Skip to content

Cjl/giga state hash - #4341

Draft
cody-littley wants to merge 8 commits into
mainfrom
cjl/giga-state-hash
Draft

cody-littley wants to merge 8 commits into
mainfrom
cjl/giga-state-hash

Conversation

@cody-littley

Copy link
Copy Markdown
Contributor
  • New methods on StateDB for getting recent hashes, and for signaling when safe to delete
  • HashVault internalized inside StateDB
  • HashVault no longer permits gaps in blocks
  • HashVault's "crash on equivocation" feature is now optional via configuration
  • StateDB setup/recovery now must consider HashVault

@cursor

cursor Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

PR Summary

High Risk
Changes core state open/recovery, equivocation handling, and durable hash history; misconfiguration or recovery edge cases could prevent startup or weaken slash protection.

Overview
Giga StateDB now owns the Pebble hash vault as SC’s first hash listener, records FlatKV block hashes on commit, and exposes GetBlockHeight / GetBlockHash on the StateDB interface. Open and recovery were reworked: NewStateDB takes HashVaultConfig and an optional rollbackTo, with offline recoverStores planning rewinds when the vault is empty or behind SC (including configurable hash-vault-empty-rollback-blocks, default 1000). Rollbacks no longer truncate the vault; re-execution is checked against stored hashes. An empty WAL requires SC, SS, and the vault to already agree.

Operator config replaces the old unsafe kill switch. hash-vault-disabled-unsafe is gone in favor of hash-vault-halt-on-mismatch (default: log and replace recorded hashes) and hash-vault-empty-rollback-blocks. The vault refuses height gaps, can Get / Reset / accept mismatches without halting, and joins the storage garbage collector prune set. Block hash plumbing uses uint64 across listeners and lthash.BlockHash. GigaRouter no longer configures hash vault directly; Autobahn storage wiring passes node config into GigaStorageConfig.HashVaultConfig.

Reviewed by Cursor Bugbot for commit e7df1c3. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread sei-db/state_db/giga/state_db_recovery.go
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow Buf / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedSep 29, 2026, 4:15 PM

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread sei-db/config/giga_config.go
seidroid[bot]
seidroid Bot previously requested changes Sep 25, 2026

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR moves the hash vault into the giga StateDB and makes it record FlatKV state checksums. Two problems block it: existing Autobahn nodes keep the same vault directory, which still holds the old app hashes, so they will fail to open on upgrade; and the app hash sent to AppQC voting is no longer checked for equivocation before it is published.

Findings: 2 blocking | 2 non-blocking | 3 posted inline

Blockers

  • None at the file/PR level.
  • 2 blocking issue(s) flagged inline on specific lines.

Non-blocking

  • [suggestion] hash-vault-disabled-unsafe is removed with no deprecation policy. Viper ignores unknown keys, so an operator who set it to true gets a node that silently runs the vault with halting on. Log a startup warning when the old key is present, or add a release note pointing to hash-vault-halt-on-mismatch = false (see REVIEW_GUIDELINES §5).
  • 1 suggestion(s)/nit(s) flagged inline on specific lines.

Comment thread sei-db/config/giga_config.go
Comment thread sei-tendermint/internal/p2p/giga_router_common.go
Comment thread sei-db/state_db/giga/types/state_db.go
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.64924% with 98 lines in your changes missing coverage. Please review.
✅ Project coverage is 67.48%. Comparing base (398513d) to head (e7df1c3).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
sei-db/state_db/giga/state_db_recovery.go 76.47% 24 Missing ⚠️
sei-db/state_db/sc/hashvault/pebble_hashvault.go 80.18% 21 Missing ⚠️
sei-db/state_db/giga/state_db.go 79.76% 17 Missing ⚠️
sei-db/state_db/giga/state_db_replay.go 76.27% 14 Missing ⚠️
...state_db/sc/hashvault/pebble_hashvault_rollback.go 66.66% 9 Missing ⚠️
giga/evmonly/memory_store.go 0.00% 6 Missing ⚠️
sei-db/state_db/giga/state_db_hash_vault.go 76.19% 5 Missing ⚠️
sei-db/config/giga_config.go 80.00% 1 Missing ⚠️
sei-db/state_db/sc/flatkv/snapshot.go 83.33% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #4341      +/-   ##
==========================================
- Coverage   67.74%   67.48%   -0.27%     
==========================================
  Files        2174     2120      -54     
  Lines      168819   164708    -4111     
==========================================
- Hits       114374   111156    -3218     
+ Misses      54436    53543     -893     
  Partials        9        9              
Flag Coverage Δ
sei-chain-pr 82.59% <83.72%> (?)
sei-db 74.81% <ø> (ø)
sei-db-state-db ?
sei-db-state-db-pr 83.69% <78.12%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
config/tendermintbase/tendermintbase.go 100.00% <100.00%> (ø)
giga/metrics/autobahn_loop.go 92.59% <ø> (ø)
sei-db/bootstrap/recovery.go 88.65% <100.00%> (+0.48%) ⬆️
sei-db/bootstrap/storage_manager.go 80.00% <100.00%> (ø)
sei-db/state_db/sc/composite/hashlog.go 56.25% <100.00%> (ø)
sei-db/state_db/sc/composite/store.go 79.06% <100.00%> (ø)
sei-db/state_db/sc/flatkv/finalization_manager.go 87.09% <100.00%> (ø)
sei-db/state_db/sc/flatkv/lthash/hash_engine.go 83.33% <100.00%> (ø)
.../state_db/sc/flatkv/lthash/hash_engine_messages.go 61.53% <ø> (ø)
sei-db/state_db/sc/flatkv/store.go 86.98% <100.00%> (+3.08%) ⬆️
... and 20 more

... and 125 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread giga/evmonly/giga_store.go Outdated
}
// PLACEHOLDER: keeps the newest placeholderBlockHashRetention blocks' hashes. A real threshold, set by
// what giga execution needs block hashes for, should be wired in here.
if err := stateStore.PruneBlockHashesBelow(blockHashesPrunedBelow(req.Context.Number)); err != nil {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm a bit confused how we see things work. Why the prune signal comes from execution?

I thought our agreed API in March offsite was:

  • consensus prepares the blocks ready for execution, and notifies storage (by saving into BlockDB)
  • storage triggers execution whenever it sees fit
  • after execution, storage notifies consensus which AppHash is ready for voting
  • then consensus notifies storage which ones are ready for pruning
    ?

Did I remember that correctly?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on our discussion (offline), I've changed things in the following way:

  • Pruning methods are now removed from public API
  • HashVault now determines its retention window via the rollback window and the lookback window, just like other stores
  • A hard requirement: it is now unsafe to allow the lookback window config to be smaller than the number of blocks in an epoch. Not enforced in code, we may enforce a minimum in code at a later date.

}

// GetBlockHash returns the hash the hash vault holds for blockNumber.
func (s *StateDB) GetBlockHash(blockNumber uint64) ([32]byte, gigatypes.BlockHashStatus, error) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, I thought we said GetAppHash. If GetBlockHash succeeds means this blocks has executed and the states are persisted in storage that works as well, but the consensus protocol might need AppHash to send out AppVote.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Active discussion on this on slack, will continue the discussion there.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread sei-db/state_db/sc/hashvault/hashvault_config.go

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit bfb833b. Configure here.

Comment thread sei-db/state_db/giga/state_db_recovery.go
Comment thread sei-db/config/giga_config.go
Comment thread cmd/seid/cmd/legacy_config_fuzz_test.go Outdated
@cody-littley

Copy link
Copy Markdown
Contributor Author

@seidroid review

@seidroid seidroid Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR moves the hash vault into the giga StateDB, where it records FlatKV state checksums. It adds recovery and refill logic and includes good tests. Nothing blocks merge, but two points need an explicit decision or a small fix: the AppQC-published app hash no longer has an equivocation guard, and legacy app hashes stay in the reused vault directory.

Findings: 0 blocking | 2 non-blocking | 2 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • None at the file/PR level.
  • 2 suggestion(s)/nit(s) flagged inline on specific lines.

Comment thread sei-tendermint/internal/p2p/giga_router_common.go
Comment thread sei-db/config/giga_config.go
@seidroid
seidroid Bot dismissed their stale review September 29, 2026 16:24

Superseded: latest AI review found no blocking issues.

@cody-littley
cody-littley marked this pull request as draft September 30, 2026 15:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants