Skip to content

refactor: reject legacy BLS storage formats - #5323

Draft
lklimek wants to merge 16 commits into
chore/rust-dashcore-1112-v5.1from
refactor/retire-legacy-bls-storage
Draft

lklimek wants to merge 16 commits into
chore/rust-dashcore-1112-v5.1from
refactor/retire-legacy-bls-storage

Conversation

@lklimek

@lklimek lklimek commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Basic explanation

What this does: Proposes retiring old on-disk Platform state and quorum formats. Loading one returns a migration instruction instead of decoding it.

Value: Removes the C++ bls-signatures dependency from the default production node. Tests and explicit mocks builds still use it.

Risks: This intentionally prevents direct startup from older databases and snapshots. The proposed migration is to run Platform v4.0.0 on the database and successfully commit at least one block before upgrading. The complete upgrade path has not been tested.

Draft for developer consultation — not ready to merge. Decide whether to require that intermediate migration or retain compatibility readers/adapters. This proposal removes the whole Platform-state V0 reader, including its non-BLS fields; retaining the historical schema with an explicit failing decoder is also a discussion point.

Issue being fixed or feature implemented

Stacked on #5320; target branch: test/bls-backend-compatibility. The parent PR retains historical storage support. This PR isolates the compatibility-policy decision from the BLS backend migration.

Production uses of the separate C++ BLS crate are in old storage readers. v4.0.0 writes Platform-state V1 and quorum-storage V2, while still being able to read older records.

What was done?

  • Remove Platform-state V0 and quorum-storage V0/V1 readers and conversions.
  • Keep their enum positions reserved with an uninhabited UnsupportedLegacyBlsStorage payload. Its decoder immediately returns an error directing the operator to v4.0.0; it does not parse the old payload or panic.
  • Preserve Platform-state V1/V2 and quorum-storage V2 tags, layouts and serialized bytes.
  • Remove bls-signatures from default features; retain it for tests and the explicit mocks feature.
  • Test rejection of old testnet/devnet records and owned/borrowed quorum decoding. Keep a supported-format fixture serialized before reader removal and check the existing serialization hash.

In-place changes to shipped generations

This changes local database compatibility, not block execution rules. Serialization already writes supported formats for all protocol versions. The proposed rejection applies when loading old records, including outer Platform-state V0 records; no version table or protocol activation changes are introduced.

How Has This Been Tested?

  • cargo test -p drive-abci --lib --all-features --locked --offline platform_types: 121 tests, covering legacy errors, preserved supported tags and byte round trips.
  • cargo clippy -p drive-abci --all-targets --all-features --locked --offline -- --no-deps -D warnings.
  • Formatting and whitespace checks.
  • The normal/build dependency tree for default drive-abci excludes bls-signatures and bls-dash-sys.

No full replay or end-to-end v1.0 → v4.0.0 → this branch upgrade was run. Tests prove decoder behavior and supported serialization compatibility, not the complete operational migration procedure.

Breaking Changes

Direct loading of Platform-state V0 and quorum-storage V0/V1 databases/snapshots becomes unsupported. Operators must first have v4.0.0 successfully commit a block on that database; merely launching the binary is insufficient.

The title omits ! because the repository reserves it for consensus-breaking changes.

Checklist:

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional/e2e tests
  • I have added "!" to the title and described breaking changes in the corresponding section if my code contains any
  • I have made corresponding changes to the documentation if needed
  • If I added or changed GroveDB structure, I described it in the area's structure.rs, regenerated grovedb-structure.json, and checked the structure viewer link posted on this pull request

For repository code-owners and collaborators only

  • I have assigned this pull request to a milestone

🤖 Co-authored by Claudius the Magnificent AI Agent

lklimek and others added 10 commits October 7, 2026 08:00
Record signatures, secure aggregates, scalar boundary behavior, key generation
and persisted validator bytes before replacing the BLS implementation.
All eight compatibility tests pass on the original backend.

Co-authored-by: Codex <noreply@openai.com>
Preserve historical scalar reduction, infinity parsing, signature bytes and
validator serialization with the previously committed compatibility vectors.
Adapt repository consumers and replace the blst git patch with registry 0.3.17.

Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
…ions

Reserve legacy enum tags while rejecting their payloads at deserialization.
Require v4.0.0 to commit a block before opening older databases. Remove
legacy readers and the default production dependency on bls-signatures;
retain the dependency only for tests and explicit mocks.

Test legacy rejection, supported storage tags, persisted-state round trips,
and the existing serialization hash using a pre-removal fixture.

Co-Authored-By: Codex <noreply@openai.com>
Move the signature implementation under bls and export PublicKey, SecretKey,
Signature and BlsError from dpp::bls. Update all repository consumers and
remove the former dpp::bls_signatures path.

Co-Authored-By: Codex <noreply@openai.com>
Move BLS Serde support under bls/serde.rs. Share key parsing between
Deserialize and field adapters while retaining tuple decoding for bincode
and deserialize_any for buffered tagged fields. Deprecate the old adapter
re-export and retain its optional-key path.

Co-Authored-By: Codex <noreply@openai.com>
Restore Platform-state V0 and quorum-storage V0/V1 readers and their
production dependency. Keep their removal separate from the backend
migration so the compatibility policy can be discussed independently.
Adapt restored imports to dpp::bls.

Co-Authored-By: Codex <noreply@openai.com>
Reject Platform-state V0 and quorum-storage V0/V1 with an instruction to
run v4.0.0 and commit a block before upgrading. Preserve format tags and
supported serialized bytes. Restrict the C++ BLS dependency to tests and
explicit mocks.

Isolated from #5320 for developer consultation on storage compatibility
and the required intermediate upgrade.

Co-Authored-By: Codex <noreply@openai.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thepastaclaw

thepastaclaw commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

🕓 Review not started yet because this PR is a draft.

  • Request normal review — click when the PR is ready for review.
  • Request priority review — click to move this review to the front of the queue.

Commit 7b90856. Normal review starts when eligible; priority review starts as soon as a slot is available.

@lklimek
lklimek marked this pull request as ready for review October 7, 2026 11:24
@lklimek
lklimek marked this pull request as draft October 7, 2026 11:26
lklimek and others added 4 commits October 7, 2026 11:34
…siblings

The supported-format fixture lived in a separate `.hex` file loaded
through `include_str!` at two call sites, unlike the other platform
state fixtures, which are named statics in `test/fixture/platform_state.rs`.

Move it there as `PLATFORM_STATE_V8_DEVNET_SUPPORTED`, with its
provenance on the static instead of on one of its two uses.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

<sub>🤖 Co-authored by [Claudius the Magnificent](https://github.com/lklimek/claudius) AI Agent</sub>
Cover DPP legacy-key conversion with frozen vectors and preserve infinity rejection across basic and aggregate verification. Document the Rust API migration in the changelog.

Co-Authored-By: Codex <noreply@openai.com>
Keep PublicKey opaque while representing infinity and validated backend points with a private enum. Preserve encodings and validation behavior.

Co-Authored-By: Codex <noreply@openai.com>
@lklimek
lklimek marked this pull request as ready for review October 7, 2026 13:10
@lklimek
lklimek marked this pull request as draft October 7, 2026 13:11
Base automatically changed from test/bls-backend-compatibility to chore/rust-dashcore-1112-v5.1 October 7, 2026 15:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants