Skip to content

chore(ci): publish circom-generated witness generator sources with releases - #58

Open
davidrusu wants to merge 1 commit into
mainfrom
ci/publish-witness-sources
Open

davidrusu wants to merge 1 commit into
mainfrom
ci/publish-witness-sources

Conversation

@davidrusu

Copy link
Copy Markdown
Contributor

Why

Witness-generation failures only report a line in the generated C++, e.g.
Circuit constraint violated in poq.cpp:52038: Fr_isTrue(&expaux[0]). The release tarballs ship poq/libpoq.a and friends but not the generated poq.cpp. To map that line back to the circom source you have to regenerate the C++ with the exact circom version CI used (CIRCOM_TAG, v2.2.2) and the same flags (--c --r1cs --no_asm --O2). We just had to do this by hand: line 52038 of v0.5.7's poq.cpp is the assert for blend/poq.circom:134 (the "selected role is correct" constraint). With the generated sources in the release, that lookup takes seconds.

What

  • compile-witness-generator action: new optional upload-sources input (default "false"). When it is set, the action uploads the {circuit}_cpp/ directory as a {circuit}-{version}-witness-sources artifact. The upload runs after the main.cpp return patch, the CalcWit leak patch, the FFI file copy and the Makefile replacement, and before any OS-specific patching or compilation, so it contains exactly the sources CI compiles. It leaves out the .dat, which already ships in every platform bundle as witness_generator.dat.
  • build-linux (x86_64): sets upload-sources: "true" for all four circuits. It then bundles them into logos-blockchain-circuits-{version}-witness-sources.tar.gz, which holds {pol,poq,signature,poc}_cpp/, VERSION and CIRCOM_VERSION. This also runs on PRs, so CI checks the packaging.
  • New upload-witness-sources job, gated the same way as upload-artifacts (tags or workflow_dispatch): it attaches the tarball to the draft release.
  • docs/build-pipeline.md: a short note on the new asset.

Why a separate asset

The generated C++ does not depend on the target, so we publish it once instead of copying it into all four per-platform tarballs. This also leaves the per-platform bundle layout and contents unchanged. rust/logos-blockchain-circuits-build downloads and unpacks those bundles, and circuits-nix-hashes.json pins their hashes, so neither is affected.

Testing

  • actionlint passes on ci.yml.
  • The packaging steps will run on this PR's CI. The release upload job only runs on tags or workflow_dispatch, so this PR does not exercise it end to end.

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant