On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.
- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
host/src/pinned.rs embeds and checks them at every start; the prove modes
refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
48 lines
3.9 KiB
Bash
Executable file
48 lines
3.9 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Builds igneum-prove-wsl2.zip (double-click setup and proof run for a Windows 11 PC) on the Mac.
|
|
# Packs this directory plus the proving sources and the execution layer's evm-types crate under package/, so the
|
|
# path dependency resolves on the PC without the repository. Usage: windows-wsl2/make-package.sh [out zip, default ~/Desktop/igneum-prove-wsl2.zip]
|
|
set -euo pipefail
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
ROOT="$(cd "$HERE/../.." && pwd)"
|
|
OUT="${1:-$HOME/Desktop/igneum-prove-wsl2.zip}"
|
|
STAGE="$(mktemp -d)/igneum-prove-wsl2"
|
|
PKG="$STAGE/package"
|
|
mkdir -p "$PKG/proving" "$PKG/vendor/igneum-node-exec/igneum"
|
|
cp "$HERE/SETUP-PROVER.bat" "$HERE/setup-prover.ps1" "$HERE/setup-wsl.sh" "$HERE/prove-block.sh" "$HERE/PROVE-BLOCK.bat" "$HERE/prove-shard.sh" "$HERE/PROVE-SHARD.bat" "$HERE/README.txt" "$STAGE/"
|
|
rsync -a --exclude "target*" --exclude Cargo.lock "$ROOT/proving/igneum-prove" "$PKG/proving/"
|
|
cp "$ROOT/proving/igneum-prove/Cargo.lock" "$PKG/proving/igneum-prove/" 2>/dev/null || true
|
|
rsync -a "$ROOT/proving/fixtures" "$PKG/proving/"
|
|
# the package travels to a PC and is built there against a kept target dir: stamp every file now (cargo rebuilds by mtime)
|
|
find "$PKG" -type f -exec touch {} +
|
|
rsync -a --exclude target "$ROOT/vendor/igneum-node-exec/igneum/evm-types" "$PKG/vendor/igneum-node-exec/igneum/"
|
|
# evm-types inherits thiserror from the node's workspace; pin it inline (the node's Cargo.toml line 346: 2.0.18) so the crate builds alone.
|
|
perl -pi -e 's/^thiserror\.workspace = true/thiserror = { version = "2.0.18", default-features = false }/' "$PKG/vendor/igneum-node-exec/igneum/evm-types/Cargo.toml"
|
|
# The exporters' inputs, so the fixtures can be regenerated on the PC too.
|
|
mkdir -p "$PKG/tools/evm-smoke" "$PKG/tools/prove-fixtures" && cp "$ROOT/tools/evm-smoke/seq.json" "$PKG/tools/evm-smoke/" 2>/dev/null || true
|
|
cp "$ROOT/tools/prove-fixtures/seq.json" "$PKG/tools/prove-fixtures/" 2>/dev/null || true
|
|
for f in "$STAGE/SETUP-PROVER.bat" "$STAGE/PROVE-BLOCK.bat" "$STAGE/PROVE-SHARD.bat" "$STAGE/README.txt" "$STAGE/setup-prover.ps1"; do perl -pi -e 's/\r?\n/\r\n/' "$f"; done
|
|
for f in "$STAGE/setup-wsl.sh" "$STAGE/prove-block.sh" "$STAGE/prove-shard.sh"; do perl -pi -e 's/\r\n/\n/' "$f"; chmod +x "$f"; done
|
|
# GATE (4 October 2026, after the second RTX 5090 run failed in its first second with a guest and host pair that had never
|
|
# run together): the host is built here from the same sources that go into the package and must execute the shard
|
|
# fixture and verify every block fixture natively before any zip exists. SKIP_GATE=1 skips it (never for a package that ships).
|
|
if [ "${SKIP_GATE:-0}" != "1" ]; then
|
|
echo "gate: building the host from the packaged sources and running the fixtures on this machine's CPU"
|
|
GATE_LOG="$(mktemp)"
|
|
if ! (cd "$ROOT/proving/igneum-prove" && "$ROOT/tools/lock/with-lock.sh" build env PATH="$HOME/.cargo/bin:$PATH" nice -n 19 cargo build --release -j 4 -p igneum-prove-host >"$GATE_LOG" 2>&1); then
|
|
echo "GATE FAILED: the host does not build; see $GATE_LOG"; exit 1
|
|
fi
|
|
H="$ROOT/proving/igneum-prove/target/release/igneum-prove-host"
|
|
for f in "$ROOT"/proving/fixtures/block-*.json; do
|
|
if ! "$H" "$f" --mode native >>"$GATE_LOG" 2>&1; then echo "GATE FAILED: native run of $(basename "$f"); see $GATE_LOG"; exit 1; fi
|
|
done
|
|
if ! "$ROOT/tools/lock/with-lock.sh" measure "$H" "$ROOT/proving/fixtures/block-338-shard1.json" --mode execute --shard 0 >>"$GATE_LOG" 2>&1; then
|
|
echo "GATE FAILED: the guest did not execute the shard fixture (the exact failure the PC hit on 4 October); see $GATE_LOG"; exit 1
|
|
fi
|
|
"$H" --mode id | tee -a "$GATE_LOG" # the pinned program ids this package carries (the PC's build embeds the same elf/ files)
|
|
echo "gate: passed ($(grep -c '^RESULT' "$GATE_LOG") RESULT lines)"
|
|
fi
|
|
rm -f "$OUT"
|
|
(cd "$(dirname "$STAGE")" && zip -qr "$OUT" "$(basename "$STAGE")")
|
|
ls -la "$OUT"
|
|
unzip -l "$OUT" | tail -n +4 | awk '{print $4}' | sed '/^$/d' | grep -v '/$' | head -40
|