Skip to content

feat!: Aztec v6 (@aztec-labs), block-duration-ms input, SHA-pinned actions - #3

Merged
alejoamiras merged 7 commits into
mainfrom
worktree-aztec-v6-update
Oct 1, 2026
Merged

alejoamiras merged 7 commits into
mainfrom
worktree-aztec-v6-update

Conversation

@alejoamiras

@alejoamiras alejoamiras commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Moves aztec-benchmark to Aztec v6 and unblocks aztec-standards#38.

Changes

  • Aztec v6. v6 renamed its packages from @aztec/* to @aztec-labs/*, and the peers now follow at >=6.0.0-0 <7. The package version becomes 6.0.0-rc.1; v5 users stay on 5.0.1.
  • New block-duration-ms input on pr-benchmark.yml and update-baseline.yml. With the local network's default 3 s blocks, a transaction can use at most 55,836 DA gas, and aztec-standards' Vault class publish needs 63,776. Setting "6000" (mainnet's block time) raises the limit to 117,624. Leaving the input empty keeps today's behaviour.
  • Every action pinned to a commit SHA. The workflows used floating tags like setup-aztec@v0, so a caller pinning our workflow didn't actually pin what ran.
  • Small hardening:
    • the reusable workflows no longer persist the checkout token;
    • pre-release.yml no longer uses secrets: inherit;
    • no ${{ }} inside run: blocks;
    • the action calls npx --no. The unscoped aztec-benchmark npm package belongs to someone else, and plain npx could download and run it.

Testing

  • aztec-standards CI: its scratch PR fix: action name defi-wonderland/aztec-benchmark#45 ran against this branch.
    • With "6000", the Vault benchmark passes.
    • With the input omitted, it fails exactly as before, at 55,836.
    • With "6s", it stops in the first step.
    • update-baseline passes.
  • Local v6 network: it reports exactly 55,836 and 117,624. The packed 6.0.0-rc.1 ran a benchmark end to end.
  • Build output: the built JS is byte-identical to 5.0.1, because the Aztec imports are only used as types.

Notes

  • Please squash-merge. Merging also publishes a canary build to npm; that is existing behaviour.
  • Follow-ups for separate PRs: npm trusted publishing (OIDC), a CI check that actions stay pinned, and narrower workflow permissions.
Releasing 6.0.0-rc.1 (after merge)
  1. Set S to the squash commit on main, then tag it: git tag -s v6.0.0-rc.1 $S -m v6.0.0-rc.1 && git push origin v6.0.0-rc.1.
  2. Create the release: gh release create v6.0.0-rc.1 --verify-tag --target main --prerelease --generate-notes. The target must be main, not a SHA, or publish.yml skips publishing.
  3. In the publish.yml run, confirm the head SHA is $S, then approve the Publisher environment. It publishes under the rc dist-tag, and latest stays at 5.0.1.
  4. If the run was skipped, dispatch it from main instead: gh workflow run publish.yml --ref main -f version=6.0.0-rc.1.

🤖 Generated with Claude Code

alejoamiras and others added 7 commits September 30, 2026 14:32
Floating tags (setup-aztec@v0, create-or-update-comment@v4, checkout@v4,
upload-artifact@v4, setup-node@v4) let upstream change what runs, and a
caller's SHA pin on these reusable workflows did not pin them.

Also stop persisting the checkout token in the reusable workflows (PR
code and installers run in the same job) and stop passing all repo
secrets to the upstream pre-release workflow, which uses none.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move ${{ }} expressions used inside run: into step env (publish.yml
version/tag checks, the comment-minimize step), quote $GITHUB_OUTPUT, and
make the action's npx call refuse to install: the unscoped
`aztec-benchmark` npm package belongs to a third party.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…lows

Callers can set the local network's SEQ_BLOCK_DURATION_MS. The per-tx DA
gas cap scales with blocks per checkpoint: the 3 s default admits 55836,
6000 ms (mainnet's block duration) admits 117624, enough for large
contract-class publications. The value is validated before checkout because
Aztec parses it with parseFloat ("6s" would mean 6 ms); empty keeps today's
environment untouched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rity model

Replace the non-existent @v0 refs with commit-SHA pins, add contents: read
to the example permissions, complete the PR Benchmark inputs table, and
explain why the per-tx DA cap depends on block duration.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Aztec v6 renamed its npm scope from @Aztec to @aztec-labs. Peers are now
@aztec-labs/aztec.js and @aztec-labs/wallets at >=6.0.0-0 <7 (any 6.0.0
pre-release, since upstream's latest tag points at a nightly), and
config.aztecVersion moves to 6.0.0-rc.1.

The CLI only uses these packages in type positions, so the emitted
dist/*.js is byte-identical to 5.0.1; only the .d.ts specifiers change.

BREAKING CHANGE: requires @aztec-labs/* v6 peers; v5 (@aztec/*) consumers stay on 5.0.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-echo invariant

The trigger warning applies to pr-benchmark.yml only (update-baseline runs
on push), and on fork PRs the failed comment step also skips the baseline
upload. The validator comment now records why the value is never echoed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
alejoamiras added a commit to AztecProtocol/aztec-standards that referenced this pull request Sep 30, 2026
The Vault benchmark's setup publishes the Vault contract class (63,776 DA
gas). The local network's default 3s blocks cap a tx at 55,836, and
aztec-benchmark's reusable workflows had no way to change that.

Pin both workflows to AztecProtocol/aztec-benchmark#3, which adds a
block-duration-ms input, and pass 6000 (mainnet's 6s blocks: 117,624).
This is a pre-release commit; swap it for the v6.0.0-rc.1 tag commit
before merging.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alejoamiras
alejoamiras merged commit 879fa93 into main Oct 1, 2026
4 checks passed
@alejoamiras
alejoamiras deleted the worktree-aztec-v6-update branch October 1, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants