igneum/tools/ci
igneum-labs 64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
..
windows Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened 2026-10-04 13:52:45 +00:00
check-workflow-shell.mjs Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page 2026-10-04 22:54:56 +00:00
copied-sources-check.sh Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule 2026-10-05 09:12:38 +00:00
forbidden-strings.txt CI on every push: igneum-pow tests, census build, simulator quick modes, site build + link check, identity grep 2026-10-04 09:57:34 +00:00
identity-check.sh CI identity grep: .log files get the generic scrub too; the 4 October difficulty record carried a home path (every master run red since c01b954) 2026-10-04 19:09:09 +00:00
link-check.mjs CI on every push: igneum-pow tests, census build, simulator quick modes, site build + link check, identity grep 2026-10-04 09:57:34 +00:00
pinned-guests-check.sh Proving: pinned guest programs, the verifier on SP1's light verifier 2026-10-05 12:54:31 +00:00