Skip to content

Mirror the powers-of-tau file into our own bucket - #125

Merged
zjma merged 1 commit into
mainfrom
zjma/fix-ptau-mirror
Sep 3, 2026
Merged

zjma merged 1 commit into
mainfrom
zjma/fix-ptau-mirror

Conversation

@zjma

@zjma zjma commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Problem

task.sh setup procure-testing-setup downloads powersOfTau28_hez_final_21.ptau from the Polygon zkEVM public GCS bucket. That bucket revoked anonymous access on 2026-09-02, so the download now fails:

AccessDenied: Anonymous caller does not have storage.objects.get access to
//storage.googleapis.com/projects/_/buckets/zkevm/objects/ptau/powersOfTau28_hez_final_21.ptau

Every other public Hermez mirror I could find (hermez S3 eu-west-1, PSE pse-trusted-setup-ppot) returns 403 as well — this looks like the public hosting for these files was withdrawn wholesale.

This took out the internal-ops [Keyless] e2e tests workflow, which has failed every 4-hourly run since 2026-09-02 20:00 UTC (last green: 16:00 UTC, whose log shows the ptau download still succeeding at 16:05).

Fix

Mirror the file into gs://aptos-circuit-testing-setups and try it first, keeping upstream as a fallback in case it comes back.

That bucket was chosen because it is already anonymously readable — the CI job that needs this file has no GCP credentials at all, so the mirror has to be fetchable unauthenticated. It is also already this repo's setup-cache bucket (setups/cache.py), so the file sits with related assets rather than in new infrastructure.

The PTAU_CHECKSUM verification is unchanged and still runs regardless of which source served the file.

Verification

The mirrored object was verified end-to-end, unauthenticated, through the exact urllib path this code uses:

HTTP 200
bytes: 2416002200 (expect 2416002200)
got  : cdc7c94a6635bc91466d8c7d96faefe1d17ecc98a3596a748ca1e6c895f8c2b4
want : cdc7c94a6635bc91466d8c7d96faefe1d17ecc98a3596a748ca1e6c895f8c2b4
RESULT: MATCH

The source file came from our own circuit-v4.0.0-ph2-ceremony S3 bucket (pot/phase_1.ptau, uploaded by the ceremony script, min_power = 21). It matches both independently recorded expected values: the PTAU_CHECKSUM sha256 here, and EXPECTED_B2SUMS[21] in internal-ops scripts/keyless/utils.py.

The fallback logic itself was unit-tested for three cases — mirror up (upstream never touched), mirror down/upstream up (falls through), both down (clean exit(2) instead of an unhandled traceback).

Not verified locally: the full keyless e2e suite, which needs a complete aptos-core + circuit build. That runs in the internal-ops workflow.

Related

aptos-labs/internal-ops has a companion PR fixing the same dead URL in start_ceremony_with_p0tion.py.

🤖 Generated with Claude Code

The testing setup downloads powersOfTau28_hez_final_21.ptau from the Polygon
zkEVM public GCS bucket. That bucket revoked anonymous access on 2026-09-02,
and every other public Hermez mirror (hermez S3, PSE) now returns 403 as well,
so `task.sh setup procure-testing-setup` fails outright with

    HTTPError: HTTP Error 403: Forbidden

This broke the internal-ops "[Keyless] e2e tests" workflow, which has failed
every 4-hourly run since 2026-09-02 20:00 UTC.

Mirror the file into gs://aptos-circuit-testing-setups (the bucket this repo
already uses as its setup cache, and which is anonymously readable, so CI needs
no credentials) and try it first, keeping upstream as a fallback in case it
comes back. Verified end-to-end: an unauthenticated urllib download of the
mirrored URL returns all 2416002200 bytes and matches PTAU_CHECKSUM.

Also fail with a clear message rather than an unhandled HTTPError traceback
when no source works.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@alinush
alinush self-requested a review September 3, 2026 17:25
@zjma
zjma merged commit dc10a06 into main Sep 3, 2026
6 of 7 checks passed
@zjma
zjma deleted the zjma/fix-ptau-mirror branch September 3, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants