igneum/.github/workflows/ci.yml
igneum-labs 64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00

71 lines
3 KiB
YAML

# CI on every push and pull request (private repository, free runner minutes).
#
# What runs: the lottery-hash crate's tests (igneum-pow, release profile), the census tool's build, the two Python
# simulators' --quick modes (each under two minutes), the site build with an internal link check, and the gh-free
# identity grep of the public export list (tools/ci/forbidden-strings.txt).
#
# What does not run, on purpose: the node fork (vendor/igneum-node*, a rusty-kaspa fork of about 500 crates with
# rocksdb, blst and the execution layer) is gitignored here and too big for the free runners today (a cold build is
# 20 to 55 minutes on 2 to 8 vCPU, docs/bench-log.md). The workflow builds igneum-pow only; the fork's own tests run
# on the Mac and the seed node (infra/seed-nodes, infra/fast-time).
name: ci
on:
push:
pull_request:
jobs:
pow:
name: igneum-pow tests, igneum-census build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: toolchain
run: rustc --version && cargo --version
- name: igneum-pow tests (release)
working-directory: igneum-pow
run: cargo test --release
- name: igneum-census build (release)
working-directory: igneum-census
run: cargo build --release
sims:
name: simulators, quick modes
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- run: python3 -m pip install --quiet numpy
- name: finality_v2.py --quick (under two minutes)
working-directory: sim
run: time timeout 120 python3 finality_v2.py --quick > finality_quick.md
- name: difficulty/sim.py --quick (under two minutes)
working-directory: sim/difficulty
run: time timeout 120 python3 sim.py --quick > difficulty_quick.md
- uses: actions/upload-artifact@v4
with:
name: sim-quick-output
path: |
sim/finality_quick.md
sim/difficulty/difficulty_quick.md
site:
name: site build, link check, identity grep
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
- name: site build
run: node site/build.mjs
- name: internal link check of site/*.html
run: node tools/ci/link-check.mjs
- name: identity grep of the public export list
run: bash tools/ci/identity-check.sh
- name: copied sources are re-stamped before a build
run: bash tools/ci/copied-sources-check.sh
- name: pinned guest programs match their manifest and are built only by pin-guests.sh
run: bash tools/ci/pinned-guests-check.sh
- name: relay unit tests (parsers, secret compare, the wake endpoint)
run: node --test relay/test/parse.test.mjs relay/test/auth.test.mjs relay/test/wake.test.mjs
- name: miner app notice strip (ordering, keys, wording, timers)
run: node --test app/igneum-app/ui/notices.test.mjs