build(devnet): pin lean-quickstart to the lambdaclass keygen branch - #624
Conversation
`make run-devnet` broke after the leanVM bump (#606). Upstream lean-quickstart still generates validator keys with hash-sig-cli, whose keys use an older XMSS format: the node refuses the genesis at parse time (`pubkey has length 52 (expected 32)`). The lambdaclass/lean-quickstart `devnet5-ethlambda-keygen` branch generates keys with `ethlambda keygen` and runs the devnet-5 client images. The recipe passes KEYGEN_IMAGE so the keys come from the image under test and always match its leanVM revision. An existing lean-quickstart/ is never re-cloned, so a stale clone kept failing silently; the recipe now warns when the clone is not on the pinned branch. The image-tag sed also stops at `}`, because matching through it removed the closing brace of a `${VAR:-image}` default and broke ethlambda-cmd.sh.
🤖 Kimi Code ReviewI'll review this PR diff focusing on the Makefile changes for the devnet tooling. This appears to be infrastructure/tooling rather than consensus-critical code, but I'll check for correctness and maintainability issues. Review: Makefile changes (PR #624)1. Branch check logic is fragile (Lines 108-109)@[ "$$(git -C lean-quickstart rev-parse --abbrev-ref HEAD)" = "$(LEAN_QUICKSTART_BRANCH)" ] \
|| echo "⚠️ lean-quickstart/ is not on the pinned $(LEAN_QUICKSTART_BRANCH) branch; delete it to re-clone"Problem: This warning is non-blocking. The Suggestion: Make this a hard error or add a force-clone option. At minimum, use @if [ "$$(git -C lean-quickstart rev-parse --abbrev-ref HEAD)" != "$(LEAN_QUICKSTART_BRANCH)" ]; then \
echo "⚠️ lean-quickstart/ is not on the pinned $(LEAN_QUICKSTART_BRANCH) branch; delete it to re-clone" >&2; \
exit 1; \
fi2.
|
| Severity | Item | Location |
|---|---|---|
| Medium | Non-blocking branch mismatch warning | Lines 108-109 |
| Low | sed pattern brittleness |
Line 115 |
| Low | Missing .PHONY |
lean-quickstart target |
| Low | Unconditional rm -rf |
Line 111 |
The consensus-critical code paths (state transition, fork choice, XMSS) are untouched in this PR. The changes are devnet infrastructure only.
Automated review by Kimi (Moonshot AI) · kimi-k2.6 · custom prompt
🤖 Codex Code ReviewI found one correctness issue; otherwise this looks fine.
A few quick notes:
Automated review by OpenAI Codex · gpt-5.4 · custom prompt |
🤖 Claude Code ReviewReview of PR 624 (Makefile only, The change is small and sensible. It points Findings
Verdict: Looks good overall. Nothing here affects consensus code. Points 1 and 4 are the ones worth checking before merge. Automated review by Claude (Anthropic) · sonnet · custom prompt |
…anch The run-devnet check only compared branch names, so a clone on the right branch kept running its old commit after the pin moved upstream, with no warning. On the pinned branch, the recipe now also compares HEAD against the remote tip via `git ls-remote`, which reads the ref without touching the clone. It only warns: the recipe rewrites ethlambda-cmd.sh in place, so the clone is always dirty and an automatic pull would conflict. The branch name check still runs first, since it works offline and makes the remote comparison redundant when it fails.
Motivation
make run-devnethas been broken since the leanVM bump in #606. Upstream lean-quickstart still generates validator keys withhash-sig-cli, and those keys use an older XMSS format, so every node refuses the genesis at parse time:Changes
Clone lean-quickstart from
lambdaclass/lean-quickstart@devnet5-ethlambda-keygeninstead of upstreammain. That branch:ethlambda keygen(image chosen byKEYGEN_IMAGE)Pass
KEYGEN_IMAGE=ghcr.io/lambdaclass/ethlambda:$(DOCKER_TAG), so the keys come from the image under test and match its leanVM revision.Warn when an existing
lean-quickstart/is out of date. The target never re-clones, so a stale clone used to keep failing without any hint. Two checks, in order:HEADmatches the branch tip on the remote, read withgit ls-remoteso the clone is left untouched. This catches a clone left behind after the pinned branch moves upstream. If the remote can't be reached, the check is skipped with a notice.Both only warn: the recipe rewrites
ethlambda-cmd.shin place, so the clone is always dirty and an automatic pull would conflict.The image-tag
sednow stops at}. Matching through it deleted the closing brace of a${VAR:-image}default, which brokeethlambda-cmd.shwithunexpected EOF.Repo and branch can be overridden with
LEAN_QUICKSTART_REPO/LEAN_QUICKSTART_BRANCH.How to test
rm -rf lean-quickstart # only if you have an old clone; save anything local first make run-devnetTested with
make -o docker-build run-devneton a fresh clone of the pinned branch:leanvm_rev48a90420The freshness check was tested on its own against the four cases: up to date (silent), wrong branch, right branch but not at the remote tip, and remote unreachable.
Finality was not reached in that run because a parallel
cargobuild had the host at load 65 on 11 cores, so the nodes' ticks fell behind wall clock. A rerun on an idle machine should confirm it.A separate 5-client run (one validator per devnet-5 client) loaded keys on every client and justified slot 3. It then stalled: grandine hit its "parent not found" wedge and ream fell behind on CPU. That is why the default roster is ethlambda-only.