Windows payload: the Linux prover pair is required and travels in the inputs (flat names), placed at wsl2\bin with SHA256SUMS

The CI payload had never carried igneum-prove-host or igneum-prove-export for WSL2 (make-payload.sh's warning branch), so every PC ran a stale pair built by setup-wsl.sh from an old package; after 0.3.14 no PC verified peer proofs or exported segments. push-inputs.sh refuses to publish without the pair (IGNEUM_PROVE_LINUX names the folder) and make-payload.sh refuses a payload without it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-06 18:54:44 +00:00
parent 7943f83c17
commit 18b154de9c
2 changed files with 25 additions and 4 deletions

View file

@ -93,10 +93,18 @@ cp "$HERE/stop-igneum.ps1" "$STAGE/stop-igneum.ps1"
# them as /mnt/<drive>/.../wsl2/bin/igneum-prove-host from Ubuntu-24.04; Set up runs wsl2\setup-wsl.sh.
PROVE_LINUX="${IGNEUM_PROVE_LINUX:-$ROOT/proving/igneum-prove/target-linux/x86_64-unknown-linux-gnu/release}"
mkdir -p "$STAGE/wsl2/bin" "$STAGE/wsl2/fixtures"
if [ -f "$PROVE_LINUX/igneum-prove-host" ] && [ -f "$PROVE_LINUX/igneum-prove-export" ]; then
cp "$PROVE_LINUX/igneum-prove-host" "$PROVE_LINUX/igneum-prove-export" "$STAGE/wsl2/bin/"
echo "prover (WSL2): igneum-prove-host $(stat -f %z "$PROVE_LINUX/igneum-prove-host") bytes, igneum-prove-export $(stat -f %z "$PROVE_LINUX/igneum-prove-export") bytes"
else echo "warning: no Linux igneum-prove-host/igneum-prove-export in $PROVE_LINUX (cargo zigbuild --target x86_64-unknown-linux-gnu.2.36 --features igneum-prove-host/cuda); the Proving tile will ask for the WSL2 setup, which builds them"; fi
# 6 October 2026 (0.3.15): the pair is REQUIRED. First from the inputs next to the exes (push-inputs.sh ships them flat as
# igneum-prove-host.linux-x86_64 and igneum-prove-export.linux-x86_64, which is what CI has), else from PROVE_LINUX (a Mac
# build); a payload without them shipped every PC a stale prover from 0.3.5 to 0.3.14 (no peer-proof verification, no exports).
for b in igneum-prove-host igneum-prove-export; do
if [ -f "$REL/$b.linux-x86_64" ]; then cp "$REL/$b.linux-x86_64" "$STAGE/wsl2/bin/$b"; src="the inputs ($REL)"
elif [ -f "$PROVE_LINUX/$b" ]; then cp "$PROVE_LINUX/$b" "$STAGE/wsl2/bin/$b"; src="$PROVE_LINUX"
else echo "no Linux $b (looked at $REL/$b.linux-x86_64 and $PROVE_LINUX/$b); the payload never ships without the WSL2 prover pair again" >&2; exit 1; fi
chmod +x "$STAGE/wsl2/bin/$b"
echo "prover (WSL2): $b $(stat -f %z "$STAGE/wsl2/bin/$b" 2>/dev/null || stat -c %s "$STAGE/wsl2/bin/$b") bytes from $src"
done
# the shas the app and a job can check the installed pair against (a stale host is loud at the node's start from 0.3.15)
(cd "$STAGE/wsl2/bin" && { shasum -a 256 igneum-prove-host igneum-prove-export 2>/dev/null || sha256sum igneum-prove-host igneum-prove-export; } > SHA256SUMS)
cp "$ROOT"/proving/windows-wsl2/*.sh "$ROOT"/proving/windows-wsl2/*.ps1 "$ROOT"/proving/windows-wsl2/*.bat "$ROOT/proving/windows-wsl2/README.txt" "$STAGE/wsl2/"
cp "$ROOT"/proving/fixtures/*.json "$STAGE/wsl2/fixtures/"

View file

@ -62,6 +62,19 @@ else echo "warning: no $NVRTC_DIR/igneum-worker-cuda.exe (run $NVRTC_DIR/build-w
[ -f "$CL_WORKER" ] && cp "$CL_WORKER" "$STAGE/" || echo "warning: no $CL_WORKER"
[ -f "$TELEMETRY" ] && cp "$TELEMETRY" "$STAGE/" || echo "warning: no $TELEMETRY (AMD cards show no draw or temperature)"
# the Linux x86_64 prover pair for the PCs' WSL2 (6 October 2026: the CI payload had never carried it, so every PC ran a stale
# host and exporter built by setup-wsl.sh from an old package, and no PC verified peer proofs or exported segments after
# 0.3.14). The pair travels flat in the zip under distinct names (inputs.rs allows plain file names only); make-payload.sh
# puts them at wsl2\bin\igneum-prove-host and igneum-prove-export, candidate 1 of the WSL lookup (src/wslhost.rs). Refused
# without them: IGNEUM_PROVE_LINUX names the folder (the box's target-remote/release or the Mac's zigbuild target-linux).
PROVE_LINUX="${IGNEUM_PROVE_LINUX:-$ROOT/proving/igneum-prove/target-linux/x86_64-unknown-linux-gnu/release}"
for b in igneum-prove-host igneum-prove-export; do
[ -f "$PROVE_LINUX/$b" ] || { echo "no Linux $b in $PROVE_LINUX (build the pair on igneum-build-1 with tools/build-remote.sh from proving/igneum-prove, or cargo zigbuild --target x86_64-unknown-linux-gnu.2.36 --features igneum-prove-host/cuda); the PCs' provers would stay stale" >&2; exit 1; }
file "$PROVE_LINUX/$b" | grep -q "ELF 64-bit.*x86-64" || { echo "$PROVE_LINUX/$b is not a Linux x86_64 ELF" >&2; exit 1; }
cp "$PROVE_LINUX/$b" "$STAGE/$b.linux-x86_64"
echo "$b.linux-x86_64: $(stat -f %z "$PROVE_LINUX/$b") bytes from $PROVE_LINUX"
done
# the signer, built from the app crate (it includes src/manifest.rs and src/inputs.rs, so it signs what the runner verifies)
KEY="$HOME/.config/igneum/ota-signing-key"
PUB="$HOME/.config/igneum/ota-signing-key.pub"