2954 Commits

Author SHA1 Message Date
moudyellaz
fea373e317 fix(indexer): record cross-zone dispatch keys as seen only after the block applies
verify_block populated the seen-set before accept_block, so a dispatch verified in a block that then parked poisoned seen without the inbox ever recording the key on chain, letting a later forged dispatch reuse the key to skip re-derivation. verify_block now returns the verified keys and the ingest loop records them via record_seen only on AcceptOutcome::Applied, so seen mirrors the inbox's on-chain seen-shard.
2026-07-14 21:38:50 +02:00
moudyellaz
a16e22c46c refactor!(cross-zone): deploy programs at genesis instead of builtins
Cross-zone builtin programs are no longer registered in the production
genesis. A zone that participates declares the ones it uses via a new
GenesisAction::DeployProgram (sequencer) and a matching deploy_programs
list (indexer), both resolved through CrossZoneProgram and registered
with with_programs. Cross-zone genesis accounts (inbox config,
wrapped-token config) are seeded through the state constructor for a
receiving zone, and bridge-lock holdings are seeded from their actions
regardless of receiving config, dropping V03State::insert_genesis_account.
GenesisAction amounts now use the Balance alias. Documents cross_zone as
the reference LEZ adapter and the bridge demo as not production-safe.

The sequencer's DeployProgram set and the indexer's deploy_programs are
configured separately, so both nodes now log a deterministic genesis
fingerprint (V03State::genesis_fingerprint) at startup: equal values
confirm the two genesis states agree, a mismatch flags a divergent
deploy set.

BREAKING CHANGE: the genesis state root changes (cross-zone builtins are
out of production genesis) and the sequencer/indexer configs gain the
DeployProgram / deploy_programs list that cross-zone-participating zones
must set.
2026-07-13 19:12:24 +02:00
moudyellaz
de2dc8e04d fix(indexer): accept a replayed cross-zone dispatch instead of halting
The Option B verifier returned Err on a cross-zone dispatch whose message key
was already in its seen set, and that halts indexer ingestion. A legitimate
re-delivery, for example after a sequencer restart re-injects, could then
permanently stall an honest indexer. The inbox already treats a re-delivered
message as an idempotent no-op on chain, so the verifier now continues past an
already-seen key instead of bailing. Forgery detection on first-seen dispatches
is unchanged.

Also notes that one pinned block-signing key per peer is sufficient until
decentralized sequencing, and strengthens the replay test so it only passes via
the seen-key short-circuit.
2026-07-13 11:06:49 +02:00
moudyellaz
b8e21ed276 chore(cross-zone): remove duplicate top-level programs core crates
Remove the stale top-level programs/ core crates (bridge_lock_core,
cross_zone_inbox_core, cross_zone_outbox_core, ping_core, wrapped_token_core),
leftover copies from the initial cross-zone port before programs moved to the
per-program-crate layout. The live cores under lez/programs/*/core keep the
same package names and remain the ones actually used.
2026-07-13 08:29:36 +02:00
Moudy
cac4921581
Merge pull request #542 from logos-blockchain/moudy/feat-cross-zone-messaging
feat!(cross-zone): async LEZ to LEZ cross-zone messaging
2026-07-11 02:24:34 +02:00
moudyellaz
eff31df9ce Merge origin/dev 2026-07-11 01:12:00 +02:00
moudyellaz
c9b6df2be9 chore(cross-zone): remove stale old-style program_methods guest bins 2026-07-10 19:02:23 +02:00
erhant
5e53c34e80
Merge pull request #581 from logos-blockchain/erhant/indexer-recoverable-invalid-blocks
feat(indexer): recoverable invalid blocks
2026-07-10 18:58:10 +03:00
erhant
ce37428e1e fix(indexer): handle park_undeserializable errors properly 2026-07-10 18:35:01 +03:00
erhant
1560b27d02 refactor(indexer): auto-cancel token on Drop 2026-07-10 18:35:01 +03:00
erhant
d22f8b540b refactor(indexer): make put_block own the breakpoint schedule
`RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p storage -p indexer_core`
2026-07-10 18:35:01 +03:00
erhant
280885532b refactor(indexer): rename AcceptOutcome::ApplyFailed to RetryableFailure 2026-07-10 18:35:01 +03:00
erhant
9587cf96be refactor(indexer): remove now-redundant last_breakpoint_id meta cell 2026-07-10 18:35:01 +03:00
erhant
4d0be72973 chore(indexer): comment 2026-07-10 18:35:01 +03:00
erhant
2e49cdfd9c fix(indexer): harden stall durability and breakpoint guards w.r.t. Copilot review 2026-07-10 18:35:01 +03:00
erhant
587836e47c fix(indexer): stop ingest loop cooperatively on shutdown 2026-07-10 18:35:01 +03:00
erhant
ff6d40f4df fix(indexer): retry apply failures before parking 2026-07-10 18:35:01 +03:00
erhant
07eaf1021a fix(indexer): do not park immediately on possibly-transient apply failures 2026-07-10 18:35:01 +03:00
erhant
ed6a3f56dd fix(indexer): snapshot breakpoint state from the validated scratch state 2026-07-10 18:35:01 +03:00
erhant
c297ad31d2 fix(indexer): seed breakpoint meta only on fresh store
`RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p storage -p indexer_core`
2026-07-10 18:35:01 +03:00
erhant
e706211631 fix(indexer): walk down to nearest breakpoint 2026-07-10 18:35:01 +03:00
erhant
93c311be3b fix(indexer): initial prep for breakpoint fix 2026-07-10 18:35:01 +03:00
erhant
88736d7421 fix(indexer): keep track of L1 slot of last inscription for correct tracking 2026-07-10 18:35:01 +03:00
erhant
f188dbdb97 test(indexer): rename test, move to more suitable file 2026-07-10 18:35:01 +03:00
erhant
f99d7fef59 chore: clippy docfix + bump crossbeam-epoch (RUSTSEC-2026-0204) 2026-07-10 18:35:01 +03:00
erhant
025105b570 fix(indexer): allow recovery from parked-and-stalled store (w.r.t Copilot review)
refactor(indexer): move chain-consistency code within a dedicated file
2026-07-10 18:35:01 +03:00
erhant
1ca3de47b9 chore: docfix w.r.t Copilot 2026-07-10 18:35:00 +03:00
erhant
2c395b95a6 chore: fix typos, enable ignored test 2026-07-10 18:35:00 +03:00
erhant
f563f675ac fix(indexer): tend to @schouhy reviews, allow re-applied old blocks 2026-07-10 18:35:00 +03:00
erhant
0985df9059 chore: typo fix ChainConsistency [skip ci] 2026-07-10 18:35:00 +03:00
erhant
16888478dd refactor(indexer): tend to several reviews by @schouhy 2026-07-10 18:35:00 +03:00
erhant
82a16f1ab7 fix(indexer): use better error types, tend to few @Arjentix PR review 2026-07-10 18:35:00 +03:00
erhant
f94a63d8cf fix(indexer)!: address several reviews, use better return types with conversions, some docfixes
BREAKING CHANGE: dropping the serde rename attrs changes the FFI
`query_status` JSON: `state` values are now variant-cased
(`caught_up` -> `CaughtUp`) and fields snake_case
(`indexedBlockId` -> `indexed_block_id`, `lastError` -> `last_error`).
Consumers (lez-indexer-module, lez-explorer-ui) must update their parsing.
2026-07-10 18:35:00 +03:00
erhant
da95e86083 chore: very small comment about future fix [skip ci] 2026-07-10 18:35:00 +03:00
erhant
b5ed8548d5 fix(indexer): catch the edge case of re-using the last valid tip on restart 2026-07-10 18:35:00 +03:00
erhant
255a94c8ed fix(indexer): attend to copilot comments, rm Store error from a park case 2026-07-10 18:35:00 +03:00
erhant
aceb863ff2 chore: rm redundant unit test [skip ci] 2026-07-10 18:35:00 +03:00
erhant
db48877ca6 fix(indexer): run the chain-identity check even when the store is parked 2026-07-10 18:35:00 +03:00
erhant
2b5379a0c7 fix(indexer): run the chain-identity check even when the store is parked 2026-07-10 18:35:00 +03:00
erhant
66434256da fix(indexer): detect chain reset via anchor block, **not** deterministic genesis
test `RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core`
2026-07-10 18:35:00 +03:00
erhant
b989974f90 chore: greatly increase timeout 2026-07-10 18:35:00 +03:00
erhant
06ec24540a feat(indexer): run genesis-consistency check at service and FFI startup 2026-07-10 18:35:00 +03:00
erhant
aa46b69b79 feat(indexer): add startup genesis-consistency check
test `RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core`
2026-07-10 18:35:00 +03:00
erhant
a583c1f21a test(indexer): cover stall recovery and full StallReason roundtrip
test `RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core`
2026-07-10 18:35:00 +03:00
erhant
eaf2e2d07f feat(indexer): expose status over RPC and add integration coverage
test `RUST_LOG=info RISC0_DEV_MODE=1 cargo test -p integration_tests --test bridge --indexer_status_rpc_reports_caught_up_with_no_stall --exact --nocapture --include-ignored`
2026-07-10 18:35:00 +03:00
erhant
b71b01f94b chore: fix linter 2026-07-10 18:35:00 +03:00
erhant
de55d2699b feat(indexer): park ingest loop on bad blocks instead of skipping
`RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core`
2026-07-10 18:35:00 +03:00
erhant
c49cc7bc29 refactor(indexer): use "stall reason" instead of "chain breaker" 2026-07-10 18:35:00 +03:00
erhant
e28cceffab feat(indexer): add Stalled status and chain breaker snapshot
test `RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core --lib status`
2026-07-10 18:35:00 +03:00
erhant
6ab6455482 feat(indexer): add accept_block with chain-linkage check and atomic apply
test `RISC0_DEV_MODE=1 RISC0_SKIP_BUILD=1 cargo test -p indexer_core --lib accept_tests`
2026-07-10 18:35:00 +03:00