Four real kernels go through the RISC Zero pipeline. The prover runs on the operator's machine with one GPU, away from every live surface. The output is a 256-byte Groth16 seal that anyone can check on their own device in milliseconds with no network.
Follow four real kernels through the RISC Zero pipeline, from counting cycles to a 256-byte seal you can check offline, and see what that seal does and does not prove.
| Step | What happens | Where |
|---|---|---|
| 1 Kernel | The JavaScript kernel source is hashed. That SHA-256 is the kernel digest published in the Graph Index. | Public repo |
| 2 Vectors | Fixture vectors supply the policy parameters. The cycle cost is the maximum across all of them. | Public repo |
| 3 Preflight | runq-cpu exec runs the guest without proving and reports cycles. No GPU and no lock. The 30 million line splits FAST from SLOW. | Proving machine |
| 4 Queue | The GPU is a singleton with a file lock. One prove at a time, and none may start in quiet hours (22:00 to 07:00 ET). | Proving machine |
| 5 Guest | One universal RV32IM guest embeds QuickJS. It takes the kernel source and inputs, runs them and commits a journal: kernel digest, output and version. | Proving machine |
| 6 GPU | Execution is cut into segments of 2^po2 cycles and the RTX 3080 proves each one with CUDA. Peak memory is per segment, so a long job needs time and the same card. | Proving machine |
| 7 Recursion | Segment receipts are lifted and joined pairwise into one succinct STARK receipt, which is verified and archived. | Proving machine |
| 8 Groth16 | A Docker step wraps the STARK into a Groth16 proof on BN254: 256 bytes, about 252 seconds per kernel. | Proving machine |
| 9 Publish | The receipt is attached at audit_signature.compute_proof. It sits outside the hash, so the execution_hash never changes. | Public repo |
| 10 Verify | verifySeal rebuilds the claim from the ImageID and the journal and runs one pairing check. Zero dependencies, offline, milliseconds. | Your device |
A valid seal says the published guest, running source whose SHA-256 is the kernel digest, produced exactly this output. A verifier checks it without re-running the kernel and without seeing the inputs.
The seal does not bind the policy parameters shown next to it. Checking that those inputs match yours stays your step. The guest source is not yet public, so the ImageID's reproducibility is the operator's statement until a third party rebuilds it.
Proving never runs in a browser, the Cloudflare Worker or CI (SPEC.md §18.2). The live surfaces only verify.
Kernel names, kernel digests and the ImageID prefix come from chaingraph.json. Cycle counts and prove times are measured values from the zkVM compute-integrity explainer and the prove runbook: art-124 policy core 2.12 M cycles and about 26 s, art-09 8.9 M cycles and about 62 s at po2 18, rca-01 1.56 G cycles and about 2.4 h at po2 19, a faithful URL parser 5.4 G cycles. Per-vector splits, segment counts and seal bytes shown here are illustrative, and the animation compresses time.