release rules file (the standing rules as main set them, the kept-datadir gate as rule 4); the 0.3.20 plan's row for main's three additions
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
7d1dedd818
commit
3f106ae626
2 changed files with 19 additions and 0 deletions
|
|
@ -393,3 +393,5 @@ Speculative builds on the candidate from the ship worktree, box only, sequential
|
|||
**N13, the kept-datadir death (the fleet, starting 6a3432a3 on pool-1's kept 0.3.17 copy):** `called Result::unwrap() on an Err value: DeserializationError(Io(Kind(UnexpectedEof)))` at consensus/src/model/stores/virtual_state.rs:250. Cause: 10db4b61 (0.3.16 feature line, vote-or-burn and the signing bonus) added `silent: bool` to `BlockRewardData` under `#[serde(default)]`; bincode is not self-describing and ignores serde defaults, so the virtual-state row a 0.3.17 node wrote (three-field rewards in `mergeset_rewards`) reads short on every build from 10db4b61 on: dc141409, 8097d600, 6b94c823, 6a3432a3, 09124180 all die at start on any kept 0.3.17 datadir; no canary saw it because every canary wiped. Fix b7cc37e7: the store reads the live row in the current layout first; on a deserialization error it decodes the row as a mirror of the v1 layout, converts with `silent` false and rewrites it under the same key in the current layout; version suffix unchanged. Test green on build-2 (a v1 row in a temp DB: the current layout reads it short, the store reads and rewrites it, a second open reads first-try) plus the kaspad check.
|
||||
|
||||
**The pin rule now:** candidate b7cc37e7 (8097d600 → 6b94c823 → 6a3432a3 → 09124180 → b7cc37e7), igneum-pow 8c728ca3. No fallback commit on the line (6b94c823 dies on a kept datadir); if b7cc37e7's gates are not green by 15:30 BST, 5899f603 stays live and 0.3.20 ships later on green. New gate before the canary, whatever the pin: the kept-datadir start, the pinned binary on a copy of a standing 0.3.17 box's datadir on a scratch pod, the rewrite line as the pass (the fleet). The node lane's clock: b7cc37e7's build about 14:45 BST, the kept-datadir read about 14:50, digest and ten-minute gates about 15:05, the 12 GB claim line about 14:50 to 15:00 on the 6a3432a3 pod (claim code unchanged). The build-server lane's a/b pairs are void and rebuild on b7cc37e7; the shipper's speculative builds on 6a3432a3 stopped by pid (script 30520 and its child) and restart on b7cc37e7; the vendor worktree now at b7cc37e7. Also: the amended v4 packs were stale in the app tree (igneum-pow's recheck tests read the old program id c120d7963abdcd96 from program.json); proto-cuda/packs-ca3-v4 taken from 8c728ca3 as its own commit; tests rerunning on the box.
|
||||
|
||||
**Main (13:1x BST):** the fallback reading stands (b7cc37e7 by 15:30 BST or 5899f603 stays live and 0.3.20 ships later today on green). Three additions: (1) standing rule, every canary runs a wiped and a kept datadir, the kept-datadir start a named gate in every release, in docs/plans/release-rules.md (rule 4) and the miner-reliability register as its own fault class (asked of the reliability lane); (2) the Windows shape: the pinned Windows node once against a copy of PC 2's datadir (PC 2 only) before PC 1 gets the build (asked of the build-server lane, with the pairs moved to b7cc37e7); (3) the 16:00 report stands, but on green earlier the publish goes out on green with the clock time. The fleet has the rule and runs the kept start on the pod copy, then the wipe canary on c18-1, then the kept read on c18-1 before its restart step.
|
||||
|
|
|
|||
17
docs/plans/release-rules.md
Normal file
17
docs/plans/release-rules.md
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
# Release rules (the shipper's standing rules, as main set them)
|
||||
|
||||
Every cut of the Igneum Miner app and its node runs under these. The dated plan for each cut (docs/plans/release-<version>.md) records how each rule was met.
|
||||
|
||||
1. **Versions are three-part.** A hotfix takes the next number; the feature tree moves up. The app's parser returns None on a fourth part.
|
||||
2. **Nothing is staged in the live downloads folder.** Stage in a scratch copy with `IGNEUM_DLSITE=<copy> publish-manifest.sh --no-deploy`; the live folder changes only in the deploy step. `publish-jobs.sh --deploy` is jobs-only. No lane removes a scratch directory it did not create.
|
||||
3. **The deploy gate is a full canary on the fleet's pods:** the fresh join through the headers proof on a WIPED datadir (decisive), synced, ten minutes mining, the hub holding a block, the relay and poison cases. Main may call the deploy on the decisive read plus a diff argument.
|
||||
4. **The kept-datadir start is a named gate in every release (main, 7 October 2026, after ledger N13).** Every canary runs both a wiped datadir and a KEPT one: a copy of a standing box's datadir from the live release, the pinned binary started on the copy on a scratch pod, "synced" or the store's rewrite line as the pass. The Windows shape too: the pinned Windows node once against a copy of PC 2's datadir (PC 2 only, never PC 1) before PC 1 gets the build. The miner-reliability register carries it as its own fault class. Why: every node build from 10db4b61 died at start on a kept 0.3.17 datadir (bincode ignores serde defaults) and no canary saw it because every canary wiped.
|
||||
5. **Rollout is one box at a time:** read back, a lock line from the hub between boxes; hold if the frozen table's signed share reads under 75. Miners first; the hands and the seed LAST, by the build-server lane on the shipper's line. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK).
|
||||
6. **Read-back is by commit string plus digest plus engine:** on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees `strings igneumd | grep -c igneum-pow/src/` above zero. The miner embeds no commit string; its pairing is the build line and the sha.
|
||||
7. **igneum-pow pairing:** a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file).
|
||||
8. **glibc classes:** HiveOS 2.31 (`--ship hive`, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (`--ship seed`), fleet 24.04 boxes native 2.39.
|
||||
9. **The Mac builds only the macOS binaries and the DMG,** one at a time under the build lock; every other build, suite and the Windows cross-build runs on the box or a PC; the app gate is `build-remote.sh -- test --release` from the crate dir.
|
||||
10. **A pin is green on its own suites and gates.** Lines taken on one binary carry to another only when the code is byte-identical, stated in the tip. No known-red pins: a stale test takes a test-only commit on top.
|
||||
11. **Kill by pid, never by name,** on the shared Mac; a merge worktree never checks out master.
|
||||
12. **The Discord card only when every platform is live.** Live manifest changes beyond the binaries (a moved consensus floor) go out only on the project lead's explicit word, staged beside the release with their digest and a one-line diff.
|
||||
13. **Ship on green:** no calendar waits; when the gates are green, publish and state the clock time (UK). Checkpoints are for slips, not for waiting.
|
||||
Loading…
Reference in a new issue