Skip to content

feat(proposer): fold envelope signing into Gloas consensus - #1313

Merged
shane-moore merged 1 commit into
sigp:epbsfrom
shane-moore:feat/1309-proposer-envelope-fold
Sep 25, 2026
Merged

shane-moore merged 1 commit into
sigp:epbsfrom
shane-moore:feat/1309-proposer-envelope-fold

Conversation

@shane-moore

@shane-moore shane-moore commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Merge order: #1311 → #1312 → #1313. All three target epbs; rebase remaining branches after each merge.

Problem, Evidence, and Context (Required)

Final layer for #1309, dependent on #1312. Anchor previously decided bare Gloas block bytes and signed the envelope through a separate dissemination duty. SIP-94 §§4, 6 and 7 requires the payload root in the decided value and envelope shares in the proposer packet.

For example, when an operator proposes A but consensus decides B, it must sign B's block and derived envelope. Its local contents can be published only when their full blinded value matches the decision.

Change Overview (Required)

  • Decide {Block, PayloadRoot} and derive the five-field blinded envelope from that decision.
  • Enable stateless production and send one proposer packet. Block and envelope signatures reconstruct independently; the later publication callback only validates and waits.
  • Activate two-entry Gloas proposer admission while retaining pre-Gloas and RANDAO singleton rules.
  • Remove the separate dissemination duty, store, routing and retired wire values with the replacement. The exhaustive doppelganger dispatcher also needs its retired arms removed.

Review only this layer.

Risks, Trade-offs, and Mitigations (Required)

This changes the Gloas proposer wire contract and shared collector use. Activate the fold and legacy retirement together. Retaining two independent signing calls would violate the one-packet rule. Complete decision binding, unchanged block slashing checks, bounded companion evidence and independent thresholds are covered by local tests.

Source and fixture comparisons use go-ssv ssvlabs/ssv#2901 (56916c7) and ssv-spec ssvlabs/ssv-spec#633 (bfd054d). Those are evolving references; local parity does not establish mixed-client runtime compatibility.

Validation (Required)

Acceptance criteria, verified by executed local unit and integration tests:

  • Gloas DataSSZ carries {Block, PayloadRoot}, with the specified self-build/external presence check and unchanged justified reproposals.
  • Derive the blinded envelope entirely from the decided value.
  • Send one proposer packet containing the block share and, for self-build, the envelope share. Reconstruct independently so envelope failure cannot delay the block.
  • Accept valid block-only final packets and the §7 two-entry form; preserve pre-Gloas and RANDAO singleton rules.
  • Publish an envelope only when its complete blinded value matches the decided value. Verified at the signing callback boundary, without live BN publication.
  • Retire the separate dissemination/signing flow when the replacement activates.

Executed on the complete stack:

  • cargo check --workspace --tests --locked: passed.
  • make test: 987 passed, 0 failed after initializing the pinned SSV spec submodule.
  • cargo nextest run --locked -p ssv_types -p qbft -p signature_collector -p message_validator -p message_receiver -p anchor_validator_store -p operator_doppelganger: 522 passed, 0 skipped.
  • make cargo-fmt-check, make lint, git diff --check: passed.
  • make audit-CI: passed with 12 allowed warnings under the existing repository policy.

The tests cover a prepared QBFT reproposal, the Go block/wrapper encoding, progressive envelope hash, local-versus-decided contents, every blinded field, missing local payload root, slashing rejection and independent deadlines. Live mixed-client interoperability and deployment have not been exercised.

Rollback (Required for behavior or runtime changes; optional otherwise)

Revert this activation as a unit before reverting either prerequisite. Coordinate rollback with the committee's Gloas wire format; do not restore only part of the retired flow.

Blockers / Dependencies (Optional)

Merge #1311 and #1312 first. Lighthouse sigp/lighthouse#10036 remains an unmerged pinned dependency. The source branch is stacked in shane-moore/anchor; the epbs diff includes prerequisite commits until they land.

Additional Info / Next Steps (Optional)

No live mixed-client compatibility claim. Lighthouse's retained local builder URL when another block is decided remains the previously identified SIP SHOULD-level difference.

@codecov-commenter

codecov-commenter commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.90576% with 20 lines in your changes missing coverage. Please review.
⚠️ Please upload report for BASE (epbs@f93c9eb). Learn more about missing BASE report.

Files with missing lines Patch % Lines
anchor/validator_store/src/lib.rs 93.15% 13 Missing ⚠️
anchor/common/ssv_types/src/consensus.rs 98.26% 2 Missing ⚠️
anchor/message_validator/src/partial_signature.rs 98.97% 2 Missing ⚠️
anchor/client/src/lib.rs 0.00% 1 Missing ⚠️
...idator_store/src/testing/decided_block_root_e2e.rs 93.33% 1 Missing ⚠️
...or/validator_store/src/testing/envelope_signing.rs 99.73% 1 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             epbs    #1313   +/-   ##
=======================================
  Coverage        ?   80.71%           
=======================================
  Files           ?      179           
  Lines           ?    41016           
  Branches        ?        0           
=======================================
  Hits            ?    33107           
  Misses          ?     7909           
  Partials        ?        0           
Flag Coverage Δ
rust 80.71% <97.90%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@shane-moore shane-moore left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 3b0ace93. No actionable code findings survived self-audit.

Both shares derive from the decided Gloas wrapper, after the block slashing check. Publication checks the complete blinded envelope against that decision, and the later callback only waits for its signature. Two-entry admission is restricted to Gloas proposer PostConsensus packets; the separate dissemination flow and retired wire values are removed together.

Verified the hosted debug and release logs: 985 tests passed in each, on a tree identical to this head. Coverage includes the Go encoding fixture, fixed envelope root, prepared reproposal preservation, local/decided mismatches, slashing rejection and payload deadlines. No local test rerun was performed. The passing local-testnet configuration covers Anchor-only Fulu/Boole, so mixed-client Gloas runtime compatibility remains unverified.

Landing note: GitHub currently reports conflicts with epbs. Resolve those and verify the resulting head before merging.

Reviewed by gpt-6 astra high.

Decide the block and payload root together and derive envelope signing
from that decision. Enable stateless production, send paired shares and
validate complete envelope bindings before local publication. Retire the
separate dissemination flow with the replacement.

Refs sigp#1309.
@shane-moore
shane-moore force-pushed the feat/1309-proposer-envelope-fold branch from 3b0ace9 to 33bad73 Compare September 25, 2026 03:10
@shane-moore
shane-moore merged commit 50885d0 into sigp:epbs Sep 25, 2026
20 checks passed
@shane-moore
shane-moore deleted the feat/1309-proposer-envelope-fold branch September 25, 2026 03:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants