igneum/proving/igneum-prove/pin-guests.sh
igneum-labs 64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00

21 lines
1.4 KiB
Bash
Executable file

#!/usr/bin/env bash
# Re-pins the guest programs (host/src/pinned.rs): builds both SP1 guests from the sources here, derives their
# verifying keys and program ids, writes proving/igneum-prove/elf/, rebuilds the host so it embeds them, and runs
# the host's unit tests. Every prover and verifier must then move to a host built from the new elf/ together
# (proving/README.md, "Pinned guest programs"). Needs the Succinct toolchain (cargo prove); run on the Mac through
# the build lock. Usage: proving/igneum-prove/pin-guests.sh
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
LOCK="$HERE/../../tools/lock/with-lock.sh"; [ -x "$LOCK" ] || LOCK=/Users/joshm/Projects/igneum/tools/lock/with-lock.sh
export PATH="$HOME/.cargo/bin:$HOME/.sp1/bin:$PATH"
cd "$HERE"
echo "1/4 building the guests and the pin tool"
"$LOCK" build env IGNEUM_BUILD_GUESTS=1 nice -n 19 cargo build --release -j 4 -p igneum-prove-host --bin igneum-prove-pin
echo "2/4 pinning"
./target/release/igneum-prove-pin
echo "3/4 rebuilding the host with the pinned files embedded"
"$LOCK" build env nice -n 19 cargo build --release -j 4 -p igneum-prove-host --bin igneum-prove-host
./target/release/igneum-prove-host --mode id
echo "4/4 unit tests"
"$LOCK" build env nice -n 19 cargo test --release -j 4 -p igneum-prove-host --bin igneum-prove-host
echo "pinned: commit proving/igneum-prove/elf/ with the host change; every prover and verifier moves together"