Packaging row verified on PC 2 (floor-pc2-verify: the manifest check, the tampered copy refused, the app's install into ~/.sp1/bin, one shard on the 12 GB profile through the shipped server, the live server put back); the plan's row marked verified, the bench-log row
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
7a17321dc9
commit
d2c5692ebe
2 changed files with 21 additions and 0 deletions
|
|
@ -2420,6 +2420,18 @@ SP1 upgrade: `tools/prover-floor/pc2-build-server.ps1` is the recipe, the patch
|
|||
v6.8.1), the app's per-card profile (`provedefault.rs`: 12 GB at 2^26, 16 GB at 2^27, 24 GB at upstream's 24 GB
|
||||
threshold, 32 GB at the full one) and the HOME or path switch that points the SDK at the project's server.
|
||||
|
||||
The packaging row (6 October 2026, 12:20 to 12:52Z, branch prover-floor, commits c53aecb to the tip): the server
|
||||
built on CI and the PCs from `packaging/prover/build-server.sh`, signed on the Mac (`igneum-ota-sign sign-server`),
|
||||
carried by the Windows payload (`wsl2\bin\sp1-gpu-server`, `wsl2\prover-server.json`, `.sig`), verified and
|
||||
installed by the app (`src/proverserver.rs`), the tiers from the measured rows (`provedefault::profile`), the stock
|
||||
fallback; 147 app tests. Verification on PC 2 (job `floor-pc2-verify`, 58 s): the manifest's sha256 and size against
|
||||
PC 2's v4 server ok; a tampered copy refused; the app's install script installed it at `~/.sp1/bin` and kept it on
|
||||
the second run; one v1 shard on the 12 GB profile through the installed server: **9,886 MiB, 5.9 s, VERIFIED** (the
|
||||
SDK spawned the shipped server: its `FLOOR opts` line read `element_threshold=67108864`); the restore script removed
|
||||
it and PC 2's stock server came back from the copy (c2642ad1). Consequence: the public line "12 GB mines and proves
|
||||
(2^26), 16 GB and up at 2^27" ships with 0.3.13 on this path; the Windows installer grows about 60 MB zipped; no
|
||||
Mac or Linux user gets the server yet (no CUDA on a Mac; the Linux app proves on the CPU).
|
||||
|
||||
Consequences (the rule of 5 October 2026), as they stood after sweep 1 (superseded by the reading above for the 12 and 16 GB tiers): the shipped SP1 GPU server refuses every
|
||||
card under 24 GB before allocating, so 8, 12 and 16 GB NVIDIA cards cannot prove on it whatever the shard; the v1
|
||||
patch takes the shard's term out (20.5 to 12.7 GB on the v1 shard) at a 1.26x time cost (5.3 s against 4.2 s,
|
||||
|
|
|
|||
|
|
@ -144,6 +144,15 @@ The tier table, measured (bench-log "prover floor"; alone / beside the card's ow
|
|||
| 24 and 32 GB (the 5090) | patched, upstream's threshold | 16,851 (4.0 s) | | unchanged, 3.7 GB more headroom than stock |
|
||||
| any card under 24 GB | stock | refused before allocating | | the 24 GB gate until the server ships |
|
||||
|
||||
Verified on PC 2 (job `floor-pc2-verify`, 12:50:54 to 12:51:51Z, the manifest for PC 2's v4 server 68b2f512 signed
|
||||
on the Mac with the OTA key, fetched as `floor-pc2-manifest`): the manifest's sha256 and size against the binary ok;
|
||||
a tampered copy (one byte appended) refused; the app's install script put the server at `~/.sp1/bin/sp1-gpu-server`
|
||||
("installed", then "kept" on the second run), `--version` 6.8.1; one v1 shard on the 12 GB profile through the
|
||||
installed server with the default HOME (the SDK spawned the shipped one: `element_threshold=67108864` in its own
|
||||
line) at 9,886 MiB on the 5090 in 5.9 s, VERIFIED; the restore script removed it and the live server came back from
|
||||
the copy. The signing path on the Mac: `sign-server` and `verify-server embedded` agree, a tampered manifest and a
|
||||
wrong binary are refused.
|
||||
|
||||
What the next cut's shipper must do (0.3.13), in order: (1) run the `prover-server` workflow on master (or merge
|
||||
prover-floor and let the push trigger it; about 40 minutes cold on the hosted runner, approximate); (2) on the Mac,
|
||||
`packaging/prover/push-server.sh --run <run id>` (the OTA key, the dl token and the Vercel login as for
|
||||
|
|
|
|||
Loading…
Reference in a new issue