Skip to content

Networks from a spec: check, provision/join, and genesis creation - #14

Merged
abhijitkrm merged 6 commits into
mainfrom
feat/network-spec
Oct 10, 2026
Merged

abhijitkrm merged 6 commits into
mainfrom
feat/network-spec

Conversation

@abhijitkrm

@abhijitkrm abhijitkrm commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

This replaces node-setup's run-genesis, run-validator and run-archive scripts with cometcli commands built on one network spec.

Phase 1: spec and checks

  • network import: from network-config.env files, or --from-node (a running network, with its genesis saved byte for byte).
  • network show.
  • network check: reviews the spec (--prod adds production rules), compares it with the chain's live parameters, and checks every node's config.toml, app.toml and container command against its role (validator, archive, rpc).

Phase 2: provision and join

  • node provision sets up a node on a host, local or over SSH:
    • init in the image as the home's owner
    • install the genesis
    • render the configs for its role from evmd init's own defaults, keeping comments; a rendered node passes network check
    • write the compose file (ws-origins flag, archive --pruning nothing, validator RPC on 127.0.0.1, 60s stop grace) and start it
  • It refuses a home that already holds a validator key; --reconfigure only re-renders configs.
  • val create reads the consensus key and moniker from the node.
  • Decimal transaction fields (cosmos.Dec) follow the chain's cosmos-sdk version: plain decimals on v0.54+, scaled integers before. On cosmos/evm v0.7.2, 5% commission had been read as 5×10¹⁶.

Phase 3: new networks

  • genesis create runs the distributed workflow with cometcli as coordinator:
    • keys on each validator's host
    • base genesis patched from the spec, the same edits as init-genesis.sh
    • each gentx signed on its own host
    • collect and strict validate
    • render, start, and wait for blocks
  • Mnemonics go only to the terminal or to 0600 files.

Tested:

  • Local cosmos/evm v0.7.2:
    • joined an archive and two validators to a running network, all passing their role checks
    • created a 4-validator network from the run-genesis env in one command: producing blocks in 3s, all four signing, network check reported everything matching the spec
    • the patched genesis passes the real evmd validate-genesis
  • primium-1, read-only: network check (0 FAIL; real warnings) and the scaled-commission encoding for v0.53.

Also: known questions are answered without a configured model.

🤖 Generated with Claude Code

abhijitkrm and others added 2 commits October 9, 2026 20:15
A network is described once, ~/.cometcli/networks/<chain-id>.yaml: chain
and EVM ids, genesis gov/staking/slashing/feemarket/EVM/mint/distribution
params, consensus timing, services, DB backend, image and its naming.

- network import: from node-setup's network-config.env files (genesis
  first, validator/archive fill the rest); unknown keys kept under extra
- network show
- network check: the spec's own sanity (and with --prod, test-only values
  — voting/unbonding periods, LAN timeouts, ws_origins *, default min
  deposit), the chain's live params against it, and every node of the
  chain against its role:
    all: db_backend = app-db-backend (empty = same), the app-side
      mempool on cosmos/evm v0.7+ and never on v0.6, gas price, EVM
      chain id, services, ws-origins passed as a CLI flag
    validator: consensus timeouts, external_address; --prod: no CORS,
      unsafe-cors, insecure unlock, swagger, debug/personal
    archive: pruning nothing (app.toml or --pruning), tx_index kv
    rpc: tx_index kv
- network.* tools run without an active profile

Run on primium-1: all four validators lack --json-rpc.ws-origins, three
have open CORS and insecure unlock, and the live params differ from the
node-setup env (60s unbonding/voting, 100-block window vs 600s, 10000).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- network import --from-node: the spec from a running node (identity and
  live params from the chain, timing/services/fees from its config, the
  image from its container) and its genesis.json, byte for byte
- spec fee_denom: EVM chains pay fees in another denom than they bond
- rendering: the role's settings patched into evmd init's own configs
  (comments kept); a rendered node passes network check — tested against
  real v0.7.2 defaults for every role, test and prod
- node provision: image present, home writable (else the one-time chown),
  init as the home's owner in the home (the image's workdir isn't
  writable: 'mkdir data: permission denied'), genesis, configs, compose
  (ws-origins flag, --pruning nothing for archives, validator RPC on
  127.0.0.1, 60s stop grace) and start; refuses a home holding a
  validator key; --reconfigure re-renders only; --docker_network and
  --port_offset for several nodes on one machine
- val create: consensus key and moniker from the node; refuses while
  catching up; the approval shows the full message (ed25519 key type
  registered)
- cosmos.Dec tx fields follow the chain's cosmos-sdk: plain decimals on
  v0.54+, scaled integers before — 5% commission was read as 5x10^16 on
  cosmos/evm v0.7.2
- wait.until synced works for nodes that aren't validators
- profile add --container-key

Tested on a local drill network (cosmos/evm v0.7.2): an archive and two
validators provisioned, synced in 10s, the validators created and in
consensus; all three pass network check.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abhijitkrm abhijitkrm changed the title Network spec, role profiles and network check Network spec, checks, and provisioning validators/archives from it Oct 9, 2026
genesis create <chain-id> --validators v1,v2,… runs node-setup's
distributed genesis workflow with cometcli as the coordinator:
- each validator's host: init in the image (node and consensus keys stay
  there), the operator key in the node's own keyring (test or file)
- base genesis from the spec: staking/gov/slashing/mint/distribution/
  feemarket params, EVM precompiles by name (sorted, as evmd requires),
  access control, erc20, denom metadata, block gas — the edits
  init-genesis.sh makes, in Go, decimals without float noise; every
  validator funded plus --accounts
- each gentx signed on its own host; only the gentx comes back
- collect-gentxs and a strict validate-genesis
- the final genesis on every node (and saved for later joins), configs
  rendered with every other validator as a peer, compose, start, and a
  wait for blocks
Mnemonics go only to the terminal or --mnemonics-to files (0600). Homes
that already hold a node are never touched.

Also: network import --chain-id (a new network from existing settings);
known questions are answered without a model configured (the TUI says
so; only model questions fail).

Tested locally: a 4-validator cosmos/evm v0.7.2 network created from
node-setup's run-genesis env in one command — producing blocks in 3s,
all four bonded and signing, and network check: everything matches the
spec, live params included. The patched genesis also passes the real
evmd validate-genesis.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abhijitkrm abhijitkrm changed the title Network spec, checks, and provisioning validators/archives from it Networks from a spec: check, provision/join, and genesis creation Oct 9, 2026
abhijitkrm and others added 2 commits October 9, 2026 21:33
- node-home-permission-denied: "mkdir data: permission denied" at
  start — the container's user doesn't own the home, or its workdir
  isn't writable (new logs.permission_denied category; not docker-socket
  errors)
- node-db-backend-data-mismatch: "failed to initialize database: EOF"
  with matching config files — the data was written by the other backend
  (new logs.db_init_eof)
- evm-ws-origins-config-only (advisory): WebSocket enabled but origins
  only in app.toml, which cosmos-evm mangles — browsers get 403 (new
  signals proc.ws_origins_flag from the container command, app.json_rpc_ws)
- the mempool rule follows the CometBFT version: "app" on 0.38 (v0.6)
  can't start, "app" with max-txs < 0 can't either

Seen live on primium-1: all four validators match the ws-origins advisory.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- genesis create --keyring file: the operator keys on every validator are
  encrypted; the password comes from COMETCLI_CONTAINER_KEYRING_PASSWORD
  or is asked twice on the terminal (a typo would lock the keys), 8+
  characters; gentxs are signed with it on each host
- signing reads COMETCLI_CONTAINER_KEYRING_PASSWORD before asking: the
  CLI always asked on the terminal, so scripts and watch couldn't sign
  with a file keyring although the docs said the variable works

Tested: a 2-validator network created with file keyrings (keys encrypted
at rest, no plaintext keyring), a transfer signed later with the
container's file keyring, and a wrong password refused clearly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abhijitkrm
abhijitkrm added this pull request to stack #16 October 10, 2026 09:27
@abhijitkrm
abhijitkrm merged commit bf9ad18 into main Oct 10, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant