Skip to content

fix(cli): derive prover-check gas limits from on-chain BlockGasLimit - #1371

Open
mdbig1 wants to merge 2 commits into
usc-devfrom
fix/prover-check-gas-limit
Open

mdbig1 wants to merge 2 commits into
usc-devfrom
fix/prover-check-gas-limit

Conversation

@mdbig1

@mdbig1 mdbig1 commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

What

Removes the hardcoded singleTxnGasLimit = 25_000_000n from prover-check.ts and replaces it with two tiers, both derived from the on-chain block gas limit the script already reads:

Band Result
> blockGasLimit (75M) fail — unsubmittable
>= 70% (52.5M) fail — over budget (unchanged)
below pass

The ceiling is checked before the budget at each site, so the more severe condition reports first.

Why

25M is below 52.5M, so the hardcoded check always fired first and the dynamic 70% check at the end of the loop was unreachable dead code. #1193 described the cap as applying "in addition to" the 70% check; in practice it replaced it, two days after 6070eb4 deliberately made that check track the runtime.

25M does not correspond to anything on chain — it appears only in this script, while the runtime sets BLOCK_GAS_LIMIT = 75_000_000 (runtime/src/lib.rs:450). The 70% threshold, by contrast, is grounded: 8d158c4 raised it to 70% after a real observation of 51,094,512 gas, so the 25M cap would have rejected the very transaction that motivated the threshold.

Effect in CI: this has been paging the team on healthy proofs. Over 974 totalGas samples from the last four runs, 2 exceeded 25M and 0 exceeded 52.5M. Genuinely oversize proofs (e.g. gasForDecoding 119227432 on 08-28, above the real 75M limit) still fail, now with a message naming a limit that exists.

Ceiling comparisons use > rather than >=: a transaction whose gas exactly equals the block gas limit is still submittable. The 70% budget keeps >=.

Testing

  • yarn lint — clean (eslint 8.57.0, --max-warnings 0)
  • npx tsc --noEmit — clean
  • npx prettier --check — clean

Alert volume

Separately, all three Slack steps were if: always(), so every job reported on success as well. check-for alone posts 4 messages per run and the two compare jobs add 2 more — twice a day on weekdays, roughly 60 messages a week. Fixing the gas logic removes the false failures but not that baseline, so the three steps are now if: failure().

Since they only fire on failure, the job.status == 'failure' && ... || '' conditional in each message was always true and has been dropped; the wording changes from "complete!" to "FAILED!".

if: always() is kept on Upload proofs — the compare-proofs-* jobs consume those artifacts, and they are wanted precisely when a run fails. check-snapshot.yml is left on always(); it posts a handful of messages a month and is not a spam source.

Trade-off worth naming: with failure-only alerting, a workflow that silently stops running looks the same as a healthy one. If that matters, a periodic heartbeat post would cover it — not included here.

Note

The same logic was copied into gluwa/asc-sdk (#140 there), which additionally never received 6070eb4's dynamic read. Fixed separately in that repo.

@cursor

cursor Bot commented Sep 16, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Changes affect CI alerting and a CLI validation script used in scheduled checks; no runtime, auth, or on-chain submission logic is modified.

Overview
Prover-check drops the hardcoded 25M gas cap and aligns limits with the on-chain EVM block gas limit already fetched from a finalized block. Per-proof checks now fail when verification, decoding, or margined total gas exceeds that ceiling (unsubmittable), then still fail at ≥70% of the limit (budget). Ceiling is evaluated before the budget so errors name the right constraint.

CI Slack noise: In check-prover.yml, the prover matrix and both proof-diff jobs only post to #noti-creditcoin-snapshots on failure, with messages prefixed by workflow name and explicit FAILED wording (success pings removed). check-snapshot.yml keeps notify-on-always but prefixes messages with github.workflow for clarity.

Reviewed by Cursor Bugbot for commit 055bc37. Bugbot is set up for automated code reviews on this repo. Configure here.

@mdbig1
mdbig1 force-pushed the fix/prover-check-gas-limit branch from 7577ae9 to 055bc37 Compare September 16, 2026 18:46
@gluwa-bot

Copy link
Copy Markdown
Contributor

Overview

Image reference gluwa/creditcoin3:latest gluwa/creditcoin3:latest
- digest dfb918c3c546 f797b879a18c
- tag latest latest
- provenance 7e92a94 2fb3d46
- vulnerabilities critical: 3 high: 16 medium: 21 low: 4 unspecified: 13 critical: 2 high: 13 medium: 11 low: 3 unspecified: 11
- platform linux/amd64 linux/amd64
- size 430 MB 431 MB (+552 kB)
- packages 405 404 (-1)
Base Image ubuntu:26.04
also known as:
latest
resolute
ubuntu:26.04
also known as:
latest
resolute
rolling
- vulnerabilities critical: 1 high: 7 medium: 12 low: 1 unspecified: 2 critical: 1 high: 5 medium: 2 low: 0
Labels (1 changes)
  • ± 1 changed
  • 3 unchanged
-org.opencontainers.image.created=2026-06-27T04:19:04.617438+00:00
+org.opencontainers.image.created=2026-08-17T09:02:45.677319+00:00
 org.opencontainers.image.description=The Ubuntu container image maintained by Canonical

Ubuntu is a Debian-based Linux operating system that runs from the desktop to the cloud, to all your internet connected things.
It is the world's most popular operating system across public clouds and OpenStack clouds.
It is the number one platform for containers; from Docker to Kubernetes to LXD, Ubuntu can run your containers at scale.
Fast, secure and simple, Ubuntu powers millions of PCs worldwide.

 org.opencontainers.image.title=ubuntu
 org.opencontainers.image.version=26.04
Policies (2 improved, 0 worsened)
Policy Name gluwa/creditcoin3:latest gluwa/creditcoin3:latest Change Standing
Default non-root user No Change
No copyleft licenses ⚠️ 373 ⚠️ 361 -12 Improved
No fixable critical or high vulnerabilities ⚠️ 19 ⚠️ 15 -4 Improved
No high-profile vulnerabilities No Change
No outdated base images ⚠️ ⚠️ No Change
No unapproved base images No Change
Supply chain attestations No Change
Packages and Vulnerabilities (47 package changes and 15 vulnerability changes)
  • ➖ 1 packages removed
  • ♾️ 46 packages changed
  • 337 packages unchanged
  • ✔️ 15 vulnerabilities removed
Changes for packages of type deb (35 changes)
Package Version
gluwa/creditcoin3:latest
Version
gluwa/creditcoin3:latest
♾️ base-files 14ubuntu6.1 14ubuntu6.2
♾️ bsdutils 1:2.41.3-3ubuntu2 1:2.41.3-3ubuntu2.2
♾️ curl 8.18.0-1ubuntu2.3 8.18.0-1ubuntu2.5
♾️ diffutils 1:3.12-1 1:3.12-1ubuntu0.1
♾️ gnu-coreutils 9.7-3ubuntu2 9.7-3ubuntu2.1
♾️ gpgv 2.4.8-4ubuntu3 2.4.8-4ubuntu3.1
♾️ libattr1 1:2.5.2-4 1:2.5.2-4ubuntu0.1
♾️ libaudit-common 1:4.1.2-1build1 1:4.1.2-1ubuntu0.1
♾️ libaudit1 1:4.1.2-1build1 1:4.1.2-1ubuntu0.1
♾️ libblkid1 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ libbz2-1.0 1.0.8-6build2 1.0.8-6ubuntu0.1
♾️ libc-bin 2.43-2ubuntu2.3 2.43-2ubuntu2.4
♾️ libc-gconv-modules-extra 2.43-2ubuntu2.3 2.43-2ubuntu2.4
♾️ libc6 2.43-2ubuntu2.3 2.43-2ubuntu2.4
♾️ libcurl4t64 8.18.0-1ubuntu2.3 8.18.0-1ubuntu2.5
♾️ libgcrypt20 1.12.0-2ubuntu1 1.12.0-2ubuntu1.1
♾️ libmount1 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ libpam-modules 1.7.0-5ubuntu3.1 1.7.0-5ubuntu3.2
♾️ libpam-modules-bin 1.7.0-5ubuntu3.1 1.7.0-5ubuntu3.2
♾️ libpam-runtime 1.7.0-5ubuntu3.1 1.7.0-5ubuntu3.2
♾️ libpam0g 1.7.0-5ubuntu3.1 1.7.0-5ubuntu3.2
♾️ libpq5 18.4-0ubuntu0.26.04.1 18.6-0ubuntu0.26.04.1
♾️ libsmartcols1 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ libssh2-1t64 1.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4
♾️ libssl3t64 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.5
♾️ libsystemd0 259.5-0ubuntu3.3 259.5-0ubuntu3.4
♾️ libudev1 259.5-0ubuntu3.3 259.5-0ubuntu3.4
♾️ libuuid1 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ login 1:4.16.0-2+really2.41.3-3ubuntu2 1:4.16.0-2+really2.41.3-3ubuntu2.2
♾️ mount 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ openssl 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.5
♾️ openssl-provider-legacy 3.5.5-1ubuntu3.3 3.5.5-1ubuntu3.5
♾️ perl-base 5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3
♾️ util-linux 2.41.3-3ubuntu2 2.41.3-3ubuntu2.2
♾️ zlib1g 1:1.3.dfsg+really1.3.1-1ubuntu3 1:1.3.dfsg+really1.3.1-1ubuntu3.1
Changes for packages of type golang (6 changes)
Package Version
gluwa/creditcoin3:latest
Version
gluwa/creditcoin3:latest
♾️ github.com/canonical/pebble 1.31.1-0.20260528050051-33f10658d3fd 1.32.2-0.20260721212935-faa1696b477d
♾️ github.com/gorilla/websocket 1.5.1 1.5.3
critical: 0 high: 0 medium: 1 low: 0
Removed vulnerabilities (1):
  • medium : GHSA--w67g--5rqw--f597
golang.org/x/net 0.40.0
critical: 1 high: 2 medium: 7 low: 0
Removed vulnerabilities (10):
  • critical : CVE--2026--39821
  • high : CVE--2026--46600
  • high : CVE--2026--33814
  • medium : CVE--2026--25680
  • medium : CVE--2026--42506
  • medium : CVE--2026--42502
  • medium : CVE--2026--27136
  • medium : CVE--2026--25681
  • medium : CVE--2025--58190
  • medium : CVE--2025--47911
♾️ golang.org/x/sys 0.33.0 0.46.0
critical: 0 high: 0 medium: 0 low: 1
Removed vulnerabilities (1):
  • low : CVE--2026--39824
♾️ golang.org/x/term 0.32.0 0.44.0
♾️ stdlib 1.26.3 1.26.5
critical: 1 high: 6 medium: 4 low: 0 unspecified: 2 critical: 1 high: 5 medium: 2 low: 0
Removed vulnerabilities (5):
  • high : CVE--2026--42504
  • medium : CVE--2026--27145
  • medium : CVE--2026--42507
  • unspecified : CVE--2026--42505
  • unspecified : CVE--2026--39822
Changes for packages of type npm (6 changes)
Package Version
gluwa/creditcoin3:latest
Version
gluwa/creditcoin3:latest
♾️ @types/node 26.1.2 22.7.5
♾️ node-gyp 13.0.1 13.0.2
♾️ picomatch 4.0.5 4.0.7
♾️ undici 8.10.0 8.10.2
♾️ undici-types 8.3.0 6.21.0
♾️ ws 8.21.2 8.21.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants