From 6a63c1fdab0c32c3851fcf6ceca36e0c2dfa854a Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 18:55:15 +0000 Subject: [PATCH] Bridge doc: recovery locks (F04) fail closed on the verifier, which reads only weight against the installed table and knows no lock kind Co-Authored-By: Claude Fable 5.1 --- docs/bridge/light-client-bridge.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/docs/bridge/light-client-bridge.md b/docs/bridge/light-client-bridge.md index f165c57b7..a90cae0e9 100644 --- a/docs/bridge/light-client-bridge.md +++ b/docs/bridge/light-client-bridge.md @@ -48,6 +48,12 @@ Measured on the test EVM: a 29-voter table costs about 5.3 million gas to instal verifies in about 3.9 million gas (the pairing and the two map-to-curve calls dominate; a G1 addition per signer is 375 gas). On Sepolia at a 1 gwei tip that is under 0.01 ETH per certificate. +Recovery locks (finality rule v4's majority-continuity recovery after an empty window, review B item F04) are not a +kind the contract knows: the certificate bytes carry no lock label, so the verifier reads only weight against the +installed table and accepts the final rule alone. A certificate signed by over half but under two thirds of the +table returns `ok = false` and `submitCertificate` reverts: a recovery lock is never recorded as final, and a +consumer that needs recovery locks must carry its own state, since nothing here tells them apart. + ## What the account proof proves `verifyAccount(stateRoot, account, proof)` walks an Ethereum account proof (the `eth_getProof` shape: RLP nodes from