From 7ffae7b97a459f3594e7457e518cb980aca646d3 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Mon, 5 Oct 2026 22:33:31 +0000 Subject: [PATCH] Prover floor: the build recipe as it ran (Go pinned, the binary's sha256 and targets), the RISC Zero contingency figures with their source, playbook fixes Co-Authored-By: Claude Fable 5.1 --- docs/analysis/prover-floor.md | 24 +++++++++++++++++++++++ tools/prover-floor/make-build-playbook.sh | 21 +++++++++++++++----- tools/prover-floor/pc2-build-server.ps1 | 21 +++++++++++++++----- 3 files changed, 56 insertions(+), 10 deletions(-) diff --git a/docs/analysis/prover-floor.md b/docs/analysis/prover-floor.md index 0b2950ca8..b46b39272 100644 --- a/docs/analysis/prover-floor.md +++ b/docs/analysis/prover-floor.md @@ -89,3 +89,27 @@ upgrade repeats the clone, patch, build and measurement. The verifying key and t (the patch changes buffer sizes and the shard split, not the circuits), which the `verify-segment` and `--mode compressed` VERIFIED lines of the unpatched host show on every row below. The packaging path is a row for the proving plan before 0.3.12, not this branch. + +## Step 4 contingency, read not measured: RISC Zero's CUDA prover and its memory per segment + +If SP1 could not be brought under 11 GB, the alternative's floor is read from its operators' documentation (not +measured here; a PC 2 run would be the measurement): Boundless' prover guide +(https://docs.boundless.network/provers/performance-optimization) sets the segment size cap by VRAM as 8 GB: +po2 19, 16 GB: po2 20, 20 GB: po2 21, 40 GB: po2 22, with measured peaks po2 20: 13,835 MiB, po2 21: 22,905 MiB, +po2 22: 41,089 MiB; RISC Zero's PR 3761 adds `low_vram` and `pinned_witgen` to fit po2 22 on a 24 GB 4090. So +RISC Zero proves a 2^19-cycle segment inside 8 GB and a 2^20 one inside 16 GB, and a shard of 4.7 M cycles is +9 segments at po2 19 plus lift and join steps (times not on the page). Adopting it would cost a second guest (the +chain rule in the RISC Zero zkVM), a second pinned program id, a second verifier in the node and no shared +aggregation between the two formats: `docs/analysis/amd-proving.md` and the proving plan carry that row already. + +### The build, as it ran (job `floor-build-3`, 22:28:24 to 22:32:29Z) + +Three runs: `floor-build-1` (22:17Z) and `floor-build-2` (22:24Z) failed in 2 to 4 minutes on +`crates/recursion/gnark-ffi/build.rs:70`, "Failed to build Go library: NotFound" (no `go` on PC 2; the first run's +playbook lost its own log, a bug fixed before the second). `floor-build-3` fetched go1.27.1 (tarball sha256 +`63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445`, checked before unpacking under +`/opt/igneum-floor/go`, on the job's PATH only) and built in **240 s** (46 crates on the warm target of run 2, 8 +niced jobs, 16 cores). The binary: `/opt/igneum-floor/bin/sp1-gpu-server`, **166,768,224 bytes, sha256 +`5568108bf7fb9b0e525d8a08926b7046e51136ffaea53f0ca858631d0e938878`**, `--version` 6.8.1, `cuobjdump --list-elf` +sm_86, sm_89, sm_120 (the stock 251,306,680-byte server lists sm_80, 86, 89, 90, 100, 120 and compute_120 PTX). +The live `/root/.sp1/bin/sp1-gpu-server` (c2642ad1...) was never touched; the miners mined throughout. diff --git a/tools/prover-floor/make-build-playbook.sh b/tools/prover-floor/make-build-playbook.sh index 07f0d117c..7845980a1 100755 --- a/tools/prover-floor/make-build-playbook.sh +++ b/tools/prover-floor/make-build-playbook.sh @@ -41,21 +41,32 @@ echo "RESULT source \$(git describe --tags --always) \$(git rev-parse HEAD)" git apply "\$PATCH" || { echo "RESULT build_failed patch does not apply"; exit 2; } touch sp1-gpu/crates/prover_components/src/builder.rs sp1-gpu/crates/jagged_tracegen/src/lib.rs sp1-gpu/crates/server/src/server.rs echo "RESULT patched \$(git diff --stat | tail -1)" +# Go, as the release workflow installs it (the server's native-gnark feature compiles the gnark library with go; +# the wrap path is never run by a compressed proof, but the feature is upstream's and stays): a pinned tarball +# unpacked under /opt/igneum-floor, on this job's PATH only, no package installed on the PC. if ! command -v go >/dev/null 2>&1; then - sed -i 's/sp1-prover = { workspace = true, features = \["native-gnark"\] }/sp1-prover = { workspace = true }/' sp1-gpu/crates/server/Cargo.toml - echo "RESULT native_gnark dropped: no go toolchain on PC 2 (the gnark wrap is not used by compressed proofs)" + if [ ! -x \$FLOOR/go/bin/go ]; then + echo "STAGE go \$(stamp) fetching go1.27.1 (70,553,950 bytes, sha256 63d339f0...)" + curl -sSL -o \$FLOOR/go.tgz https://go.dev/dl/go1.27.1.linux-amd64.tar.gz || { echo "RESULT build_failed go download"; exit 2; } + echo "63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 \$FLOOR/go.tgz" | sha256sum -c - >/dev/null || { echo "RESULT build_failed go sha256 mismatch: \$(sha256sum \$FLOOR/go.tgz)"; exit 2; } + echo "RESULT go_tarball sha256 \$(sha256sum \$FLOOR/go.tgz | cut -c1-64) matches 63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445" + tar -xzf \$FLOOR/go.tgz -C \$FLOOR && rm -f \$FLOOR/go.tgz + fi + export PATH="\$FLOOR/go/bin:\$PATH" GOPATH=\$FLOOR/gopath GOCACHE=\$FLOOR/gocache GOFLAGS=-mod=mod fi +echo "RESULT go \$(go version 2>&1 | head -1)" +LOG=\$FLOOR/logs/build.log; : > "\$LOG" +echo "RESULT dirs \$(ls -ld \$FLOOR \$FLOOR/logs 2>&1 | tr '\\n' ' ') pwd=\$(pwd)" export CUDA_ARCHS=86,89,120 CARGO_TARGET_DIR=\$FLOOR/target JOBS=8 echo "STAGE build \$(stamp) jobs=\$JOBS" t0=\$(date +%s) -nice -n 19 cargo build --release --bin sp1-gpu-server -j \$JOBS > \$FLOOR/logs/build-\$(date -u +%Y%m%dT%H%M%SZ).log 2>&1 & +nice -n 19 cargo build --release --bin sp1-gpu-server -j \$JOBS >> "\$LOG" 2>&1 & BP=\$! -LOG=\$(ls -t \$FLOOR/logs/build-*.log | head -1) while kill -0 \$BP 2>/dev/null; do sleep 120; echo "STAGE building \$(stamp) \$(( (\$(date +%s) - t0) / 60 )) min: \$(grep -c '^ Compiling' "\$LOG") crates compiled, last: \$(grep '^ Compiling' "\$LOG" | tail -1 | tr -s ' ' | cut -c1-80)"; done wait \$BP; rc=\$? echo "RESULT build_exit \$rc time_s=\$(( \$(date +%s) - t0 )) crates=\$(grep -c '^ Compiling' "\$LOG")" -if [ \$rc -ne 0 ]; then echo "RESULT build_failed"; grep -n -B2 -A12 '^error' "\$LOG" | head -80; exit 2; fi +if [ \$rc -ne 0 ]; then echo "RESULT build_failed"; echo "== error lines =="; grep -n -B2 -A12 -E '^(error|warning: unused manifest| process didn|caused by)' "\$LOG" | head -100; echo "== log tail =="; tail -n 60 "\$LOG"; exit 2; fi BIN=\$FLOOR/target/release/sp1-gpu-server cp "\$BIN" \$FLOOR/bin/sp1-gpu-server && cp "\$BIN" \$FLOOR/home/.sp1/bin/sp1-gpu-server && chmod +x \$FLOOR/bin/sp1-gpu-server \$FLOOR/home/.sp1/bin/sp1-gpu-server echo "RESULT binary bytes=\$(stat -c %s "\$BIN") sha256=\$(sha256sum "\$BIN" | cut -c1-64) version=\$(\$BIN --version 2>/dev/null)" diff --git a/tools/prover-floor/pc2-build-server.ps1 b/tools/prover-floor/pc2-build-server.ps1 index f1359a339..f35e59b27 100644 --- a/tools/prover-floor/pc2-build-server.ps1 +++ b/tools/prover-floor/pc2-build-server.ps1 @@ -31,21 +31,32 @@ echo "RESULT source $(git describe --tags --always) $(git rev-parse HEAD)" git apply "$PATCH" || { echo "RESULT build_failed patch does not apply"; exit 2; } touch sp1-gpu/crates/prover_components/src/builder.rs sp1-gpu/crates/jagged_tracegen/src/lib.rs sp1-gpu/crates/server/src/server.rs echo "RESULT patched $(git diff --stat | tail -1)" +# Go, as the release workflow installs it (the server's native-gnark feature compiles the gnark library with go; +# the wrap path is never run by a compressed proof, but the feature is upstream's and stays): a pinned tarball +# unpacked under /opt/igneum-floor, on this job's PATH only, no package installed on the PC. if ! command -v go >/dev/null 2>&1; then - sed -i 's/sp1-prover = { workspace = true, features = \["native-gnark"\] }/sp1-prover = { workspace = true }/' sp1-gpu/crates/server/Cargo.toml - echo "RESULT native_gnark dropped: no go toolchain on PC 2 (the gnark wrap is not used by compressed proofs)" + if [ ! -x $FLOOR/go/bin/go ]; then + echo "STAGE go $(stamp) fetching go1.27.1 (70,553,950 bytes, sha256 63d339f0...)" + curl -sSL -o $FLOOR/go.tgz https://go.dev/dl/go1.27.1.linux-amd64.tar.gz || { echo "RESULT build_failed go download"; exit 2; } + echo "63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 $FLOOR/go.tgz" | sha256sum -c - >/dev/null || { echo "RESULT build_failed go sha256 mismatch: $(sha256sum $FLOOR/go.tgz)"; exit 2; } + echo "RESULT go_tarball sha256 $(sha256sum $FLOOR/go.tgz | cut -c1-64) matches 63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445" + tar -xzf $FLOOR/go.tgz -C $FLOOR && rm -f $FLOOR/go.tgz + fi + export PATH="$FLOOR/go/bin:$PATH" GOPATH=$FLOOR/gopath GOCACHE=$FLOOR/gocache GOFLAGS=-mod=mod fi +echo "RESULT go $(go version 2>&1 | head -1)" +LOG=$FLOOR/logs/build.log; : > "$LOG" +echo "RESULT dirs $(ls -ld $FLOOR $FLOOR/logs 2>&1 | tr '\n' ' ') pwd=$(pwd)" export CUDA_ARCHS=86,89,120 CARGO_TARGET_DIR=$FLOOR/target JOBS=8 echo "STAGE build $(stamp) jobs=$JOBS" t0=$(date +%s) -nice -n 19 cargo build --release --bin sp1-gpu-server -j $JOBS > $FLOOR/logs/build-$(date -u +%Y%m%dT%H%M%SZ).log 2>&1 & +nice -n 19 cargo build --release --bin sp1-gpu-server -j $JOBS >> "$LOG" 2>&1 & BP=$! -LOG=$(ls -t $FLOOR/logs/build-*.log | head -1) while kill -0 $BP 2>/dev/null; do sleep 120; echo "STAGE building $(stamp) $(( ($(date +%s) - t0) / 60 )) min: $(grep -c '^ Compiling' "$LOG") crates compiled, last: $(grep '^ Compiling' "$LOG" | tail -1 | tr -s ' ' | cut -c1-80)"; done wait $BP; rc=$? echo "RESULT build_exit $rc time_s=$(( $(date +%s) - t0 )) crates=$(grep -c '^ Compiling' "$LOG")" -if [ $rc -ne 0 ]; then echo "RESULT build_failed"; grep -n -B2 -A12 '^error' "$LOG" | head -80; exit 2; fi +if [ $rc -ne 0 ]; then echo "RESULT build_failed"; echo "== error lines =="; grep -n -B2 -A12 -E '^(error|warning: unused manifest| process didn|caused by)' "$LOG" | head -100; echo "== log tail =="; tail -n 60 "$LOG"; exit 2; fi BIN=$FLOOR/target/release/sp1-gpu-server cp "$BIN" $FLOOR/bin/sp1-gpu-server && cp "$BIN" $FLOOR/home/.sp1/bin/sp1-gpu-server && chmod +x $FLOOR/bin/sp1-gpu-server $FLOOR/home/.sp1/bin/sp1-gpu-server echo "RESULT binary bytes=$(stat -c %s "$BIN") sha256=$(sha256sum "$BIN" | cut -c1-64) version=$($BIN --version 2>/dev/null)"