Commit graph

32 commits

Author SHA1 Message Date
igneum-labs
830efc63e1 Prover floor patch v2: every trace buffer sized to its padded need (setup keys and shards), the sweep-2 points
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:41:37 +00:00
igneum-labs
1402989cdd Prover floor: SP1 6.8.1 GPU server memory model from source (the 24 GB panic, the threshold-sized trace buffers), the floor patch for sp1-gpu, the PC 2 toolchain, build and sweep playbooks
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:11:24 +00:00
igneum-labs
3a96e7371c Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 16:28:21 +00:00
igneum-labs
24aaa0e254 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:24:35 +00:00
igneum-labs
3be4e3ef2a txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
60df95a300 Merge program-id: pinned shard and aggregator guests (elf/ + manifest), fast verify with the pinned key, CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	proving/igneum-prove/host/build.rs
2026-10-05 13:00:54 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
0cba49cfe0 Prover: the 5 October post-root assertion explained (stale build, empty-segment plan), fixture 58927, fixture test, source stamp
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.

The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit d6d6153 (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.

So the prover core needs no rule change: the fix is commit d6d6153, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:

- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
  statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
  segment's shard ends at the root after the rewards, never the pre-root. With the pre-d6d6153 rule put back
  the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
  untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
  printed on the first line of every run, so a stale build names itself in the log instead of in a line
  number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.

The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:50:40 +00:00
igneum-labs
5174a3600a wsl scripts: the re-stamp prunes every target dir, not only one level deep (touching target made cargo skip the rebuild)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:51:10 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
aa9b4da932 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
a36ea68b45 Jobs reader: the app's closing report counts as final and error lines are collected; prove-shard.sh fails the job when a stage fails
Three watchers never saw a job finish because the closing upload starts with the app header, not the SUMMARY line,
and a shard run whose stages failed still exited 0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:59:13 +00:00
igneum-labs
23a0a9b9e1 prove-shard.sh: touch the copied sources so cargo-prove rebuilds the guests on the PC
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:56:36 +00:00
igneum-labs
8f95ebb1ea Prove package: a build gate executes the shard fixture and every block fixture on the Mac before any zip exists
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:49:25 +00:00
igneum-labs
63174a5b6a Relay: its own key (relay-key) replaces the intake key for the Mac tools and clients; relay token rotated 4 Oct 2026 (round 4, X23); prove package excludes cross-build folders
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:25:19 +00:00
igneum-labs
c1db1a0707 Prove host: lock file for the serde dependency
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:17:55 +00:00
igneum-labs
ec0ede62b9 Relay: run and task posts need the console token (round 4, X23); prove host saves proofs buffered (ledger P20, second gap)
The intake key sits in every miner package, so the relay now lets it report only (drop text and files, ack, done,
register, upload). Posting a run or task, or renaming and re-roling a machine, needs the console token.
The prove host wrote proofs through SP1's unbuffered save: on WSL2 under /mnt/c the 18 MB core proof of a shard
took longer to save than to prove. Proofs now go through a 4 MB buffer with a timed 'saved' line, and
prove-shard.sh keeps results on the Linux side and copies them per stage. Ledger P20 updated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:14:10 +00:00
igneum-labs
1c1dbd93d6 Console: a job is done only on the app's closing report; prove-shard.sh takes every block fixture after the first argument
The console marked any job with a RESULT line as done, so a running shard job read as finished. Done now means
the SUMMARY line carries finished_at or the job's closing 'job <id>: <status> (exit N)' line is present.
prove-shard.sh dropped the third fixture argument (block-344-shards4) because it read only $2.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 17:52:35 +00:00
igneum-labs
072e736604 Proving v0: the app's prove setting, Proving tile and Set up hook; spec 7.7 (records, assignment, payout, activation as implemented); proving-v0 plan status; ledger P21 and P22; test script fixes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:09:32 +00:00
igneum-labs
d6d6153c9f Proving v0: payouts in the shard statement (fixture, ShardInput, executor), the empty-segment plan fix, host modes compressed and verify, exporter reads payouts; the app's prover service (src/prover.rs); the 3-node test network script (tools/proving-v0/run.mjs); proving_v0_activation_daa in the fast-time profile
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:06:26 +00:00
igneum-labs
6671d88a95 Proving host: the setup line splits prover-client creation from the two key setups (ledger P20 gap); simnet export and generator results kept with the fixtures
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:26 +00:00
igneum-labs
f5bf494344 Docs: ledger P12 fixed in the proving code and P20 fixed in the host; spec 7.6 shard statement definitions and the provisional S_p; benchmark standard rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:17 +00:00
igneum-labs
748912af9c Prover package: PROVE-SHARD.bat runs the shard at S_p and the two- and four-shard blocks on the GPU
prove-shard.sh: mode shard on block-338-shard1 (execute, core, compressed), then mode block on block-341-shards2 and block-344-shards4 (compressed proof per shard, aggregation), RESULT lines with timestamps, log uploaded after each stage. PROVE-BLOCK.bat keeps the small block (mode all; the CPU comparison is mode shard now). make-package.sh packs the aggregator crate and the simnet export too; README rewritten for the shard run.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:09:33 +00:00
igneum-labs
b64a31c77f Proving fixtures: blocks of one, two and four shards at S_p from a private simnet, plus the v1 cut of the v0 blocks
tools/prove-fixtures: a one-node simnet on ports 29300+ and a generator that lands bursts of equal-sized modexp calls, transfers and Counter increments in one chain block (blocks 338, 341, 344: 0.90, 1.80 and 3.60 S_p). block-56-transfers-3shards is a test cut at 200 pgas for the Mac CPU multi-shard check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:05 +00:00
igneum-labs
f71af23dcb Proving: aggregator guest, host modes shard and block with per-stage timestamps, exporter with shard plans
Two SP1 programs: the shard guest and the aggregator guest (deferred proof verification of the shard vk). Host modes native (cut, witnesses, chain and sums, three tamper checks, stub), execute (cycles per shard and for the aggregator), shard (execute, core, compressed, each verified), block (compressed proof per shard, aggregation, verified against the shard program id and the claim). Every stage prints a STAGE line and a RESULT line with a UTC timestamp so a silent gap is visible, and the host holds a Tokio runtime for the whole run and drops the proof system inside it, for the sp1-cuda Drop panic (ledger P20). The exporter writes v1 fixtures with the plan and every shard's expected roots, links and witness size; --budget makes a test cut.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:05 +00:00
igneum-labs
9bea7c718b Proving: shard cutter, MPT witnesses, shard and block statements in igneum-prove-core
The executor runs any contiguous range of a segment from a carried-in position and emits a boundary per transaction (cumulative gas and pgas, the carry link, the state root natively); the planner cuts at transaction boundaries to at most S_p pgas (provisional S_p = B_p / 4, the specification has no number yet), deterministically from the trace. Witnesses are partial Merkle Patricia tries (touched leaves in full, every untouched subtree as a hash, collapse-safe siblings carried) for the account trie and each touched storage trie; the guest rebuilds the pre-root from them, refuses any read they do not cover, and rebuilds the post-root after execution. The shard statement commits the prover's payout address (ledger P12) and the carry links; the block statement verifies the shard proofs in order, chains roots, links and transaction commitments, and carries the provers and the shard program id (design 5.1, 5.3). Port moved to igneum-exec b7fca5a0 (spec 7.5 pgas cap and abort).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:04 +00:00
igneum-labs
f55712e2f6 Prover package: protobuf-compiler in the apt list (the host build's prost crate needs protoc)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:46:32 +00:00
igneum-labs
e5c7f3d0ef Prover package: strip the UTF-16 nulls from the WSL distro list so an installed Ubuntu is detected
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:28:39 +00:00
igneum-labs
51e1330233 Prover package: the elevated setup window stays open
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:26:31 +00:00
igneum-labs
d0fe4eeb3d Prover package: define the log upload before the build step uses it
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 08:25:58 +00:00
igneum-labs
326953e0ac Proving v0: SP1 guest and host for one Igneum block, real-block fixtures, versioned ProofSystem trait, WSL2 package for the RTX 5090 run
proving/igneum-prove: core (port of igneum-exec at fb33069 as the block statement), program (SP1 v6.8.1 guest),
host (execute, core, compressed; ProofSystem trait with the stub and the SP1 implementation), export (cuts a block
out of igneum_exportSegments and checks every state root against the node's). Fixtures block-78-increment and
block-56-transfers from the 3-node simnet. proving/windows-wsl2: SETUP-PROVER.bat, setup-wsl.sh, PROVE-BLOCK.bat,
make-package.sh. docs/plans/proving-v0.md: the devnet v4 shard plan, what tonight's proof shows and does not, the
morning acceptance line. Mac CPU baseline (block 78: 626 k cycles, core 22.0 s and 7.3 MB, compressed 55.7 s and
1.27 MB, both verified) appended to docs/bench-log.md, left uncommitted because that file carries another agent's
pending changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:30:12 +00:00