Commit Graph
3435 Commits
Author SHA1 Message Date
agureev 1c87ce7fca doc: document changes 2026-08-22 20:07:18 +00:00
Artem Gureev 8435c88098 feat(indexer): capture events at block ingest 2026-08-22 20:07:18 +00:00
Artem Gureev dc7aeeb3b1 feat(storage): store per-block events in a new column family 2026-08-22 20:07:18 +00:00
Artem Gureev 5ea8774b40 feat(common): surface per-transaction events from block application 2026-08-22 20:07:18 +00:00
Artem Gureev 5bf8a0e088 test(lee): pin state purity against event emission 2026-08-22 20:07:18 +00:00
agureev d7a143d26c chore: docs + artifacts 2026-08-22 14:11:14 +00:00
Artem Gureev a32afb2efb test(lee): selector round-trip and private-path emitter coverage 2026-08-22 14:07:39 +00:00
Artem Gureev aab4e5651a feat!(lee): add event selector field
BREAKING!

Before: Program outputs carried and opaque vector of event blobs.

After: Outputs now bear a vector of `ProgramOutputs` struct which also
have selectors attached.

Mitigation: Apply selectors to all event emissions for current programs.
2026-08-22 11:06:17 +00:00
Artem Gureev 4ed6fcc1cd test(lee): use expect in the emitter test helper 2026-08-22 10:23:35 +00:00
Artem Gureev ed0415db87 refactor(lee): use InstructionData for the emitter chain payload 2026-08-22 10:20:29 +00:00
agureev 39b3018058 chore: artifacts 2026-08-22 13:35:58 +04:00
Artem GureevandSergio Chouhy 43a85f8eb0 doc: update lee/state_machine/core/src/program/mod.rs
Co-authored-by: Sergio Chouhy <41742639+schouhy@users.noreply.github.com>
2026-08-22 09:05:11 +00:00
agureev e5d4d87ca6 doc: add privacy event-drop documentation 2026-08-22 09:05:11 +00:00
agureev 87fb34fd34 chore: docs 2026-08-22 09:05:11 +00:00
Artem Gureev 225470c5a2 test(lee): parameterized event-emitter guest and coverage 2026-08-22 08:42:56 +00:00
Artem Gureev a080dce0af feat(lee): thread program events through public validation 2026-08-22 08:41:30 +00:00
Artem Gureev f414aa03c0 feat!(lee): add events to ProgramOutput
BREAKING!

Before: Program output did not contain events.

After: Program outputs contain an extra vector field of events.

Mitigation: migrate the programs to use the updated output struct.
2026-08-22 08:38:19 +00:00
Sergio Chouhy 1adf2432b2 Merge pull request #725 from logos-blockchain/schouhy/lez-seqeuncer-self-join-finality-queue
feat(sequencer): Implement sequencer join/exit queues
2026-08-21 14:54:28 -03:00
Sergio Chouhy cade003868 fix(lez/sequencer): use slot to track finalized config ops 2026-08-21 11:33:01 -03:00
Sergio Chouhy c1644a8cc5 feat(sequencer): implement sequencer join/exit queues 2026-08-21 11:32:31 -03:00
7dac077487 test: add cucumber environment with initial ported integration tests (#741)
This PR introduces the initial Cucumber-based integration test framework for the LEZ, building on the testing-framework integration work started by @andrussal, adds the first set of Cucumber integration scenarios and establishes reusable infrastructure for future Cucumber scenarios.

---------

Co-authored-by: Andrus Salumets <salumets.andrus@gmail.com>
Co-authored-by: Sergio Chouhy <sergio.chouhy@gmail.com>
Co-authored-by: Sergio Chouhy <41742639+schouhy@users.noreply.github.com>
Co-authored-by: Roman <zajic@zajic.net>
Co-authored-by: Daniil Polyakov <arjentix@gmail.com>
Co-authored-by: Moudy <m.ellaz@hotmail.com>
Co-authored-by: andrussal <salumets.andrus@gmail.com>
2026-08-20 21:15:05 +02:00
Moudy 03f46bf191 Merge pull request #731 from logos-blockchain/moudy/cross-zone-halt-operability 2026-08-20 13:00:44 +02:00
moudyellaz 2d7dbf4d85 Merge remote-tracking branch 'origin/dev' into moudy/cross-zone-halt-operability
# Conflicts:
#	artifacts/lez/programs/cross_zone_inbox.bin
#	artifacts/lez/programs/ping_receiver.bin
#	artifacts/lez/programs/wrapped_token.bin
#	test_fixtures/fixtures/prebuilt_sequencer_db.dump
2026-08-20 12:13:50 +02:00
Moudy 84eb345ea9 Merge pull request #771 from logos-blockchain/moudy/cross-zone-target-auth
feat(cross-zone)!: land source authority and guest cycle hygiene to dev
2026-08-20 08:34:18 +02:00
moudyellaz cbdb5e7646 Merge remote-tracking branch 'origin/dev' into moudy/cross-zone-target-auth
# Conflicts:
#	test_fixtures/fixtures/prebuilt_sequencer_db.dump
2026-08-20 02:37:25 +02:00
Daniil Polyakov 8f7a93e2ca Merge pull request #736 from logos-blockchain/arjentix/actors-phase-2
refactor(sequencer): actor architecture, phase 2: Storage Actor
2026-08-20 01:27:08 +03:00
moudyellaz 968a17f867 Merge remote-tracking branch 'origin/dev' into moudy/cross-zone-target-auth
# Conflicts:
#	Cargo.lock
#	artifacts/lez/programs/amm.bin
#	artifacts/lez/programs/associated_token_account.bin
#	artifacts/lez/programs/authenticated_transfer.bin
#	artifacts/lez/programs/bridge.bin
#	artifacts/lez/programs/bridge_lock.bin
#	artifacts/lez/programs/clock.bin
#	artifacts/lez/programs/cross_zone_inbox.bin
#	artifacts/lez/programs/cross_zone_outbox.bin
#	artifacts/lez/programs/faucet.bin
#	artifacts/lez/programs/pinata.bin
#	artifacts/lez/programs/pinata_token.bin
#	artifacts/lez/programs/ping_receiver.bin
#	artifacts/lez/programs/ping_sender.bin
#	artifacts/lez/programs/token.bin
#	artifacts/lez/programs/vault.bin
#	artifacts/lez/programs/wrapped_token.bin
#	test_fixtures/fixtures/prebuilt_sequencer_db.dump
2026-08-19 23:40:53 +02:00
Daniil Polyakov 578350beea refactor(sequencer, storage): move transaction index into StorageActor 2026-08-20 00:37:23 +03:00
Daniil Polyakov 6290f09127 fix(executor): make GetBlockRange bounded, non-over-allocating and non-blocking 2026-08-20 00:37:23 +03:00
Daniil Polyakov 8af13dd29d fix(ci): pass GITHUB_ACTIONS in ci image 2026-08-20 00:37:23 +03:00
Daniil Polyakov 7249f2f881 refactor(sequencer): actor architecture, phase 2: Storage Actor 2026-08-20 00:37:23 +03:00
moudyellaz 3d9c10fbce Merge remote-tracking branch 'origin/moudy/cross-zone-peer-cache-bound' into moudy/cross-zone-halt-operability 2026-08-19 21:13:18 +02:00
Moudy 7bcf5f04c6 Merge pull request #763 from logos-blockchain/moudy/cross-zone-peer-key-set
feat(cross_zone)!: accept peer blocks signed by any key in a configured set
2026-08-19 21:04:11 +02:00
Moudy dbb8e9245c Merge pull request #743 from logos-blockchain/moudy/cross-zone-peer-cache-bound
feat(indexer): bound the peer-block cache behind a hash-certified refetch
2026-08-19 20:35:37 +02:00
Moudy 4993885b6e Merge pull request #712 from logos-blockchain/moudy/cross-zone-source-authority
feat(cross-zone)!: let a target's peer sources be updated by a named authority
2026-08-19 20:34:28 +02:00
Moudy 9a7a71abf2 Merge pull request #718 from logos-blockchain/moudy/pending-dispatch-per-key
fix(storage): store pending cross-zone dispatches as per-message entries
2026-08-19 02:35:03 +02:00
moudyellaz 7c9d9dac10 Merge remote-tracking branch 'origin/dev' into moudy/pending-dispatch-per-key
# Conflicts:
#	lez/sequencer/core/src/cross_zone_watcher.rs
2026-08-19 01:59:01 +02:00
jonesmarvin8 96c8577db8 refactor(lee): fold program storage into public_state (#723)
V03State.programs is gone; deployed programs now live directly in public_state, keyed by AccountId::from(program_id) same as any other account. insert_program sets program_owner to a new reserved sentinel, PROGRAM_STORAGE_OWNER, instead of leaving it at the default.

That ownership choice is load-bearing now in a way it wasn't before: once program accounts share the same map as everything else, they're reachable through ordinary dispatch, so program_owner determines whether they're claimable/writable. Left unclaimed, a program invocation could legitimately claim a program's storage account via the normal claim path and then rewrite its elf; self-ownership has the same flaw, since it authorizes exactly the program whose own invocation would touch its own storage account. The reserved sentinel makes every program account unwritable by construction, since no real chained_call.program_id will ever derive to it.

Also centralizes the program-ownership check behind V03State::get_program and applies the program_owner AccountId migration to code added after the earlier rebase.
2026-08-18 12:44:06 -04:00
moudyellaz 72782beb34 chore: regenerate artifacts and the test fixture, bump h2 for RUSTSEC-2026-0258 2026-08-18 18:35:15 +02:00
moudyellaz aeb71b73ad test(cross_zone): cover multi-key acceptance at every enforcement site 2026-08-18 18:20:49 +02:00
moudyellaz 4309c2a214 feat(cross_zone)!: accept peer blocks signed by any key in a configured set
BREAKING CHANGE: CrossZonePeer.expected_block_signing_pubkey (single optional
key) is renamed to expected_block_signing_pubkeys (a list, empty = unchecked),
and cross-zone config now refuses unknown fields at startup.
2026-08-18 18:06:25 +02:00
jonesmarvin8andClaude Sonnet 5 2ba1ecd609 refactor!(lee): Change program_owner: ProgramId to AccountId (#722)
* feat(lee): store deployed programs as Account-shaped state, keyed by AccountId

Program-as-Account migration, first slice: V03State.programs becomes
HashMap<AccountId, Account> instead of HashMap<ProgramId, Program>,
with the elf held directly in Account.data. The map key is derived
from ProgramId via a new 1:1 From<ProgramId> for AccountId conversion
(both types are exactly 32 bytes) rather than a hash, since ProgramId
is already content-derived from the elf.

Account.program_owner stays ProgramId-typed everywhere - this only
changes how deployed programs are stored and looked up host-side, not
the dispatch/authorization model any guest program logic depends on.
Dispatch resolves a ChainedCall's program_id by converting to
AccountId, fetching the Account, and reconstructing a Program via
new_unchecked for execution.

DATA_MAX_LENGTH is raised from 100 KiB to 700 KiB to fit real program
elfs (observed 375 KB-631 KB) directly in Account.data; noted in its
docstring as a rough placeholder pending real transaction/block-size
budget analysis.

* fix(lee): store deployed programs as Account-shaped state, correct SeenShard cap

Corrects lee/state_machine internals for the Program-as-Account migration
and fixes SeenShard::MAX_DELIVERIES, which was still calibrated for the
old 100 KiB DATA_MAX_LENGTH instead of the current 700 KiB cap. Rebuilds
program artifacts and the sequencer test fixture to match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* address PR #720 review nits

- Use FIXME instead of TODO for the temporary ProgramId->AccountId
  conversion, per review convention for patches guaranteed to be
  fixed later.
- Derive cross_zone_inbox's MAX_DELIVERIES from DATA_MAX_LENGTH
  instead of a hand-recomputed literal, so it stays in sync
  automatically the next time the cap changes.

* feat(lee): migrate Account.program_owner from ProgramId to AccountId

Account.program_owner is now AccountId-typed instead of ProgramId,
via a new bijective From<ProgramId> for AccountId / From<AccountId>
for ProgramId conversion pair (pure byte reinterpretation, not a
hash - both types are exactly 32 bytes). Adds DEFAULT_PROGRAM_OWNER
as the AccountId-typed counterpart to DEFAULT_PROGRAM_ID, used at
every program_owner comparison/claim site instead of an inline
AccountId::default().

Touches every call site across lee_core, lee (including the
guest-side privacy-preserving circuit), all 16 deployed guest
programs, wallet/wallet-ffi, indexer_ffi/indexer_service/
indexer_service_protocol, sequencer_core, testnet_initial_state,
system_accounts, cross_zone, storage, cycle_bench, and
integration_tests - mostly mechanical .into() conversions, plus two
simplifications: wallet's manual base58 encode/decode of
program_owner was dead code once it's AccountId (which already has
Display/FromStr), and the FFI crates' program_owner field now reuses
the existing generic FfiBytes32 wrapper instead of the now-unused
FfiProgramId one.

Rebuilds every guest ELF artifact and the prebuilt sequencer test
fixture via just build-artifacts, since execute_and_prove runs
against the checked-in precompiled privacy_preserving_circuit.bin,
which isn't rebuilt automatically by cargo test/check.

* chore(lee): rebuild artifacts after rebase, drop unused base58 dep

Rebases marvin/program-as-account-2 onto the updated
marvin/program-as-account (SeenShard cap fix), regenerating program
and circuit artifacts plus the sequencer test fixture to match.
Also removes lez/wallet's now-unused base58 dependency, dead since
AccountId gained its own Display/FromStr base58 encoding.

* docs(lee): trim DEFAULT_PROGRAM_OWNER and From<AccountId> for ProgramId docs

* test(lee): add known-answer tests for ProgramId/AccountId conversion, rebuild artifacts

* fix(lee): apply program_owner AccountId migration to code added after rebase

dev grew new program_owner call sites (sequencer_stake genesis/config
handling, committee_discovery, a new selective_pda_delegator test
program, and related tests) after this branch's ProgramId->AccountId
migration commit was originally written, so they predated the .into()
sweep and didn't conflict during the rebase - they just still assumed
the old ProgramId-typed field. Converts all of them, fixes a stray
unseparated hex literal clippy caught along the way, and rebuilds
artifacts against the fixed source.

* chore(lee): regenerate test fixture after rebasing onto dev

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-18 11:26:57 -04:00
jonesmarvin8andClaude Sonnet 5 d52c76e2b5 refactor(lee): change programs shape (#720)
* feat(lee): store deployed programs as Account-shaped state, keyed by AccountId

Program-as-Account migration, first slice: V03State.programs becomes
HashMap<AccountId, Account> instead of HashMap<ProgramId, Program>,
with the elf held directly in Account.data. The map key is derived
from ProgramId via a new 1:1 From<ProgramId> for AccountId conversion
(both types are exactly 32 bytes) rather than a hash, since ProgramId
is already content-derived from the elf.

Account.program_owner stays ProgramId-typed everywhere - this only
changes how deployed programs are stored and looked up host-side, not
the dispatch/authorization model any guest program logic depends on.
Dispatch resolves a ChainedCall's program_id by converting to
AccountId, fetching the Account, and reconstructing a Program via
new_unchecked for execution.

DATA_MAX_LENGTH is raised from 100 KiB to 700 KiB to fit real program
elfs (observed 375 KB-631 KB) directly in Account.data; noted in its
docstring as a rough placeholder pending real transaction/block-size
budget analysis.

* fix(lee): store deployed programs as Account-shaped state, correct SeenShard cap

Corrects lee/state_machine internals for the Program-as-Account migration
and fixes SeenShard::MAX_DELIVERIES, which was still calibrated for the
old 100 KiB DATA_MAX_LENGTH instead of the current 700 KiB cap. Rebuilds
program artifacts and the sequencer test fixture to match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* address PR #720 review nits

- Use FIXME instead of TODO for the temporary ProgramId->AccountId
  conversion, per review convention for patches guaranteed to be
  fixed later.
- Derive cross_zone_inbox's MAX_DELIVERIES from DATA_MAX_LENGTH
  instead of a hand-recomputed literal, so it stays in sync
  automatically the next time the cap changes.

* chore: regenerate artifacts after rebasing onto dev

Binary program artifacts and the prebuilt sequencer DB dump were left
as rebase-conflict placeholders; regenerated via `just build-artifacts`
against the fully rebased source.

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-18 10:06:42 -04:00
Artem Gureev 3a718c32f5 Merge pull request #683 from logos-blockchain/artem/private-authorization-longevity
fix!(lee): scope private PDA authorization to the callee subtree
2026-08-18 17:31:14 +04:00
agureev 9b75c38a6d chore: update dep to fix deny 2026-08-18 15:11:03 +04:00
Moudy f2058b4c38 Merge pull request #744 from logos-blockchain/moudy/guest-cycle-hygiene
perf(lez)!: borrow account data in the guests instead of cloning
2026-08-18 00:57:09 +02:00
moudyellaz af090f3ce9 refactor(indexer): make the cache window a NonZeroU32 2026-08-18 00:55:58 +02:00
Moudy 3e1412ee6a Merge pull request #721 from logos-blockchain/moudy/cross-zone-shared-acceptance
fix(cross-zone): one peer-block acceptance policy for watcher and verifier
2026-08-18 00:33:09 +02:00
agureev 7b6b439eb2 chore: artifacts 2026-08-17 22:20:01 +04:00
Artem Gureev f83cf9b300 perf(lee): extend the caller set for the child authorization scope 2026-08-17 17:29:56 +00:00