fix: skip finalization advance for stale finalized sources#802
Merged
tcoratger merged 3 commits intoMay 30, 2026
Merged
Conversation
Collaborator
|
@latifkasuli Please let me know when ready for review |
Contributor
Author
|
Ready for review now. I re-ran the focused validation:
All passed. |
Rebase the stale-source finalization fix onto current main: the spec file moved under the spec/ package and attestation specs renamed validator_ids to validator_indices. Also fix the new test expectation. Building justified_slots via model_copy(update=...) bypassed Pydantic validation, leaving data as a list instead of a tuple, so the post-state comparison failed even with the fix applied. Use the canonical constructor instead. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
17be451 to
bf2e9d2
Compare
Add the boundary case raised in review: a source whose slot equals the finalized slot. Such a source is already final, so it may justify a newer target but must never re-finalize. This locks the > (not >=) intent of the finalization-advance guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
tcoratger
approved these changes
May 30, 2026
MegaRedHand
added a commit
to lambdaclass/leanSpec
that referenced
this pull request
Jun 1, 2026
The state transition only advances finalization when the attestation source lies strictly past the finalized boundary (PR leanEthereum#802). A source at the boundary is already final: it may justify a newer target but must not re-finalize. The tiered block-building scorer projected finalization independently and used a non-strict source check, so an entry whose source sat exactly on the finalized boundary was classed FINALIZE and over-ranked ahead of genuine justify entries, reordering selection near the data-entry cap. Mirror the strict source guard in the scorer and add a regression test covering a source at the finalized boundary.
MegaRedHand
added a commit
to lambdaclass/ethlambda
that referenced
this pull request
Jun 2, 2026
## Summary Ports [leanSpec #802](leanEthereum/leanSpec#802) to ethlambda. A supermajority attestation whose source checkpoint sits **at or behind the finalized boundary** is a valid justification anchor (`is_slot_justified` treats slots `<= finalized.slot` as already justified), so it may justify a newer target. But once it crosses the supermajority threshold, the finalization logic scanned `source.slot + 1 .. target.slot` and could try to advance (rewind/re-finalize) below the finalized boundary. The fix gates finalization advancement on `source.slot > finalized_slot`. Stale or boundary sources may still justify newer targets; they no longer try to rewind or scan below the finalized boundary. ## Relationship to #402 This supersedes [#402](#402) (`fix(stf): reject blocks justifying a target whose source is below finalized`), which was the pre-#802 attempt that fixed the issue by *rejecting* such blocks. The spec instead **accepts** the justification and only skips the finalization advance, so this PR follows the merged spec approach. #402 can be closed in favor of this. ## Changes Two mirrored spots get the `source.slot > finalized_slot` guard: | Location | Role | |----------|------| | `try_finalize` (state transition) | The actual finalization advance | | `score_entry` (block builder) | Projects/scores finalization while packing blocks | ## Tests - `state_transition`: `stale_finalized_source_justifies_without_rewinding_finalization` — supermajority from a stale source justifies the target while finalization stays pinned. - `block_builder`: `score_entry_does_not_finalize_source_at_boundary` — a boundary source is scored `Justify`, not `Finalize`. ``` cargo test -p ethlambda-state-transition --lib # 2 passed cargo test -p ethlambda-blockchain --lib block_builder # 8 passed ``` fmt + clippy (`-D warnings`) clean on both crates. Co-authored-by: Pablo Deymonnaz <pdeymon@fi.uba.ar>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This fixes an Lstar finalization edge case where an attestation with a source checkpoint at or behind the current finalized boundary could justify a newer target, then incorrectly enter the finalization-advance scan from below the finalized boundary.
Finalized sources are valid justification anchors:
JustifiedSlots.is_slot_justified()treats slots at or belowlatest_finalized.slotas already justified. But once such an attestation crossed the supermajority threshold, the finalization logic scannedsource.slot + 1 .. target.slotand calledSlot.is_justifiable_after(finalized_slot)on candidate slots beforefinalized_slot, triggeringCandidate slot must not be before finalized slot.The fix gates finalization advancement on
source.slot > finalized_slot. Stale finalized sources may still justify newer targets, but they no longer try to rewind or scan below the finalized boundary.Validation
uv run --group test fill tests/consensus/lstar/state_transition/test_finalization.py --fork=Lstar --clean -quv run --group lint ruff check src/lean_spec/forks/lstar/spec.py tests/consensus/lstar/state_transition/test_finalization.pyuv run --group lint ruff format --check src/lean_spec/forks/lstar/spec.py tests/consensus/lstar/state_transition/test_finalization.py