igneum/proving/igneum-prove/host/Cargo.toml
igneum-labs 64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00

42 lines
1.4 KiB
TOML

[package]
name = "igneum-prove-host"
description = "SP1 host: loads a block fixture, cuts and witnesses its shards, proves one shard (execute, core, compressed) or the whole block (shard proofs plus aggregation), prints cycles, times and sizes with timestamps, verifies every proof; holds the versioned ProofSystem trait"
version.workspace = true
edition.workspace = true
license.workspace = true
[dependencies]
igneum-prove-core.workspace = true
igneum-evm-types.workspace = true
sp1-sdk = { workspace = true, features = ["blocking"] }
alloy-primitives.workspace = true
alloy-trie.workspace = true
alloy-rlp.workspace = true
bincode.workspace = true
serde.workspace = true
serde_json.workspace = true
anyhow.workspace = true
hex.workspace = true
sha2 = "0.10"
tokio = { version = "1", features = ["rt-multi-thread", "time"] }
# To read the program id a compressed proof was made with (the sp1_vk_digest in its recursion public values).
sp1-recursion-executor = "=6.8.1"
sp1-hypercube = "=6.8.1"
sp1-primitives = "=6.8.1"
[[bin]]
name = "igneum-prove-host"
path = "src/main.rs"
# Does not embed the pinned files, so it builds before elf/ exists.
[[bin]]
name = "igneum-prove-pin"
path = "src/bin/pin.rs"
[build-dependencies]
sp1-build.workspace = true
[features]
default = []
# The CUDA prover (SP1_PROVER=cuda): Linux x86_64 only, the SDK downloads sp1-gpu-server into ~/.sp1/bin.
cuda = ["sp1-sdk/cuda"]