# Release Notes

> Apogee VM v1.0.0, the first release. What it proves, what it ships, how it was measured and checked, and its known limits.

## v1.0.0

The first release of Apogee VM: a RISC-V zkVM that proves RV32IMAC programs and settles their proofs on Ethereum. The specification this site reproduces is the repository's `docs/` at source revision `3571370`.

### What it proves

That a program, named by a digest of its image, ran on a public input to an exit status and wrote a journal, carried through a recursion tree to one Groth16 proof that `ApogeeVerifier.sol` checks. Proofs are succinct, not zero-knowledge.

### What ships

- **The machine.** RV32IMAC on one hart; the 59 instructions of RV32IMA with compressed instructions expanded at load; a guest SDK with three memory regions for input, advice and output.
- **The proof system.** 23 circuit families over BN254's scalar field, each a layered GKR circuit: seven instruction families, five memory-window families, six delegations and five recursion families. One read/write memory multiset over the whole execution; LogUp lookups over five channels.
- **Delegations.** `KECCAK_F`, `SHA256_COMP`, `POSEIDON2`, `FR_ARITH`, `MOD_MUL` and `EC_ADD`, reached from the SDK and from patched `k256`, `ark-ff` and `revm-precompile`.
- **Commitments.** Mercury over KZG on the PSE perpetual powers of tau, one 704-byte opening per shard; deferred verification for recursion.
- **The prover.** A two-pass streaming prover whose memory follows the shards in flight.
- **Settlement.** A recursion tree of leaf and node programs in a recursion format with field memory and four coprocessors; a Groth16 decider with bound wires and a two-phase ceremony; `ApogeeVerifier.sol`.
- **The Ethereum workload.** A revm guest with a mini-block binary and a stateless validator for Osaka, BPO1, BPO2 and Amsterdam.
- **Tools.** `bench`, the cycle profiler, the prover's debug log, `checker`, `artifact-dump`, the `verifier` CLI, `kat-gen`, and two reference oracles.
- **No outside cryptography.** Fields, curve, pairing, MSM, hash, PCS, GKR and Groth16 are implemented in the repository.

### Measured

Block 257,510 of `glamsterdam-devnet-8` (60 transactions, 101.5 Mgas, 198M cycles): a base proof of 207 shards in 2,481 s on 32 vCPUs with a 174 GiB peak; a recursion tree of 116 shards; a decider proof in 18.5 s; on-chain verification for 3,620,026 gas. All 67,251 `tests-zkevm` v21.0.1 pairs match natively. [Performance](https://apogee.gweb3networks.com/docs/architecture/performance) has every figure.

### Known limits

Not zero-knowledge; advice unbound by design; at most 16,380 bytes each of public input and journal; `sc.w` always succeeds; traps are not provable; a fixed set of six base delegations; prover memory set by the shards in flight; the decider key per root shape and only as trustworthy as its ceremony. [The security model](https://apogee.gweb3networks.com/docs/architecture/security#limits) lists every limit with its reason.

### Documentation

This site, in English, French (Canada), Simplified Chinese and German, with the normative specification in English in every language. The [AI Companion](https://apogee.gweb3networks.com/docs/launch/ai-companion) and [`llms.txt`](/llms.txt) serve AI agents.
