Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 🚀 New features to boost your workflow:
|
prajwolrg
force-pushed
the
functional-asm-upgrade-test
branch
from
October 1, 2026 10:28
c53e1a9 to
c466a8e
Compare
prajwolrg
marked this pull request as ready for review
October 1, 2026 10:35
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🔒 AI Security Review (claude-opus-5-5)✅ No security issues found. |
irnb
added this pull request to stack #303
October 1, 2026 10:45
A standalone test tool needs to post admin envelopes against an existing regtest node, where there is no harness. Funding and envelope assembly only need a bitcoind wallet and the magic bytes, so they now take those directly and the harness methods delegate to them.
The Python functional tests have no way to sign an admin action or build an envelope, so they cannot activate an ASM upgrade. Shelling out to a binary built on the integration-test harness keeps a single implementation of the admin signing message and wire format, the same approach alpen's strata-test-cli and strata-bridge's dev-cli take.
The admin signer was derived from the MuSig2 test key, whose secret the suite does not have, so no test could sign an admin action. It is now a known key. Envs can also lower the admin confirmation depth and list more than one execution target, which an upgrade test needs.
Upgrade coverage so far ran native services without a prover. This drives the real runner with both programs loaded through an admin activation and checks that the recursive proof chain continues past the switch. Native backend only: spec 1 has no SP1 guest yet.
prajwolrg
force-pushed
the
functional-asm-upgrade-test
branch
from
October 1, 2026 11:41
c466a8e to
135fd38
Compare
🔒 AI Security Review (claude-opus-5-5)✅ No security issues found. |
9 of 14 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds a functional test that upgrades a running
strata-asm-runnerfrom spec 0 to spec 1 (the claim-v1 ruleset from #291) and checks that proving continues across the switch. Until now, upgrade coverage wasasm_upgrade_recovery, which runs native services with a test spec and no prover.The test loads both programs, activates spec 1 with a signed admin
AsmStfVkupdate, and asserts the spec of every block. Blocks up to and including the enacting block run under spec 0, and every later block runs under spec 1. It then waits for the ASM proof of the first spec 1 block and a Moho proof past it. That Moho proof can only exist if the recursion accepted step proofs from both programs.Type of Change
Notes to Reviewers
Stacked on #291. Review that first; this PR's diff is only the four commits on top.
Entry point:
functional-tests/tests/fn_asm_upgrade_test.py, thenenvs/upgrade_env.py.The Python suite gets the admin transaction from a new
asm-test-clibinary in theintegration-testscrate instead of building it in Python. Building it in Python would duplicate the admin signing message, the SSZ wire format, and the envelope assembly, and any drift would show up only as an ignored tx and a timeout. The binary reuses the harness code, so there is one implementation. alpen'sstrata-test-cliand strata-bridge'sdev-cliwork the same way.Every env now uses a known admin key. The old signer came from the MuSig2 test key, whose secret the suite does not have.
The test runs only on the native backend. Each SP1 guest compiles one spec, and spec 1 has no guest yet, so
UpgradeEnvfails at startup underASM_PROVER_BACKEND=sp1with a clear message. CI runs native only.Testing: the full functional suite passes locally (21 tests, including the new one). So do
asm_admin,asm_upgrade_recovery,asm_admin_to_stfandasm_checkpoint, which use the refactored envelope builder. Each commit passes clippy, rustfmt, ruff and ty on its own.Checklist
Related Issues
Part of the ASM upgradability epic, STR-4106.
🤖 Generated with Claude Code