igneum/.github/workflows/prover-server.yml

88 lines
4.2 KiB
YAML

# The project's GPU prover server (prover floor, 6 October 2026): SP1's sp1-gpu-server 6.8.1 rebuilt from source
# with proving/prover-floor/sp1-gpu-6.8.1-floor.patch, which sizes the server's buffers to the shard instead of
# to a 24 GB card (bench-log "prover floor": the RTX 4070 12 GB mines and proves at threshold 2^26). One recipe,
# packaging/prover/build-server.sh, shared with the PCs' WSL2 path (tools/prover-floor/pc2-build-server.ps1).
#
# What comes out: the artifact sp1-gpu-server-floor (the binary, its sha256, build.json). Nothing is signed here:
# packaging/prover/push-server.sh on the Mac downloads the artifact by run id, writes prover-server.json (the SP1
# version and commit, the patch's sha256, the CUDA targets, the binary's sha256 and size, this run's id), signs it
# with the OTA key the apps trust and publishes the three files to the downloads host; the Windows build
# (windows.yml) fetches and verifies them for the payload; the app verifies them again before use.
#
# Not byte-reproducible across machines (SP1's prover-types build script stamps the build time into the binary), so
# the signed manifest names THIS build; the PC build is a behavioural cross-check (the same fixtures, verified).
# The CUDA toolkit comes from Jimver/cuda-toolkit (nvcc, nvtx, cudart only), as SP1's own release workflow does.
name: prover-server
on:
workflow_dispatch:
inputs:
cuda_archs:
description: "CUDA_ARCHS (default 80,86,89,120: 3060/3090 sm_86, 4060 to 4090 sm_89, 5080/5090 sm_120, A100 sm_80)"
default: "80,86,89,120"
required: false
push:
branches: [master]
paths:
- 'proving/prover-floor/sp1-gpu-6.8.1-floor.patch'
- 'packaging/prover/build-server.sh'
- '.github/workflows/prover-server.yml'
permissions:
contents: read
jobs:
build:
name: sp1-gpu-server 6.8.1 + floor patch (linux x86_64)
runs-on: ubuntu-24.04
timeout-minutes: 120
steps:
- uses: actions/checkout@v4
- name: free disk (the CUDA toolkit and the SP1 tree need about 20 GB)
run: |
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /opt/hostedtoolcache/CodeQL || true
df -h / | tail -1
- name: CUDA 12.8.1 (nvcc, nvtx, cudart)
uses: Jimver/cuda-toolkit@v0.2.23
with:
cuda: '12.8.1'
method: 'network'
sub-packages: '["nvcc", "nvtx", "cudart"]'
use-github-cache: false
use-local-cache: false
- name: Go 1.27 (the server's native-gnark feature)
uses: actions/setup-go@v5
with:
go-version: '1.27.1'
- name: protoc, cmake, clang
run: |
sudo apt-get update -qq
sudo apt-get install -y -qq protobuf-compiler cmake clang pkg-config libssl-dev
nvcc --version | tail -1; protoc --version; cmake --version | head -1; go version
- name: Rust stable
run: rustup toolchain install stable --profile minimal && rustup default stable
- name: cargo cache
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
/tmp/igneum-sp1-6.8.1/target
key: prover-server-${{ runner.os }}-${{ hashFiles('proving/prover-floor/sp1-gpu-6.8.1-floor.patch') }}-${{ github.event.inputs.cuda_archs || '80,86,89,120' }}
restore-keys: prover-server-${{ runner.os }}-
- name: build (packaging/prover/build-server.sh)
env:
CUDA_ARCHS: ${{ github.event.inputs.cuda_archs || '80,86,89,120' }}
CARGO_JOBS: 4
run: |
set -euo pipefail
bash packaging/prover/build-server.sh build/prover-server /tmp/igneum-sp1-6.8.1
cat build/prover-server/build.json
cat build/prover-server/sp1-gpu-server.sha256
- name: the binary answers --version
run: |
v="$(build/prover-server/sp1-gpu-server --version)"
echo "version: $v"; [ "$v" = "6.8.1" ] || { echo "::error::the server reports $v, not 6.8.1 (the SDK refuses it)"; exit 1; }
- uses: actions/upload-artifact@v4
with:
name: sp1-gpu-server-floor
path: build/prover-server/
if-no-files-found: error
retention-days: 90