Skip to content

enforce deployment limits on beacon blocks - #32

Open
mohammadfawaz wants to merge 5 commits into
mainfrom
enforce-deployment-limits
Open

enforce deployment limits on beacon blocks#32
mohammadfawaz wants to merge 5 commits into
mainfrom
enforce-deployment-limits

Conversation

@mohammadfawaz

@mohammadfawaz mohammadfawaz commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Motivation

Devnode beacon blocks skip proof verification, but they must enforce deployment limits. snarkVM 4.9.0 does not apply the block-wide spend and synthesis limits to beacon blocks. This can let an invalid deployment enter a development ledger.

This change keeps the released snarkVM 4.9.0 dependency. The devnode calculates and applies the beacon limits before it advances a block. Placeholder proofs and the existing dev_skip_checks behavior stay active.

Changes

  • Apply the beacon spend limit from consensus V16.
  • Apply the beacon synthesis limit from consensus V18.
  • Preserve transaction order when a limit or snarkVM aborts a candidate.
  • Return an error and do not create a block after an automatic-mode abort.
  • In manual mode, remove aborted transactions and keep valid transactions for a retry.

Test Plan

  • Run cargo fmt --all -- --check.
  • Run cargo test --locked.
  • Confirm that all 6 unit tests and all 6 integration tests pass.
  • Confirm that a real deployment cost from snarkVM crosses the beacon spend ceiling and aborts the excess candidate.
  • Confirm that raw snarkVM 4.9.0 accepts deployments that exceed the block synthesis limit.
  • Confirm that the devnode rejects the over-limit deployments.
  • Confirm that a later valid deployment with the same public fee payer stays valid.
  • Confirm that an oversized automatic deployment returns 422 on /v2 and does not change the ledger height.
  • Confirm that manual block creation returns 422, removes the aborted deployment, keeps valid deployments, and permits a successful retry.

Related PRs

@mohammadfawaz mohammadfawaz self-assigned this Aug 4, 2026
@mohammadfawaz
mohammadfawaz marked this pull request as ready for review August 4, 2026 16:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the devnode’s REST block-minting path to proactively enforce beacon-block deployment limits (spend from consensus V16 and synthesis from consensus V18) that snarkVM 4.9.0 does not apply to beacon blocks, while preserving the existing dev_skip_checks behavior.

Changes:

  • Adds limit calculation + transaction filtering for beacon-block preparation, and wires it into both auto and manual block creation flows.
  • Ensures transaction order is preserved across aborts, and changes behavior so aborted candidates return an error and do not produce a block (with manual mode retaining non-aborted buffered transactions for retry).
  • Expands unit tests and REST API docs to cover the new behavior and error semantics.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
src/start.rs Adds a guard test asserting the latest TEST_CONSENSUS_VERSION_HEIGHTS entry aligns with V18 expectations.
src/rest/routes.rs Implements beacon spend/synthesis limit enforcement during block preparation and updates auto/manual block creation behavior; adds extensive tests.
docs/rest-api.md Documents new 422 behavior and limit enforcement semantics for /transaction/broadcast and /block/create.
Suppressed comments (1)

src/rest/routes.rs:1124

  • This test mirrors the same min_certificates computation as beacon_block_limits, but it currently uses ceil(max_certificates/3) * 2, which overestimates a 2/3 quorum for some max_certificates values. Update it to match the corrected ceil(2*max_certificates/3) formula so the expected limits stay aligned with the implementation.
        let min_certificates = max_certificates.saturating_add(2).saturating_div(3).saturating_mul(2);

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/rest/routes.rs
let max_certificates = active_consensus_value(&N::MAX_CERTIFICATES, consensus_version)
.map(u64::from)
.ok_or_else(|| anyhow!("Missing MAX_CERTIFICATES for consensus version {consensus_version}"))?;
let min_certificates = max_certificates.saturating_add(2).saturating_div(3).saturating_mul(2);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants