Commit graph

28 commits

Author SHA1 Message Date
igneum-labs
fa6bbb0d5f txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
9cd5fe4645 Merge program-id: pinned shard and aggregator guests (elf/ + manifest), fast verify with the pinned key, CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	proving/igneum-prove/host/build.rs
2026-10-05 13:00:54 +00:00
igneum-labs
08bb0dc047 Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
885f2d022f Prover: the 5 October post-root assertion explained (stale build, empty-segment plan), fixture 58927, fixture test, source stamp
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.

The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit ed1cbb0 (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.

So the prover core needs no rule change: the fix is commit ed1cbb0, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:

- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
  statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
  segment's shard ends at the root after the rewards, never the pre-root. With the pre-ed1cbb0 rule put back
  the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
  untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
  printed on the first line of every run, so a stale build names itself in the log instead of in a line
  number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.

The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:50:40 +00:00
igneum-labs
e27942797d wsl scripts: the re-stamp prunes every target dir, not only one level deep (touching target made cargo skip the rebuild)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:51:10 +00:00
igneum-labs
9fc1486e6d Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
9014a111a1 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
d5986d253c Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
11b01cbabd Jobs reader: the app's closing report counts as final and error lines are collected; prove-shard.sh fails the job when a stage fails
Three watchers never saw a job finish because the closing upload starts with the app header, not the SUMMARY line,
and a shard run whose stages failed still exited 0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:59:13 +00:00
igneum-labs
48868dbb03 prove-shard.sh: touch the copied sources so cargo-prove rebuilds the guests on the PC
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:56:36 +00:00
igneum-labs
a71cd97bdd Prove package: a build gate executes the shard fixture and every block fixture on the Mac before any zip exists
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:49:25 +00:00
igneum-labs
53fae2c8ea Relay: its own key (relay-key) replaces the intake key for the Mac tools and clients; relay token rotated 4 Oct 2026 (round 4, X23); prove package excludes cross-build folders
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:25:19 +00:00
igneum-labs
ce5bb840aa Prove host: lock file for the serde dependency
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:17:55 +00:00
igneum-labs
df8c469723 Relay: run and task posts need the console token (round 4, X23); prove host saves proofs buffered (ledger P20, second gap)
The intake key sits in every miner package, so the relay now lets it report only (drop text and files, ack, done,
register, upload). Posting a run or task, or renaming and re-roling a machine, needs the console token.
The prove host wrote proofs through SP1's unbuffered save: on WSL2 under /mnt/c the 18 MB core proof of a shard
took longer to save than to prove. Proofs now go through a 4 MB buffer with a timed 'saved' line, and
prove-shard.sh keeps results on the Linux side and copies them per stage. Ledger P20 updated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:14:10 +00:00
igneum-labs
8ab852ce21 Console: a job is done only on the app's closing report; prove-shard.sh takes every block fixture after the first argument
The console marked any job with a RESULT line as done, so a running shard job read as finished. Done now means
the SUMMARY line carries finished_at or the job's closing 'job <id>: <status> (exit N)' line is present.
prove-shard.sh dropped the third fixture argument (block-344-shards4) because it read only $2.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 17:52:35 +00:00
igneum-labs
0df5ba7e6d Proving v0: the app's prove setting, Proving tile and Set up hook; spec 7.7 (records, assignment, payout, activation as implemented); proving-v0 plan status; ledger P21 and P22; test script fixes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:09:32 +00:00
igneum-labs
ed1cbb02eb Proving v0: payouts in the shard statement (fixture, ShardInput, executor), the empty-segment plan fix, host modes compressed and verify, exporter reads payouts; the app's prover service (src/prover.rs); the 3-node test network script (tools/proving-v0/run.mjs); proving_v0_activation_daa in the fast-time profile
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:06:26 +00:00
igneum-labs
305c595f53 Proving host: the setup line splits prover-client creation from the two key setups (ledger P20 gap); simnet export and generator results kept with the fixtures
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:26 +00:00
igneum-labs
fcc4a2e31c Docs: ledger P12 fixed in the proving code and P20 fixed in the host; spec 7.6 shard statement definitions and the provisional S_p; benchmark standard rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:17 +00:00
igneum-labs
5cce9d3db2 Prover package: PROVE-SHARD.bat runs the shard at S_p and the two- and four-shard blocks on the GPU
prove-shard.sh: mode shard on block-338-shard1 (execute, core, compressed), then mode block on block-341-shards2 and block-344-shards4 (compressed proof per shard, aggregation), RESULT lines with timestamps, log uploaded after each stage. PROVE-BLOCK.bat keeps the small block (mode all; the CPU comparison is mode shard now). make-package.sh packs the aggregator crate and the simnet export too; README rewritten for the shard run.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:09:33 +00:00
igneum-labs
9e05bf5ace Proving fixtures: blocks of one, two and four shards at S_p from a private simnet, plus the v1 cut of the v0 blocks
tools/prove-fixtures: a one-node simnet on ports 29300+ and a generator that lands bursts of equal-sized modexp calls, transfers and Counter increments in one chain block (blocks 338, 341, 344: 0.90, 1.80 and 3.60 S_p). block-56-transfers-3shards is a test cut at 200 pgas for the Mac CPU multi-shard check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:05 +00:00
igneum-labs
b0199d1659 Proving: aggregator guest, host modes shard and block with per-stage timestamps, exporter with shard plans
Two SP1 programs: the shard guest and the aggregator guest (deferred proof verification of the shard vk). Host modes native (cut, witnesses, chain and sums, three tamper checks, stub), execute (cycles per shard and for the aggregator), shard (execute, core, compressed, each verified), block (compressed proof per shard, aggregation, verified against the shard program id and the claim). Every stage prints a STAGE line and a RESULT line with a UTC timestamp so a silent gap is visible, and the host holds a Tokio runtime for the whole run and drops the proof system inside it, for the sp1-cuda Drop panic (ledger P20). The exporter writes v1 fixtures with the plan and every shard's expected roots, links and witness size; --budget makes a test cut.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:05 +00:00
igneum-labs
11710c4f77 Proving: shard cutter, MPT witnesses, shard and block statements in igneum-prove-core
The executor runs any contiguous range of a segment from a carried-in position and emits a boundary per transaction (cumulative gas and pgas, the carry link, the state root natively); the planner cuts at transaction boundaries to at most S_p pgas (provisional S_p = B_p / 4, the specification has no number yet), deterministically from the trace. Witnesses are partial Merkle Patricia tries (touched leaves in full, every untouched subtree as a hash, collapse-safe siblings carried) for the account trie and each touched storage trie; the guest rebuilds the pre-root from them, refuses any read they do not cover, and rebuilds the post-root after execution. The shard statement commits the prover's payout address (ledger P12) and the carry links; the block statement verifies the shard proofs in order, chains roots, links and transaction commitments, and carries the provers and the shard program id (design 5.1, 5.3). Port moved to igneum-exec b7fca5a0 (spec 7.5 pgas cap and abort).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:04 +00:00
igneum-labs
3d998b5c7f Prover package: protobuf-compiler in the apt list (the host build's prost crate needs protoc)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:46:32 +00:00
igneum-labs
f77e351706 Prover package: strip the UTF-16 nulls from the WSL distro list so an installed Ubuntu is detected
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:28:39 +00:00
igneum-labs
f8ab74df3e Prover package: the elevated setup window stays open
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:26:31 +00:00
igneum-labs
72b26a2a33 Prover package: define the log upload before the build step uses it
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:25:58 +00:00
igneum-labs
baf0094f76 Proving v0: SP1 guest and host for one Igneum block, real-block fixtures, versioned ProofSystem trait, WSL2 package for the RTX 5090 run
proving/igneum-prove: core (port of igneum-exec at fb33069 as the block statement), program (SP1 v6.8.1 guest),
host (execute, core, compressed; ProofSystem trait with the stub and the SP1 implementation), export (cuts a block
out of igneum_exportSegments and checks every state root against the node's). Fixtures block-78-increment and
block-56-transfers from the 3-node simnet. proving/windows-wsl2: SETUP-PROVER.bat, setup-wsl.sh, PROVE-BLOCK.bat,
make-package.sh. docs/plans/proving-v0.md: the devnet v4 shard plan, what tonight's proof shows and does not, the
morning acceptance line. Mac CPU baseline (block 78: 626 k cycles, core 22.0 s and 7.3 MB, compressed 55.7 s and
1.27 MB, both verified) appended to docs/bench-log.md, left uncommitted because that file carries another agent's
pending changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:30:12 +00:00