igneum/proving
2026-10-07 08:57:03 +00:00
..
fixtures Proving v1: prover on by default, the aggregated segment record, host modes chain, aggregate and verify-segment, the app's aggregator step, spec 7.8, the fast-time harness and the coverage tool 2026-10-05 20:21:04 +00:00
igneum-prove second-prover: the ProofSystem trait in igneum-prove-core (one trait, no SDK; versions 1 sp1 and 2 risc0), Risc0ProofSystem behind it, the shadow runner and its tunnel, the pinned-guests check over both manifests, the plan, the ledger rows P7 and D6, the design note 2026-10-07 08:57:03 +00:00
igneum-prove-r0 second-prover: the ProofSystem trait in igneum-prove-core (one trait, no SDK; versions 1 sp1 and 2 risc0), Risc0ProofSystem behind it, the shadow runner and its tunnel, the pinned-guests check over both manifests, the plan, the ledger rows P7 and D6, the design note 2026-10-07 08:57:03 +00:00
prover-floor Prover floor patch v2: every trace buffer sized to its padded need (setup keys and shards), the sweep-2 points 2026-10-05 22:41:37 +00:00
windows-wsl2 Aggregation cost on the 5090 (5 October, night): the chained aggregation is 2.1 s alone and 9.7 s beside the miner, the batch-log2 curve (2^16 buys 1.6x for a fifth of the hash rate), batch and tree folds estimated, two streams and SP1 knobs closed; the host times the stdin build and names the knobs, --save-shards; the PC 2 job scripts and the readers 2026-10-06 07:04:50 +00:00
README.md second-prover: the ProofSystem trait in igneum-prove-core (one trait, no SDK; versions 1 sp1 and 2 risc0), Risc0ProofSystem behind it, the shadow runner and its tunnel, the pinned-guests check over both manifests, the plan, the ledger rows P7 and D6, the design note 2026-10-07 08:57:03 +00:00

proving

Igneum proving: v0 (3 October 2026, one SP1 proof per block) and the devnet v4 shards (4 October 2026). Plan, status and measurements: docs/plans/proving-v0.md; numbers: docs/bench-log.md.

  • igneum-prove/: Cargo workspace. core (the port of the execution layer's executor at b7fca5a0; the cutter plan.rs, the partial-trie witnesses trie.rs and witness.rs, the shard statement shard.rs, the block statement agg.rs), program (the shard guest), aggregator (the aggregator guest, SP1 deferred proofs of the shard program), host (modes native, execute, shard, block, all; the versioned ProofSystem trait with the stub and the SP1 implementation in host/src/proof_system.rs), export (cuts a real block out of an igneum_exportSegments dump, checks the port against the node's state roots, plans the shards and checks every witness).
  • fixtures/: block-338-shard1, block-341-shards2, block-344-shards4 (one, two and four shards at S_p = 7.5 M pgas, from the private simnet of tools/prove-fixtures), block-78-increment and block-56-transfers (the v0 blocks, one shard each), block-56-transfers-3shards (a test cut at 200 pgas for the CPU multi-shard check), fees-switch-prototype, fees-v1-shards2 and fees-v1-shards3 (5 October 2026: one simnet chain across the fees_v1_activation_daa switch at DAA 800, a prototype block below it and v1 blocks at S_p = 30,000 pgas above it; docs/plans/fee-switch-devnet.md).
  • The fee schedule (5 October 2026): every fixture and shard input carries the node's schedule (fees: both tables and the switch, core/src/config.rs) and the block's DAA score; the executor reads the set at that score and raises the base fees to its floors as the node does. A fixture without fees is the devnet as compiled (prototype, never). The exporter takes the schedule from the dump (feesV1ActivationDaa, fees, per-segment daaScore, written by tools/prove-fixtures/gen.mjs) or from --fees-v1-activation-daa and --fees-base.
  • igneum-prove-r0/: proof system version 2, RISC Zero 3.0.6 (mission item 9, 7 October 2026; docs/plans/second-prover.md). Its own Cargo workspace (RISC Zero's crate patches cannot share SP1's): methods/guest (the shard guest, the same shard_statement and the same 328 committed bytes), host (igneum-prove-r0-host, the SP1 host's CLI shape: --mode native|execute|compressed, --mode verify --proof <file> --statement 0x.., --mode id; Risc0ProofSystem in host/src/proof_system.rs implements the trait), elf/ (the pinned guest igneum-prove-r0-guest.bin and manifest-r0.json, image id 0x9ae0f416...; pin-guest.sh is the only script that builds it, tools/ci/pinned-guests-check.sh checks both manifests). CUDA: --features cuda on a machine with nvcc; a plain build proves on the CPU.
  • windows-wsl2/: SETUP-PROVER.bat, PROVE-SHARD.bat (the shard at S_p and the two- and four-shard blocks on the GPU), PROVE-BLOCK.bat (the small block) and the Linux scripts for the project lead's PC; make-package.sh builds the zip.

The ProofSystem trait and the second system (7 October 2026)

The trait of design 5.6 lives in igneum-prove-core (core/src/proof_system.rs: ProofSystem, SegmentClaim, ShardWitness, PgasTable, VERSION_SP1 = 1, VERSION_RISC0 = 2), a crate with no zkVM SDK, so every proof system implements one trait: version 0 the stub and version 1 SP1 in host/src/proof_system.rs, version 2 RISC Zero in ../igneum-prove-r0/host/src/proof_system.rs. Every version commits the same statement bytes; a record's statement is keccak256 of them, so two systems either agree on 32 bytes or they do not.

The shadow runner, tools/shadow/shadow.py, proves every shard of every exported segment with both hosts, re-verifies each proof with its own host, records agreement (out/rows.jsonl, out/summary.json) and raises the alert on a disagreement (out/alert.json, the node's igneum_proofDisagreement, the Discord incident hook). On the node (fork branch second-prover-node): the active list (IGNEUM_PROOF_ACTIVE_SYSTEMS, version 1 alone by default), the stop switch (no proof record carried until one third of the weight window's blue blocks signal a system through the IGNT coinbase section) and the status (igneum_getProofTrust). Plan, gate and numbers: docs/plans/second-prover.md.

Pinned guest programs (5 October 2026)

The two SP1 guests are build artefacts committed under igneum-prove/elf/: igneum-prove-program.elf and igneum-prove-aggregator.elf, their verifying keys (.vk, bincode) and manifest.json (SHA-256 of every file, the program ids, the SP1 crate and circuit versions, when and where they were pinned). The host embeds these files (host/src/pinned.rs), never a guest it compiled itself, checks every hash against the manifest at each start, refuses in the prove modes when SP1's key setup does not derive the manifest's program id, and in --mode verify uses the pinned key with SP1's light verifier (no prover client, no key generation). igneum-prove-host --mode id prints the pinned ids with no setup.

Why: on 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every proof from PC 2's host (0x05db1aca...). Both were built from the same guest sources; host/build.rs compiled the guest on each machine and the two toolchains produced different ELFs, so a node only ever included its own prover's records. The node's verifier also spent 114 s to 138 s per proof in the prover client and key setups before a 0.1 s to 0.4 s verify.

  • A normal host build compiles nothing for the zkVM and needs no Succinct toolchain.
  • Changing a guest: igneum-prove/pin-guests.sh (builds both guests with IGNEUM_BUILD_GUESTS=1, runs igneum-prove-pin, rebuilds the host, runs the unit tests). Commit elf/ with the change. tools/ci/pinned-guests-check.sh fails CI when elf/ and its manifest disagree or when any other script builds a guest.
  • A new pin is a new program id: every prover and verifier must move together, and proofs made with the old id are rejected by a verifier with the new one (the verify line then says program id 0x... IS NOT OURS). Rollout order: (1) stop the provers (the app's prove setting off on every machine); (2) wait until every record in flight is either included or expired (igneum_getProvingStatus shows an empty pool on every node); (3) install the new host on every node (DMG on the Mac, igneum-prove-wsl2.zip and SETUP-PROVER.bat on the PCs: the package carries elf/, so the PC build embeds the same files) and restart the nodes; (4) confirm --mode id prints the same shard program id on every machine; (5) turn the provers back on.

Build and run (the Succinct toolchain, curl -L https://sp1up.succinct.xyz | bash && sp1up, is needed only to re-pin the guests):

cd proving/igneum-prove
cargo build --release -p igneum-prove-export -p igneum-prove-host   # add --features igneum-prove-host/cuda on Linux x86_64 with an NVIDIA card
./target/release/igneum-prove-export ../../tools/prove-fixtures/seq.json 344 ../fixtures/block-344-shards4.json   # replay, plan, witnesses; --budget <pgas> for a test cut
./target/release/igneum-prove-host ../fixtures/block-344-shards4.json --mode native     # cut, witnesses, chain and sums, tamper checks
./target/release/igneum-prove-host ../fixtures/block-344-shards4.json --mode execute    # SP1 cycles per shard and for the aggregator
./target/release/igneum-prove-host ../fixtures/block-338-shard1.json --mode shard --shard 0 --out results.json   # execute, core, compressed, verified
SP1_PROVER=cuda ./target/release/igneum-prove-host ../fixtures/block-344-shards4.json --mode block --out results.json   # shard proofs plus aggregation

Fixtures of real size: tools/prove-fixtures/net.sh start (a one-node simnet on ports 29300+), node tools/prove-fixtures/gen.mjs (bursts of modexp calls, transfers and Counter increments landed in one block, then the export), then the exporter per block.