igneum/packaging/prover/fetch-server.sh

26 lines
1.9 KiB
Bash
Executable file

#!/usr/bin/env bash
# Fetches the published GPU prover server (packaging/prover/push-server.sh) into a folder for the payload: the
# manifest, its signature and the binary from the downloads host, the signature checked with the key the apps carry
# (igneum-ota-sign verify-server embedded) and the binary's sha256 and size checked against the manifest.
#
# packaging/prover/fetch-server.sh [out dir, default proving/prover-floor/server] [--signer path]
#
# A host without the three files (404) is reported and leaves the folder empty: the payload then ships no server and
# the app runs SP1's stock one (24 GB cards). A manifest that is there but does not verify FAILS the fetch.
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"; ROOT="$(cd "$HERE/../.." && pwd)"
OUT="$ROOT/proving/prover-floor/server"; SIGNER=""
while [ $# -gt 0 ]; do case "$1" in --signer) SIGNER="$2"; shift 2 ;; *) OUT="$1"; shift ;; esac; done
TOKEN="${DL_TOKEN:-$(tr -d '[:space:]' < "$HOME/.config/igneum/dl-token")}"
BASE="https://dl.igneum.network/dl/$TOKEN"
[ -n "$SIGNER" ] || SIGNER="$ROOT/app/igneum-app/target/release/igneum-ota-sign"
[ -x "$SIGNER" ] || [ -x "$SIGNER.exe" ] || { echo "no igneum-ota-sign at $SIGNER (cargo build --release --bin igneum-ota-sign)" >&2; exit 2; }
mkdir -p "$OUT"
if ! curl -fsSL --retry 3 -o "$OUT/prover-server.json" "$BASE/prover-server.json"; then
echo "no prover-server.json on the downloads host: the payload ships no GPU server (the app uses SP1's stock one, 24 GB cards)"; rm -f "$OUT/prover-server.json"; exit 0
fi
curl -fsSL --retry 3 -o "$OUT/prover-server.json.sig" "$BASE/prover-server.json.sig"
curl -fsSL --retry 3 -o "$OUT/sp1-gpu-server" "$BASE/sp1-gpu-server"
"$SIGNER" verify-server embedded "$OUT/prover-server.json" "$OUT/prover-server.json.sig" --binary "$OUT/sp1-gpu-server"
chmod +x "$OUT/sp1-gpu-server"
echo "fetched into $OUT: $(ls -la "$OUT" | tail -n +2 | awk '{print $NF, $5}' | tr '\n' ' ')"