upgrade/steps/0100-deploy-base-contracts.ts Outdated
@dry914
dry914 requested a review from a team as a code owner September 3, 2026 12:23

@tamtamchik tamtamchik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree with @dry914 comments, need to extend tests a bit

AlexandrMov and others added 8 commits September 9, 2026 13:21
The Gloas pivot in deploy-params-testnet.toml is 898 x 32 = 28736, the fork
epoch of the kurtosis devnet deployed on 2026-09-04. The public
glamsterdam-devnet-11 (genesis 2026-09-09 10:00 UTC) forks at epoch 1125,
so the verifier pivot and change slots become 1125 x 32 = 36000.
hweawer added a commit to lidofinance/late-prover-bot that referenced this pull request Sep 11, 2026
lidofinance/core#1940 stops anchoring the proven block through EIP-4788:

    verifyValidatorExitDelay(
        ProvableBeaconBlockHeader recentBlock,   // root read from EIP-4788
        BlockRootsHeaderWitness  targetBlock,    // proven against recentBlock.stateRoot
        ValidatorWitness[]       witnesses,      // proven against targetBlock.stateRoot
        ExitRequestData          exitRequests)

That removes the withheld-payload problem for the deadline block outright. Its
root now comes out of the recent state's block_roots ring, so it no longer
matters whether an execution block ever carried its successor's timestamp, and
the deadline block is simply the first proposed block at or after the deadline -
no forward walk, no advance. Only the recent block still needs an entry in the
beacon roots buffer, which is what resolveProvableAnchor already guarantees for
the finalized anchor; its doc now says so.

The bot builds the new witness from the state it already downloads each cycle,
so the extra proof costs nothing beyond the proof itself. Two bounds come with
the shape and are now enforced where they belong: a deadline that is not yet
behind the finalized anchor waits for the next cycle instead of being proven
against a state that cannot contain it, and the current-slot path is bounded by
recentSlot - targetSlot <= SLOTS_PER_HISTORICAL_ROOT - the size of the ring,
which is exactly where the historical-summaries path takes over. That bound
replaces the head-relative isSlotOld check, so the bot and the contract now
switch paths on the same condition.

Verified against the deployed contract on a fork of a Gloas devnet: a proof
built by this code is accepted end to end and the module records a 552 h delay
for a real Lido key. scripts/devnet-proof-fixture.ts builds that fixture from a
live devnet; it fails loudly if the anchor's root is not in the EIP-4788 buffer.
@dry914 dry914 self-assigned this Sep 17, 2026
@dry914 dry914 added solidity Smart contract code changes next upgrade Things to pickup for the next protocol upgrade labels Sep 17, 2026
@dry914
dry914 changed the base branch from gloas to develop September 17, 2026 18:19
@dry914 dry914 changed the title Gloas verifiers Gloas: verifiers Sep 17, 2026
Comment thread contracts/upgrade/UpgradeVoteScript.sol Fixed
Comment thread contracts/upgrade/UpgradeTemplate.sol Fixed
Comment thread contracts/upgrade/UpgradeTemplate.sol Fixed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

next upgrade Things to pickup for the next protocol upgrade solidity Smart contract code changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants