igneum/tools/reference-apps/oracle
2026-10-08 17:01:08 +00:00
..
artifacts Reference apps, the review's four orders: /receipt is a transaction inclusion receipt in title, copy, file and the offline verifier's output (a payment receipt authenticates the outcome and is named as the next step); /light states its trusted inputs in one block and reads as a verification path with stated trust assumptions; /oracle discloses the deployer-installed voter table and the unchecked aggregator signature on the page and in trust() (oracle redeployed on the shared verifier, 0x3ad71d46, chain id accepted before and after the class v5 floor); the four words included, executed, proven, finalised defined once in site/partials/terms.html and injected on the three pages 2026-10-08 14:48:23 +00:00
contracts Reference apps, the review's four orders: /receipt is a transaction inclusion receipt in title, copy, file and the offline verifier's output (a payment receipt authenticates the outcome and is named as the next step); /light states its trusted inputs in one block and reads as a verification path with stated trust assumptions; /oracle discloses the deployer-installed voter table and the unchecked aggregator signature on the page and in trust() (oracle redeployed on the shared verifier, 0x3ad71d46, chain id accepted before and after the class v5 floor); the four words included, executed, proven, finalised defined once in site/partials/terms.html and injected on the three pages 2026-10-08 14:48:23 +00:00
.gitignore Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
compile.mjs Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
demo.mjs Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
deploy.mjs Oracle for the 2.0 devnet on Sepolia (0xbb345004…, statements with chain id 4465, on the shared verifier); /oracle says the shared verifier's installed table is Devnet 3's until devnet-4's lands 2026-10-08 16:54:21 +00:00
deployment.json /oracle: the igneum-devnet-4 verifier (0x874D8Be5…) set on the devnet-4 oracle; its table installs at the chain's first lock (about 23:00 on 8 October) 2026-10-08 17:01:08 +00:00
lib.mjs Reference apps, the review's four orders: /receipt is a transaction inclusion receipt in title, copy, file and the offline verifier's output (a payment receipt authenticates the outcome and is named as the next step); /light states its trusted inputs in one block and reads as a verification path with stated trust assumptions; /oracle discloses the deployer-installed voter table and the unchecked aggregator signature on the page and in trust() (oracle redeployed on the shared verifier, 0x3ad71d46, chain id accepted before and after the class v5 floor); the four words included, executed, proven, finalised defined once in site/partials/terms.html and injected on the three pages 2026-10-08 14:48:23 +00:00
package-lock.json Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
package.json Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
README.md Reference apps: the Sepolia state oracle (tools/reference-apps/oracle: IgneumStateOracle with keyed BLAKE2b through the EIP-152 precompile, the body merkle path, the IGNS record parse and an MPT verifier; StubCertificateVerifier as the stand-in; deploy, demo and the negative cases through eth_call, 34 passed on Sepolia), its addresses on /oracle 2026-10-08 10:41:57 +00:00
real-verifier.mjs Reference apps: the oracle on the shared IgneumCertificateVerifier (setVerifier 12:36 BST; certificate 2232 recorded with a real BLS check, block 28439's root stored under it, provenBalance equal to the node's eth_getProof); real-verifier.mjs; the tests skip the synthetic part when the shared verifier is installed; /oracle carries the addresses; the test page's transaction search respects the RPC's rate 2026-10-08 11:38:09 +00:00
test.mjs Reference apps, the review's four orders: /receipt is a transaction inclusion receipt in title, copy, file and the offline verifier's output (a payment receipt authenticates the outcome and is named as the next step); /light states its trusted inputs in one block and reads as a verification path with stated trust assumptions; /oracle discloses the deployer-installed voter table and the unchecked aggregator signature on the page and in trust() (oracle redeployed on the shared verifier, 0x3ad71d46, chain id accepted before and after the class v5 floor); the four words included, executed, proven, finalised defined once in site/partials/terms.html and injected on the three pages 2026-10-08 14:48:23 +00:00

Igneum Devnet 3 state oracle on Sepolia

A contract on Ethereum Sepolia that stores proven Devnet 3 state roots and lets other contracts read a proven Devnet 3 balance or storage slot. Certificates are read from the shared verifier (IIgneumCertificateVerifier); a StubCertificateVerifier stands in until the real one lands (setVerifier, deployer only, swaps it).

Addresses, transaction hashes, blocks and gas are in deployment.json (every write is appended under writes).

What the oracle checks on chain

  1. Every header in the path is hashed with keyed BLAKE2b-256 ("BlockHash") through the EIP-152 precompile and parsed out of the same bytes. Each next header must list the previous hash among its level-0 parents. The last hash must be the checkpoint the verifier holds for the given certificate index.
  2. The carrier's coinbase transaction is hashed ("TransactionHash") and the merkle path ("MerkleBranchHash", a missing right child is 32 zero bytes) must reach the carrier's hash_merkle_root, parsed from the header bytes.
  3. The coinbase payload is walked from the transaction bytes (so it is bound to the hash); the nested sections IGNS || IGNP || IGNF are taken from the end; the chosen 586-byte segment record gives the statement's number, block hash and post_root (number must equal the record's last, block hash must equal the record's block, chain id must be Devnet 3's 0x116f). The root is stored under the number with the certificate index.
  4. provenBalance, provenAccount and provenStorage verify eth_getProof account and storage proofs against the stored post_root with the contract's own RLP and keccak-keyed Merkle Patricia trie walk, and revert with a reason on any mismatch.

Not checked on chain in this slice (also stated by trust()): the aggregator's BLS signature over the segment record and the ZK proof behind it. Also not checked: the segment record's version field (the layout is fixed either way).

Files

  • contracts/Blake2b.sol: keyed BLAKE2b-256 over the precompile at 0x09.
  • contracts/Mpt.sol: RLP reading, MPT proofs, account and storage decoding.
  • contracts/IIgneumCertificateVerifier.sol, contracts/StubCertificateVerifier.sol, contracts/IgneumStateOracle.sol.
  • compile.mjs: solc-js (via IR, optimizer 200, cancun) to artifacts/*.json.
  • deploy.mjs: EIP-1559 deploy of the stub and the oracle, writes deployment.json (--force, --oracle-only).
  • demo.mjs: submits the certificate and the state root for fixtures/dn3-balance.json (or the synthetic vector when the fixture is absent) and prints the Sepolia-read balance beside the fixture's.
  • test.mjs: the vectors and negatives through eth_call. Part A is the receipt fixture (real headers, a real merkle path); part B is a seeded synthetic vector (segment record, coinbase, three-header path, account and storage proofs); part C is the balance fixture when it exists.
  • lib.mjs: the byte layouts, a JS mirror of the BLAKE2b driver (checked against @noble/hashes), the trie builder.

Run

node compile.mjs
node deploy.mjs
node test.mjs
node demo.mjs

The deployer key is read from ~/.config/igneum/sepolia-deployer. Sepolia's gas schedule is repriced (a plain transfer estimates 12,000 gas), so the numbers in deployment.json are what this network charges.