Repository navigation
feat: multi-GPU proving - #1403
Merged
Merged
Conversation
hero78119
marked this pull request as draft
September 4, 2026 08:43
hero78119
marked this pull request as ready for review
September 8, 2026 12:32
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Ceno used process-global CUDA state and could prove base shards and recursion on only one device. Device ownership, memory validation, replay assignment, failure propagation, and base-to-recursion GPU reuse were implicit.
Design Rationale
Each selected GPU owns its HAL, CUDA context, stream bindings, AOT replay state, and base prover. Round-robin ownership (
shard_id % device_count) is deterministic: owned shards retain compact witnesses, while unowned shards fast-flight through canonical execution and replay-digest updates without compact witness arenas. Depth-one queues bound memory and apply backpressure.The collector accepts out-of-order results, validates ownership and completeness, restores canonical shard order, and runs one full-trace Rust verification. Failures cancel all workers without cross-device retry.
Recursion V2 uses an event-driven DAG over the same GPU set. Consecutive base proofs immediately unlock leaf tasks; completed nodes notify eligible parents through a blocking scheduler. Leaf work is prioritized, followed by the deepest ready intermediate layer and root. A GPU joins recursion only after its base state is dropped, synchronized, and trimmed.
Shard-independent exact-VK recursion assets are built once and overlapped with AOT/base work. Shard count later binds the lightweight recursion plan and constructs only additional required depths. Recursion may run speculatively, but root publication remains gated on canonical base verification and the root proof is independently verified.
Change Highlights
gkr_iop: worker-owned HALs with scoped context and stream bindings.ceno_emul: canonical AOT replay with owned compact capture and unowned fast flight.ceno_zkvm: device discovery, validation, conservative shared shard limits, round-robin replay/proving, bounded collection, fail-first diagnostics, and base-to-recursion release events.ceno_recursion_v2: exact-VK host-asset templates, deterministic recursion DAG, blocking multi-worker scheduling, device-local hydration, and streaming root completion.Benchmark / Performance Impact
Workload: Reth block
23817600, chain ID 1, 11 shards,max_cell_per_shard=4500000000, lanes 4, cache level 1, jagged reshape height 23, and a 3048 MiB booking margin. Both comparisons ran serially on the same dual-RTX-4090 self-hosted runner; only the selected device list differs.One GPU (
--gpu-devices 0)The raw proof timer is not an equivalent comparison: the baseline built exact-VK recursion assets for 3.318532 s outside that timer. The latest path starts the 6.229 s host-template build during setup and fully overlaps it (
template_wait_ms=0,bind_ms=0), so the setup-normalized and full-lifecycle rows are the fair comparisons. The raw recursion worker is slower because it performs four legal post-trim device hydrations (425 ms total), but streaming overlaps 1.163 s with base proving and reduces the exposed recursion tail by 0.552 s.Two GPUs (
--gpu-devices 0,1)GPU 0 proves even shards and GPU 1 proves odd shards. All 11 proof-queue waits are zero, so replay produces every next owned shard before its current proof finishes. Unowned shards use fast-flight replay with zero compact rows/bytes. Streaming recursion schedules the six-task 4/4 DAG as dependencies become ready: GPU 0 executes four tasks and GPU 1 executes two leaf tasks. This overlaps 2.281 s of recursion with base proving and cuts the exposed recursion tail by 3.353 s. The remaining base-vector slowdown comes from duplicated replay/resource contention, six-even/five-odd round-robin imbalance, and run variance; it does not erase the E2E improvement.
Latest one GPU vs. two GPUs
The same-revision two-GPU run therefore improves proof wall by 37.40%, rather than the ideal 50%. The gap is expected from duplicated replay, non-shard serial work and verification, six-versus-five round-robin imbalance, and GPU/host resource contention. The zero queue waits show that replay is not starving either prover after its first owned shard.
Correctness and evidence
0,2,4,6,8,10; GPU 1 owns1,3,5,7,9.c08df94610ba7e74c27c97019cb572d834f096bb, benchmark038f4e97f68c423691ddcdc14ca236dba71534a2, ceno-gpudceb5e7e04dddf7f49ac0c7ffb2ef8cf91c536d3,CUDA_ARCH=89,120(RTX 4090 loads SASS 89).Raw logs:
Testing
Risks and Rollout
Follow-ups (optional)
Copilot Reviewer Directive (keep this section)
When Copilot reviews this PR, apply
.github/copilot-instructions.mdstrictly.