From 0133d9a989eae9c16f48bb8e1b8e22f27b6cbbbc Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 22:55:58 +0100 Subject: [PATCH 1/6] Upgrade tonic/prost stack, sha2 0.11, and Actions v7. Coordinate gRPC crates (tonic-prost / tonic-prost-build) so Dependabot cannot skew versions; keep bincode on 1.3 and ignore majors (3.0.0 is an unmaintained stub). Co-authored-by: Cursor --- .github/dependabot.yml | 18 ++ .github/workflows/ci.yml | 4 +- .github/workflows/sp1-execute.yml | 8 +- CHANGELOG.md | 1 + clients/rust/Cargo.lock | 473 ++++++++++++------------------ clients/rust/Cargo.toml | 7 +- clients/rust/build.rs | 2 +- host/Cargo.lock | 347 +++++++++++++++++++--- host/compliance_lib/Cargo.toml | 2 +- host/prove_server/Cargo.toml | 9 +- host/prove_server/build.rs | 2 +- host/receipt/Cargo.toml | 2 +- 12 files changed, 527 insertions(+), 348 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f0e4014..5ccddc2 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,11 +5,29 @@ updates: schedule: interval: monthly open-pull-requests-limit: 5 + ignore: + # bincode 3.0.0 is an intentional unmaintained stub that only fails to compile. + - dependency-name: bincode + update-types: ["version-update:semver-major"] + groups: + tonic-prost: + patterns: + - "tonic" + - "tonic-*" + - "prost" + - "prost-*" - package-ecosystem: cargo directory: /clients/rust schedule: interval: monthly open-pull-requests-limit: 3 + groups: + tonic-prost: + patterns: + - "tonic" + - "tonic-*" + - "prost" + - "prost-*" - package-ecosystem: github-actions directory: / schedule: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 189e9c0..d997ec3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,7 +9,7 @@ jobs: lean-mock: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Install deps run: | sudo apt-get update -qq @@ -47,7 +47,7 @@ jobs: rust-mock: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: dtolnay/rust-toolchain@stable - name: Test receipt + compliance working-directory: host diff --git a/.github/workflows/sp1-execute.yml b/.github/workflows/sp1-execute.yml index 2d68249..280c958 100644 --- a/.github/workflows/sp1-execute.yml +++ b/.github/workflows/sp1-execute.yml @@ -43,7 +43,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 180 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: path: lean-tee - uses: dtolnay/rust-toolchain@stable @@ -79,7 +79,7 @@ jobs: CARGO_TERM_COLOR: always run: bash scripts/sp1_execute_ci.sh - name: Upload guest digests - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: sp1-guest-digests path: lean-tee/artifacts/sp1_guest_digests.json @@ -93,7 +93,7 @@ jobs: (github.event_name == 'workflow_dispatch' && inputs.prove_one && inputs.prove_heavy) timeout-minutes: 240 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: path: lean-tee - uses: dtolnay/rust-toolchain@stable @@ -124,7 +124,7 @@ jobs: CARGO_TERM_COLOR: always run: bash scripts/sp1_execute_ci.sh - name: Upload guest digests (post-prove) - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: sp1-guest-digests-heavy path: lean-tee/artifacts/sp1_guest_digests.json diff --git a/CHANGELOG.md b/CHANGELOG.md index bfe6613..8a2c459 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,7 @@ ## Unreleased +- Coordinated Dependabot upgrades: tonic/tonic-prost/prost 0.14, sha2 0.11, Actions checkout/upload-artifact v7; ignore bincode majors (3.0.0 is an unmaintained stub) - Pin lean-grpc dependency to **v1.1.0** (was v1.0.0) - Mid-tier Lean SP1 guest + `sp1_lean_mid_smoke --prove` (Init-free mix/rounds; laptop-oriented) - Spike smoke: optional `--prove` for CPU prove+verify diff --git a/clients/rust/Cargo.lock b/clients/rust/Cargo.lock index 2b56e7a..715d34e 100644 --- a/clients/rust/Cargo.lock +++ b/clients/rust/Cargo.lock @@ -18,26 +18,16 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "330a5ed07fa54e4702c9d6c4174f74427fc0ef6e214bbd677ae50a5099946470" [[package]] -name = "async-stream" -version = "0.3.6" +name = "arrayref" +version = "0.3.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0b5a71a6f37880a80d1d7f19efd781e4b5de42c88f0722cc13bcb6cc2cfe8476" -dependencies = [ - "async-stream-impl", - "futures-core", - "pin-project-lite", -] +checksum = "76a2e8124351fda1ef8aaaa3bbd7ebbcb486bbcd4225aca0aa0d84bb2db8fecb" [[package]] -name = "async-stream-impl" -version = "0.3.6" +name = "arrayvec" +version = "0.7.8" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c7c24de15d275a1ecfd47a380fb4d5ec9bfe0933f309ed5e705b775596a3574d" -dependencies = [ - "proc-macro2", - "quote", - "syn 2.0.119", -] +checksum = "d3fb67a6e08acf24fdeccbac2cb6ac4305825bd1f117462e0e6f2f193345ad56" [[package]] name = "async-trait" @@ -56,19 +46,12 @@ version = "1.1.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "1505bd5d3d116872e7271a6d4e16d81d0c8570876c8de68093a09ac269d8aac0" -[[package]] -name = "autocfg" -version = "1.5.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53" - [[package]] name = "axum" -version = "0.7.9" +version = "0.8.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "edca88bc138befd0323b20752846e6587272d3b03b0343c8ea28a6f819e6e71f" +checksum = "31b698c5f9a010f6573133b09e0de5408834d0c82f8d7475a89fc1867a71cd90" dependencies = [ - "async-trait", "axum-core", "bytes", "futures-util", @@ -81,29 +64,26 @@ dependencies = [ "mime", "percent-encoding", "pin-project-lite", - "rustversion", - "serde", + "serde_core", "sync_wrapper", - "tower 0.5.3", + "tower", "tower-layer", "tower-service", ] [[package]] name = "axum-core" -version = "0.4.5" +version = "0.5.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "09f2bd6146b97ae3359fa0cc6d6b376d9539582c7b4220f041a33ec24c226199" +checksum = "08c78f31d7b1291f7ee735c1c6780ccde7785daae9a9206026862dab7d8792d1" dependencies = [ - "async-trait", "bytes", - "futures-util", + "futures-core", "http", "http-body", "http-body-util", "mime", "pin-project-lite", - "rustversion", "sync_wrapper", "tower-layer", "tower-service", @@ -121,13 +101,27 @@ version = "2.13.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" +[[package]] +name = "blake3" +version = "1.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "76ae7bad254120e9e4c63bafc385310756f90c484eac0e36b8317cf09cb92a77" +dependencies = [ + "arrayref", + "arrayvec", + "cc", + "cfg-if", + "constant_time_eq", + "cpufeatures", +] + [[package]] name = "block-buffer" -version = "0.10.4" +version = "0.12.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71" +checksum = "d2f6c7dbe95a6ed67ad9f18e57daf93a2f034c524b99fd2b76d18fdfeb6660aa" dependencies = [ - "generic-array", + "hybrid-array", ] [[package]] @@ -136,38 +130,60 @@ version = "1.12.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "fc652a48c352aef3ea3aed32080501cf3ef6ed5da78602a020c991775b0aff04" +[[package]] +name = "cc" +version = "1.4.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5add81bb678e6cb321aff7fa0dc7689ad82b112dbc032cea19f91d6b8e3582b9" +dependencies = [ + "find-msvc-tools", + "shlex", +] + [[package]] name = "cfg-if" version = "1.0.4" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" +[[package]] +name = "const-oid" +version = "0.10.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a6ef517f0926dd24a1582492c791b6a4818a4d94e789a334894aa15b0d12f55c" + +[[package]] +name = "constant_time_eq" +version = "0.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3d52eff69cd5e647efe296129160853a42795992097e8af39800e1060caeea9b" + [[package]] name = "cpufeatures" -version = "0.2.17" +version = "0.3.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "59ed5838eebb26a2bb2e58f6d5b5316989ae9d08bab10e0e6d103e656d1b0280" +checksum = "8b2a41393f66f16b0823bb79094d54ac5fbd34ab292ddafb9a0456ac9f87d201" dependencies = [ "libc", ] [[package]] name = "crypto-common" -version = "0.1.7" +version = "0.2.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a" +checksum = "ce6e4c961d6cd6c9a86db418387425e8bdeaf05b3c8bc1411e6dca4c252f1453" dependencies = [ - "generic-array", - "typenum", + "hybrid-array", ] [[package]] name = "digest" -version = "0.10.7" +version = "0.11.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" +checksum = "f1dd6dbb5841937940781866fa1281a1ff7bd3bf827091440879f9994983d5c2" dependencies = [ "block-buffer", + "const-oid", "crypto-common", ] @@ -190,7 +206,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" dependencies = [ "libc", - "windows-sys 0.61.2", + "windows-sys", ] [[package]] @@ -199,6 +215,12 @@ version = "2.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "da7c62ceae207dd37ea5b845da6a0696c799f85e97da1ab5b7910be3c1c80223" +[[package]] +name = "find-msvc-tools" +version = "0.1.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582" + [[package]] name = "fixedbitset" version = "0.5.7" @@ -211,6 +233,12 @@ version = "1.0.7" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1" +[[package]] +name = "foldhash" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d9c4f5dac5e15c24eb999c26181a6ca40b39fe946cbe4c263c7209467bc83af2" + [[package]] name = "futures-channel" version = "0.3.33" @@ -250,27 +278,6 @@ dependencies = [ "slab", ] -[[package]] -name = "generic-array" -version = "0.14.7" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "85649ca51fd72272d7821adaf274ad91c288277713d9c18820d8499a7ff69e9a" -dependencies = [ - "typenum", - "version_check", -] - -[[package]] -name = "getrandom" -version = "0.2.17" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ff2abc00be7fca6ebc474524697ae276ad847ad0a6b3faa4bcb027e9a4614ad0" -dependencies = [ - "cfg-if", - "libc", - "wasi", -] - [[package]] name = "getrandom" version = "0.4.3" @@ -294,7 +301,7 @@ dependencies = [ "futures-core", "futures-sink", "http", - "indexmap 2.14.0", + "indexmap", "slab", "tokio", "tokio-util", @@ -303,9 +310,12 @@ dependencies = [ [[package]] name = "hashbrown" -version = "0.12.3" +version = "0.15.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8a9ee70c43aaf417c914396645a0fa852624801b24ebb7ae78fe8272889ac888" +checksum = "9229cfe53dfd69f0609a49f65461bd93001ea1ef889cd5529dd176593f5338a1" +dependencies = [ + "foldhash", +] [[package]] name = "hashbrown" @@ -370,6 +380,15 @@ version = "1.0.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "df3b46402a9d5adb4c86a0cf463f42e19994e3ee891101b1841f30a545cb49a9" +[[package]] +name = "hybrid-array" +version = "0.4.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "707114b52a152fa7bdb290cd7cd5912d9467273b6d74e21b8d81aca1f8533f6b" +dependencies = [ + "typenum", +] + [[package]] name = "hyper" version = "1.11.0" @@ -419,22 +438,12 @@ dependencies = [ "hyper", "libc", "pin-project-lite", - "socket2 0.6.5", + "socket2", "tokio", "tower-service", "tracing", ] -[[package]] -name = "indexmap" -version = "1.9.3" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "bd070e393353796e801d209ad339e89596eb4c8d430d18ede6a1cced8fafbd99" -dependencies = [ - "autocfg", - "hashbrown 0.12.3", -] - [[package]] name = "indexmap" version = "2.14.0" @@ -462,7 +471,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" [[package]] name = "lean_tee_client" -version = "0.1.0" +version = "1.0.1" dependencies = [ "hex", "lean_tee_receipt", @@ -470,13 +479,15 @@ dependencies = [ "protoc-bin-vendored", "tokio", "tonic", - "tonic-build", + "tonic-prost", + "tonic-prost-build", ] [[package]] name = "lean_tee_receipt" -version = "0.1.0" +version = "1.0.1" dependencies = [ + "blake3", "hex", "sha2", ] @@ -501,9 +512,9 @@ checksum = "0ceec5bc11778974d1bcb055b18002eba7f4b3518b6a0081b3af5f21666da9ad" [[package]] name = "matchit" -version = "0.7.3" +version = "0.8.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0e7465ac9959cc2b1404e8e2367b43684a6d13790fe23056cc8c6c5a6b7bcb94" +checksum = "47e1ffaa40ddd1f3ed91f717a33c8c0ee23fff369e3aa8772b9605cc1d22f4c3" [[package]] name = "memchr" @@ -525,7 +536,7 @@ checksum = "30d65c71f1ce40ab09135ce117d742b9f8a19ff91a41a8b57ed50bc2de59c427" dependencies = [ "libc", "wasi", - "windows-sys 0.61.2", + "windows-sys", ] [[package]] @@ -548,12 +559,13 @@ checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220" [[package]] name = "petgraph" -version = "0.7.1" +version = "0.8.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3672b37090dbd86368a4145bc067582552b29c27377cad4e0a306c97f9bd7772" +checksum = "8701b58ea97060d5e5b155d383a69952a60943f0e6dfe30b04c287beb0b27455" dependencies = [ "fixedbitset", - "indexmap 2.14.0", + "hashbrown 0.15.5", + "indexmap", ] [[package]] @@ -582,15 +594,6 @@ version = "0.2.17" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" -[[package]] -name = "ppv-lite86" -version = "0.2.21" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "85eae3c4ed2f50dcfe72643da4befc30deadb458a9b590d720cde2f2b1e97da9" -dependencies = [ - "zerocopy", -] - [[package]] name = "prettyplease" version = "0.2.37" @@ -612,9 +615,9 @@ dependencies = [ [[package]] name = "prost" -version = "0.13.5" +version = "0.14.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2796faa41db3ec313a31f7624d9286acf277b52de526150b7e69f3debf891ee5" +checksum = "528ac67416ff8646872a3c02cad9cc4ee5dc9f9540c9b10771855c95cb2e5ae1" dependencies = [ "bytes", "prost-derive", @@ -622,19 +625,20 @@ dependencies = [ [[package]] name = "prost-build" -version = "0.13.5" +version = "0.14.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "be769465445e8c1474e9c5dac2018218498557af32d9ed057325ec9a41ae81bf" +checksum = "03da047801ff44bb6a4d407d4860c05fd70bb81714e6b2f3812603d5b145b042" dependencies = [ "heck", "itertools", "log", "multimap", - "once_cell", "petgraph", "prettyplease", "prost", "prost-types", + "pulldown-cmark", + "pulldown-cmark-to-cmark", "regex", "syn 2.0.119", "tempfile", @@ -642,9 +646,9 @@ dependencies = [ [[package]] name = "prost-derive" -version = "0.13.5" +version = "0.14.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8a56d757972c98b346a9b766e3f02746cde6dd1cd1d1d563472929fdd74bec4d" +checksum = "b570b25f7617e43d59005d0990ccb79e950a423952cea19671b7a876da390adf" dependencies = [ "anyhow", "itertools", @@ -655,9 +659,9 @@ dependencies = [ [[package]] name = "prost-types" -version = "0.13.5" +version = "0.14.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "52c2c1bf36ddb1a1c396b3601a3cec27c2462e45f07c386894ec3ccf5332bd16" +checksum = "f94967dc7688f3054c7fac87473ffae4cc4c3904800e2d9f5b857246d8963b0a" dependencies = [ "prost", ] @@ -727,49 +731,39 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "95067976aca6421a523e491fce939a3e65249bac4b977adee0ee9771568e8aa3" [[package]] -name = "quote" -version = "1.0.47" +name = "pulldown-cmark" +version = "0.13.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" +checksum = "e9f068eba8e7071c5f9511831b44f32c740d5adf574e990f946ddb53db2f314e" dependencies = [ - "proc-macro2", + "bitflags", + "memchr", + "unicase", ] [[package]] -name = "r-efi" -version = "6.0.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" - -[[package]] -name = "rand" -version = "0.8.7" +name = "pulldown-cmark-to-cmark" +version = "22.0.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "22f6172bdec972074665ed81ed53b71da00bfc44b65a753cfde883ec4c702a1a" +checksum = "50793def1b900256624a709439404384204a5dc3a6ec580281bfaac35e882e90" dependencies = [ - "libc", - "rand_chacha", - "rand_core", + "pulldown-cmark", ] [[package]] -name = "rand_chacha" -version = "0.3.1" +name = "quote" +version = "1.0.47" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88" +checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" dependencies = [ - "ppv-lite86", - "rand_core", + "proc-macro2", ] [[package]] -name = "rand_core" -version = "0.6.4" +name = "r-efi" +version = "6.0.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c" -dependencies = [ - "getrandom 0.2.17", -] +checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" [[package]] name = "regex" @@ -810,22 +804,7 @@ dependencies = [ "errno", "libc", "linux-raw-sys", - "windows-sys 0.61.2", -] - -[[package]] -name = "rustversion" -version = "1.0.23" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" - -[[package]] -name = "serde" -version = "1.0.229" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "4148590afebada386688f18773da617792bf2ef03ffc1e4cbd2b1d45b023e0ba" -dependencies = [ - "serde_core", + "windows-sys", ] [[package]] @@ -850,15 +829,21 @@ dependencies = [ [[package]] name = "sha2" -version = "0.10.9" +version = "0.11.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a7507d819769d01a365ab707794a4084392c824f54a7a6a7862f8c3d0892b283" +checksum = "446ba717509524cb3f22f17ecc096f10f4822d76ab5c0b9822c5f9c284e825f4" dependencies = [ "cfg-if", "cpufeatures", "digest", ] +[[package]] +name = "shlex" +version = "2.0.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8fadd59c855ef2080decdef8ff161eb6661b86933c9d82e5ba29dc602a55aba" + [[package]] name = "slab" version = "0.4.12" @@ -871,16 +856,6 @@ version = "1.15.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" -[[package]] -name = "socket2" -version = "0.5.10" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e22376abed350d73dd1cd119b57ffccad95b4e585a7cda43e286245ce23c0678" -dependencies = [ - "libc", - "windows-sys 0.52.0", -] - [[package]] name = "socket2" version = "0.6.5" @@ -888,7 +863,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "c3d1e2c7f27f8d4cb10542a02c49005dbd6e93095799d6f3be745fae9f8fedd4" dependencies = [ "libc", - "windows-sys 0.61.2", + "windows-sys", ] [[package]] @@ -926,10 +901,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "32497e9a4c7b38532efcdebeef879707aa9f794296a4f0244f6f69e9bc8574bd" dependencies = [ "fastrand", - "getrandom 0.4.3", + "getrandom", "once_cell", "rustix", - "windows-sys 0.61.2", + "windows-sys", ] [[package]] @@ -942,9 +917,9 @@ dependencies = [ "libc", "mio", "pin-project-lite", - "socket2 0.6.5", + "socket2", "tokio-macros", - "windows-sys 0.61.2", + "windows-sys", ] [[package]] @@ -985,11 +960,10 @@ dependencies = [ [[package]] name = "tonic" -version = "0.12.3" +version = "0.14.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "877c5b330756d856ffcc4553ab34a5684481ade925ecc54bcd1bf02b1d0d4d52" +checksum = "ac2a5518c70fa84342385732db33fb3f44bc4cc748936eb5833d2df34d6445ef" dependencies = [ - "async-stream", "async-trait", "axum", "base64", @@ -1003,11 +977,11 @@ dependencies = [ "hyper-util", "percent-encoding", "pin-project", - "prost", - "socket2 0.5.10", + "socket2", + "sync_wrapper", "tokio", "tokio-stream", - "tower 0.4.13", + "tower", "tower-layer", "tower-service", "tracing", @@ -1015,36 +989,41 @@ dependencies = [ [[package]] name = "tonic-build" -version = "0.12.3" +version = "0.14.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9557ce109ea773b399c9b9e5dca39294110b74f1f342cb347a80d1fce8c26a11" +checksum = "c68f61875ac5293cf72e6c8cf0158086428c82c37229e98c840878f1706b0322" dependencies = [ "prettyplease", "proc-macro2", - "prost-build", - "prost-types", "quote", "syn 2.0.119", ] [[package]] -name = "tower" -version = "0.4.13" +name = "tonic-prost" +version = "0.14.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b8fa9be0de6cf49e536ce1851f987bd21a43b771b09473c3549a6c853db37c1c" +checksum = "50849f68853be452acf590cde0b146665b8d507b3b8af17261df47e02c209ea0" dependencies = [ - "futures-core", - "futures-util", - "indexmap 1.9.3", - "pin-project", - "pin-project-lite", - "rand", - "slab", - "tokio", - "tokio-util", - "tower-layer", - "tower-service", - "tracing", + "bytes", + "prost", + "tonic", +] + +[[package]] +name = "tonic-prost-build" +version = "0.14.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "654e5643eff75d7f8c99197ce1440ed19a3474eada74c12bbac488b2cafdae27" +dependencies = [ + "prettyplease", + "proc-macro2", + "prost-build", + "prost-types", + "quote", + "syn 2.0.119", + "tempfile", + "tonic-build", ] [[package]] @@ -1055,10 +1034,15 @@ checksum = "ebe5ef63511595f1344e2d5cfa636d973292adc0eec1f0ad45fae9f0851ab1d4" dependencies = [ "futures-core", "futures-util", + "indexmap", "pin-project-lite", + "slab", "sync_wrapper", + "tokio", + "tokio-util", "tower-layer", "tower-service", + "tracing", ] [[package]] @@ -1117,16 +1101,16 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "b6f5e870be6c3b371b77fe0ee0bafb859fa4964b4404c27de1d380043c4dda20" [[package]] -name = "unicode-ident" -version = "1.0.24" +name = "unicase" +version = "2.9.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75" +checksum = "dbc4bc3a9f746d862c45cb89d705aa10f187bb96c76001afab07a0d35ce60142" [[package]] -name = "version_check" -version = "0.9.5" +name = "unicode-ident" +version = "1.0.24" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a" +checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75" [[package]] name = "want" @@ -1149,15 +1133,6 @@ version = "0.2.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" -[[package]] -name = "windows-sys" -version = "0.52.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d" -dependencies = [ - "windows-targets", -] - [[package]] name = "windows-sys" version = "0.61.2" @@ -1166,87 +1141,3 @@ checksum = "ae137229bcbd6cdf0f7b80a31df61766145077ddf49416a728b02cb3921ff3fc" dependencies = [ "windows-link", ] - -[[package]] -name = "windows-targets" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973" -dependencies = [ - "windows_aarch64_gnullvm", - "windows_aarch64_msvc", - "windows_i686_gnu", - "windows_i686_gnullvm", - "windows_i686_msvc", - "windows_x86_64_gnu", - "windows_x86_64_gnullvm", - "windows_x86_64_msvc", -] - -[[package]] -name = "windows_aarch64_gnullvm" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3" - -[[package]] -name = "windows_aarch64_msvc" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469" - -[[package]] -name = "windows_i686_gnu" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8e9b5ad5ab802e97eb8e295ac6720e509ee4c243f69d781394014ebfe8bbfa0b" - -[[package]] -name = "windows_i686_gnullvm" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66" - -[[package]] -name = "windows_i686_msvc" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66" - -[[package]] -name = "windows_x86_64_gnu" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78" - -[[package]] -name = "windows_x86_64_gnullvm" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d" - -[[package]] -name = "windows_x86_64_msvc" -version = "0.52.6" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "589f6da84c646204747d1270a2a5661ea66ed1cced2631d546fdfb155959f9ec" - -[[package]] -name = "zerocopy" -version = "0.8.55" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b5a105cd7b140f6eeec8acff2ea38135d3cab283ada58540f629fe51e46696eb" -dependencies = [ - "zerocopy-derive", -] - -[[package]] -name = "zerocopy-derive" -version = "0.8.55" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0fe976fb70c78cd64cccfe3a6fc142244e8a77b70959b30faf9d0ac37ee228eb" -dependencies = [ - "proc-macro2", - "quote", - "syn 2.0.119", -] diff --git a/clients/rust/Cargo.toml b/clients/rust/Cargo.toml index 5b5ea7b..f3a6b54 100644 --- a/clients/rust/Cargo.toml +++ b/clients/rust/Cargo.toml @@ -7,11 +7,12 @@ description = "Thin tonic client for lean_tee.v1 Tee + Prove" [dependencies] lean_tee_receipt = { path = "../../host/receipt" } -prost = "0.13" +prost = "0.14" tokio = { version = "1", features = ["macros", "rt-multi-thread"] } -tonic = { version = "0.12", features = ["transport"] } +tonic = { version = "0.14", features = ["transport"] } +tonic-prost = "0.14" hex = "0.4" [build-dependencies] protoc-bin-vendored = "3" -tonic-build = "0.12" +tonic-prost-build = "0.14" diff --git a/clients/rust/build.rs b/clients/rust/build.rs index bf5a5c6..5b8cad3 100644 --- a/clients/rust/build.rs +++ b/clients/rust/build.rs @@ -6,7 +6,7 @@ fn main() -> Result<(), Box> { std::env::set_var("PROTOC", &protoc); let proto = "../../proto/lean_tee/v1/tee.proto"; println!("cargo:rerun-if-changed={proto}"); - tonic_build::configure() + tonic_prost_build::configure() .build_client(true) .build_server(false) .compile_protos(&[proto], &["../../proto"])?; diff --git a/host/Cargo.lock b/host/Cargo.lock index 8738b95..71401e1 100644 --- a/host/Cargo.lock +++ b/host/Cargo.lock @@ -213,14 +213,14 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "edca88bc138befd0323b20752846e6587272d3b03b0343c8ea28a6f819e6e71f" dependencies = [ "async-trait", - "axum-core", + "axum-core 0.4.5", "bytes", "futures-util", "http", "http-body", "http-body-util", "itoa", - "matchit", + "matchit 0.7.3", "memchr", "mime", "percent-encoding", @@ -233,6 +233,31 @@ dependencies = [ "tower-service", ] +[[package]] +name = "axum" +version = "0.8.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "31b698c5f9a010f6573133b09e0de5408834d0c82f8d7475a89fc1867a71cd90" +dependencies = [ + "axum-core 0.5.6", + "bytes", + "futures-util", + "http", + "http-body", + "http-body-util", + "itoa", + "matchit 0.8.4", + "memchr", + "mime", + "percent-encoding", + "pin-project-lite", + "serde_core", + "sync_wrapper", + "tower 0.5.3", + "tower-layer", + "tower-service", +] + [[package]] name = "axum-core" version = "0.4.5" @@ -253,6 +278,24 @@ dependencies = [ "tower-service", ] +[[package]] +name = "axum-core" +version = "0.5.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "08c78f31d7b1291f7ee735c1c6780ccde7785daae9a9206026862dab7d8792d1" +dependencies = [ + "bytes", + "futures-core", + "http", + "http-body", + "http-body-util", + "mime", + "pin-project-lite", + "sync_wrapper", + "tower-layer", + "tower-service", +] + [[package]] name = "backtrace" version = "0.3.76" @@ -337,6 +380,15 @@ dependencies = [ "generic-array 0.14.9", ] +[[package]] +name = "block-buffer" +version = "0.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d2f6c7dbe95a6ed67ad9f18e57daf93a2f034c524b99fd2b76d18fdfeb6660aa" +dependencies = [ + "hybrid-array", +] + [[package]] name = "bumpalo" version = "3.20.3" @@ -528,6 +580,12 @@ version = "0.9.6" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8" +[[package]] +name = "const-oid" +version = "0.10.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a6ef517f0926dd24a1582492c791b6a4818a4d94e789a334894aa15b0d12f55c" + [[package]] name = "const_format" version = "0.2.36" @@ -702,6 +760,15 @@ dependencies = [ "typenum", ] +[[package]] +name = "crypto-common" +version = "0.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ce6e4c961d6cd6c9a86db418387425e8bdeaf05b3c8bc1411e6dca4c252f1453" +dependencies = [ + "hybrid-array", +] + [[package]] name = "dashu" version = "0.4.4" @@ -807,7 +874,7 @@ version = "0.7.10" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb" dependencies = [ - "const-oid", + "const-oid 0.9.6", "pem-rfc7468", "zeroize", ] @@ -855,12 +922,23 @@ version = "0.10.7" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" dependencies = [ - "block-buffer", - "const-oid", - "crypto-common", + "block-buffer 0.10.4", + "const-oid 0.9.6", + "crypto-common 0.1.6", "subtle", ] +[[package]] +name = "digest" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f1dd6dbb5841937940781866fa1281a1ff7bd3bf827091440879f9994983d5c2" +dependencies = [ + "block-buffer 0.12.1", + "const-oid 0.10.2", + "crypto-common 0.2.2", +] + [[package]] name = "dirs" version = "5.0.1" @@ -933,7 +1011,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "ee27f32b5c5292967d2d4a9d7f1e0b0aed2c15daded5a60300e4abb9d8020bca" dependencies = [ "der", - "digest", + "digest 0.10.7", "elliptic-curve", "rfc6979", "serdect", @@ -964,7 +1042,7 @@ checksum = "b5e6043086bf7973472e0c7dff2142ea0b680d30e18d9cc40f267efbf222bd47" dependencies = [ "base16ct", "crypto-bigint", - "digest", + "digest 0.10.7", "ff", "generic-array 0.14.9", "group", @@ -1390,7 +1468,7 @@ version = "0.12.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "6c49c37c09c17a53d937dfbb742eb3a961d65a994e6bcdcf37e7399d0cc8ab5e" dependencies = [ - "digest", + "digest 0.10.7", ] [[package]] @@ -1438,6 +1516,15 @@ version = "1.0.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "df3b46402a9d5adb4c86a0cf463f42e19994e3ee891101b1841f30a545cb49a9" +[[package]] +name = "hybrid-array" +version = "0.4.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "707114b52a152fa7bdb290cd7cd5912d9467273b6d74e21b8d81aca1f8533f6b" +dependencies = [ + "typenum", +] + [[package]] name = "hyper" version = "1.11.0" @@ -1747,7 +1834,7 @@ dependencies = [ "elliptic-curve", "once_cell", "serdect", - "sha2", + "sha2 0.10.9", "signature", ] @@ -1781,7 +1868,7 @@ version = "1.0.1" dependencies = [ "hex", "lean_tee_receipt", - "sha2", + "sha2 0.11.0", ] [[package]] @@ -1834,15 +1921,16 @@ dependencies = [ "hex", "lean_tee_compliance", "lean_tee_receipt", - "prost", + "prost 0.14.4", "protoc-bin-vendored", "serde", - "sha2", + "sha2 0.11.0", "sp1-build", "sp1-sdk", "tokio", - "tonic", - "tonic-build", + "tonic 0.14.6", + "tonic-prost", + "tonic-prost-build", "tracing", "tracing-subscriber", ] @@ -1854,7 +1942,7 @@ dependencies = [ "blake3", "hex", "serde_json", - "sha2", + "sha2 0.11.0", ] [[package]] @@ -1950,6 +2038,12 @@ version = "0.7.3" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "0e7465ac9959cc2b1404e8e2367b43684a6d13790fe23056cc8c6c5a6b7bcb94" +[[package]] +name = "matchit" +version = "0.8.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "47e1ffaa40ddd1f3ed91f717a33c8c0ee23fff369e3aa8772b9605cc1d22f4c3" + [[package]] name = "md-5" version = "0.10.6" @@ -1957,7 +2051,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "d89e7ee0cfbedfc4da3340218492196241d89eefb6dab27de5df917a6d2e78cf" dependencies = [ "cfg-if", - "digest", + "digest 0.10.7", ] [[package]] @@ -2257,7 +2351,7 @@ dependencies = [ "ecdsa", "elliptic-curve", "primeorder", - "sha2", + "sha2 0.10.9", ] [[package]] @@ -2614,6 +2708,17 @@ dependencies = [ "indexmap 2.14.0", ] +[[package]] +name = "petgraph" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8701b58ea97060d5e5b155d383a69952a60943f0e6dfe30b04c287beb0b27455" +dependencies = [ + "fixedbitset", + "hashbrown 0.15.5", + "indexmap 2.14.0", +] + [[package]] name = "pin-project" version = "1.1.13" @@ -2756,7 +2861,17 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "2796faa41db3ec313a31f7624d9286acf277b52de526150b7e69f3debf891ee5" dependencies = [ "bytes", - "prost-derive", + "prost-derive 0.13.5", +] + +[[package]] +name = "prost" +version = "0.14.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "528ac67416ff8646872a3c02cad9cc4ee5dc9f9540c9b10771855c95cb2e5ae1" +dependencies = [ + "bytes", + "prost-derive 0.14.4", ] [[package]] @@ -2770,10 +2885,31 @@ dependencies = [ "log", "multimap", "once_cell", - "petgraph", + "petgraph 0.7.1", + "prettyplease", + "prost 0.13.5", + "prost-types 0.13.5", + "regex", + "syn 2.0.119", + "tempfile", +] + +[[package]] +name = "prost-build" +version = "0.14.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "03da047801ff44bb6a4d407d4860c05fd70bb81714e6b2f3812603d5b145b042" +dependencies = [ + "heck", + "itertools 0.14.0", + "log", + "multimap", + "petgraph 0.8.3", "prettyplease", - "prost", - "prost-types", + "prost 0.14.4", + "prost-types 0.14.4", + "pulldown-cmark", + "pulldown-cmark-to-cmark", "regex", "syn 2.0.119", "tempfile", @@ -2792,13 +2928,35 @@ dependencies = [ "syn 2.0.119", ] +[[package]] +name = "prost-derive" +version = "0.14.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b570b25f7617e43d59005d0990ccb79e950a423952cea19671b7a876da390adf" +dependencies = [ + "anyhow", + "itertools 0.14.0", + "proc-macro2", + "quote", + "syn 2.0.119", +] + [[package]] name = "prost-types" version = "0.13.5" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "52c2c1bf36ddb1a1c396b3601a3cec27c2462e45f07c386894ec3ccf5332bd16" dependencies = [ - "prost", + "prost 0.13.5", +] + +[[package]] +name = "prost-types" +version = "0.14.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f94967dc7688f3054c7fac87473ffae4cc4c3904800e2d9f5b857246d8963b0a" +dependencies = [ + "prost 0.14.4", ] [[package]] @@ -2865,6 +3023,26 @@ version = "3.2.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "95067976aca6421a523e491fce939a3e65249bac4b977adee0ee9771568e8aa3" +[[package]] +name = "pulldown-cmark" +version = "0.13.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e9f068eba8e7071c5f9511831b44f32c740d5adf574e990f946ddb53db2f314e" +dependencies = [ + "bitflags", + "memchr", + "unicase", +] + +[[package]] +name = "pulldown-cmark-to-cmark" +version = "22.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "50793def1b900256624a709439404384204a5dc3a6ec580281bfaac35e882e90" +dependencies = [ + "pulldown-cmark", +] + [[package]] name = "quinn" version = "0.11.11" @@ -3456,7 +3634,18 @@ checksum = "a7507d819769d01a365ab707794a4084392c824f54a7a6a7862f8c3d0892b283" dependencies = [ "cfg-if", "cpufeatures 0.2.17", - "digest", + "digest 0.10.7", +] + +[[package]] +name = "sha2" +version = "0.11.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "446ba717509524cb3f22f17ecc096f10f4822d76ab5c0b9822c5f9c284e825f4" +dependencies = [ + "cfg-if", + "cpufeatures 0.3.0", + "digest 0.11.3", ] [[package]] @@ -3490,7 +3679,7 @@ version = "2.2.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "77549399552de45a898a580c1b41d445bf730df867cc44e6c0233bbc4b8329de" dependencies = [ - "digest", + "digest 0.10.7", "rand_core 0.6.4", ] @@ -4046,7 +4235,7 @@ dependencies = [ "hashbrown 0.14.5", "hex", "libc", - "sha2", + "sha2 0.10.9", "sp1-core-executor", "sp1-core-executor-runner-binary", "sp1-jit", @@ -4243,7 +4432,7 @@ dependencies = [ "lazy_static", "num-bigint 0.4.8", "serde", - "sha2", + "sha2 0.10.9", "slop-algebra", "slop-bn254", "slop-challenger", @@ -4281,7 +4470,7 @@ dependencies = [ "serde", "serde_json", "serial_test", - "sha2", + "sha2 0.10.9", "slop-air", "slop-algebra", "slop-basefold", @@ -4311,7 +4500,7 @@ dependencies = [ "tempfile", "thiserror 1.0.69", "tokio", - "tonic", + "tonic 0.12.3", "tracing", "tracing-appender", "tracing-subscriber", @@ -4330,14 +4519,14 @@ dependencies = [ "futures-util", "hashbrown 0.14.5", "mti", - "prost", + "prost 0.13.5", "serde", "sp1-core-machine", "sp1-hypercube", "sp1-primitives", "tokio", - "tonic", - "tonic-build", + "tonic 0.12.3", + "tonic-build 0.12.3", "tracing", ] @@ -4439,7 +4628,7 @@ dependencies = [ "num-bigint 0.4.8", "serde", "serde_json", - "sha2", + "sha2 0.10.9", "slop-algebra", "slop-symmetric", "sp1-hypercube", @@ -4491,7 +4680,7 @@ dependencies = [ "k256", "num-bigint 0.4.8", "serde", - "sha2", + "sha2 0.10.9", "sp1-build", "sp1-core-executor", "sp1-core-executor-runner", @@ -4522,7 +4711,7 @@ dependencies = [ "hex", "lazy_static", "serde", - "sha2", + "sha2 0.10.9", "slop-algebra", "slop-challenger", "slop-primitives", @@ -4550,7 +4739,7 @@ dependencies = [ "lazy_static", "libm", "rand 0.8.7", - "sha2", + "sha2 0.10.9", "sp1-lib", "sp1-primitives", ] @@ -4999,7 +5188,7 @@ checksum = "877c5b330756d856ffcc4553ab34a5684481ade925ecc54bcd1bf02b1d0d4d52" dependencies = [ "async-stream", "async-trait", - "axum", + "axum 0.7.9", "base64", "bytes", "h2", @@ -5011,7 +5200,7 @@ dependencies = [ "hyper-util", "percent-encoding", "pin-project", - "prost", + "prost 0.13.5", "rustls-pemfile", "socket2 0.5.10", "tokio", @@ -5023,6 +5212,35 @@ dependencies = [ "tracing", ] +[[package]] +name = "tonic" +version = "0.14.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac2a5518c70fa84342385732db33fb3f44bc4cc748936eb5833d2df34d6445ef" +dependencies = [ + "async-trait", + "axum 0.8.9", + "base64", + "bytes", + "h2", + "http", + "http-body", + "http-body-util", + "hyper", + "hyper-timeout", + "hyper-util", + "percent-encoding", + "pin-project", + "socket2 0.6.5", + "sync_wrapper", + "tokio", + "tokio-stream", + "tower 0.5.3", + "tower-layer", + "tower-service", + "tracing", +] + [[package]] name = "tonic-build" version = "0.12.3" @@ -5031,12 +5249,51 @@ checksum = "9557ce109ea773b399c9b9e5dca39294110b74f1f342cb347a80d1fce8c26a11" dependencies = [ "prettyplease", "proc-macro2", - "prost-build", - "prost-types", + "prost-build 0.13.5", + "prost-types 0.13.5", "quote", "syn 2.0.119", ] +[[package]] +name = "tonic-build" +version = "0.14.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c68f61875ac5293cf72e6c8cf0158086428c82c37229e98c840878f1706b0322" +dependencies = [ + "prettyplease", + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "tonic-prost" +version = "0.14.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "50849f68853be452acf590cde0b146665b8d507b3b8af17261df47e02c209ea0" +dependencies = [ + "bytes", + "prost 0.14.4", + "tonic 0.14.6", +] + +[[package]] +name = "tonic-prost-build" +version = "0.14.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "654e5643eff75d7f8c99197ce1440ed19a3474eada74c12bbac488b2cafdae27" +dependencies = [ + "prettyplease", + "proc-macro2", + "prost-build 0.14.4", + "prost-types 0.14.4", + "quote", + "syn 2.0.119", + "tempfile", + "tonic-build 0.14.6", +] + [[package]] name = "tower" version = "0.4.13" @@ -5065,11 +5322,15 @@ checksum = "ebe5ef63511595f1344e2d5cfa636d973292adc0eec1f0ad45fae9f0851ab1d4" dependencies = [ "futures-core", "futures-util", + "indexmap 2.14.0", "pin-project-lite", + "slab", "sync_wrapper", "tokio", + "tokio-util", "tower-layer", "tower-service", + "tracing", ] [[package]] @@ -5232,6 +5493,12 @@ version = "1.20.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "b6f5e870be6c3b371b77fe0ee0bafb859fa4964b4404c27de1d380043c4dda20" +[[package]] +name = "unicase" +version = "2.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "dbc4bc3a9f746d862c45cb89d705aa10f187bb96c76001afab07a0d35ce60142" + [[package]] name = "unicode-ident" version = "1.0.24" diff --git a/host/compliance_lib/Cargo.toml b/host/compliance_lib/Cargo.toml index 8113f38..2c2f8cd 100644 --- a/host/compliance_lib/Cargo.toml +++ b/host/compliance_lib/Cargo.toml @@ -8,4 +8,4 @@ description = "lean-tee compliance operator (guest + host); receipt crypto via l [dependencies] hex = "0.4" lean_tee_receipt = { path = "../receipt" } -sha2 = "0.10" +sha2 = "0.11" diff --git a/host/prove_server/Cargo.toml b/host/prove_server/Cargo.toml index 16daa93..1bfdd25 100644 --- a/host/prove_server/Cargo.toml +++ b/host/prove_server/Cargo.toml @@ -44,10 +44,11 @@ lean_tee_compliance = { path = "../compliance_lib" } lean_tee_receipt = { path = "../receipt" } bytes = "1" hex = "0.4" -prost = "0.13" -sha2 = "0.10" +prost = "0.14" +sha2 = "0.11" tokio = { version = "1", features = ["macros", "rt-multi-thread", "net", "signal"] } -tonic = { version = "0.12", features = ["transport"] } +tonic = { version = "0.14", features = ["transport"] } +tonic-prost = "0.14" tracing = "0.1" tracing-subscriber = { version = "0.3", features = ["env-filter"] } serde = { version = "1", features = ["derive"], optional = true } @@ -56,5 +57,5 @@ sp1-sdk = { version = "6.3.1", default-features = false, features = ["blocking"] [build-dependencies] protoc-bin-vendored = "3" -tonic-build = "0.12" +tonic-prost-build = "0.14" sp1-build = { version = "6.3.1", optional = true } diff --git a/host/prove_server/build.rs b/host/prove_server/build.rs index 4330561..a6ea59d 100644 --- a/host/prove_server/build.rs +++ b/host/prove_server/build.rs @@ -25,7 +25,7 @@ fn main() -> Result<(), Box> { std::env::set_var("PROTOC", &protoc); let proto = "../../proto/lean_tee/v1/tee.proto"; println!("cargo:rerun-if-changed={proto}"); - tonic_build::configure() + tonic_prost_build::configure() .build_client(false) .build_server(true) .compile_protos(&[proto], &["../../proto"])?; diff --git a/host/receipt/Cargo.toml b/host/receipt/Cargo.toml index 4b32dee..877ba6f 100644 --- a/host/receipt/Cargo.toml +++ b/host/receipt/Cargo.toml @@ -8,7 +8,7 @@ description = "lean-tee receipt crypto: CryptoSuites, resultHash, mock proof (An [dependencies] blake3 = "1.5" hex = "0.4" -sha2 = "0.10" +sha2 = "0.11" [dev-dependencies] serde_json = "1" From 65c60bcc8a0df1808fa9113f824ee3f01e08a475 Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 22:58:56 +0100 Subject: [PATCH 2/6] ci: retrigger checks for dependabot upgrades Co-authored-by: Cursor From 2b9caf3f4fed601680cb79d71d2f77955db00e4b Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 23:14:55 +0100 Subject: [PATCH 3/6] Refresh SP1 guest ELF digest from Linux execute CI. Co-authored-by: Cursor --- artifacts/sp1_guest_digests.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/artifacts/sp1_guest_digests.json b/artifacts/sp1_guest_digests.json index ae15a11..9bbbdb7 100644 --- a/artifacts/sp1_guest_digests.json +++ b/artifacts/sp1_guest_digests.json @@ -3,7 +3,7 @@ "profile": "lean-tee-v2", "code_id_example": "lean-tee/compliance_operator/lean-sp1/v1", "code_hash": "bec5a1b6fd790b3332da9ebdd744dbe4d58612fa9de64321298ddea05a40784f", - "elf_sha256": "23e1bf0a53cc733746c898e561fde4eeffef403f53425f1e49c62d05f524744a", + "elf_sha256": "cfaef020528620feed5e970d4828137f443a53328539b3a64483a84ad3ef3554", "elf_bytes": 2128064, "vk_hash_bytes": "49223f521ef81309217bbfb46f9820ed68a26bf52a5911801b90df8a025bd915", "vk_bytes32": "0x0092447ea47be04c250bddfda6f9820edd144d7eaa9644600dc86fc5025bd915", From 68d8a23c758dedcff554e52d21ea6487bb92c071 Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 23:29:13 +0100 Subject: [PATCH 4/6] ci: retrigger lean-mock/rust-mock after Dependabot upgrades. Co-authored-by: Cursor From 505e2ffc3cde7c202b0a1977f145da02090efc98 Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 23:42:34 +0100 Subject: [PATCH 5/6] Disable automatic SP1 smoke in CI; keep manual dispatch only. GitHub-hosted runners lack the RAM/CPU for reliable SP1 execute/prove; run scripts/sp1_execute_ci.sh locally instead. Co-authored-by: Cursor --- .github/PULL_REQUEST_TEMPLATE.md | 2 +- .github/workflows/sp1-execute.yml | 44 +++++++++---------------------- CHANGELOG.md | 1 + CONTRIBUTING.md | 2 +- docs/GUEST_PROG.md | 2 +- docs/LEAN_SP1_GUEST.md | 2 +- docs/PRODUCT.md | 2 +- docs/SLA.md | 2 +- host/README.md | 2 +- 9 files changed, 20 insertions(+), 39 deletions(-) diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index d79ff24..770b817 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -6,7 +6,7 @@ - [ ] Mock path: `bash scripts/ci.sh` (or relevant demos) when touching receipts / guests / gRPC - [ ] Rust: `cd host && cargo test -p lean_tee_receipt -p lean_tee_compliance` if host crypto/guests change -- [ ] SP1: note `sp1-execute` impact if guest/runtime/digests change +- [ ] SP1: if guest/runtime/digests change, run `scripts/sp1_execute_ci.sh` locally (CI smoke is manual-only for now) - [ ] Docs/proto updated if wire or Accept semantics change ## Checklist diff --git a/.github/workflows/sp1-execute.yml b/.github/workflows/sp1-execute.yml index 280c958..e877ed4 100644 --- a/.github/workflows/sp1-execute.yml +++ b/.github/workflows/sp1-execute.yml @@ -1,33 +1,19 @@ name: sp1-execute -# SP1 path: PR/push (path-filtered), weekly execute + digest pin check, -# weekly heavy prove on a larger runner, manual dispatch overrides. +# SP1 Lean guest smoke + digest pin. Manual only for now — GitHub-hosted +# runners do not have enough RAM/CPU for reliable execute/prove. Run locally +# (or on a suitably sized self-hosted runner) via: +# bash scripts/sp1_execute_ci.sh +# gh workflow run sp1-execute.yml -f prove_one=false -f prove_heavy=false +# Re-enable pull_request / push / schedule when adequate compute is available. on: - pull_request: - paths: &sp1_paths - - "host/guest_lean/**" - - "host/guest_lean_spike/**" - - "host/lean_sp1_runtime/**" - - "host/lean_sp1_init_min/**" - - "host/prove_server/**" - - "LeanTee/GuestSp1.lean" - - "LeanTee/GuestProg.lean" - - "scripts/sp1_*" - - "artifacts/sp1_guest_digests.json" - - ".github/workflows/sp1-execute.yml" - push: - branches: [main, lean-sp1-guest] - paths: *sp1_paths - schedule: - - cron: "17 6 * * 1" # weekly Monday 06:17 UTC — execute + digest pin - - cron: "47 7 * * 1" # weekly Monday 07:47 UTC — real CPU prove (larger runner) workflow_dispatch: inputs: prove_one: description: "Also run one prove (mock unless prove_heavy)" type: boolean - default: true + default: false prove_heavy: description: "Real CPU prove+verify of Lean ELF (needs prove_one; uses larger runner job)" type: boolean @@ -35,11 +21,7 @@ on: jobs: sp1-execute: - if: | - github.event_name == 'pull_request' || - github.event_name == 'push' || - (github.event_name == 'schedule' && github.event.schedule == '17 6 * * 1') || - (github.event_name == 'workflow_dispatch' && !inputs.prove_heavy) + if: ${{ !inputs.prove_heavy }} runs-on: ubuntu-latest timeout-minutes: 180 steps: @@ -72,8 +54,7 @@ jobs: - name: SP1 Lean guest smoke (execute + digest pin) working-directory: lean-tee env: - # PR: execute + mock prove-one. Schedule: execute-only. Manual: inputs. - SP1_PROVE_ONE: ${{ github.event_name == 'pull_request' && '1' || (github.event_name == 'workflow_dispatch' && inputs.prove_one && '1' || '0') }} + SP1_PROVE_ONE: ${{ inputs.prove_one && '1' || '0' }} SP1_PROVE_HEAVY: "0" SP1_CHECK_DIGESTS: "1" CARGO_TERM_COLOR: always @@ -86,11 +67,10 @@ jobs: if-no-files-found: error sp1-prove-heavy: - # 32 GiB RAM — enable GitHub larger runners for the org/repo if this job queues forever. + # Needs a larger runner (≈32 GiB). Skip unless org has ubuntu-latest-8-cores + # (or equivalent) enabled — otherwise this job queues forever / OOMs. runs-on: ubuntu-latest-8-cores - if: | - (github.event_name == 'schedule' && github.event.schedule == '47 7 * * 1') || - (github.event_name == 'workflow_dispatch' && inputs.prove_one && inputs.prove_heavy) + if: ${{ inputs.prove_one && inputs.prove_heavy }} timeout-minutes: 240 steps: - uses: actions/checkout@v7 diff --git a/CHANGELOG.md b/CHANGELOG.md index 8a2c459..ef08bdb 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,7 @@ ## Unreleased +- SP1 `sp1-execute` CI: disable PR/push/schedule; keep `workflow_dispatch` only (GH runners lack SP1 compute) — run `scripts/sp1_execute_ci.sh` locally - Coordinated Dependabot upgrades: tonic/tonic-prost/prost 0.14, sha2 0.11, Actions checkout/upload-artifact v7; ignore bincode majors (3.0.0 is an unmaintained stub) - Pin lean-grpc dependency to **v1.1.0** (was v1.0.0) - Mid-tier Lean SP1 guest + `sp1_lean_mid_smoke --prove` (Init-free mix/rounds; laptop-oriented) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a951b2c..325780d 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -71,7 +71,7 @@ Do not run real CPU `SP1_PROVER=cpu --prove-one` on ≤16 GiB machines without 1. Branch from `main` (or the active integration branch agreed with maintainers). 2. Ensure mock CI paths pass locally when touching receipts, guests, or gRPC. -3. If you change the Lean SP1 guest or runtime patches, run or note `sp1-execute` workflow impact. +3. If you change the Lean SP1 guest or runtime patches, run `bash scripts/sp1_execute_ci.sh` locally (and refresh `artifacts/sp1_guest_digests.json` from Linux if digests change). Automatic `sp1-execute` CI is off for now — GH runners lack the compute. 4. Describe **why** in the PR body; link issues if any. 5. Do not commit secrets, `.env` files, `host/target/`, `.cache/`, or editor junk (e.g. `.#`). diff --git a/docs/GUEST_PROG.md b/docs/GUEST_PROG.md index 06f3b28..6e2edd2 100644 --- a/docs/GUEST_PROG.md +++ b/docs/GUEST_PROG.md @@ -99,7 +99,7 @@ bash scripts/sp1_test_careful.sh bash scripts/sp1_execute_ci.sh ``` -Workflow: [`.github/workflows/sp1-execute.yml`](../.github/workflows/sp1-execute.yml) (weekly + `workflow_dispatch`). +Workflow: [`.github/workflows/sp1-execute.yml`](../.github/workflows/sp1-execute.yml) (`workflow_dispatch` only for now; prefer local `scripts/sp1_execute_ci.sh`). ## Honest claims diff --git a/docs/LEAN_SP1_GUEST.md b/docs/LEAN_SP1_GUEST.md index c378da3..0ff3d92 100644 --- a/docs/LEAN_SP1_GUEST.md +++ b/docs/LEAN_SP1_GUEST.md @@ -131,7 +131,7 @@ bash scripts/sp1_guest_digest.sh # → artifacts/sp1_guest_dige # sp1_smoke --execute-only --print-digests --write-digests artifacts/sp1_guest_digests.json ``` -CI uploads the same JSON as the `sp1-guest-digests` artifact on `sp1-execute`. Real CPU prove+verify of one Lean-ELF case is **gated** (`workflow_dispatch` → `prove_one` + `prove_heavy`). Do **not** run local `SP1_PROVER=cpu --prove-one` on ≤16 GiB hosts — it can OOM/lock the machine; scripts require ≥10 GiB free or `SP1_PROVE_HEAVY_FORCE=1`. +CI uploads the same JSON as the `sp1-guest-digests` artifact when `sp1-execute` is run manually. Automatic PR/push/schedule SP1 smoke is **off** (GH runners lack compute) — use `bash scripts/sp1_execute_ci.sh` locally. Real CPU prove+verify of one Lean-ELF case is **gated** (`workflow_dispatch` → `prove_one` + `prove_heavy`). Do **not** run local `SP1_PROVER=cpu --prove-one` on ≤16 GiB hosts — it can OOM/lock the machine; scripts require ≥10 GiB free or `SP1_PROVE_HEAVY_FORCE=1`. ### SP1 FENCE note diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md index 3a9e161..5df48e4 100644 --- a/docs/PRODUCT.md +++ b/docs/PRODUCT.md @@ -42,7 +42,7 @@ Registry file: [`config/guests/registry.json`](../config/guests/registry.json) ( | Proof | SP1 Hypercube proof commitment | Deterministic mock digest | | Suitable for | **Production integrity** | CI, demos only — **never production** | | Confidentiality | No | No | -| CI gate | Weekly + manual SP1 execute ([`sp1-execute.yml`](../.github/workflows/sp1-execute.yml)) | Push/PR mock demos | +| CI gate | SP1 smoke is **manual / local only** for now ([`sp1-execute.yml`](../.github/workflows/sp1-execute.yml) `workflow_dispatch`; GH runners lack compute) | Push/PR mock demos | `LEAN_TEE_DEFAULT_PROFILE` defaults to **`lean-tee-v2`**. Without `LEAN_TEE_PROVE_ADDR`, the server **refuses to start** unless `LEAN_TEE_ALLOW_MOCK_V2=1` (demos only). Wire SP1 `prove_server` for real v2. diff --git a/docs/SLA.md b/docs/SLA.md index d3926a9..e772af4 100644 --- a/docs/SLA.md +++ b/docs/SLA.md @@ -14,7 +14,7 @@ It does **not** mean: | Profile | Expectation | | --- | --- | -| `lean-tee-v2` (SP1) | **Production default.** Host must verify SP1 before advertising `proof_ref`. Prove latency depends on hardware (`SP1_PROVER`, CPU RAM). Gated CI: weekly SP1 execute-only. | +| `lean-tee-v2` (SP1) | **Production default.** Host must verify SP1 before advertising `proof_ref`. Prove latency depends on hardware (`SP1_PROVER`, CPU RAM). SP1 execute smoke: local / manual dispatch only (GH-hosted runners lack compute for now). | | `lean-tee-v1` (mock) | **CI/dev only.** Deterministic mock digest. Not production attestation — never the hero path. | ## Durable jobs diff --git a/host/README.md b/host/README.md index a41c5db..5dd2333 100644 --- a/host/README.md +++ b/host/README.md @@ -45,7 +45,7 @@ SP1_PROVER=mock ./target/release/sp1_smoke --prove-one 0 # SDK prove/verify path # Do NOT run SP1_PROVER=cpu --prove-one on ≤16GiB laptops (hard lock / OOM risk). ``` -GitHub Actions (`sp1-execute`): schedule = execute + digests; manual `prove_one` = mock prove; `prove_one` + `prove_heavy` = one real CPU prove (use only when the runner has headroom). +GitHub Actions (`sp1-execute`): **manual `workflow_dispatch` only** for now (GH-hosted runners lack SP1 compute). Prefer `bash scripts/sp1_execute_ci.sh` locally. Optional `prove_one` = mock prove; `prove_one` + `prove_heavy` = one real CPU prove on a larger runner. ## Prove gRPC (for Lean Tee) From 895cdfa5ff47bf62b6130ed0f64c4f72057e2371 Mon Sep 17 00:00:00 2001 From: Robert Betts Date: Thu, 6 Aug 2026 23:59:28 +0100 Subject: [PATCH 6/6] Support Linux and macOS for sealed_worker and SP1 scripts. Use platform cfg for prctl vs PT_DENY_ATTACH, and portable mem/PROTOC helpers so local smokes run on Darwin. Co-authored-by: Cursor --- CHANGELOG.md | 1 + CONTRIBUTING.md | 5 +- docs/CONFIDENTIALITY.md | 4 +- docs/GETTING_STARTED.md | 23 ++++-- host/README.md | 6 ++ host/confidential/src/bin/sealed_worker.rs | 12 +++- scripts/lib/platform.sh | 81 ++++++++++++++++++++++ scripts/sp1_execute_ci.sh | 10 +-- scripts/sp1_guest_digest.sh | 4 +- scripts/sp1_test_careful.sh | 10 +-- 10 files changed, 136 insertions(+), 20 deletions(-) create mode 100644 scripts/lib/platform.sh diff --git a/CHANGELOG.md b/CHANGELOG.md index ef08bdb..69c0903 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,7 @@ ## Unreleased +- First-class Linux + macOS: `sealed_worker` cfg-splits Linux `prctl` / macOS `PT_DENY_ATTACH`; SP1 scripts use portable mem/`PROTOC` helpers (`scripts/lib/platform.sh`) - SP1 `sp1-execute` CI: disable PR/push/schedule; keep `workflow_dispatch` only (GH runners lack SP1 compute) — run `scripts/sp1_execute_ci.sh` locally - Coordinated Dependabot upgrades: tonic/tonic-prost/prost 0.14, sha2 0.11, Actions checkout/upload-artifact v7; ignore bincode majors (3.0.0 is an unmaintained stub) - Pin lean-grpc dependency to **v1.1.0** (was v1.0.0) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 325780d..53410c9 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -6,6 +6,7 @@ By participating, you agree to follow our [Code of Conduct](CODE_OF_CONDUCT.md). ## Before you start - Read [docs/GETTING_STARTED.md](docs/GETTING_STARTED.md) for toolchain setup. +- **Supported platforms:** Linux and macOS (CI is Linux; macOS is first-class locally). - **Mock path** (`lean-tee-v1`) is the default for local iteration — no SP1 required. - **Production integrity** (`lean-tee-v2`) needs SP1; see [host/README.md](host/README.md). @@ -16,7 +17,9 @@ git clone https://github.com/RileyBetts/lean-tee.git cd lean-tee # elan installs Lean 4.32.1 from lean-toolchain curl https://raw.githubusercontent.com/leanprover/elan/master/elan-init.sh -sSf | sh -s -- -y -sudo apt-get install -y libssl-dev pkg-config # Debian/Ubuntu +# Linux: sudo apt-get install -y libssl-dev pkg-config +# macOS: brew install openssl pkg-config +# export PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" lake update # fetches lean-grpc v1.1.0 into .lake/packages lake build receiptTests teeServer teeClient diff --git a/docs/CONFIDENTIALITY.md b/docs/CONFIDENTIALITY.md index c042fd6..f490dce 100644 --- a/docs/CONFIDENTIALITY.md +++ b/docs/CONFIDENTIALITY.md @@ -39,7 +39,9 @@ bash scripts/confidentiality_local_demo.sh The `sealed_worker` process: -- Sets `RLIMIT_CORE=0` and `PR_SET_DUMPABLE=0` (harder unprivileged ptrace / core dumps) +- Sets `RLIMIT_CORE=0` on Linux and macOS (no core dumps) +- **Linux:** `PR_SET_DUMPABLE=0` (harder unprivileged ptrace / Yama) +- **macOS:** `PT_DENY_ATTACH` (best-effort anti-attach; not Yama-equivalent) - Zeroizes secret buffers after use - Never logs secret bytes - Optional `LEAN_TEE_SEALED_MLOCK=1` (`mlockall`, best-effort) diff --git a/docs/GETTING_STARTED.md b/docs/GETTING_STARTED.md index 8a12554..32ea3d1 100644 --- a/docs/GETTING_STARTED.md +++ b/docs/GETTING_STARTED.md @@ -2,12 +2,14 @@ This guide gets you from a fresh clone to a **working mock demo** in under fifteen minutes. Production SP1 integrity (`lean-tee-v2`) is covered at the end. +**Supported platforms:** Linux and macOS (CI reference is Linux; macOS is first-class for local build and smokes). + ## What you need | Tool | Version / notes | | --- | --- | | [Lean 4](https://leanprover.github.io/lean4/doc/setup.html) (elan) | **4.32.1** — pinned in [`lean-toolchain`](../lean-toolchain) | -| OpenSSL dev | `libssl-dev` + `pkg-config` (host Lake build links `-lssl`) | +| OpenSSL dev | Host Lake build links `-lssl` (see install below) | | Rust (optional) | Stable — for `host/` crates and clients | | Python 3 (optional) | Stdlib client; `pytest` for tests | | [SP1](https://docs.succinct.xyz/docs/sp1/getting-started/install) (optional) | **6.3.1** — only for `lean-tee-v2` prove path | @@ -24,7 +26,12 @@ cd lean-tee curl https://raw.githubusercontent.com/leanprover/elan/master/elan-init.sh -sSf \ | sh -s -- -y --default-toolchain leanprover/lean4:v4.32.1 -sudo apt-get install -y libssl-dev pkg-config # Debian/Ubuntu; adjust on macOS +# OpenSSL + pkg-config +# Linux (Debian/Ubuntu): +sudo apt-get install -y libssl-dev pkg-config +# macOS (Homebrew): +# brew install openssl pkg-config +# export PKG_CONFIG_PATH="$(brew --prefix openssl)/lib/pkgconfig" lake update lake build receiptTests teeServer teeClient teeLoopback @@ -70,10 +77,12 @@ assert ok, reason Mock prove is **CI/demo only**. For production integrity: -1. Install SP1: `curl -L https://sp1up.succinct.xyz | bash && sp1up && sp1up --c-toolchain` -2. Build host: `cd host && cargo build -p lean_tee_prove_server --release --features sp1` -3. Smoke: `bash scripts/sp1_execute_ci.sh` (execute + digest pin) -4. Run `prove_server` with `SP1_PROVER=cpu` and point `teeServer` at it: +1. Install SP1: `curl -L https://sp1.succinct.xyz | bash && sp1up && sp1up --c-toolchain` +2. **macOS only:** Homebrew libs for the SP1 RISC-V gcc (`cc1plus` dylibs): + `brew install isl gmp mpfr libmpc` +3. Build host: `cd host && cargo build -p lean_tee_prove_server --release --features sp1` +4. Smoke: `bash scripts/sp1_execute_ci.sh` (execute + digest pin; portable on Linux and macOS) +5. Run `prove_server` with `SP1_PROVER=cpu` and point `teeServer` at it: ```bash export LEAN_TEE_DEFAULT_PROFILE=lean-tee-v2 @@ -81,7 +90,7 @@ export LEAN_TEE_PROVE_ADDR=127.0.0.1:50072 # prove_server in one terminal; teeServer in another ``` -Pin counterparties to published digests in [`artifacts/sp1_guest_digests.json`](../artifacts/sp1_guest_digests.json). Plain-English SP1 background: [sp1-integrity-crib-sheet.html](sp1-integrity-crib-sheet.html). +Pin counterparties to published digests in [`artifacts/sp1_guest_digests.json`](../artifacts/sp1_guest_digests.json) (Linux CI is the pin source of truth; local Mac rebuilds may differ). Plain-English SP1 background: [sp1-integrity-crib-sheet.html](sp1-integrity-crib-sheet.html). Details: [host/README.md](../host/README.md), [LEAN_SP1_GUEST.md](LEAN_SP1_GUEST.md). diff --git a/host/README.md b/host/README.md index 5dd2333..b51bb57 100644 --- a/host/README.md +++ b/host/README.md @@ -2,6 +2,8 @@ Requires [SP1](https://docs.succinct.xyz/docs/sp1/getting-started/install) (`sp1up` → `cargo prove`, version **6.3.1** aligned with this workspace). +**Platforms:** Linux and macOS. Published ELF/vk digests are pinned from Linux CI; Mac rebuilds may produce different digests. + ## Layout | Crate | Role | @@ -17,7 +19,11 @@ Requires [SP1](https://docs.succinct.xyz/docs/sp1/getting-started/install) (`sp1 curl -L https://sp1.succinct.xyz | bash source ~/.bashrc # or: export PATH="$HOME/.sp1/bin:$PATH" sp1up +sp1up --c-toolchain # RISC-V gcc for Lean guest C cargo prove --version # expect sp1 ~6.3.x + +# macOS: libs expected by SP1's riscv64-unknown-elf-g++ (cc1plus) +# brew install isl gmp mpfr libmpc ``` ## Thorough SP1 test (careful / low OOM risk) diff --git a/host/confidential/src/bin/sealed_worker.rs b/host/confidential/src/bin/sealed_worker.rs index 9599953..d335c01 100644 --- a/host/confidential/src/bin/sealed_worker.rs +++ b/host/confidential/src/bin/sealed_worker.rs @@ -13,7 +13,7 @@ use std::process; use zeroize::{Zeroize, Zeroizing}; fn harden_against_weaker_agents() { - // Disable core dumps for this process. + // Disable core dumps for this process (Linux + macOS). #[cfg(unix)] unsafe { let lim = libc::rlimit { @@ -21,9 +21,17 @@ fn harden_against_weaker_agents() { rlim_max: 0, }; let _ = libc::setrlimit(libc::RLIMIT_CORE, &lim); - // Not dumpable → harder for unprivileged ptrace attach (Yama/ptrace). + } + // Not dumpable → harder for unprivileged ptrace attach (Yama/ptrace). Linux only. + #[cfg(target_os = "linux")] + unsafe { let _ = libc::prctl(libc::PR_SET_DUMPABLE, 0, 0, 0, 0); } + // Best-effort Darwin anti-attach (not equivalent to Linux PR_SET_DUMPABLE / Yama). + #[cfg(target_os = "macos")] + unsafe { + let _ = libc::ptrace(libc::PT_DENY_ATTACH, 0, std::ptr::null_mut(), 0); + } // Optional mlock of current pages (best-effort; ignore failure). if std::env::var("LEAN_TEE_SEALED_MLOCK").ok().as_deref() == Some("1") { #[cfg(unix)] diff --git a/scripts/lib/platform.sh b/scripts/lib/platform.sh new file mode 100644 index 0000000..4c8b572 --- /dev/null +++ b/scripts/lib/platform.sh @@ -0,0 +1,81 @@ +# Copyright © 2026 Riley Betts Ltd (rileybetts.ai) +# SPDX-License-Identifier: Apache-2.0 + +# Portable helpers for Linux + macOS SP1 / host scripts. +# shellcheck shell=bash + +# Print a short memory summary. Never fails under `set -e`. +print_mem_summary() { + if command -v free >/dev/null 2>&1; then + free -h | head -2 || true + elif [[ "$(uname -s)" == "Darwin" ]]; then + local pages page_size free_p inactive_p avail_kib memsize + page_size="$(pagesize 2>/dev/null || sysctl -n hw.pagesize 2>/dev/null || echo 4096)" + pages="$(vm_stat 2>/dev/null || true)" + free_p="$(printf '%s\n' "$pages" | awk '/Pages free/ {gsub(/\./,"",$3); print $3}')" + inactive_p="$(printf '%s\n' "$pages" | awk '/Pages inactive/ {gsub(/\./,"",$3); print $3}')" + free_p="${free_p:-0}" + inactive_p="${inactive_p:-0}" + avail_kib=$(( (free_p + inactive_p) * page_size / 1024 )) + memsize="$(sysctl -n hw.memsize 2>/dev/null || echo 0)" + echo "Darwin mem: hw.memsize=${memsize} approx_available_kib=${avail_kib} (free+inactive pages)" + else + echo "mem summary unavailable on $(uname -s)" + fi +} + +# Approximate available memory in KiB (nonempty integer). +# Linux: MemAvailable from /proc/meminfo. +# Darwin: (Pages free + Pages inactive) * pagesize / 1024. +mem_available_kib() { + local kib + if [[ -r /proc/meminfo ]]; then + kib="$(awk '/MemAvailable:/ {print $2}' /proc/meminfo 2>/dev/null || true)" + if [[ -n "${kib:-}" ]]; then + echo "$kib" + return 0 + fi + fi + if [[ "$(uname -s)" == "Darwin" ]]; then + local page_size free_p inactive_p pages + page_size="$(pagesize 2>/dev/null || sysctl -n hw.pagesize 2>/dev/null || echo 4096)" + pages="$(vm_stat 2>/dev/null || true)" + free_p="$(printf '%s\n' "$pages" | awk '/Pages free/ {gsub(/\./,"",$3); print $3}')" + inactive_p="$(printf '%s\n' "$pages" | awk '/Pages inactive/ {gsub(/\./,"",$3); print $3}')" + free_p="${free_p:-0}" + inactive_p="${inactive_p:-0}" + echo $(( (free_p + inactive_p) * page_size / 1024 )) + return 0 + fi + echo 0 +} + +# Resolve a protoc binary: PATH first, else cargo vendored crate by OS/arch. +default_protoc() { + if command -v protoc >/dev/null 2>&1; then + command -v protoc + return 0 + fi + local os arch tag crate_dir + case "$(uname -s)" in + Linux) os=linux ;; + Darwin) os=macos ;; + *) os=linux ;; + esac + case "$(uname -m)" in + x86_64|amd64) arch=x86_64 ;; + aarch64|arm64) arch=aarch_64 ;; + *) arch=x86_64 ;; + esac + tag="${os}-${arch}" + crate_dir="$( + ls -d "${HOME}/.cargo/registry/src"/index.crates.io-*/protoc-bin-vendored-"${tag}"-* 2>/dev/null \ + | sort -V | tail -1 || true + )" + if [[ -n "${crate_dir}" && -x "${crate_dir}/bin/protoc" ]]; then + echo "${crate_dir}/bin/protoc" + return 0 + fi + # Last resort: historical linux x86_64 pin (CI). + echo "${HOME}/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/protoc-bin-vendored-linux-x86_64-3.2.0/bin/protoc" +} diff --git a/scripts/sp1_execute_ci.sh b/scripts/sp1_execute_ci.sh index 743c307..041d6be 100755 --- a/scripts/sp1_execute_ci.sh +++ b/scripts/sp1_execute_ci.sh @@ -6,10 +6,12 @@ # Measured guest is Lean-compiled (`lean_tee_guest_lean`). set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" +# shellcheck source=lib/platform.sh +source "$ROOT/scripts/lib/platform.sh" export PATH="${HOME}/.elan/bin:${HOME}/.sp1/bin:${HOME}/.sp1/riscv/bin:${PATH}" export CARGO_TARGET_DIR="${CARGO_TARGET_DIR:-$ROOT/host/target}" export SP1_PROVER="${SP1_PROVER:-cpu}" -export PROTOC="${PROTOC:-$HOME/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/protoc-bin-vendored-linux-x86_64-3.2.0/bin/protoc}" +export PROTOC="${PROTOC:-$(default_protoc)}" export CC_riscv64im_succinct_zkvm_elf="${CC_riscv64im_succinct_zkvm_elf:-$HOME/.sp1/riscv/bin/riscv64-unknown-elf-gcc}" if ! command -v cargo-prove >/dev/null 2>&1; then @@ -30,7 +32,7 @@ if [[ ! -d "$ROOT/.lake/packages/lean-grpc" && ! -d "$ROOT/../lean-grpc" ]]; the lake update fi echo "== free memory ==" -free -h | head -2 +print_mem_summary echo "== Lean SP1 runtime + guest archive ==" bash scripts/sp1_lean_runtime_fetch.sh @@ -63,9 +65,9 @@ if [[ "${SP1_PROVE_ONE:-}" == "1" ]]; then if [[ "${SP1_PROVE_HEAVY:-}" == "1" ]]; then # Real CPU prove of the Lean ELF routinely needs >>8 GiB free; on 16 GiB # laptops this has hard-locked the machine. Abort unless explicitly forced. - avail_kib="$(awk '/MemAvailable:/ {print $2}' /proc/meminfo 2>/dev/null || echo 0)" + avail_kib="$(mem_available_kib)" need_kib=$((10 * 1024 * 1024)) # 10 GiB - free -h | head -2 + print_mem_summary if [[ "${SP1_PROVE_HEAVY_FORCE:-}" != "1" && "${GITHUB_ACTIONS:-}" != "true" && "${avail_kib}" -lt "${need_kib}" ]]; then echo "SP1_PROVE_HEAVY refused: MemAvailable=${avail_kib} KiB (<10 GiB)." >&2 echo "Use Actions prove_heavy / a larger machine, or SP1_PROVE_HEAVY_FORCE=1 (OOM/lockup risk)." >&2 diff --git a/scripts/sp1_guest_digest.sh b/scripts/sp1_guest_digest.sh index a48cd00..5a73b0f 100755 --- a/scripts/sp1_guest_digest.sh +++ b/scripts/sp1_guest_digest.sh @@ -6,11 +6,13 @@ # Wire Measurement stays codeHash+configHash; these digests pin the executable. set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" +# shellcheck source=lib/platform.sh +source "$ROOT/scripts/lib/platform.sh" OUT="${1:-$ROOT/artifacts/sp1_guest_digests.json}" export PATH="${HOME}/.elan/bin:${HOME}/.sp1/bin:${HOME}/.sp1/riscv/bin:${PATH}" export CARGO_TARGET_DIR="${CARGO_TARGET_DIR:-$ROOT/host/target}" export SP1_PROVER="${SP1_PROVER:-cpu}" -export PROTOC="${PROTOC:-$HOME/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/protoc-bin-vendored-linux-x86_64-3.2.0/bin/protoc}" +export PROTOC="${PROTOC:-$(default_protoc)}" export CC_riscv64im_succinct_zkvm_elf="${CC_riscv64im_succinct_zkvm_elf:-$HOME/.sp1/riscv/bin/riscv64-unknown-elf-gcc}" if ! command -v cargo-prove >/dev/null 2>&1; then diff --git a/scripts/sp1_test_careful.sh b/scripts/sp1_test_careful.sh index f832a78..650c2e5 100755 --- a/scripts/sp1_test_careful.sh +++ b/scripts/sp1_test_careful.sh @@ -5,10 +5,12 @@ # Staged SP1 tests — avoids proving three cases back-to-back (OOM risk on 16GB). set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" +# shellcheck source=lib/platform.sh +source "$ROOT/scripts/lib/platform.sh" export PATH="${HOME}/.sp1/bin:${PATH}" export CARGO_TARGET_DIR="${CARGO_TARGET_DIR:-$ROOT/host/target}" export SP1_PROVER="${SP1_PROVER:-cpu}" -export PROTOC="${PROTOC:-$HOME/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/protoc-bin-vendored-linux-x86_64-3.2.0/bin/protoc}" +export PROTOC="${PROTOC:-$(default_protoc)}" if ! command -v cargo-prove >/dev/null 2>&1; then echo "cargo-prove not on PATH; run: source ~/.bashrc && sp1up" >&2 @@ -18,7 +20,7 @@ fi cd "$ROOT/host" echo "== free memory ==" -free -h | head -2 +print_mem_summary echo "== Lean SP1 runtime + guest archive ==" cd "$ROOT" @@ -37,9 +39,9 @@ echo "== SP1 prove+verify one case (default: mock — safe on 16GB laptops) ==" echo " Real CPU prove is gated (can hard-lock ≤16GB hosts)." echo " Prefer GitHub Actions prove_heavy, or: SP1_PROVE_HEAVY=1 SP1_PROVE_HEAVY_FORCE=1 $0" if [[ "${SP1_PROVE_HEAVY:-}" == "1" ]]; then - avail_kib="$(awk '/MemAvailable:/ {print $2}' /proc/meminfo 2>/dev/null || echo 0)" + avail_kib="$(mem_available_kib)" need_kib=$((10 * 1024 * 1024)) - free -h | head -2 + print_mem_summary if [[ "${SP1_PROVE_HEAVY_FORCE:-}" != "1" && "${GITHUB_ACTIONS:-}" != "true" && "${avail_kib}" -lt "${need_kib}" ]]; then echo "SP1_PROVE_HEAVY refused: MemAvailable=${avail_kib} KiB (<10 GiB)." >&2 echo "Do not force on a laptop you care about; use CI prove_heavy / a big machine." >&2