On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.
- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
host/src/pinned.rs embeds and checks them at every start; the prove modes
refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
42 lines
1.4 KiB
TOML
42 lines
1.4 KiB
TOML
[package]
|
|
name = "igneum-prove-host"
|
|
description = "SP1 host: loads a block fixture, cuts and witnesses its shards, proves one shard (execute, core, compressed) or the whole block (shard proofs plus aggregation), prints cycles, times and sizes with timestamps, verifies every proof; holds the versioned ProofSystem trait"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
|
|
[dependencies]
|
|
igneum-prove-core.workspace = true
|
|
igneum-evm-types.workspace = true
|
|
sp1-sdk = { workspace = true, features = ["blocking"] }
|
|
alloy-primitives.workspace = true
|
|
alloy-trie.workspace = true
|
|
alloy-rlp.workspace = true
|
|
bincode.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
anyhow.workspace = true
|
|
hex.workspace = true
|
|
sha2 = "0.10"
|
|
tokio = { version = "1", features = ["rt-multi-thread", "time"] }
|
|
# To read the program id a compressed proof was made with (the sp1_vk_digest in its recursion public values).
|
|
sp1-recursion-executor = "=6.8.1"
|
|
sp1-hypercube = "=6.8.1"
|
|
sp1-primitives = "=6.8.1"
|
|
|
|
[[bin]]
|
|
name = "igneum-prove-host"
|
|
path = "src/main.rs"
|
|
|
|
# Does not embed the pinned files, so it builds before elf/ exists.
|
|
[[bin]]
|
|
name = "igneum-prove-pin"
|
|
path = "src/bin/pin.rs"
|
|
|
|
[build-dependencies]
|
|
sp1-build.workspace = true
|
|
|
|
[features]
|
|
default = []
|
|
# The CUDA prover (SP1_PROVER=cuda): Linux x86_64 only, the SDK downloads sp1-gpu-server into ~/.sp1/bin.
|
|
cuda = ["sp1-sdk/cuda"]
|