From 3e0c0c90c85c52a80c1c8e8fe43fcce45691b28b Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 08:58:45 +0000 Subject: [PATCH] fin-proof: the re-measure after the two fixes and the Merkle table (fp-2, RTX 5090), bench-log and design 6.2a Co-Authored-By: Claude Fable 5.1 --- docs/bench-log.md | 25 +++++++++++++++++++++++++ docs/design/finality-in-proof.md | 11 +++++++++-- 2 files changed, 34 insertions(+), 2 deletions(-) diff --git a/docs/bench-log.md b/docs/bench-log.md index 74d2dc530..1f96716c4 100644 --- a/docs/bench-log.md +++ b/docs/bench-log.md @@ -2688,3 +2688,28 @@ Reading. Two costs, both linear in the table, both with a named fix: Reading, per block at launch traffic (one certificate per 30 blocks): today's guest costs an aggregator 10.9 s a block plus 43 s once per 30 blocks, about 12.3 s a block against 3.1 s plain, 4x, at 1,000 keys on a 4090 by itself; with the two fixes above (sha2 precompile, validated keys stored) the fold's 32 M cycles become a few million and the certificate's 45 M about 8 M, so the aggregation lands near 4 s a block plus 8 s per certificate, about 4.3 s a block, 1.4x (approximate, from the cycle rows; the re-measure is the next item). The 12 GB-card question of 5 October is untouched: shard provers never see the fold; only the aggregator (a 24 GB card in the app's rule) pays it. Per tier: home miner, any card, mining only: nothing changes. Shard prover (12 GB): nothing, the fold is the aggregator's. Aggregator (24 GB card): 4x the aggregation time today at 1,000 voters, 1.4x after the two fixes, paid from the same aggregator share (`proving_v1_aggregator_share_bps` is the parameter to revisit when the fixed guest is measured). Pool: nothing. Holder, wallet, tab: "locked, voter set verified in the proof" from 504 bytes and one verification, no node asked for the voter set. Rollup customer: the same proof carries state and finality. Node operator: the witness is 123 KB a block at 1,000 keys (the key table rides with every block in the prototype; the Merkle table takes it to a few KB). Devnet: nothing, the switch is never. + +### After the two fixes and the Merkle key table (the same day, 08:5x UTC; the fp-2 pod, RunPod RTX 5090 32 GB, the fleet image, SP1 6.8.1 cuda, the card to itself; guest 0x4ab78fb1; `fin-proof-artefacts/fp2/`) + +The three changes between the morning's rows and these: the sha2 precompile patch for the guest (every fold, ring and history hash), the certificate path over the signers' uncompressed points (on the curve and compressing to the committed key: no square root, no subgroup check per signer; the reveal's proof of possession did that once), and the key table as a Merkle tree (one path per touched key in the fold; the full table once per certificate, rebuilt over the dense slot prefix). Level 1 of the colouring was built in the same window but the synthetic witness carries no headers, so these rows are level 0's arithmetic; the headers' BLAKE2b (16 a block, software) is the one cost not in them. + +| Keys in the table | Plain aggregator | Fold, no certificate (81047 to 81052) | Extra for the fold | Certificate block 81053 (signers) | Extra for the certificate alone | Witness bytes per block (fold / certificate block) | +|---|---|---|---|---|---|---| +| 100 | 1,362,263 | 1,912,729 to 1,962,xxx | 0.55 to 0.60 M | 7,311,232 (70) | 5.4 M | 4.8 KB / 27 KB | +| 1,000 | 1,362,263 | the same 1,912,729 to 1,962,xxx | 0.55 to 0.60 M | 19,905,947 (700) | 18.0 M | 4.8 KB / 208 KB | +| 3,429 | 1,362,263 | the same | 0.55 to 0.60 M | 62,414,311 (3,429) | 60.5 M | 4.8 KB / 803 KB | + +Reading. The fold no longer depends on the table size: 0.55 M cycles a block at 100, 1,000 and 3,429 keys (against 4.3 M, 32 M and 106 M in the morning), 427 to 463 SHA compressions on the precompile, and the witness is 4.8 KB a block whatever the table (against 123 KB at 1,000 keys). The certificate is where the table is still paid: the dense rebuild of the key table is 3N SHA compressions (4,664 at 1,000 keys, 14,384 at 3,429) and the per-signer part is now the on-curve check and the point decode (51,214 Fp multiplications at 700 signers against 465,614 in the morning; no G1 doublings at all). Per signer the certificate costs about 18 K cycles (was 64 K). Frontier gate (a), under 50 M cycles a certificate: holds at 1,000 voters (18.0 M, was 44.8 M) and misses at 3,429 (60.5 M, was 188 M). What is left in the 3,429 row is the table rebuild and the sort, not the curve; the next lever is a committed running total so the certificate step needs only the signers' leaves (a Merkle multiproof) and never the full table: the fold then maintains `total` through the dust, ban and leave transitions it already touches plus a due-list for the time crossings, and the certificate cost becomes per signer only (about 18 K each, 3,429 signers 62 M of which the rebuild is most). Not built this round. + +#### Prove time on the RTX 5090 (fp-2, the card to itself), a chain of 8 blocks + +| Run | Shard proof per block | Aggregation per block | Certificate block | End to end, 8 blocks | Final proof bytes | +|---|---|---|---|---|---| +| Plain (no finality input) | 2.1 to 2.7 s | 2.2 to 2.8 s | none | 42.4 s | 1,272,909 | +| With the fold, 1,000 keys, after the fixes | 2.4 to 2.7 s | 2.7 to 3.0 s | 8.2 s (700 signers) | 50.3 s | 1,273,073 | + +`final-at` on the finality proof: VERIFIED in 0.418 s, "not final (latest lock: checkpoint 2702 at chain block 81049)" for the proof's own block 81053, the right answer; the lock 2,808 of 4,008 signed. + +The ratio, per block at launch traffic (one certificate per 30 blocks): plain 2.6 s a block; with the extension 2.85 s plus 8.2 s once in 30, 3.1 s a block, 1.2x (the morning's guest on the 4090 was 4x: 12.3 s against 3.1 s). At 3,429 signers the certificate block would be about 25 s (approximate, from the cycle ratio 60.5 to 18.0 M against the 8.2 s row), 3.6 s a block, 1.4x. + +Per tier, revised: a home miner on any card, mining only, nothing changes; a shard prover (12 GB) never sees the fold; an aggregator (24 GB card) pays 1.2x today's aggregation time at 1,000 voters and 1.4x at 3,429, from the same aggregator share; a pool, nothing; a holder, the wallet, the tab get "locked, voter set verified in the proof" from 504 bytes and one verification, and at level 1 the blue set is pinned to headers (the remaining freedom is a colour swap inside one chain block's mergeset); a rollup customer's bridge verifies one proof for state and finality; a node operator relays 4.8 KB of witness a block plus the table once per certificate (208 KB at 1,000 keys, 803 KB at 3,429, the next lever's target); the devnet, nothing, the switch is never. diff --git a/docs/design/finality-in-proof.md b/docs/design/finality-in-proof.md index c048229f2..18c57a22c 100644 --- a/docs/design/finality-in-proof.md +++ b/docs/design/finality-in-proof.md @@ -161,8 +161,15 @@ The fold is the key table hashed in and out with software SHA-256 (31 K cycles a At one certificate per 30 blocks: 12.3 s a block against 3.1 s, 4x today at 1,000 keys; about 1.4x after the two fixes (approximate, from the cycle rows). -### 6.2a After the two fixes and the Merkle table -To be filled from the fp-2 run (RTX 5090, 7 October 2026, 10:xx UK): the same rows as 6.1 and 6.2 on the pinned guest 0x4ab78fb1. +### 6.2a After the two fixes and the Merkle table (measured 7 October 2026, 08:5x UTC, the fp-2 pod's RTX 5090; `docs/bench-log.md`, the same entry) + +| Keys | Plain aggregator | Fold, no certificate | Certificate block (signers) | +|---|---|---|---| +| 100 | 1.36 M | 1.91 to 1.96 M | 7.3 M (70) | +| 1,000 | 1.36 M | the same | 19.9 M (700) | +| 3,429 | 1.36 M | the same | 62.4 M (3,429) | + +The fold is 0.55 M a block whatever the table (4.8 KB of witness); the certificate is 18 K cycles a signer plus the table rebuild (3N SHA compressions). Gate (a) holds at 1,000 voters (18.0 M extra) and misses at 3,429 (60.5 M); the next lever is a committed running total, so the certificate takes only the signers' leaves by multiproof. On the 5090: plain aggregation 2.2 to 2.8 s a block, with the fold 2.7 to 3.0 s, the certificate block 8.2 s; 42.4 against 50.3 s for 8 blocks; at one certificate per 30 blocks 1.2x at 1,000 voters, about 1.4x at 3,429. ### 6.3 Verifier time (measured) `verify-segment` 0.090 s on the finality proof (0.076 to 0.091 s on the plain one, the same light verifier); `final-at` answers from the 504 bytes of public values in under a microsecond after the verification; a browser's WASM verify of the wrapped proof stays frontier 3.4's measurement.