Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
3f8eaaf
consensus/bor, eth, miner, internal/cli: add sequence store publisher…
cffls Aug 10, 2026
be1f617
eth/sequencer, miner, eth: cover the consumer path, decompose oversiz…
cffls Aug 13, 2026
dff3867
eth/sequencer: drop an ineffectual assignment the linter flagged
cffls Aug 13, 2026
525f258
eth/sequencer, miner, eth: widen patch coverage over store shapes and…
cffls Aug 14, 2026
7171904
miner, eth/sequencer, internal/cli: address review findings
cffls Aug 21, 2026
96412ea
eth/sequencer, eth: floor the backfill at milestone finality
cffls Aug 24, 2026
6ecbd13
eth/sequencer, miner: cover the partial floor drain and the grace re-…
cffls Aug 24, 2026
1c28849
miner: fix a chainConfig swap race in the adoption floor tests
cffls Aug 24, 2026
4f2727b
consensus, eth, miner: fix sequencer reorg holds, partial adoption, a…
cffls Aug 26, 2026
eff7587
miner: deflake TestStoreOwnedHeightDiscardsTheBuild
cffls Aug 27, 2026
8181bd4
eth/sequencer, miner: consensus-verify foreign store seals, clear ref…
cffls Aug 29, 2026
1095d6c
eth, core: harden pending preconfirmation lifecycle
0xrukimedo Aug 31, 2026
eb201fd
eth, gasprice: harden preconfirmation RPC flow
0xrukimedo Aug 31, 2026
7e5f884
eth/sequencer: let a takeover seal over a clean store boundary
cffls Aug 31, 2026
0b47aee
eth/sequencer: cap barrier refusals, bound the gate's seal verification
cffls Aug 31, 2026
0aedd6c
eth/sequencer: pass the seal barrier on a verified mid-drain suffix
cffls Sep 1, 2026
ad793b0
eth/sequencer: name the journal-mirror rung
cffls Sep 1, 2026
73af77d
Merge branch 'cffls/sequence-publisher' into feat/pbc-rpc-endpoints
0xrukimedo Sep 2, 2026
5e3ba2f
add check for nil entry
0xrukimedo Sep 2, 2026
f138c7a
eth/sequencer: keep preconf stream live during seal verification
0xrukimedo Sep 2, 2026
fb01631
eth, sequencer: validate Sequence Store pending RPC pipeline
0xrukimedo Sep 2, 2026
87a2603
eth/sequencer: stop the ack watchdog and contention streak from firin…
cffls Sep 2, 2026
aa32267
Merge branch 'cffls/sequence-publisher' into feat/pbc-rpc-endpoints
cffls Sep 2, 2026
faa1239
eth, ethapi: cover pending parent-state RPC paths
0xrukimedo Sep 3, 2026
a5b26ef
eth/sequencer: reduce pending view publication overhead
0xrukimedo Sep 3, 2026
1fd61e8
reduce state copies while building payload
0xrukimedo Sep 3, 2026
5abfcc6
Skip nil log entries in pending_helpers
0xrukimedo Sep 3, 2026
4dedaa6
Handle nil log entries in receipt cloning
0xrukimedo Sep 3, 2026
796727f
rpc, ethapi: release the execution slot while eth_sendRawTransactionS…
pratikspatil024 Sep 4, 2026
7bfc070
PR comments
0xrukimedo Sep 4, 2026
151ef46
remove docs
0xrukimedo Sep 4, 2026
d314363
ethapi, rawdb: make bor_getInvalidPreconfBlocks take a block range
cffls Sep 4, 2026
69deae9
Merge remote-tracking branch 'origin/develop' into cffls/sequence-pub…
cffls Sep 4, 2026
89143d7
use pre conf events and batching
0xrukimedo Sep 4, 2026
d6e82ca
lint
0xrukimedo Sep 4, 2026
a2adc08
Merge pull request #2373 from 0xPolygon/feat/pbc-rpc-endpoints
cffls Sep 4, 2026
4b07a05
params: version bump to v2.10.2-beta
pratikspatil024 Sep 7, 2026
1552c89
Merge pull request #2393 from 0xPolygon/cffls/pending-head-fallback
cffls Sep 8, 2026
1932baa
eth: preserve preconfirmation RPC availability (#2394)
0xrukimedo Sep 8, 2026
1e20c79
internal/cli/server: require sequencer publisher-endpoint only for pr…
cffls Sep 8, 2026
b56ff74
eth/sequencer: cap coalesced published records at the store message l…
cffls Sep 10, 2026
a6ee9b5
params: gofmt version constant comments
lucca30 Sep 15, 2026
7e6f183
sequencer: stop paying for a store that is not answering (#2406)
pratikspatil024 Sep 16, 2026
f13a0de
Merge branch 'develop' of github.com:0xPolygon/bor into v2.10.2-candi…
pratikspatil024 Sep 17, 2026
44ec7db
sequencer, rawdb, ethapi: audit the store for the window a node did n…
pratikspatil024 Sep 17, 2026
d42ed48
ci: add kurtosis sequencer e2e workflow
cffls Sep 17, 2026
f620a4b
eth/sequencer: trip read breaker on a frozen store tail
cffls Sep 17, 2026
a3f8f71
Merge branch 'develop' of github.com:0xPolygon/bor into v2.10.2-candi…
pratikspatil024 Sep 18, 2026
bd81167
core/txpool, eth, p2p: control rebroadcast and peer traffic (#2418)
0xrukimedo Sep 18, 2026
726d228
core, eth: detect and self-heal missing contract code on stateless ve…
lucca30 Sep 18, 2026
68a4609
Merge pull request #2423 from 0xPolygon/cffls/ci-sequencer-e2e
cffls Sep 18, 2026
8a4713f
Merge pull request #2419 from 0xPolygon/cffls/sequence-publisher
cffls Sep 18, 2026
b731e7e
eth, eth/fetcher: bound witness page count by the gas-derived ceiling…
lucca30 Sep 18, 2026
2b053a3
eth/sequencer, rawdb: record served preconfirmations to close the ope…
kamuikatsurgi Sep 21, 2026
cfc796f
eth/sequencer: stop falsely invalidating state-sync (sprint-start) bl…
kamuikatsurgi Sep 21, 2026
9d49625
Merge branch 'develop' of github.com:0xPolygon/bor into v2.10.2-candi…
pratikspatil024 Sep 22, 2026
b50f0e8
eth/protocols/wit, eth: WIT2 size oracle — accept non-deterministic w…
lucca30 Sep 22, 2026
d59b632
eth/downloader: restrict sync penalty exemptions to trusted peers (#2…
0xrukimedo Sep 21, 2026
77cb718
eth/downloader/whitelist: accept re-import of canonical blocks below …
lucca30 Sep 22, 2026
7fd8e52
eth/sequencer: number preconfirmation logs per block (#2430)
cffls Sep 22, 2026
39419d3
eth/downloader, eth/downloader/whitelist, internal/cli/server: forwar…
pratikspatil024 Sep 22, 2026
df97556
eth/sequencer: judge served preconf commitments the audit watermark a…
kamuikatsurgi Sep 22, 2026
57e265c
Bump up version to v2.10.2-beta2
cffls Sep 22, 2026
c3e748b
eth: extend the pending head fallback to PendingLogRange (#2437)
cffls Sep 22, 2026
afcb7d9
core, eth/sequencer, internal/ethapi: preserve preconf receipts acros…
kamuikatsurgi Sep 23, 2026
065a531
Bump up version to v2.10.2-beta3
cffls Sep 23, 2026
ded9d72
eth, eth/sequencer: skip receipt copy on pending state reads (#2444)
kamuikatsurgi Sep 26, 2026
c98a9b3
core, eth, internal/syncx: don't switch to snap sync mid-SetHead (#2456)
kamuikatsurgi Sep 28, 2026
1676806
Bump up version to v2.10.2-beta4
cffls Sep 28, 2026
90e48b3
eth/sequencer: don't hold a build behind our own acked parent seal (#…
cffls Sep 28, 2026
b2760dc
Bump up version to v2.10.2-beta5
cffls Sep 28, 2026
60b9707
Bump up version to v2.10.2
cffls Sep 29, 2026
9c445ef
v2.10.2 candidate (#2466)
kamuikatsurgi Sep 30, 2026
8f9d7cb
Merge branch 'master' into lmartins/backmerge-v2.10.2
lucca30 Oct 5, 2026
040598e
p2p: use jailedUntil in peer jail test after backmerge
lucca30 Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
212 changes: 212 additions & 0 deletions .github/workflows/kurtosis-sequencer-e2e.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,212 @@
name: Kurtosis Sequencer E2E Tests

# Exercises the sequence-store publisher and consumer end to end against a
# bor built from this checkout: publishers live after Rio, production
# through a store outage, the recovery backfill, preconf receipts on the RPC
# node, and the store chaos episodes. The suites and devnet config live in
# pos-workflows; this workflow only supplies the bor under test.
#
# Scoped to the sequencing branch: pos-workflows runs the same suites, but
# builds bor from a fixed ref, so it cannot gate a bor PR.
on:
push:
branches:
- 'cffls/sequence-publisher'
pull_request:
branches:
- 'cffls/sequence-publisher'
types: [opened, synchronize, reopened]
workflow_dispatch:

concurrency:
group: kurtosis-sequencer-e2e-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

env:
ENCLAVE_NAME: kurtosis-sequencer-e2e
# sequence-store publishes `dev` on every push to its default branch and
# version tags on `v*` releases; pin a vX.Y.Z once one is cut.
SEQUENCE_STORE_TAG: dev
POLYCLI_VERSION: v0.1.103

jobs:
build-bor:
permissions:
contents: read
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout bor
uses: actions/checkout@v7
with:
persist-credentials: false

- name: Build bor docker image
run: docker build -t bor:local --file Dockerfile .

- name: Save bor docker image
run: docker save bor:local | gzip > bor-image.tar.gz

- name: Upload bor docker image
uses: actions/upload-artifact@v7
with:
name: sequencer-bor-image
path: bor-image.tar.gz
retention-days: 1

build-heimdall-v2:
permissions:
contents: read
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout heimdall-v2
uses: actions/checkout@v7
with:
repository: 0xPolygon/heimdall-v2
ref: develop
persist-credentials: false

- name: Build heimdall-v2 docker image
run: docker build -t heimdall-v2:local --file Dockerfile .

- name: Save heimdall-v2 docker image
run: docker save heimdall-v2:local | gzip > heimdall-v2-image.tar.gz

- name: Upload heimdall-v2 docker image
uses: actions/upload-artifact@v7
with:
name: sequencer-heimdall-v2-image
path: heimdall-v2-image.tar.gz
retention-days: 1

e2e-tests:
needs:
- build-bor
- build-heimdall-v2
# The sequence-store image is a private ghcr package. Fork pull_request
# runs get neither repository secrets nor a token that can read it, so
# the suite would only fail at the pull; run it for trusted refs only.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
# Three suites share one enclave: functional (~25m, most of it reaching
# Rio at 4s blocks), rpc (~5m), chaos (~10m).
timeout-minutes: 75
permissions:
contents: read
id-token: write
# Lets the default GITHUB_TOKEN pull the sequence-store package, which
# this repository is granted read access on.
packages: read
steps:
# v1.4.2 is the first release tag carrying the sequence-store launcher.
- name: Checkout kurtosis-pos
uses: actions/checkout@v7
with:
repository: 0xPolygon/kurtosis-pos
ref: v1.4.2
persist-credentials: false

- name: Pre kurtosis run
uses: ./.github/actions/kurtosis/setup
with:
main_branch: develop
docker_username: ${{ secrets.DOCKERHUB }}
docker_token: ${{ secrets.DOCKERHUB_KEY }}

- name: Checkout pos-workflows
uses: actions/checkout@v7
with:
repository: 0xPolygon/pos-workflows
ref: main
path: pos-workflows
persist-credentials: false

- name: Copy kurtosis config
run: cp ./pos-workflows/configs/kurtosis-sequencer-e2e.yml ./kurtosis-sequencer-e2e.yml

# Load images
- name: Download bor docker image
uses: actions/download-artifact@v8
with:
name: sequencer-bor-image

- name: Download heimdall-v2 docker image
uses: actions/download-artifact@v8
with:
name: sequencer-heimdall-v2-image

- name: Load bor docker image
run: |
gunzip -c bor-image.tar.gz | docker load
echo "Loaded bor docker image:"
docker images bor:local --format "{{.ID}} {{.CreatedAt}}"

- name: Load heimdall-v2 docker image
run: |
gunzip -c heimdall-v2-image.tar.gz | docker load
echo "Loaded heimdall-v2 docker image:"
docker images heimdall-v2:local --format "{{.ID}} {{.CreatedAt}}"

# The package grant covers the default token; SEQUENCE_STORE_GHCR_TOKEN
# is an optional fine-grained PAT (read:packages) override.
- name: Pull sequence-store image
env:
GHCR_TOKEN: ${{ secrets.SEQUENCE_STORE_GHCR_TOKEN != '' && secrets.SEQUENCE_STORE_GHCR_TOKEN || secrets.GITHUB_TOKEN }}
run: |
echo "$GHCR_TOKEN" | docker login ghcr.io -u ${{ github.actor }} --password-stdin
docker pull ghcr.io/0xpolygon/sequence-store:${{ env.SEQUENCE_STORE_TAG }}
docker tag ghcr.io/0xpolygon/sequence-store:${{ env.SEQUENCE_STORE_TAG }} seqstore:local
docker images seqstore:local --format "{{.ID}} {{.CreatedAt}}"

# Deploy kurtosis enclave
- name: Kurtosis run
run: kurtosis run --args-file=kurtosis-sequencer-e2e.yml --enclave=${{ env.ENCLAVE_NAME }} .

- name: Inspect enclave
run: kurtosis enclave inspect ${{ env.ENCLAVE_NAME }}

- name: Install polycli
run: |
tmp_dir=$(mktemp -d)
curl -L https://github.com/0xPolygon/polygon-cli/releases/download/${{ env.POLYCLI_VERSION }}/polycli_${{ env.POLYCLI_VERSION }}_linux_amd64.tar.gz | tar -xz -C "$tmp_dir"
mv "$tmp_dir"/* /usr/local/bin/polycli
rm -rf "$tmp_dir"
sudo chmod +x /usr/local/bin/polycli
polycli version

- name: Run sequencer e2e tests
id: sequencer-tests
working-directory: pos-workflows/tests/sequencer_tests
run: bash kurtosis_sequencer_test.sh

- name: Run sequencer rpc tests
id: sequencer-rpc-tests
working-directory: pos-workflows/tests/sequencer_tests
run: bash sequencer_rpc_test.sh

# Last: every episode breaks a store component, so the enclave is left
# perturbed even when all of them repair cleanly.
- name: Run sequencer chaos tests
id: sequencer-chaos-tests
working-directory: pos-workflows/tests/sequencer_tests
run: bash sequencer_chaos_test.sh

# Collect diagnostics on failure
- name: Collect network diagnostics and state dump
if: >-
always() && (
steps.sequencer-tests.outcome == 'failure' ||
steps.sequencer-rpc-tests.outcome == 'failure' ||
steps.sequencer-chaos-tests.outcome == 'failure')
uses: ./pos-workflows/.github/actions/network-diagnostics-and-state-dump
with:
enclave_name: ${{ env.ENCLAVE_NAME }}

# Clean up
- name: Post kurtosis run
if: always()
uses: ./.github/actions/kurtosis/cleanup
with:
main_branch: develop
enclave_name: ${{ env.ENCLAVE_NAME }}
2 changes: 1 addition & 1 deletion .golangci.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# This file configures github.com/golangci/golangci-lint.
version: '2'
run:
go: '1.26.8'
go: '1.26.5'
tests: true
linters:
default: none
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# ─── BUILDER STAGE ───────────────────────────────────────────────────────────────
FROM golang:1.26.8-alpine AS builder
FROM golang:1.26.5-alpine AS builder

ARG BOR_DIR=/var/lib/bor/
ENV BOR_DIR=$BOR_DIR
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.alltools
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Build Geth in a stock Go builder container
FROM golang:1.26.8-alpine AS builder
FROM golang:1.26.5-alpine AS builder

RUN apk add --no-cache make gcc musl-dev linux-headers git

Expand Down
1 change: 1 addition & 0 deletions cmd/geth/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,7 @@ var (
utils.BatchResponseMaxSize,
utils.RPCTxSyncDefaultTimeoutFlag,
utils.RPCTxSyncMaxTimeoutFlag,
utils.RPCTxSyncMaxConcurrentFlag,
}

metricsFlags = []cli.Flag{
Expand Down
2 changes: 1 addition & 1 deletion cmd/keeper/go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/ethereum/go-ethereum/cmd/keeper

go 1.26.8
go 1.26.5

require (
github.com/ProjectZKM/Ziren/crates/go-runtime/zkvm_runtime v0.0.0-20260104020744-7268a54d0358
Expand Down
10 changes: 10 additions & 0 deletions cmd/utils/flags.go
Original file line number Diff line number Diff line change
Expand Up @@ -681,6 +681,12 @@ var (
Value: ethconfig.Defaults.TxSyncMaxTimeout,
Category: flags.APICategory,
}
RPCTxSyncMaxConcurrentFlag = &cli.IntFlag{
Name: "rpc.txsync.maxconcurrent",
Usage: "Maximum eth_sendRawTransactionSync calls waiting for a receipt at once (0 = no limit)",
Value: ethconfig.Defaults.TxSyncMaxConcurrent,
Category: flags.APICategory,
}
// Authenticated RPC HTTP settings
AuthListenFlag = &cli.StringFlag{
Name: "authrpc.addr",
Expand Down Expand Up @@ -1891,6 +1897,10 @@ func SetEthConfig(ctx *cli.Context, stack *node.Node, cfg *ethconfig.Config) {
if ctx.IsSet(RPCTxSyncDefaultTimeoutFlag.Name) {
cfg.TxSyncDefaultTimeout = ctx.Duration(RPCTxSyncDefaultTimeoutFlag.Name)
}
if ctx.IsSet(RPCTxSyncMaxConcurrentFlag.Name) {
cfg.TxSyncMaxConcurrent = ctx.Int(RPCTxSyncMaxConcurrentFlag.Name)
}

if ctx.IsSet(RPCTxSyncMaxTimeoutFlag.Name) {
cfg.TxSyncMaxTimeout = ctx.Duration(RPCTxSyncMaxTimeoutFlag.Name)
}
Expand Down
29 changes: 28 additions & 1 deletion consensus/bor/bor.go
Original file line number Diff line number Diff line change
Expand Up @@ -1164,7 +1164,9 @@ func (c *Bor) Prepare(chain consensus.ChainHeaderReader, header *types.Header, w
if err != nil {
// If the signer is not in the active validator set, use succession 0
// so that the pending block header is still valid for RPC queries.
// Seal() will independently reject the block if unauthorized.
// Seal() will independently reject the block if unauthorized, and
// the miner keeps such a build out of the sequence store (see
// IsAuthorizedSigner).
succession = 0
}
}
Expand Down Expand Up @@ -1552,6 +1554,31 @@ func (c *Bor) commitSprintWork(chain consensus.ChainHeaderReader, header *types.

// Authorize injects a private key into the consensus engine to mint new blocks
// with.
// IsAuthorizedSigner reports whether the node's signer may seal the given
// prepared header (post-Rio: whether it is among the span's selected
// producers), mirroring Seal's refusal checks. The miner consults it before
// publishing a build's sequence: a block Seal would refuse must produce no
// store records. Nodes without a signer are not authorized.
func (c *Bor) IsAuthorizedSigner(chain consensus.ChainHeaderReader, header *types.Header) bool {
signer := c.authorizedSigner.Load().signer
if signer == (common.Address{}) {
return false
}

snap, err := c.snapshot(chain, header, nil, false)
if err != nil {
return false
}

if !snap.ValidatorSet.HasAddress(signer) && !snap.isAllowedByValidatorSetOverride(signer, header.Number.Uint64()) {
return false
}

_, err = snap.GetSignerSuccessionNumber(signer)

return err == nil
}

func (c *Bor) Authorize(currentSigner common.Address, signFn SignerFn) {
c.authorizedSigner.Store(&signer{
signer: currentSigner,
Expand Down
Loading
Loading