fin-proof: bench-log, the 100-key cycle counts on rz-4090
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
b49051f1e4
commit
78ef3ea386
1 changed files with 12 additions and 0 deletions
|
|
@ -2650,3 +2650,15 @@ Design `docs/design/finality-in-proof.md` (frontier rank 1, 3.3). The aggregator
|
|||
| Public values | 340 bytes without the finality input, 504 with (the 164-byte extension); the compressed proof size is the recursion's constant |
|
||||
|
||||
### Measurements
|
||||
|
||||
Rig: the fleet lane's rz-4090 pod (RunPod, RTX 4090 24 GB, 96 threads, 251 GB, the SP1 6.8.1 CUDA prover `sp1-gpu-server`, the host built there with `--features cuda` from this branch's sources at 589703eb plus the measurement commits), 08:2x to 08:4x UTC, nothing else on the card. The box (igneum-build-1) was held by the attack lane's exclusive measure wait, so the cycle counts ran on the pod's CPU in SP1 execute mode (deterministic, the same count anywhere). Fixtures: the eight consecutive live chain blocks 81046 to 81053 of `proving/fixtures/chain/` (one empty shard each, written before the DAA field existed, so the synthetic witness takes a DAA base of 100,000). The witness is synthetic (`--mode fin-synth`): N keys with real BLS key pairs, a 2,000-block prefix so the table and ring are full, two blue blocks a chain block, every key revealed with its first block, one certificate signed by the heaviest 70 percent of the keys over the chain block four back, carried in block 81053. The cycle count is `--mode fin-execute`: the aggregator guest in execute mode (deferred proof verification off, as the existing `execute aggregator` row) once without the finality input and once with it, per block.
|
||||
|
||||
#### Cycle count per chain block, 100 keys (70 signers), aggregator guest in execute mode
|
||||
|
||||
| Block | Plain aggregator | With the finality fold | Extra | What landed | Witness bytes (bincode) |
|
||||
|---|---|---|---|---|---|
|
||||
| 81046 | 1,306,522 | 4,724,994 | 3,418,472 | the fold, no certificate | 14,563 |
|
||||
| 81047 to 81052 | 1,426,208 | 5,673,842 to 5,911,401 | 4,247,617 to 4,485,193 | the fold, no certificate | 14,884 to 16,357 |
|
||||
| 81053 | 1,426,208 | 14,133,370 | 12,707,162 | the fold and ONE certificate (70 signers of 100 voters; lock index 2702 at chain block 81049, 2,808 of 4,008 blocks signed) | 29,371 |
|
||||
|
||||
Reading, 100 keys. The fold without a certificate costs about 4.3 M cycles a block at 100 keys (two hashes of the 11.2 KB key table, two to three ring leaves at 18 hashes each, the history append; SHA-256 is software in this guest, no precompile patch yet). The certificate costs about 8.3 M cycles on top: the syscall counts of that block are the BLS12-381 precompiles at work (700 G1 adds for the 70 signers plus the hash-to-curve and the pairing: 8,820 G1 doubles, 71,234 Fp multiplications, 13,139 Fp2 multiplications, 37,588 Fp adds, 17,419 Fp subs), so the pairing and the hash-to-curve run on SP1's bls12-381 precompiles as the design intended, and the whole certificate step is under a fifth of the frontier gate (a)'s 50 M cycles.
|
||||
|
|
|
|||
Loading…
Reference in a new issue