Conversation
PR SummaryLow Risk Overview CI Slack noise: In Reviewed by Cursor Bugbot for commit 055bc37. Bugbot is set up for automated code reviews on this repo. Configure here. |
7577ae9 to
055bc37
Compare
Overview
Labels (1 changes)
-org.opencontainers.image.created=2026-06-27T04:19:04.617438+00:00
+org.opencontainers.image.created=2026-08-17T09:02:45.677319+00:00
org.opencontainers.image.description=The Ubuntu container image maintained by Canonical
Ubuntu is a Debian-based Linux operating system that runs from the desktop to the cloud, to all your internet connected things.
It is the world's most popular operating system across public clouds and OpenStack clouds.
It is the number one platform for containers; from Docker to Kubernetes to LXD, Ubuntu can run your containers at scale.
Fast, secure and simple, Ubuntu powers millions of PCs worldwide.
org.opencontainers.image.title=ubuntu
org.opencontainers.image.version=26.04Policies (2 improved, 0 worsened)
Packages and Vulnerabilities (47 package changes and 15 vulnerability changes)
Changes for packages of type
|
| Package | Versiongluwa/creditcoin3:latest |
Versiongluwa/creditcoin3:latest |
|
|---|---|---|---|
| ♾️ | base-files | 14ubuntu6.1 |
14ubuntu6.2 |
| ♾️ | bsdutils | 1:2.41.3-3ubuntu2 |
1:2.41.3-3ubuntu2.2 |
| ♾️ | curl | 8.18.0-1ubuntu2.3 |
8.18.0-1ubuntu2.5 |
| ♾️ | diffutils | 1:3.12-1 |
1:3.12-1ubuntu0.1 |
| ♾️ | gnu-coreutils | 9.7-3ubuntu2 |
9.7-3ubuntu2.1 |
| ♾️ | gpgv | 2.4.8-4ubuntu3 |
2.4.8-4ubuntu3.1 |
| ♾️ | libattr1 | 1:2.5.2-4 |
1:2.5.2-4ubuntu0.1 |
| ♾️ | libaudit-common | 1:4.1.2-1build1 |
1:4.1.2-1ubuntu0.1 |
| ♾️ | libaudit1 | 1:4.1.2-1build1 |
1:4.1.2-1ubuntu0.1 |
| ♾️ | libblkid1 | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | libbz2-1.0 | 1.0.8-6build2 |
1.0.8-6ubuntu0.1 |
| ♾️ | libc-bin | 2.43-2ubuntu2.3 |
2.43-2ubuntu2.4 |
| ♾️ | libc-gconv-modules-extra | 2.43-2ubuntu2.3 |
2.43-2ubuntu2.4 |
| ♾️ | libc6 | 2.43-2ubuntu2.3 |
2.43-2ubuntu2.4 |
| ♾️ | libcurl4t64 | 8.18.0-1ubuntu2.3 |
8.18.0-1ubuntu2.5 |
| ♾️ | libgcrypt20 | 1.12.0-2ubuntu1 |
1.12.0-2ubuntu1.1 |
| ♾️ | libmount1 | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | libpam-modules | 1.7.0-5ubuntu3.1 |
1.7.0-5ubuntu3.2 |
| ♾️ | libpam-modules-bin | 1.7.0-5ubuntu3.1 |
1.7.0-5ubuntu3.2 |
| ♾️ | libpam-runtime | 1.7.0-5ubuntu3.1 |
1.7.0-5ubuntu3.2 |
| ♾️ | libpam0g | 1.7.0-5ubuntu3.1 |
1.7.0-5ubuntu3.2 |
| ♾️ | libpq5 | 18.4-0ubuntu0.26.04.1 |
18.6-0ubuntu0.26.04.1 |
| ♾️ | libsmartcols1 | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 |
1.11.1-1ubuntu0.26.04.4 |
| ♾️ | libssl3t64 | 3.5.5-1ubuntu3.3 |
3.5.5-1ubuntu3.5 |
| ♾️ | libsystemd0 | 259.5-0ubuntu3.3 |
259.5-0ubuntu3.4 |
| ♾️ | libudev1 | 259.5-0ubuntu3.3 |
259.5-0ubuntu3.4 |
| ♾️ | libuuid1 | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | login | 1:4.16.0-2+really2.41.3-3ubuntu2 |
1:4.16.0-2+really2.41.3-3ubuntu2.2 |
| ♾️ | mount | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | openssl | 3.5.5-1ubuntu3.3 |
3.5.5-1ubuntu3.5 |
| ♾️ | openssl-provider-legacy | 3.5.5-1ubuntu3.3 |
3.5.5-1ubuntu3.5 |
| ♾️ | perl-base | 5.40.1-7ubuntu0.1 |
5.40.1-7ubuntu0.3 |
| ♾️ | util-linux | 2.41.3-3ubuntu2 |
2.41.3-3ubuntu2.2 |
| ♾️ | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 |
1:1.3.dfsg+really1.3.1-1ubuntu3.1 |
Changes for packages of type golang (6 changes)
Changes for packages of type npm (6 changes)
| Package | Versiongluwa/creditcoin3:latest |
Versiongluwa/creditcoin3:latest |
|
|---|---|---|---|
| ♾️ | @types/node | 26.1.2 |
22.7.5 |
| ♾️ | node-gyp | 13.0.1 |
13.0.2 |
| ♾️ | picomatch | 4.0.5 |
4.0.7 |
| ♾️ | undici | 8.10.0 |
8.10.2 |
| ♾️ | undici-types | 8.3.0 |
6.21.0 |
| ♾️ | ws | 8.21.2 |
8.21.3 |
What
Removes the hardcoded
singleTxnGasLimit = 25_000_000nfromprover-check.tsand replaces it with two tiers, both derived from the on-chain block gas limit the script already reads:> blockGasLimit(75M)>= 70%(52.5M)The ceiling is checked before the budget at each site, so the more severe condition reports first.
Why
25M is below 52.5M, so the hardcoded check always fired first and the dynamic 70% check at the end of the loop was unreachable dead code. #1193 described the cap as applying "in addition to" the 70% check; in practice it replaced it, two days after 6070eb4 deliberately made that check track the runtime.
25M does not correspond to anything on chain — it appears only in this script, while the runtime sets
BLOCK_GAS_LIMIT = 75_000_000(runtime/src/lib.rs:450). The 70% threshold, by contrast, is grounded: 8d158c4 raised it to 70% after a real observation of 51,094,512 gas, so the 25M cap would have rejected the very transaction that motivated the threshold.Effect in CI: this has been paging the team on healthy proofs. Over 974
totalGassamples from the last four runs, 2 exceeded 25M and 0 exceeded 52.5M. Genuinely oversize proofs (e.g.gasForDecoding 119227432on 08-28, above the real 75M limit) still fail, now with a message naming a limit that exists.Ceiling comparisons use
>rather than>=: a transaction whose gas exactly equals the block gas limit is still submittable. The 70% budget keeps>=.Testing
yarn lint— clean (eslint 8.57.0,--max-warnings 0)npx tsc --noEmit— cleannpx prettier --check— cleanAlert volume
Separately, all three Slack steps were
if: always(), so every job reported on success as well.check-foralone posts 4 messages per run and the two compare jobs add 2 more — twice a day on weekdays, roughly 60 messages a week. Fixing the gas logic removes the false failures but not that baseline, so the three steps are nowif: failure().Since they only fire on failure, the
job.status == 'failure' && ... || ''conditional in each message was always true and has been dropped; the wording changes from "complete!" to "FAILED!".if: always()is kept on Upload proofs — thecompare-proofs-*jobs consume those artifacts, and they are wanted precisely when a run fails.check-snapshot.ymlis left onalways(); it posts a handful of messages a month and is not a spam source.Trade-off worth naming: with failure-only alerting, a workflow that silently stops running looks the same as a healthy one. If that matters, a periodic heartbeat post would cover it — not included here.
Note
The same logic was copied into
gluwa/asc-sdk(#140 there), which additionally never received 6070eb4's dynamic read. Fixed separately in that repo.