Skip to content

fix(l1): deploy the real epoch proof verifier unless REAL_VERIFIER=false - #25517

Closed
AztecBot wants to merge 1 commit into
nextfrom
cb/l1-real-verifier-default
Closed

AztecBot wants to merge 1 commit into
nextfrom
cb/l1-real-verifier-default

Conversation

@AztecBot

Copy link
Copy Markdown
Collaborator

Problem

RollupConfiguration.useRealVerifier() reads REAL_VERIFIER with a default of false. DeployRollupLib._deployVerifier deploys MockVerifier on false, and MockVerifier.verify returns true for any proof and public inputs. The verifier is fixed at Rollup construction with no setter, so running DeployAztecL1Contracts or DeployRollupForUpgrade directly through Forge without setting REAL_VERIFIER=true produces a rollup whose submitEpochRootProof accepts arbitrary proof bytes for its whole lifetime. The mock is the correct choice only for local and test networks, so it has to be an explicit opt-out, not the fail-open default.

Refs AztecProtocol/aztec-claude#840.

Change

  • RollupConfiguration.useRealVerifier() defaults to true. REAL_VERIFIER=false still selects MockVerifier for local and test deployments.
  • scripts/run_rollup_upgrade.sh no longer sets its own REAL_VERIFIER default, which duplicated the Solidity default.
  • New Foundry test test_DeploysRealVerifierByDefault runs the full deploy script with REAL_VERIFIER unset and asserts the rollup's getEpochProofVerifier() has the HonkVerifier codehash.

No on-chain contract changes. RollupCore, EpochProofLib and MockVerifier are untouched, so there is no gas impact on any deployed contract.

What this does not change

  • aztec-node's deployer (deploy_aztec_l1_contracts.ts) always sets REAL_VERIFIER explicitly to 'true' or 'false' from its realVerifier argument, so node-driven deployments and e2e tests behave exactly as before. The --real-verifier CLI flag in that repo still defaults to false; flipping that is a separate change in aztec-labs-eng/aztec-node, which is why this PR uses Refs rather than Closes.
  • Mainnet is not affected. All three rollups registered on the mainnet Registry are bound to real Honk verifiers: the canonical (v5) rollup's verifier bytecode matches the HonkVerifier.sol checked into v5-next for DeployRollupForUpgradeV5.s.sol, and the previous (v4 line) rollup's verifier code hash matches the constant pinned in DeployAlpha.s.sol. Neither mainnet script consults this default; the generic script's default only reaches a deployment when someone runs it by hand.

Tests

Red, on next before the fix:

[FAIL: epoch proof verifier is not HonkVerifier: 0x9c8a5e05...be01e64 != 0xe5d91558...271a7eef] test_DeploysRealVerifierByDefault() (gas: 72759137)

Green after the fix, and the rest of the suite:

forge test --match-path 'test/script/*'   5 passed, 0 failed
forge test                                 1119 passed, 0 failed, 3 skipped
scripts/test_rollup_upgrade.sh             anvil deploy + run_rollup_upgrade.sh, "Test completed successfully"
forge fmt --check                          clean on the changed files

Created by claudebox · group: slackbot · requested by Mike (@iAmMichaelConnor) · Slack thread

@AztecBot AztecBot added ci-draft Run CI on draft PRs. ci-no-fail-fast Sets NO_FAIL_FAST in the CI so the run is not aborted on the first failure claudebox Owned by claudebox. it can push to this PR. labels Sep 21, 2026
@AztecBot

Copy link
Copy Markdown
Collaborator Author

Closing in favour of #25520, which carries this same change (REAL_VERIFIER defaulting to true, the wrapper no longer overriding it, and the script tests setting genesis roots) together with the rest of the generic-deployer validation, and closes AztecProtocol/aztec-claude#840 on merge.


Created by claudebox · group: slackbot · requested by Mike (@iAmMichaelConnor) · Slack thread

@AztecBot AztecBot closed this Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-draft Run CI on draft PRs. ci-no-fail-fast Sets NO_FAIL_FAST in the CI so the run is not aborted on the first failure claudebox Owned by claudebox. it can push to this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant