Repository navigation
Feat/sealed paths and key rules - #161
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
feat: cheaper sealed-tree paths, bounded Merkle proof RPC, and no base-layout spend keys
Follow-up to #160 (spec 18 / tx 6). It fixes two weaknesses in the spend pipeline:
Both changes land in spec 18, which is not deployed yet.
Sealed-tree paths and the proof RPC
SealedTreePrunedBelowLevel10 → 6state_callandprivacy_getMerkleProof, p50). Costs 32_766 stored nodes per sealed tree instead of 2_046.get_merkle_pathprivacy_getMerkleProof*(client/rpc-v2)ProofGate). The excess is refused as busy (-32009) instead of stalling every other RPC.pallet-shielded-pool0.23.0.No base-layout spend keys, anywhere
A base-layout key (transfer/unshield v1 arity) binds neither the memos nor the full recipient. A copier could swap a spend's memos or alias its recipient.
register_verification_key/ batchset_active_versionunretire_versionverify_statement,verify_raw)ProofVerificationFailed) and the note stays unspent.encoding.rs.encode_transferandencode_unshieldreturnNonefor it.verify_proofbenchmark seeded its key underTRANSFER. With the new rule, mostnskipped the pairing, so regenerated weights would have come out ~40 % low. It now uses an id outside the known table. The committed weights predate this and are unaffected.setup-dev.shexample uses version 3.pallet-zk-verifier0.16.0, breaking (!).Docs and comments
shielded-pool/src/merkleandzk-verifierrestructured: numbered steps for multi-step functions, one///per config type, event and field.RUNTIME_VERSIONS.md§4 updated.Upgrade notes
zk-verifierweights should be regenerated before release.set_active_versionandunretire_versionnow read the key.@orbinum/circuits0.17.1, activate them, retire transfer/unshield v2.Testing
Unit:
cargo testforpallet-shielded-pool,pallet-zk-verifier,client/rpc-v2andorbinum-runtime, also withruntime-benchmarks,skip-proof-verification(the CItest-releaseset).-D warnings, fmt and taplo clean.ProofGatelimits and releases permits;Live dev node, real proofs:
ts-tests/e2e-cross-tree-live.cjsts-tests/e2e-spend-hardening-live.cjsts-tests/e2e-prune-cut-upgrade-live.cjs: cut 10 → 6 viasetCodeWithoutCheckson pruned 128-leaf treesKEYS_ONLY=1: key rules and the base-key exploit