docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-josh 2026-10-05 08:45:45 +01:00
parent c8b7852efd
commit 3763da77c4

View file

@ -0,0 +1,19 @@
# Release 0.3.6: what the proving activation taught us
Written 5 October 2026, 08:45 BST, while proving v0 went live on the devnet at DAA 84,100.
## Must ship in 0.3.6
| Item | Why | Where |
|---|---|---|
| The app sets `IGNEUM_PROOF_VERIFIER` for its node | On 5 October no node on the network ran a verifier (`verifier: Off` on every app node and the seed). Spec 7.7 item 4: a producer without a verifier never includes a record, so proofs were stored and never paid. The Mac app was relaunched by hand with the variable; Windows apps cannot be. | `app/igneum-app/src/engine.rs` node spawn: Mac and Linux point at the shipped `igneum-prove-host`; Windows points at a small wrapper exe that runs the WSL host (`wsl -d Ubuntu-24.04 -- /opt/igneum/igneum-prove-host --mode verify ...` with `wslpath` for the proof file). Until the wrapper exists, devnet Windows nodes run `IGNEUM_PROOF_VERIFY=trust` (devnet only, never testnet). |
| Windows payload ships `wsl2/bin/igneum-prove-host` and `igneum-prove-export` | The app's probe looks there first; today a PC needs the 20-minute WSL setup or a hand-installed `/opt/igneum`. The Linux binaries come from `infra/cross/build-linux.sh` (CUDA feature needs the CUDA toolchain in the cross image, else ship the CPU build and let setup-wsl.sh build the CUDA one). | `packaging/windows/make-payload.sh`, `Igneum-Miner.iss` |
| The proving tile shows the verifier state | A node that relays but never includes should say so on the tile and on `/live`. | `app/igneum-app/src/state.rs`, `site/api/live.mjs` (`verifier` is already in the observer report) |
| Rotation phase 2 | Branch `rotation-2` (5317305): `--dl-both`, `tools/logs.mjs --rotation`, fresh-repo script. Plan: `docs/plans/rotation-phase-2.md`. | |
| Testnet parameters behind `fees_v1_activation_daa` | Branch `testnet-prep` and the fork's `testnet-params` (agent in progress). | |
## Operational lessons from the activation (5 October 2026)
- Consensus override changes must land on every node at once: a hand node restarted early with a different `proving_v0_activation_daa` was refused by every peer (digest handshake) and sat isolated at a lower height for 20 minutes. Order that works: publish the manifest override, `update-now` to every app, wait for every app node to log the new parameters, then restart the hand nodes and the seed with the same file.
- `scratchpad/restart-hand-nodes.sh` died silently after `igneumd --version` (the 0.3.5 binary exits 1 after printing) under `set -e`; the restart it reported never happened. Every restart script ends by printing the new pids and their start times.
- Switching proving on needs no app restart: `POST <app.url>/api/prove {"on":true}` (the job `prove-on-pc2-84100` does this after installing the CUDA host into `/opt/igneum` for the app's WSL user).