Skip to content

refactor: share rust-dashcore BLS backend through dpp::bls - #5320

Merged
lklimek merged 13 commits into
chore/rust-dashcore-1112-v5.1from
test/bls-backend-compatibility
Oct 7, 2026
Merged

lklimek merged 13 commits into
chore/rust-dashcore-1112-v5.1from
test/bls-backend-compatibility

Conversation

@lklimek

@lklimek lklimek commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Basic explanation

What this does: Moves Platform signing and signature verification to the same BLS backend as rust-dashcore and consolidates the Rust API and Serde support under dpp::bls.

Value: Removes the blsful → blstrs_plus dependency chain and the workspace-wide Git patch for blst.

Risks: Cryptographic compatibility is covered by frozen vectors and differential checks; no consensus-rule change is intended. Rust callers must update BLS type imports. Retaining decoded public keys and signatures increases their in-memory size while avoiding repeated decoding during verification. Historical database readers remain supported; their proposed removal is isolated in stacked draft #5323 for discussion.

Issue being fixed or feature implemented

Stacked on #5307, targeting chore/rust-dashcore-1112-v5.1.

The previous BLS dependency chain pinned blst = 0.3.12, requiring a Git patch for WASM aggregate verification. This change shares rust-dashcore's pinned dash-pkc backend and uses registry blst 0.3.17.

What was done?

  • Introduce DPP-owned PublicKey, SecretKey, Signature and BlsError under dpp::bls; move the implementation into packages/rs-dpp/src/bls/ and update repository consumers. Remove dpp::bls_signatures.
  • Preserve Basic signing, keygen-v3, modern/legacy public-key bytes, nonzero scalar reduction, canonical infinity parsing and rejection of infinity during verification. Preserve supported binary/JSON key encodings.
  • Remove blsful, blstrs_plus and the root blst patch. Use dash-pkc revision e6402ced257c370a586ade9840ebbf545a4b7926, matching rust-dashcore. Rand versions are unchanged.
  • Consolidate Serialize/Deserialize and field adapters in bls/serde.rs, sharing the key visitor. Binary Deserialize uses deserialize_tuple(48, ...); field adapters retain deserialize_any for buffered tagged data. Keep serialization::dashcore::bls_pubkey and its option adapter as a deprecated compatibility re-export.
  • Retain the historical Platform-state V0 and quorum-storage V0/V1 readers, their format tags, and the separate C++ bls-signatures dependency used for storage compatibility and test fixtures.
  • Retain validated backend points for signature verification and aggregation; represent historically accepted canonical infinity separately and reject it during verification. PublicKey remains an opaque struct backed by a private Infinity/Validated enum. Backend verification checks remain enabled.
  • Add frozen compatibility vectors, negative-input tests and storage fixtures with provenance and reproduction instructions. Exercise DPP's legacy-key conversion for both parsed and derived keys against frozen historical bytes.
  • Freeze a complete historical V0 quorum-storage record generated at pre-migration commit 7c73e983b4c3cd9b5e2ead34bbe0360646b7b4d9. Decode through the production storage enum and restore both current and previous quorum lists, asserting keys, hashes, indexes, configuration and height metadata. Include fixture provenance, checksum and reproduction source.
  • Document the Rust API migration in the Unreleased changelog.

In-place changes to shipped generations

Signature-processing and validator methods receive type/accessor substitutions while retaining digests, protocol dispatch and cryptographic acceptance rules. Historical local storage formats remain readable. Supported serialized bytes, existing stored-state hashes and consensus rules are preserved; Serde implementation changes are covered by frozen byte fixtures and tagged-value/bincode tests.

How Has This Been Tested?

  • Historical quorum storage: all 40 drive-abci quorum-module tests passed, including the frozen V0 restoration test; drive-abci Clippy passed with --all-targets --all-features --locked --offline -- --no-deps -D warnings. The 350-byte fixture was generated successfully by the pre-migration code in a separate checkout.

  • Eight DPP frozen compatibility tests passed on the final implementation, including legacy-key conversion through DPP, Basic signatures, secure aggregation, scalar boundaries, malformed/subgroup points, infinity rejection and historical validator storage. The expanded suite also passed before changing the point representation.

  • The private-public-key-enum refactor passed the eight compatibility tests, 14 DPP BLS/Serde/core-type tests, and DPP all-target/all-feature Clippy with the same flags below.

  • Before the private-enum refactor, 259 targeted tests passed across DPP BLS/Serde/core types/signing, simple-signer, proof verification, drive-abci platform types and ChainLocks, and wallet masternode lookup/provider updates.

  • Before the private-enum refactor, Clippy passed for dpp, simple-signer, drive-proof-verifier, drive-abci and platform-wallet with --all-targets --all-features --locked --offline -- --no-deps -D warnings.

  • Formatting of the changed Rust files and whitespace checks passed.

Limitations: No full workspace runtime suite, WASM/mobile validation, live-network replay or benchmarks were run for the retained-point implementation. Backend subgroup checks during verification remain enabled; no measured speedup is claimed. Cargo emits the existing DPP manifest warning that default-features is ignored for the inherited dashcore dependency.

Breaking Changes

  • Rust API: import dpp::bls::{PublicKey, SecretKey, Signature, BlsError}. Generic blsful types and schemes are no longer exposed. Use PublicKey::to_bytes(), SecretKey::from_be_bytes() returning Option, and Basic sign(message) / Signature::from_compressed(). Key Display/Debug output uses compressed encodings.
  • Serde adapter compatibility: the former serialization::dashcore::bls_pubkey path remains as a deprecated re-export of bls::serde, including option.
  • Database compatibility: historical readers are retained. This PR imposes no new intermediate-upgrade requirement.
  • FFI signatures and ownership remain unchanged. No protocol activation is required. The title omits ! according to the repository's explicit consensus-breaking convention; the Rust source incompatibility is documented here and in CHANGELOG.md.

Checklist:

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional/e2e tests
  • I have added "!" to the title and described breaking changes in the corresponding section if my code contains any
  • I have made corresponding changes to the documentation if needed
  • If I added or changed GroveDB structure, I described it in the area's structure.rs, regenerated grovedb-structure.json, and checked the structure viewer link posted on this pull request

For repository code-owners and collaborators only

  • I have assigned this pull request to a milestone

🤖 Co-authored by Claudius the Magnificent AI Agent

Summary by CodeRabbit

  • New Features
    • Added support for BLS key generation, signing, verification, and secure signature aggregation through a unified API.
    • Added compatibility checks for BLS operations and validator data serialization.
  • Documentation
    • Documented the BLS API migration and updated usage guidance.
  • Compatibility
    • Existing serialized encodings and consensus rules remain unchanged. The former BLS serialization adapter remains available as a deprecated alias.

lklimek and others added 5 commits October 7, 2026 08:00
Record signatures, secure aggregates, scalar boundary behavior, key generation
and persisted validator bytes before replacing the BLS implementation.
All eight compatibility tests pass on the original backend.

Co-authored-by: Codex <noreply@openai.com>
Preserve historical scalar reduction, infinity parsing, signature bytes and
validator serialization with the previously committed compatibility vectors.
Adapt repository consumers and replace the blst git patch with registry 0.3.17.

Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: dashpay/platform/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 415f810b-ace7-43d1-9cc9-127211dc2737
📥 Commits

Reviewing files that changed from the base of the PR and between 7c73e98 and 1d729f9.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (61)
  • CHANGELOG.md
  • Cargo.toml
  • packages/rs-dpp/Cargo.toml
  • packages/rs-dpp/examples/generate_bls_compatibility_vectors.rs
  • packages/rs-dpp/src/bls/bls_signatures.rs
  • packages/rs-dpp/src/bls/mod.rs
  • packages/rs-dpp/src/bls/native_bls.rs
  • packages/rs-dpp/src/bls/serde.rs
  • packages/rs-dpp/src/core_types/validator/mod.rs
  • packages/rs-dpp/src/core_types/validator/v0/mod.rs
  • packages/rs-dpp/src/core_types/validator_set/mod.rs
  • packages/rs-dpp/src/core_types/validator_set/v0/mod.rs
  • packages/rs-dpp/src/errors/protocol_error.rs
  • packages/rs-dpp/src/identity/identity_public_key/key_type.rs
  • packages/rs-dpp/src/identity/identity_public_key/v0/methods/mod.rs
  • packages/rs-dpp/src/lib.rs
  • packages/rs-dpp/src/serialization/dashcore/bls_pubkey.rs
  • packages/rs-dpp/src/serialization/dashcore/mod.rs
  • packages/rs-dpp/src/serialization/mod.rs
  • packages/rs-dpp/src/signing.rs
  • packages/rs-dpp/tests/bls_compatibility.rs
  • packages/rs-dpp/tests/fixtures/bls_compatibility/README.md
  • packages/rs-dpp/tests/fixtures/bls_compatibility/vectors.json
  • packages/rs-drive-abci/src/abci/error.rs
  • packages/rs-drive-abci/src/error/execution.rs
  • packages/rs-drive-abci/src/error/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/block_end/validator_set_update/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_based_updates/update_masternode_identities/update_operator_identity/v0/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_based_updates/update_masternode_list/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_based_updates/update_masternode_list/update_state_masternode_list/v1/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_based_updates/update_quorum_info/v0/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_chain_lock/choose_quorum/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_chain_lock/choose_quorum/v0/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_chain_lock/verify_chain_lock_locally/v0/mod.rs
  • packages/rs-drive-abci/src/execution/platform_events/core_instant_send_lock/verify_recent_signature_locally/v0/mod.rs
  • packages/rs-drive-abci/src/execution/storage/store_platform_state/v1/mod.rs
  • packages/rs-drive-abci/src/mimic/mod.rs
  • packages/rs-drive-abci/src/mimic/test_quorum.rs
  • packages/rs-drive-abci/src/platform_types/commit/mod.rs
  • packages/rs-drive-abci/src/platform_types/commit/v0/mod.rs
  • packages/rs-drive-abci/src/platform_types/platform_state/platform_state_for_saving/v0/old_structures/mod.rs
  • packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/for_saving_v0.rs
  • packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/for_saving_v1.rs
  • packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/quorum_set.rs
  • packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/quorums.rs
  • packages/rs-drive-abci/src/platform_types/validator/v0/mod.rs
  • packages/rs-drive-abci/src/platform_types/validator_set/v0/mod.rs
  • packages/rs-drive-abci/src/query/document_query/v1/tests.rs
  • packages/rs-drive-abci/src/query/system/current_quorums_info/v0/mod.rs
  • packages/rs-drive-abci/tests/strategy_tests/execution.rs
  • packages/rs-drive-abci/tests/strategy_tests/main.rs
  • packages/rs-drive-abci/tests/strategy_tests/masternode_list_item_helpers.rs
  • packages/rs-drive-abci/tests/strategy_tests/masternodes.rs
  • packages/rs-drive-abci/tests/strategy_tests/query.rs
  • packages/rs-drive-abci/tests/strategy_tests/test_cases/address_tests.rs
  • packages/rs-drive-proof-verifier/src/unproved.rs
  • packages/rs-drive-proof-verifier/src/verify.rs
  • packages/rs-platform-wallet/src/masternode/locator.rs
  • packages/rs-platform-wallet/src/masternode/update_service.rs
  • packages/rs-sdk-ffi/src/system/queries/current_quorums_info.rs
  • packages/simple-signer/src/signer.rs
💤 Files with no reviewable changes (2)
  • Cargo.toml
  • packages/rs-dpp/src/serialization/dashcore/bls_pubkey.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request replaces the BLS backend API in DPP and migrates Platform, wallet, proof-verifier, and signer code to the new types. It adds Serde support and compatibility fixtures and tests for BLS operations and validator storage.

Changes

BLS Backend and API

Layer / File(s) Summary
BLS backend, API, and Serde
Cargo.toml, packages/rs-dpp/Cargo.toml, packages/rs-dpp/src/bls/*, packages/rs-dpp/src/lib.rs, packages/rs-dpp/src/serialization/*, CHANGELOG.md
DPP replaces the optional blsful dependency with dash-pkc and exposes key, signature, and error types through dpp::bls. The new API includes key and signature operations and Serde adapters. The former serialization::dashcore::bls_pubkey module becomes a deprecated alias.
DPP models and BLS operations
packages/rs-dpp/src/core_types/validator*, packages/rs-dpp/src/core_types/validator_set/*, packages/rs-dpp/src/identity/identity_public_key/*, packages/rs-dpp/src/signing.rs, packages/rs-dpp/src/errors/protocol_error.rs
Validator and validator-set public keys, identity-key handling, and signature verification adopt the new BLS types and byte-conversion methods.
Platform quorum and validator integration
packages/rs-drive-abci/src/{abci,error,execution,platform_types,query}/*, packages/rs-sdk-ffi/src/system/queries/*
Platform quorum, validator, and state code uses the DPP BLS types. Key and signature conversions use the new API; quorum selection logic remains unchanged.
Signing and verification consumers
packages/rs-drive-abci/src/{execution,platform_types,query}/*, packages/rs-drive-proof-verifier/src/*, packages/rs-platform-wallet/src/masternode/*, packages/simple-signer/src/signer.rs
Chain-lock, commit, proof, wallet, and signer code parses, signs, and serializes BLS data through the new API.
Compatibility vectors and migrated test fixtures
packages/rs-dpp/examples/*, packages/rs-dpp/tests/bls_compatibility.rs, packages/rs-dpp/tests/fixtures/bls_compatibility/*, packages/rs-drive-abci/tests/strategy_tests/*
The example generates frozen compatibility vectors. Tests cover key generation, signing, aggregation, scalar inputs, identity encodings, and validator storage; strategy-test fixtures use the replacement BLS API.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~50 minutes

Change: Refactor

Suggested reviewers: quantumexplorer

Merge Risk: ⚪ Minimal · up to 1d729

The historical quorum-state read path remains compatible, and no concrete issue currently prevents merging after normal checks.

🚥 Pre-merge checks | ✅ 4 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ❓ Inconclusive Docstring coverage is 55.03% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 149 functions across 50 files. (9 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: sharing the rust-dashcore BLS backend through dpp::bls.
Full details: Docstring Coverage

Explanation

Docstring coverage is 55.03% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 149 functions across 50 files. (9 skipped: 4 unsupported, 5 over the file limit.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thepastaclaw

thepastaclaw commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — no blockers (commit 0fabd55) · triage: critical

lklimek and others added 2 commits October 7, 2026 09:50
…ions

Reserve legacy enum tags while rejecting their payloads at deserialization.
Require v4.0.0 to commit a block before opening older databases. Remove
legacy readers and the default production dependency on bls-signatures;
retain the dependency only for tests and explicit mocks.

Test legacy rejection, supported storage tags, persisted-state round trips,
and the existing serialization hash using a pre-removal fixture.

Co-Authored-By: Codex <noreply@openai.com>
Move the signature implementation under bls and export PublicKey, SecretKey,
Signature and BlsError from dpp::bls. Update all repository consumers and
remove the former dpp::bls_signatures path.

Co-Authored-By: Codex <noreply@openai.com>
@lklimek lklimek changed the title refactor: migrate Platform BLS to rust-dashcore backend refactor: unify BLS with rust-dashcore and drop legacy storage readers Oct 7, 2026
lklimek and others added 2 commits October 7, 2026 10:31
Move BLS Serde support under bls/serde.rs. Share key parsing between
Deserialize and field adapters while retaining tuple decoding for bincode
and deserialize_any for buffered tagged fields. Deprecate the old adapter
re-export and retain its optional-key path.

Co-Authored-By: Codex <noreply@openai.com>
Restore Platform-state V0 and quorum-storage V0/V1 readers and their
production dependency. Keep their removal separate from the backend
migration so the compatibility policy can be discussed independently.
Adapt restored imports to dpp::bls.

Co-Authored-By: Codex <noreply@openai.com>
@lklimek lklimek changed the title refactor: unify BLS with rust-dashcore and drop legacy storage readers refactor: share rust-dashcore BLS backend through dpp::bls Oct 7, 2026
@lklimek
lklimek marked this pull request as ready for review October 7, 2026 11:18
@lklimek

lklimek commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

/self-reviewed

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final validation — Phase 1 + Phase 2

No blocking issue was substantiated; three non-blocking suggestions remain concerning breaking-change metadata, repeated curve-point decoding, and legacy-conversion fixture coverage. Verification was static only, with no builds, tests, or benchmarks run. The supplied CI snapshot had policy checks pending and runner/title checks queued, so successful Rust validation was not independently confirmed.

🟡 3 suggestion(s)

Review provenance

Source: reviewer 1: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: platform-versioning); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); reviewer 6: muse-spark-1.3-contributor (agent: phase1-reviewer, role: general); reviewer 7: muse-spark-1.3-contributor (agent: phase1-reviewer, role: rust-quality); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: critical by gpt-6.1-sol (effort low) — The large, cross-cutting diff replaces cryptographic signing, verification and key handling in packages/rs-dpp/src/bls/bls_signatures.rs and native_bls.rs and changes BLS serialization in bls/serde.rs, directly modifying critical surfaces despite the intended compatibility.
  • Phase 1 reviewers: muse-spark-1.3-contributor — general (completed, effort xhigh); agent phase1-reviewer, muse-spark-1.3-contributor — rust-quality (completed, effort xhigh); agent phase1-reviewer
  • Phase 1 model: muse-spark-1.3-contributor — not quota-gated; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 15% left, 5h 100% left), glm-5.3-flash (not used above high effort; tier asks max)
  • Single stage: Phase 1 and Phase 2 reviewed this head side by side, with no blocker gate between them (triage tier)
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — architecture-layering (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — platform-versioning (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — rust-quality (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — security-auditor (completed, effort xhigh); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify each finding against the current code and only fix it if needed.

In `packages/rs-dpp/src/core_types/validator/v0/mod.rs`:
- [SUGGESTION] packages/rs-dpp/src/core_types/validator/v0/mod.rs:29: Classify the BLS API replacement as breaking release metadata
  This public field now uses a different nominal key type, and the PR also removes the public dpp::bls_signatures re-export. Existing external Rust callers therefore require source changes even though wire encodings and consensus behavior remain compatible. The PR description says that ! is reserved for consensus changes, but CLAUDE.md and the checked-in PR template require it for breaking changes generally. The pinned conventional-changelog-dash preset also recognizes ! and BREAKING CHANGE notes without a consensus-only restriction. Add the breaking-change marker to the PR title, ensure the eventual release commit carries breaking-change metadata, and retain the Rust migration instructions in release notes. This API change does not require a PlatformVersion activation.

In `packages/rs-dpp/tests/bls_compatibility.rs`:
- [SUGGESTION] packages/rs-dpp/tests/bls_compatibility.rs:108-115: Assert DPP's legacy-key conversion against the frozen vectors
  The frozen legacy_public_key assertion calls dash-pkc's to_scheme directly rather than the new DPP PublicKey::to_legacy_bytes method used by the wallet locator. A regression in the DPP method can therefore leave this compatibility assertion green. The locator tests do not close that gap: they check that the encodings differ and build their matching fixtures through the same helper. Add an assertion through the DPP method alongside the upstream assertion so the frozen historical bytes cover the actual migrated consumer boundary.

In `packages/rs-dpp/src/bls/bls_signatures.rs`:
- [SUGGESTION] packages/rs-dpp/src/bls/bls_signatures.rs:178-180: Retain validated points instead of decoding them again during verification
  PublicKey::try_from and Signature::from_compressed already decode and subgroup-check non-infinity inputs, but discard the backend points. These lines repeat that decoding and validation on every verification, and the pinned IETF backend subsequently calls blst verification with both signature and public-key validation enabled. Unlike the previous decoded-point representation, this adds repeated curve work to NativeBlsModule's verification path; the InstantLock loop also re-decodes the same signature for each candidate quorum. Retain validated backend points with explicit handling for historically accepted infinity, or benchmark and document the CPU-versus-memory tradeoff before retaining the compressed-only representation. Preserve the current admission checks and verification-time infinity rejection.

Comment thread packages/rs-dpp/src/core_types/validator/v0/mod.rs
Comment thread packages/rs-dpp/tests/bls_compatibility.rs
Comment thread packages/rs-dpp/src/bls/bls_signatures.rs Outdated
lklimek and others added 2 commits October 7, 2026 12:45
Cover DPP legacy-key conversion with frozen vectors and preserve infinity rejection across basic and aggregate verification. Document the Rust API migration in the changelog.

Co-Authored-By: Codex <noreply@openai.com>
Keep PublicKey opaque while representing infinity and validated backend points with a private enum. Preserve encodings and validation behavior.

Co-Authored-By: Codex <noreply@openai.com>

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — Final validation — Phase 1 + Phase 2

Static inspection of the complete diff at 1d729f9 found no blocking defect and confirmed that the prior redundant-decoding and legacy-conversion coverage findings are fixed. One in-scope suggestion remains: directly exercise the migrated historical V0 quorum-storage conversion with frozen bytes. No builds or tests were run; the supplied CI snapshot has runner selection queued and policy/title checks pending or queued, so completed runtime validation is not established by this review.

🟡 1 suggestion(s)

Review provenance

Source: reviewer 1: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: platform-versioning); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); reviewer 6: muse-spark-1.3-contributor (agent: phase1-reviewer, role: general); reviewer 7: muse-spark-1.3-contributor (agent: phase1-reviewer, role: rust-quality); reviewer 8: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 9: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 10: gpt-6.1-sol (agent: phase2-reviewer, role: platform-versioning); reviewer 11: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 12: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: critical by gpt-6.1-sol (effort low) — The large, intricate diff replaces signing, verification, aggregation and key handling in packages/rs-dpp/src/bls/bls_signatures.rs and consolidates key serialization in packages/rs-dpp/src/bls/serde.rs, directly changing cryptographic implementation despite intending identical acceptance rules.
  • Phase 1 reviewers: muse-spark-1.3-contributor — general (completed, effort xhigh); agent phase1-reviewer, muse-spark-1.3-contributor — rust-quality (completed, effort xhigh); agent phase1-reviewer
  • Phase 1 model: muse-spark-1.3-contributor — not quota-gated; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 15% left, 5h 100% left), glm-5.3-flash (not used above high effort; tier asks max)
  • Single stage: Phase 1 and Phase 2 reviewed this head side by side, with no blocker gate between them (triage tier)
  • Fresh final gate: an independent Phase-2 review ran after iterative findings were reconciled
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — architecture-layering (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — platform-versioning (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — rust-quality (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — security-auditor (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — general (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — architecture-layering (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — platform-versioning (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — rust-quality (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — security-auditor (completed, effort xhigh); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify each finding against the current code and only fix it if needed.

In `packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/for_saving_v0.rs`:
- [SUGGESTION] packages/rs-drive-abci/src/platform_types/signature_verification_quorum_set/v0/for_saving_v0.rs:117-120: Exercise the retained V0 storage conversion with frozen bytes
  This historical reader now converts a C++ `bls_signatures::PublicKey` through the new DPP parser. The frozen storage test decodes DPP `ValidatorV0`/`ValidatorSetV0` records and standalone DPP key Serde, but never decodes a `SignatureVerificationQuorumSetForSaving::V0` record and executes this cross-library conversion. Current runtime-to-storage conversion emits V2, so ordinary current-format round trips do not exercise this reader either. Compatibility between the two constructors remains an important invariant because the existing `expect` would turn a regression into a restoration panic.

  Add a frozen pre-migration V0 quorum-storage fixture with nonempty current and previous quorum lists, decode it through the production storage enum, convert it into the runtime quorum set, and assert the restored key bytes, hashes, and indexes. This tests the boundary changed by this migration; it is a coverage suggestion, not evidence of an incompatibility or a request to redesign the historical reader.

Decode pre-migration V0 bytes through the production storage enum and verify current and previous quorum keys, hashes, indexes, configuration and heights. Include fixture provenance and a reproducible historical generator.

Co-Authored-By: Codex <noreply@openai.com>

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — Final validation — Phase 1 + Phase 2

The complete diff contains no confirmed in-scope defects in the shared BLS API, migrated consumers, or retained historical storage readers. The three prior coverage/performance suggestions are addressed; the unconditional breaking-marker request is withdrawn under the repository's consensus-only convention. This is a static assessment: no builds or tests were run, and the supplied CI snapshot still has build-runner selection queued and policy checks pending.

🔴 0 blocking | 🟡 0 suggestion(s) | 💬 0 nitpick(s)

Review provenance

Source: reviewer 1: muse-spark-1.3-contributor (agent: phase1-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: platform-versioning); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 6: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); reviewer 7: muse-spark-1.3-contributor (agent: phase1-reviewer, role: rust-quality); reviewer 8: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 9: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 10: gpt-6.1-sol (agent: phase2-reviewer, role: platform-versioning); reviewer 11: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 12: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: critical by gpt-6.1-sol (effort low) — The large, cross-cutting diff changes cryptographic key parsing, signing, verification and aggregation in packages/rs-dpp/src/bls/bls_signatures.rs and serialized key handling in packages/rs-dpp/src/bls/serde.rs, directly affecting critical surfaces despite intending compatibility.
  • Phase 1 reviewers: muse-spark-1.3-contributor — general (completed, effort xhigh); agent phase1-reviewer, muse-spark-1.3-contributor — rust-quality (completed, effort xhigh); agent phase1-reviewer
  • Phase 1 model: muse-spark-1.3-contributor — not quota-gated; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 15% left, 5h 100% left), glm-5.3-flash (not used above high effort; tier asks max)
  • Single stage: Phase 1 and Phase 2 reviewed this head side by side, with no blocker gate between them (triage tier)
  • Fresh final gate: an independent Phase-2 review ran after iterative findings were reconciled
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — architecture-layering (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — platform-versioning (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — rust-quality (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — security-auditor (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — general (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — architecture-layering (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — platform-versioning (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — rust-quality (completed, effort xhigh); agent phase2-reviewer, gpt-6.1-sol — security-auditor (completed, effort xhigh); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify the current code and confirm that no unresolved issues remain.

No unresolved findings remain from the prior review on this head.

@lklimek
lklimek merged commit 4045c13 into chore/rust-dashcore-1112-v5.1 Oct 7, 2026
11 checks passed
@lklimek
lklimek deleted the test/bls-backend-compatibility branch October 7, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants