Merge remote-tracking branch 'box/master' into live-22

# Conflicts:
#	docs/plans/release-0.3.21.md
This commit is contained in:
igneum-labs 2026-10-07 18:41:19 +00:00
commit 46334354f5
25 changed files with 720 additions and 50 deletions

View file

@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
| 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet |
| 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet |
| 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/funding.md` (the three lots) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the three cryptanalysis lots are the next test |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word |
| 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet |
| 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet |
| 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet |

View file

@ -20,7 +20,7 @@ The chip model. We price the strongest chip we can design against an RTX 5090 an
| When a stored-dataset chip pays for itself | at about USD 100 M of market cap in the first two years, not before | modelled, 7 October 2026 |
| The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class) | 5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x) | modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state |
What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is not ours: the cryptanalysis plan buys three external lots against the mixer, the chained cache and the acceptance rule.
What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.
## 3. The miner page's line
@ -30,4 +30,4 @@ Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 35
| # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification |
|---|---|---|---|---|---|---|---|
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/funding.md` (the three lots) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the three cryptanalysis lots are the next test |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word |

File diff suppressed because one or more lines are too long

View file

@ -51,6 +51,20 @@ sha256 279b1b690e854fc9, the string read back, pairing 8c728ca3 at byte 5. The d
**scene-parity-21 in (14:5x BST), ahead of ui-overlap-fixes-21 in the order because it was green on the exact tip (50ffa562) while ui-overlap-fixes still rebases:** 20c9153b (0d75bc1f the shared scene/ folder and live-dag.js 2.0.3, c1334faf the app side, 20c9153b the parity harness and its gate line). Lines: build-2 app gate 228 + 32 + 8; UI 72; pre-push 56 with four new chain-scene checks (sync byte-equal, the paint-on-push known-failed test, the feed contract, the parity render on build-2: home fold = /live = app Inspect at T+0, +2, +4 s). live-dag.js 2.0.2 → 2.0.3 (paint on every push whatever the visibility, the blank /live fix; the phone rule on the viewport width); proof-core.js unchanged 2.0.0; the site's copies moved on master f7743534 (igneum.network/live-dag.js reads 2.0.3); the source is scene/live-dag.js, both copies written by `node tools/scene/sync.mjs`, the gate refuses drift, so the 0.3.21 pack carries the 2.0.3 bytes. Users see: the light theme's ember at the brand package's #D0420D, the chain feed asking 300 s, Inspect 420 px tall (seven lanes), the phone layout no longer frozen at launch width, api/live keeping the key id in `miner`. Captures: build-2 /srv/builds/scene-parity/igneum-wt-scene-parity/_out and scratchpad/scene/parity-out.
**scene-parity-21-sizing in (15:0x BST):** 7e15bf2f on 3dc0832a: live-dag.js 2.0.4 (the box's height follows the lanes through onSize and autoHeight, for /live; the app passes neither, its frames byte-identical, the parity test equal on every comparison); scene/, site/ and the app copy byte-equal; no Rust change, the app gate of 20c9153b stands; pre-push 56 green. The same 2.0.4 is on master at b9017422 and served by igneum.network.
**pool-finish-21 in (15:0x BST):** 2eea335f (the ten pool commits rebased onto 3dc0832a, no conflict; the pool-fee sentence in site/miner.html). Lines at that tip on build-2: igneum-pool 28; the app gate 229 + 32 + 8. Merged after scene-parity-21-sizing (JS only, so the Rust gate stands). The app side of 0.3.21 now carries: driver-check, miner-reliability-21 (cbd6f3a4), gpu-logos-21 with the Prove switch fix, earnings-tidy-21, scene-parity-21 and its sizing (live-dag.js 2.0.4), pool-finish-21; still mine: the under-12 GB prove-instead switch (section 2). The app gate on the final tree runs on build-2 about 19:30 BST or as soon as the switch lands.
**N15 rides 0.3.21's node line (the node lane, 15:1x BST):** branch numbering-fix at d8bceca5 (a6864e36 then d8bceca5, from 52e96c94): chain_path checks the first added block's selected parent against the tip record before anything is appended and hands the orphan records above the fork point to the reorg unwind (the shape that left p1-5090 two high: a reorg's removed list one short at 15:51Z on 6 October); a start-time self-check once per process walks the records from the restart pin against the DAG's selected parents, names the first break, unwinds above it and lets the follower re-walk (the shape that left p2-3090-3 46 high from a snapshot carrying its source's break); recordsContinuous and continuityBreak on igneum_getProvingStatus and igneum_getExecStatus (null, true, or false with the break's block), box-prover claiming only on true. The number is canonical by construction from the pin; the carrier's refusal by number stands (the statement binds the number). Two unit tests known-failed first; the exec suite 35 and the kaspad check green on build-2 at 14:13Z; the live line is the fleet's restart of p1-5090 and p2-3090-3 on the 0.3.21 candidate (the self-check naming #155958 and #158875, the unwind, offset 0 after). The 0.3.21 node order, final, on byte 5: 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5.
**update-return-21 in (15:3x BST):** 9d838ae5, one commit on b4289c4a (the app half: ota.rs, engine.rs, jobrun.rs, ember.rs, platform.rs, main.rs, bootcheck.rs; app/windows/host.cpp; Igneum-Miner.iss /IGNOTA=2; one round, main.rs's mod list by union). Lines on the tree: build-2 app tests 247 + 32 + 8; UI 74; the Windows cross green on build-1 (igneum-app.exe 4,172,288 B sha256 5b0598ad…, system DLLs only). host.cpp compiles in the cut's windows.yml run: the named gate line. The relay half stays on update-return for the relay lane's line through master.
**first-block-21 in (16:0x BST):** 6e555d47 on 064fb02b (ladder.rs: first_block_shown persisted in ladder.json, Ladder::start_run; engine.rs start_run at load and started_at on the state; app.js staleCard, firstWait, the first rung reading the flag; the ui-mock secondblock scenario). Lines: build-2 app gate 254 + 32 + 8 (seven new ladder tests); UI 67 (view 46, one new known-failed first); pre-push 56. No installer, node or host change. Captures ~/Desktop/igneum-previews-2026-10-07/first-block/01 and 02.
**Three more in (16:2x BST):** update-return-21b a64c193f (the eGPU card kind from a USB4 or Thunderbolt router in the device's parent chain, the Power Helper's fault line and its stale-prefix fix; app 255 + 32 + 8, UI 76); first-block-21 at cc9141cb replacing 6e555d47 (main's "seen once": the first-block card waits until a window has shown it, POST api/card/seen, ladder.rs card_seen; app 255 + 32 + 8, UI 67); miner-reliability-21 at 018440ae (the register: MF-11 in the update-return lane's words, MF-12 the pool stall, MF-13 the Power Helper's stale count; code unchanged since 4a28eb59, CI success). UI tests on the merged tree 76 of 76; the app gate on build-2 at the merged tip below. GitHub refused pushes with "Internal Server Error" from about 15:25 to 16:18 BST, transient.
**The node order, final (16:3x BST):** on 55768f88: c631c64b first (the test-only fix of the two stale integration targets, 1026 → 1282; both green on build-2 at 15:34Z), then 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5; the tip's suite set runs the consensus crate whole (`-p kaspa-consensus` without `--lib`: the lib and both integration targets) beside consensus-core, the miner, kaspa-pow, the exec suite and the three checks (the suite rule from the 0.3.20 known-red finding). era-vdf-node 394a5902 is 0.3.22's.
## 6. The shape that ships: the 0.3.21 app tree over the field node c4459193 (main, 17:5x BST)
No node gate for 0.3.21: the app tree ships over the node already in the field (c4459193, the 0.3.20 pin, digest 4bbbe816 on the floor file). The 96161037 line (N15's numbering class, the bare-node proving ids) folds into 0.3.22 and later; its canary cells (kept-datadir ids BOTH PRESENT, wipe canary c22-1 synced in 42 minutes, 23 for 23, restart synced in 1 min 24 s) stand as readings, not as this release's gate.

View file

@ -57,3 +57,15 @@ Three commits on 96161037: bd710a36 the sub-version 3 re-pin (byte 7, igneum-pow
**Testnet re-arm (main, through the build-server lane):** the arming on fork e6dd3afd (digest 4fbb2152, genesis 01294fd3) is void (old object; a go on it hard-forks at sub-version 3). The node lane cuts a testnet genesis object on release-0.3.22-node in the Devnet 3 shape (byte 7 from genesis, every activation at 0 that Devnet 3 has at 0, era VDF at 0, a past genesis timestamp with the future-genesis test beside it, no override file, the testnet's seeds and chain id as they are); the build-server lane builds the seed-class pair under /srv/artefacts/testnet-<commit>/seed/ and dry-runs wave1-0320.sh against seed1/2/3 at height 0; nothing onto a seed and nothing mines before the project lead's word (not before 15 October, LG-2).
**0.3.21 Windows, the toolchain finding (18:37 BST):** PC 2's installer job (take 2, 68 s) verified the payload (igneum-app.exe 151803c7 prints "igneum-app 0.3.21", igneumd.exe 49502cc7 "igneumd 2.1.0") and stopped on PC 2's toolchain: no MSVC (no window host "Igneum Miner.exe", whose host.cpp changed in update-return-21) and no Inno Setup 6 (no installer; winget refused by the job as told). Three shapes put to main at 18:45 BST: the Mac entry now and Windows later (the manifest carries a platform that lands later; 0.3.20 Windows apps do nothing until their entry arrives); winget Inno Setup on PC 2 (still no 0.3.21 host); the host by mingw on the box (dry compile asked) or Windows held until GitHub returns and windows.yml runs. deploy.sh carries --mac-only for shape (1); the full preflight stands for the Windows entry.
**Proving on Devnet 3 opens (the fleet, 18:45 BST):** dn3-x1's first segment 1024..1031 claimed 18:44:23 BST and SUBMITTED 18:45:49 (8 of 8 shards accepted, proof 1,272,909 bytes, 86.1 s end to end, peak 8,534 MiB on a 3060 12 GB); its record waits in dn3-g1's pool for a carrier; the paid-by-key line opens the 24-hour window for the project lead's mandatory-verification rule. Sizing: about 42 segments an hour per 12 GB card against 450 an hour made, so 11 cards reach a share of one; 14 more 3060 pods renting (about USD 0.85/h together, 20 a day). The 0.3.21 warm cases (CASES-W21 END rc 0, 18:47 BST, on 96161037): the target refused every version-1026 block (44,081 seen, 0 accepted), restarted back at the tip, the hub holds 900 of its last 900; the relay cell again reads the target's own refusal, not a relayed poison block, so Devnet 3's relay run (relay on the hands pair synced before the window, the twin peered to the relay alone) is where that cell gets read, and its CASES END is the card's gate.
## 7. the project lead moves the apps to Devnet 3 tonight (19:1x BST): the pin, the tree, the clock
**the project lead's word (through main, 19:10 BST):** the apps and the site's live page move to Devnet 3 now, not tomorrow. The clock: the 0.3.22 node pin at 19:15 BST; the Mac entry about 20:15 BST on channel devnet-3 (the floor file kept in the manifest for the 0.3.20 and 0.3.21 apps until the intake shows none below 0.3.22 for 24 hours); the Windows entry as its own entry when PC 2's smoke runs, about 21:00 BST, the 0.3.21 Windows entry skipped in its favour (said in the notes); the hive 0.3.22 package with the sub-version 3 kit published with the pin, the fleet's standing boxes moving in waves after the first lock; the site's live page pointed at the dn3 observer on build-1 after the first lock (about 20:10 BST), deployed from the box with the Vercel CLI as a site-only deploy of master's live tree (GitHub dark), edge time to main. Heights ride 0.3.23, set from the 0.3.23 sweep's finish with a two-hour margin (plan: 12:00 BST 8 October, difficulty v3 at the first multiple of 7,200 DAA at or after 14:00 BST, the other two 7,200 apart).
**The pin: release-0.3.22-node = 34a2dbaa at 19:15 BST, no heights** (69d1b56e + the testnet object 6ed56f63 + the N15 kept-datadir fix dfae08e5; igneum-devnet-3 digest 83eb50cd unchanged, igneum-testnet-1 87d103b6 on the same binary). Gates on the exact commit: build-1 build 18:40:26 BST (igneumd bc25693c, node-lane pair under /srv/artefacts/0322-34a2dbaa/node-lane/); build-2 suites consensus 122, exec 37 (the new scan test), pow 17, miner 25, core 152 by 18:42:51; canary set green (shutdown 567 ms, override refused, handshake, mismatch rejection). The Devnet 3 join-and-restart read is the fleet's. Crossing cases on the fast-time harness: difficulty v3 pass GREEN 19:08 BST and known-failed FAIL as expected; the DAA-seconds rule and finality leave green on the chain's reading but the harness's checkpoint read used the wrong RPC parameter, rerun by 19:22 BST; no heights commit could carry gates by 19:15, so every height rides 0.3.23 (0.3.23 line: 18473645 = 43360992 + d840537b subsidy_per_block, gates green, digest edit list 25; daa61847 rebased by the genesis-forward lane).
**The 0.3.22 app tree at 19:15 BST, release-0.3.22 c977786b on the box mirror:** 27ab317e (release-0.3.21 44b63ac9 + driver-check 46cc41e9) + pool-finish-21 8f2aae75 (the Devnet 3 split-read tool) + signing-22 e1b01654 (vote on by default pinned by test; Overview and Cards rows read signing or silent with the reason) + key-22 6501558f (scene/live-dag.js 2.0.5 legend, the app's chain card renders it, the site untouched) + c977786b (node_peers adds dn3-g1 64.119.209.250:21703 and dn3-g2 154.64.230.67:27017; self-test reads four). App gate on build-2 GREEN at every step (last 259 + 33 + 8, rc 0); pre-push 56 on each push. Riding if on the mirror by 19:45 BST, else 0.3.23: boot-start-22 (the engine starts at boot without a logon on Windows; a headless engine never reads a closed stdin as the host leaving), the export-wait reliability item (a worker never waits on the export past one retry interval), the driver-check hold-every-card-of-the-vendor rule, the UI lane's shard words. The Mac node pair builds on 34a2dbaa under the lock from 19:12 BST (r0322/mac-node-34a2dbaa.sh), then the DMG.
**PC 2 tonight:** the take-4 0.3.21 installer (mingw host, run-20261007-175020) was picked up at 18:51:57 BST before its removal deployed and the runner's abort ended the install in its first second (the build-server lane's fault, two rules added to the job tooling: an installs-app job is never removable without --force; never remove a published job without reading the machine's latest line); the update-return lane re-ran the kept installer at 19:07:56 BST and the 0.3.21 engine then restarted four times a minute apart and died ("quit requested by the window host went away (stdin closed)" 3 s after the node start: an engine started by a parent whose stdin closes at once); the project lead reinstalled PC 2 by hand with the public 0.3.20 installer (45b2f3fb, the MSVC host; the public alias confirmed as that file by hash at 19:12:54 BST). PC 2 is read-only for every lane until its app uploads as 0.3.20; then the 0.3.22 installer job (--installs-app) and the smoke, one job at a time; then the Intel lane's driver retry with the minidump copy folded in (one UAC click). PC 1: released to the Counter lane's queue at 19:04:37 BST (the 0.3.21 MSVC host e223db18 built there in 9 s, collected by the relay Blob); one slot for the 0.3.22 host (app/windows/version.h moved to 0.3.22, host.cpp untouched).

View file

@ -135,3 +135,15 @@ Added by the launch-pack lane (branch `launch-pack`) from `docs/analysis/mission
| LG-11 A signed proving customer | One customer paying for proofs at a published rate, or a signed letter of intent with a volume, before mainnet (the owner, 7 October 2026: a mainnet gate, not a testnet gate; the weight of the Devnet 2 gate: mainnet does not open without it) | the contract or the letter in the entity's records, a redacted copy linked from `docs/evidence.md`, the rate on the site; for the paying case the job market's payout contract shows a paid job for that customer; `grep -c "rollup signs for testnet" site/journey.json` is 0 after the handoff lands | M | NOT DONE: Taiko is named as the first customer and nothing is signed; the brief and the pilot progression are ledger X13 | the owner (the signature), the execution engineer (the paid job) |
| LG-12 Hash origin daily for 90 days | The report posts every day for the first 90 days from the go, with no gap | `SELECT count(*) FROM hash_origin_reports WHERE day >= '<go date>'` reaches 90 with consecutive days; the timer's journal on the box shows a run per day | C | The job and its `--go <date>` flag exist; the timer is OWED (section 3 of the pack) | build-server lane (timer), the report |
| LG-13 The disclosure prize | USD 50,000 for a reproduced break of the published hash class, paid in fiat by Igneum Labs LTD, announced only when escrowed and only when the entity's registered address exists on its documents and the owner gives the publish word | `docs/plans/funding.md` rule 3 (escrow before announcement); the staged text in docs/plans/cryptanalysis.md 3.3 on branch `cryptanalysis` (43d9700b, not on master yet); until the word, `grep -ci "50,000" site/*.html` is 0 | M (the announcement may come earlier, on the word) | APPROVED by the owner at 09:5x UK on 7 October 2026; STAGED; nothing public mentions it | the owner (escrow, the word), the cryptanalysis lane (the announcement) |
## LG-2 waived by the owner (7 October 2026, 19:5x BST)
Launch gate LG-2 (seven daily hash-origin reports before the testnet) is waived by the owner, 7 October 2026 19:5x BST; the report
still runs daily from Devnet 3 (igneum-hash-origin-dn3.timer on build-1, 08:30 UTC, `--prefix dn3_`, DN3_GO_DATE 2026-10-07) and
from the testnet from its go. The testnet gate is now: the 24-hour proven window closed on Devnet 3 (about 19:00 BST on 8 October),
the 0.3.23 heights crossed on every Devnet 3 node, the launch text (LG-5) on the site, the seeds on the 0.3.22 object with the dry
run clean (done: fork 6ed56f63, digest 87d103b6, genesis 52a3e6a9, seed-class pair under /srv/artefacts/testnet-6ed56f63/seed/ on
build-1, three-seed dry run clean at height 0 at 18:44 BST), and the owner's word. The seeds stay armed for a go as early as the
evening of 8 October: `infra/build-server/wave1-0320.sh seeds --igneumd <that igneumd> --sha256 80932b18… --miner <that miner>
--digest 87d103b6… --commit 6ed56f63 --wipe-genesis --genesis 52a3e6a9… --go` on the word, nothing before.

View file

@ -0,0 +1,17 @@
# Devnet 3 on igneum-build-1 (0.3.22, main's order on the project lead's word, 7 October 2026): the network flag and the ports every script here
# reads. NET_FLAGS is a PLACEHOLDER until the node lane names the object's flag in its commit (igneum-devnet-3: own network id and
# p2p port, every activation at 0, no override file). Ports follow the box's pattern (devnet 266x1 p2p; Devnet 2 seed 27610/27612/27790):
NET_FLAGS="--devnet --devnet-suffix=3" # PLACEHOLDER: replace with the node lane's flag for igneum-devnet-3
IGNEUMD="/srv/artefacts/0322-69d1b56e/hands/igneumd" # the 0.3.22 candidate 69d1b56e (genesis timestamp fix; built 18:04 BST, 7 Oct 2026)
# the seed (a bare process beside the Devnet 2 one, run as build, empty datadir)
DN3_SEED_APPDIR=/home/build/dn3seed
DN3_SEED_P2P=26631 # ufw: opened 7 Oct 2026 (provision.sh P2P_PORTS carries it)
DN3_SEED_RPC=27630; DN3_SEED_JSON=27632; DN3_SEED_EVM=27810
DN3_SEED_LOG=/home/build/dn3seed.log
# the hands' SECOND instances (the old devnet runs on for a day, so these run beside node1 and observer-node, not instead).
# Reconciled with the fleet lane's staging of 17:37 BST: ITS observer-node-dn3 (/srv/hands/bin/run-observer-node-dn3.sh, unit
# igneum-observer-node-dn3, rpc 26650, wrpc json 28650, p2p 26651, evm 26850, appdir /srv/hands/observer-node-dn3, peers from
# /srv/hands/dn3/dn3.env) is the observer instance; this lane runs the seed and node1-dn3 (p2p 26671, ufw open since 16:39Z).
DN3_NODE1_APPDIR=/srv/hands/node1-dn3; DN3_NODE1_P2P=26671; DN3_NODE1_RPC=26670; DN3_NODE1_JSON=28670; DN3_NODE1_EVM=26870
DN3_OBS_APPDIR=/srv/hands/observer-node-dn3; DN3_OBS_P2P=26651; DN3_OBS_RPC=26650; DN3_OBS_JSON=28650; DN3_OBS_EVM=26850
DN3_OBS_SCRIPT=/srv/hands/bin/run-observer-node-dn3.sh # the fleet lane's; devnet3.sh observer-node starts its unit, not a copy

View file

@ -9,21 +9,24 @@
# lines. No unit yet: the processes are detached (setsid nohup) under the build user like the Devnet 2 seed; units follow once the
# network is green. The old devnet's node1 and observer-node are not touched.
set -euo pipefail
HERE=$(cd "$(dirname "$0")" && pwd); . "$HERE/devnet3.env"
HERE=$(cd "$(dirname "$0")" && pwd); . "$HERE/devnet3.conf"
KEY="${IGNEUM_BUILD_KEY:-$HOME/.ssh/igneum_ed25519}"; HOST=$(head -1 "${IGNEUM_BUILD_HOST_FILE:-$HOME/.config/igneum/build-server}" | tr -d '[:space:]')
SSH=(ssh -i "$KEY" -o BatchMode=yes -o ConnectTimeout=15 "$HOST")
say() { echo "$(TZ=Europe/London date '+%H:%M:%S %Z') devnet3: $*" >&2; }
mode="${1:-}"; shift || true; GO=0; [ "${1:-}" = --go ] && GO=1
case "$NET_FLAGS" in *suffix=3*) say "NET_FLAGS is still the placeholder ($NET_FLAGS): the node lane's flag goes into devnet3.env first" ;; esac
case "$NET_FLAGS" in *suffix=3*) say "NET_FLAGS is still the placeholder ($NET_FLAGS): the node lane's flag goes into devnet3.conf first" ;; esac
case "$IGNEUMD" in *PLACEHOLDER*) [ "$mode" = status ] || { say "IGNEUMD is the placeholder: the 0.3.22 candidate's build fills it"; [ "$GO" = 0 ] || exit 1; } ;; esac
start_one() { # <name> <appdir> <p2p bind> <rpc> <json> <evm> <log> [extra args...]
local name="$1" appdir="$2" p2p="$3" rpc="$4" json="$5" evm="$6" log="$7"; shift 7
local args="$NET_FLAGS --appdir=$appdir --rpclisten=127.0.0.1:$rpc --rpclisten-json=127.0.0.1:$json --evm-rpclisten=127.0.0.1:$evm --listen=$p2p --nodnsseed --disable-upnp --nologfiles --yes $*"
if [ "$GO" = 0 ]; then say "DRY $name: $IGNEUMD $args > $log"; return 0; fi
"${SSH[@]}" bash -s -- "$name" "$IGNEUMD" "$appdir" "$log" "$args" <<'REMOTE'
set -euo pipefail; name="$1"; bin="$2"; appdir="$3"; log="$4"; args="$5"
# ssh flattens its arguments into one remote command line, so the argument string travels base64-encoded (the first --go at
# 18:22 BST lost everything after the first flag: the seed started on the OLD devnet with digest c562d70e and port 26611)
"${SSH[@]}" bash -s -- "$name" "$IGNEUMD" "$appdir" "$log" "$(printf '%s' "$args" | base64 | tr -d '\n')" <<'REMOTE'
set -euo pipefail; name="$1"; bin="$2"; appdir="$3"; log="$4"; args="$(printf '%s' "$5" | base64 -d)"
[ -x "$bin" ] || { echo "no binary $bin"; exit 1; }
mkdir -p "$appdir"; [ -z "$(ls -A "$appdir")" ] || echo "note: $appdir is not empty"
mkdir -p "$appdir"; [ -z "$(ls -A "$appdir")" ] || echo "note: $appdir is not empty: $(ls "$appdir" | tr '\n' ' ')"
case "$args" in *--devnet-suffix=3*) ;; *) echo "REFUSED: the argument line lacks --devnet-suffix=3: $args"; exit 1 ;; esac
cd "$(dirname "$log")"; setsid nohup "$bin" $args > "$log" 2>&1 < /dev/null & pid=$!; sleep 8
echo "$name pid $pid alive=$(kill -0 $pid 2>/dev/null && echo yes || echo NO) commit-strings=$(grep -a -c "$(echo "$bin" | grep -oE '[0-9a-f]{8}' | tail -1)" /proc/$pid/exe 2>/dev/null || echo ?)"
head -1 "$log" | cut -c1-120; grep -oE "Consensus params digest: [0-9a-f]+" "$log" | head -1
@ -35,7 +38,9 @@ REMOTE
case "$mode" in
seed) start_one dn3-seed "$DN3_SEED_APPDIR" "0.0.0.0:$DN3_SEED_P2P" "$DN3_SEED_RPC" "$DN3_SEED_JSON" "$DN3_SEED_EVM" "$DN3_SEED_LOG" --maxinpeers=128 --outpeers=8 ;;
node1) start_one node1-dn3 "$DN3_NODE1_APPDIR" "0.0.0.0:$DN3_NODE1_P2P" "$DN3_NODE1_RPC" "$DN3_NODE1_JSON" "$DN3_NODE1_EVM" /srv/hands/node1-dn3.log --enable-unsynced-mining --addpeer=127.0.0.1:$DN3_SEED_P2P --maxinpeers=128 --outpeers=8 ;;
observer-node) start_one observer-dn3 "$DN3_OBS_APPDIR" "127.0.0.1:$DN3_OBS_P2P" "$DN3_OBS_RPC" "$DN3_OBS_JSON" "$DN3_OBS_EVM" /srv/hands/observer-dn3.log --addpeer=127.0.0.1:$DN3_NODE1_P2P --addpeer=127.0.0.1:$DN3_SEED_P2P ;;
status) "${SSH[@]}" "for l in $DN3_SEED_LOG /srv/hands/node1-dn3.log /srv/hands/observer-dn3.log; do [ -f \$l ] && { echo \"== \$l\"; head -1 \$l | cut -c1-100; grep -oE 'Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed' \$l | head -2; tail -1 \$l | cut -c1-120; }; done; ss -ltn | awk '{print \$4}' | grep -E ':(26631|26651|26661|27630|26650|26660)\$' | tr '\n' ' '; echo" ;;
observer-node) # the fleet lane's instance: its unit (installed 16:39Z, disabled); IGNEUMD_DN3 and DN3_PEERS come from /srv/hands/dn3/dn3.env
if [ "$GO" = 0 ]; then say "DRY observer-node: sudo systemctl enable --now igneum-observer-node-dn3 (reads $DN3_OBS_SCRIPT; dn3.env IGNEUMD_DN3 must name the 0.3.22 artefact)"; "${SSH[@]}" 'grep -E "^(IGNEUMD_DN3|DN3_PEERS|DN3_LISTEN)=" /srv/hands/dn3/dn3.env'; else
ssh -i "$KEY" -o BatchMode=yes "root@${HOST#*@}" 'systemctl enable --now igneum-observer-node-dn3 && sleep 8 && systemctl is-active igneum-observer-node-dn3 && journalctl -u igneum-observer-node-dn3 --since "-60 s" --no-pager | grep -oE "igneumd/[^ ]+|Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed|P2P Server starting on: [^ ]+" | head -4'; fi ;;
status) "${SSH[@]}" "for l in $DN3_SEED_LOG /srv/hands/node1-dn3.log; do [ -f \$l ] && { echo \"== \$l\"; head -1 \$l | cut -c1-100; grep -oE 'Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed' \$l | head -2; tail -1 \$l | cut -c1-120; }; done; ss -ltn | awk '{print \$4}' | grep -E ':(26631|26651|26671|27630|26650|26670)\$' | tr '\n' ' '; echo" ;;
*) sed -n '2,12p' "$0" | sed 's/^# \{0,1\}//'; exit 2 ;;
esac

View file

@ -33,13 +33,13 @@ bs_route() { # <class: gate|build|check|suite|bench|prove|attack|other> -> the
}
# Spill-over (the project lead, 7 October 2026, 15:02 UK: build-1 at load 139 with a queue of 1 h 40 min while build-2 read 4.5 with both
# slots free). The class is a PREFERENCE, not a pin: a job goes to its class's box unless that box has no free slot or its 1-minute
# load is above BS_SPILL_LOAD (64), in which case it goes to the other box when THAT one has a free slot under the same load
# load is above BS_SPILL_LOAD (80 since 19:4x BST, was 64), in which case it goes to the other box when THAT one has a free slot under the same load
# line; when neither qualifies it queues on its own box. The alternate of box 1 is box 2, of box 2 box 1, of box 3 box 1; a box
# without a host file is never chosen. The decision is one line on the Mac (bs_log) and travels to the box in BR_ROUTE_* for the
# JSONL row ("route": preferred, box, spilled, reason), so the dashboard shows it per job. A box is read with one ssh
# (bs_box_state: free slots of the slot count, load1); BS_ROUTE_STATE_<n> in the environment replaces the ssh for the self-test
# (tools/ci/route-spill-check.sh), "down" standing for an unreachable box.
BS_SPILL_LOAD="${BS_SPILL_LOAD:-64}"
BS_SPILL_LOAD="${BS_SPILL_LOAD:-80}" # the project lead, 7 Oct 2026 19:4x BST: both boxes to near max; was 64
bs_box_state() { # <box> -> "free=<n> slots=<n> load1=<x>" | "absent" | "down"
local b="$1" v f h
v=$(eval "printf '%s' \"\${BS_ROUTE_STATE_$b:-}\""); if [ -n "$v" ]; then printf '%s' "$v"; return 0; fi

View file

@ -190,10 +190,10 @@ if [ "${1:-}" = --self-test-slots ]; then
after() { python3 -c "import sys; sys.exit(0 if float(open(sys.argv[1]).read()) >= float(open(sys.argv[2]).read()) else 1)" "$1" "$2"; }
# 1. two concurrent builds: 45 jobs each
fake a 6 & fake b 6 & wait
[ "$(cat "$t/a.jobs")" = JOBS=45 ] && [ "$(cat "$t/b.jobs")" = JOBS=45 ] || fail "two concurrent builds got $(cat "$t/a.jobs" "$t/b.jobs" | tr '\n' ' ') (want JOBS=45 JOBS=45)"
[ "$(cat "$t/a.jobs")" = JOBS=44 ] && [ "$(cat "$t/b.jobs")" = JOBS=44 ] || fail "two concurrent builds got $(cat "$t/a.jobs" "$t/b.jobs" | tr '\n' ' ') (want JOBS=44 JOBS=44)"
# 2. one build alone: 90
fake c 1
[ "$(cat "$t/c.jobs")" = JOBS=90 ] || fail "a lone build got $(cat "$t/c.jobs") (want JOBS=90)"
[ "$(cat "$t/c.jobs")" = JOBS=88 ] || fail "a lone build got $(cat "$t/c.jobs") (want JOBS=88)"
# 3. a quiet measurement blocks an unbounded build (it starts only after the quiet ended) and lets a bounded suite run beside it
fake m 9 1 & sleep 0.5; fake d 1 & BR_CORES=1 BR_NICE=10 fake s 1 & wait # the quiet holds 9 s: longer than a slot take plus the 3 s settle
after "$t/d.start" "$t/m.end" || fail "an unbounded build started while a quiet measurement held the box (build start $(cat "$t/d.start"), quiet end $(cat "$t/m.end"))"
@ -214,8 +214,8 @@ if [ "${1:-}" = --self-test-slots ]; then
grep -q 'self-test f' "$t/locks/build-0" || fail "the holder line of the busy slot build-0 was lost when another build probed it: '$(cat "$t/locks/build-0")'"
wait
# 6. the log carries the job count and the measure flag
grep -q '"jobs":45' "$t/log/builds.jsonl" && grep -q '"measure":true' "$t/log/builds.jsonl" || fail "builds.jsonl lacks jobs or measure fields"
echo "self-test-slots: two concurrent builds 45 each, a lone build 90, a quiet blocks an unbounded build and not a bounded suite, a quiet is refused beside a slot or a lease, a run keeps off leased cores, a probe keeps the holder line, the log carries jobs and measure"; exit 0
grep -q '"jobs":44' "$t/log/builds.jsonl" && grep -q '"measure":true' "$t/log/builds.jsonl" || fail "builds.jsonl lacks jobs or measure fields"
echo "self-test-slots: two concurrent builds 44 each, a lone build 88, a quiet blocks an unbounded build and not a bounded suite, a quiet is refused beside a slot or a lease, a run keeps off leased cores, a probe keeps the holder line, the log carries jobs and measure"; exit 0
fi
# One run per worktree directory at a time (6 October 2026, 19:51:09 UK: two runs of one worktree started in the same second;
@ -318,7 +318,7 @@ PY
SLOTS_DIR="$IGNEUM_BUILD_SLOTS_DIR"
slots=$(cat "$SLOTS_DIR/slots" 2>/dev/null || echo 1); [ "$slots" -ge 1 ] 2>/dev/null || slots=1
JOBS_ALONE="${JOBS_ALONE:-90}"; JOBS_SHARED="${JOBS_SHARED:-45}"
JOBS_ALONE="${JOBS_ALONE:-88}"; JOBS_SHARED="${JOBS_SHARED:-44}" # the project lead, 7 Oct 2026: 88 of 96 cores, 8 reserved for the release builds, the seed and the observers
holder_line() { printf 'pid %s since %sZ waited %s s: %s\n' "$BR_PID" "$(date -u +%H:%M:%S)" "$1" "$BR_LABEL"; }
give_up() { # <what>
echo "build-remote: gave up waiting for $1 after 2 h" >&2
@ -469,6 +469,9 @@ BR_RUN_LOG="$RUN_LOG_DIR/$BR_HOST-$BR_T0-$BR_PID.log"; export BR_RUN_LOG
# (since the third slot on build-2, 7 Oct 2026: a bounded run takes the band its SLOT owns, counted from the top: slot 0 the last N
# cores, slot 1 the N below, slot 2 the N below that, so three bounded runs never share a core; a band below core 0 falls back to
# the last N)
# (the project lead, 7 Oct 2026 19:4x BST, both boxes to near max: a bounded run takes the LAST N cores, N = 88 by default, leaving the first 8
# to the release builds, the seed and the observer processes; with N above half the box the slots share the band, and nice 10 plus
# the per-slot jobs rule keep two suites fair; a smaller N (IGNEUM_BOUND_CORES) returns to disjoint bands per slot when it fits)
ncpu=$(nproc); cores_str="0-$((ncpu - 1))"
if [ "${BR_CORES:-0}" -gt 0 ] && [ "${BR_CORES}" -lt "$ncpu" ]; then
band=0; case "${got:-}" in ''|measure) ;; *) band=$got ;; esac

View file

@ -82,6 +82,16 @@ Stats JSON (what Hive reads from `$stats`): `hs` (kH/s per GPU), `hs_units` (`kh
digest on the downloads page; a different one means the override is stale and the node is refused.
- Ports: the bundled node listens on 26611 (p2p) and answers RPC on 127.0.0.1:26610 only.
## Shipped packs (0.3.22)
`make-hive-package.sh --kit <zip>` (repeatable) puts program-pack kits under `packs/` in the archive: the class v4 sub-version 3
kit (eight packs, program_id `a785001687d8688a` for the shared devnet's epoch 0) and Devnet 3's epoch-0 pack
`v4-devnet3-epoch0` (program_id `fce15bf61030be57`, exported under igneum-pow 017e7037 over genesis `4020cb43` as epoch and
era seed, day bytes for 7 October UTC). They are the rig's FIRST-START convenience: `h-run.sh` seeds `packs/devnet` from the
shipped pack only when the node's own export left nothing, so a rig mines from its first start; the pack is dated, and a rig
starting after epoch 0 (3,600 DAA) re-exports from its own node as before. The shipped pack is never the authority; the
pack-id gate reads `program.json`'s `program_id`.
## Building the package
infra/cross/build-linux.sh # igneumd and igneum-miner for Linux (cargo-zigbuild), into infra/cross/out

View file

@ -73,7 +73,17 @@ say "GPUs: $nv NVIDIA, $amd AMD (worker setting: $WORKER)"
# 3. the hourly program pack from the node (the workers read it with --pack; the miner writes the next one to packs/prepare)
export_pack() { [[ "$NODE_URL" == "none" ]] && return 0; rm -rf "$HERE/packs/devnet"; "$BIN/igneum-miner" export-pack "$NODE_URL" "$HERE/packs/devnet" >> "$MAIN" 2>&1; }
# a shipped pack (packs/<name>/program.json, from make-hive-package.sh --kit; 0.3.22) seeds packs/devnet ONLY when the node's own
# export left nothing: the rig's first-start convenience, never the authority (a rig starting after epoch 0 re-exports from its node;
# the miner's --prepare-packs and exit 42 keep it on the chain's program as before). SHIPPED_PACK names the directory under packs/
# (h-config.sh or the Flight Sheet; default v4-devnet3-epoch0 when it exists).
seed_pack() {
[[ -d "$HERE/packs/devnet" && -f "$HERE/packs/devnet/program.json" ]] && return 0
local sp="${SHIPPED_PACK:-v4-devnet3-epoch0}"
if [[ -f "$HERE/packs/$sp/program.json" ]]; then rm -rf "$HERE/packs/devnet"; cp -R "$HERE/packs/$sp" "$HERE/packs/devnet"; say "first start: packs/devnet seeded from the shipped pack $sp (program_id $(sed -n 's/.*"program_id" *: *"\{0,1\}\([0-9a-fx]*\)"\{0,1\}.*/\1/p' "$HERE/packs/$sp/program.json" | head -1)); the node's export replaces it"; fi
}
export_pack || say "pack export failed; the miners retry"
seed_pack
# 4. one miner per GPU, restarted on exit (exit 42 = the program changed and the worker cannot prepare: re-export the pack)
run_gpu() {

View file

@ -4,6 +4,8 @@
# and infra/cross/out-workers (the two GPU workers, build-workers-linux.sh)
# NODE_OUT=... WORKERS_OUT=... VERSION=... OUT=... other inputs; VERSION defaults to the igneumd version in version.txt
# --fake stub binaries instead (the self-test; never ship it)
# --kit <zip> (repeatable) program-pack kit(s) unpacked under packs/ in the tar (0.3.22: the sub-version 3
# kit and Devnet 3's epoch-0 pack); the rig's first-start convenience, see h-run.sh
# Output: packaging/hive/build/igneum-hive-<version>.tar.gz with the directory igneum/ inside (what Hive expects:
# the archive name carries the version, the directory does not), plus its sha256 and the Flight Sheet lines.
set -euo pipefail
@ -12,7 +14,12 @@ REPO="$(cd "$HERE/../.." && pwd)"
NODE_OUT="${NODE_OUT:-$REPO/infra/cross/out-v2}"
WORKERS_OUT="${WORKERS_OUT:-$REPO/infra/cross/out-workers}"
OUT="${OUT:-$HERE/build}"
FAKE=0; [[ "${1:-}" == "--fake" ]] && FAKE=1
# --kit <zip> (repeatable; 0.3.22, 7 October 2026): a program-pack kit unpacked under packs/ in the tar (the class v4 sub-version 3
# packs and Devnet 3's epoch-0 pack, from the hash lane), the rig's FIRST-START convenience: h-run.sh seeds packs/devnet from a
# shipped pack only when the node's own export leaves nothing, and a rig starting after epoch 0 re-exports from its own node as
# before; the shipped pack is never the authority. The pack-id gate reads program.json's program_id.
FAKE=0; KITS=()
while [[ $# -gt 0 ]]; do case "$1" in --fake) FAKE=1; shift ;; --kit) KITS+=("$2"); shift 2 ;; *) echo "unknown argument $1" >&2; exit 2 ;; esac; done
log() { printf '%s %s\n' "$(date -u +%H:%M:%S)" "$*"; }
die() { log "ERROR: $*" >&2; exit 1; }
stage="$OUT/igneum"; rm -rf "$stage"; mkdir -p "$stage/bin"
@ -34,6 +41,18 @@ else
VERSION="${VERSION:-$(head -1 "$NODE_OUT/version.txt" | awk '{print $2}')}"
fi
[[ -n "$VERSION" ]] || die "no version (VERSION=... or a version.txt with 'igneumd <version>')"
if [[ ${#KITS[@]} -gt 0 ]]; then
mkdir -p "$stage/packs"
for k in "${KITS[@]}"; do
[[ -f "$k" ]] || die "no kit zip at $k"
unzip -q -o "$k" -d "$stage/packs" || die "kit $k does not unzip"
log "kit $(basename "$k") sha256 $(shasum -a 256 "$k" 2>/dev/null | awk '{print $1}' || sha256sum "$k" | awk '{print $1}') unpacked under packs/"
done
# every pack directory holds program.json; its program_id is what the pack-id gate reads
n=0; while IFS= read -r pj; do d="$(dirname "$pj")"; id="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1])).get("program_id",""))' "$pj" 2>/dev/null || true)"; log "pack ${d#"$stage/packs/"}: program_id ${id:-?}"; n=$((n+1)); done < <(find "$stage/packs" -name program.json | sort)
[[ $n -gt 0 ]] || die "the kit(s) hold no pack (no program.json found)"
printf 'packs: %s pack(s) from %s (first-start convenience; the rig re-exports from its own node)\n' "$n" "$(for k in "${KITS[@]}"; do basename "$k"; done | tr '\n' ' ')" >> "$stage/version.txt"
fi
cp "$HERE/h-config.sh" "$HERE/h-run.sh" "$HERE/h-stats.sh" "$HERE/README.md" "$stage/"
sed "s/^CUSTOM_VERSION=.*/CUSTOM_VERSION=$VERSION/" "$HERE/h-manifest.conf" > "$stage/h-manifest.conf"
chmod +x "$stage"/h-*.sh "$stage"/bin/*

View file

@ -54,7 +54,7 @@ KIND="" TARGET="" PLATFORM="" REQUIRES="" REQUIRES_SET=0 ID="" TITLE="" EXPIRES_
SCRIPT="" SHELL_KIND="" ELEVATED=0 STOP_MINERS=0 TIMEOUT_MIN="" CARDS_OFF=""
FILE="" URL="" SHA="" SIZE="" DIR="" TO="" EXTRACT=0 EXTRACT_DIR="" FRESH=0
GLOBS=() COMMAND="" WHAT=""
ZIP="" FIXTURES="" CAP_MIN="" DISTRO="" WSL_USER="" REMOVE_ID=""
ZIP="" FIXTURES="" CAP_MIN="" DISTRO="" WSL_USER="" REMOVE_ID="" FORCE="" INSTALLS_APP=0
TARGETS="" BUDGET_MIN="" STAGE_MIN="" MIN_FREE_GB="" TESTS=1 RELAY_URL="" NICE="" CARGO_JOBS=""
case "$CMD" in
remove) REMOVE_ID="${1:-}"; [ -n "$REMOVE_ID" ] || { echo "remove <id>" >&2; exit 2; }; shift ;;
@ -67,6 +67,8 @@ while [ $# -gt 0 ]; do
--requires) REQUIRES="$2"; REQUIRES_SET=1; [ "$REQUIRES" = none ] && REQUIRES=""; shift 2 ;;
--id) ID="$2"; shift 2 ;;
--title) TITLE="$2"; shift 2 ;;
--force) FORCE="$2"; shift 2 ;; # remove: override the running-job refusal, with the reason (7 Oct 2026)
--installs-app) INSTALLS_APP=1; shift ;; # add --kind run: the script installs over the app; never removed without --force
--expires-hours) EXPIRES_H="$2"; shift 2 ;;
--script) SCRIPT="$2"; shift 2 ;;
--shell) SHELL_KIND="$2"; shift 2 ;;
@ -227,8 +229,8 @@ if [ "$CMD" = list ]; then
[ -f "$JOBS" ] || { echo "no jobs file in $DEST"; exit 0; }
"$SIGNER" verify-jobs "$PUB" "$JOBS" "$JOBS.sig" || { echo "the file in $DEST does not verify; run: $0 sign" >&2; exit 1; }
if [ -f "$SIGNED" ]; then "$SIGNER" verify-signed-jobs "$PUB" "$SIGNED" >/dev/null || { echo "the envelope in $DEST does not verify; run: $0 sign" >&2; exit 1; }; else echo "(no igneum-jobs.signed.json yet; the next write makes one)"; fi
python3 - "$JOBS" <<'PY'
import json, sys, datetime
INSTALLS_APP="$INSTALLS_APP" python3 - "$JOBS" <<'PY'
import json, sys, datetime, os
f = json.load(open(sys.argv[1]))
now = datetime.datetime.now(datetime.timezone.utc)
for j in f.get("jobs", []):
@ -353,17 +355,36 @@ except Exception: print("")' "${ZIP%.zip}.json" 2>/dev/null || true)"
esac
[ -n "$PLATFORM" ] || PLATFORM=any
[ -n "$ID" ] || ID="$KIND-$(date -u +%Y%m%d-%H%M%S)"
NEW_JOB="$(python3 -c 'import json,sys,datetime
NEW_JOB="$(INSTALLS_APP="$INSTALLS_APP" python3 -c 'import json,sys,datetime,os
a=sys.argv
now=datetime.datetime.now(datetime.timezone.utc)
t={"machine_ids": "all" if a[2]=="all" else [x.strip().lower() for x in a[2].split(",") if x.strip()], "platform": a[3]}
if os.environ.get("INSTALLS_APP")=="1" and a[5]=="run": t.setdefault("params",{})["installs_app"]=True
if a[4]: t["requires"]=[x.strip() for x in a[4].split(",") if x.strip()]
print(json.dumps({"id": a[1], "kind": a[5], "title": a[6], "created_at": now.strftime("%Y-%m-%dT%H:%M:%SZ"), "expires_at": (now+datetime.timedelta(hours=float(a[7]))).strftime("%Y-%m-%dT%H:%M:%SZ"), "target": t, "params": json.loads(a[8]), "report": "log-intake"}))' "$ID" "$TARGET" "$PLATFORM" "$REQUIRES" "$KIND" "$TITLE" "$EXPIRES_H" "$PARAMS")"
fi
# ---- the removal guard (7 October 2026, 18:53 BST: a removal reached PC 2 one second after its job had launched a silent
# installer over the running app; the runner's abort-on-removal ended the process tree and the app went dark). A remove refuses
# when any target's latest report for the id has started and carries no final line (the job is running), or when the job was
# published with --installs-app; `--force "<reason>"` overrides, and the reason is printed. The read is tools/jobs.mjs <id>.
# REMOVE_GUARD_READ=<file> replaces the read for the self-test (tools/ci/publish-jobs-check.sh).
if [ -n "$REMOVE_ID" ]; then
read_out="$( if [ -n "${REMOVE_GUARD_READ:-}" ]; then cat "$REMOVE_GUARD_READ"; else node "$ROOT/tools/jobs.mjs" "$REMOVE_ID" 2>/dev/null || true; fi )"
running="$(printf '%s\n' "$read_out" | grep -cE '^(job [^ ]+ \(.*\) on .* started|== running the)' || true)"
final="$(printf '%s\n' "$read_out" | grep -cE '^(SUMMARY: |job [^ ]+: (done|failed|aborted|timeout))' || true)"
jobs_now="$JOBS"; [ -f "$DEST/igneum-jobs.json" ] && jobs_now="$DEST/igneum-jobs.json" # the file at the destination this run writes
installs="$(python3 -c 'import json,sys; j=[x for x in json.load(open(sys.argv[1])).get("jobs",[]) if x.get("id")==sys.argv[2]]; print(1 if j and "\"installs_app\": true" in json.dumps(j[0]) else 0)' "$jobs_now" "$REMOVE_ID" 2>/dev/null || echo 0)"
if [ -z "$FORCE" ]; then
if [ "$running" -gt 0 ] && [ "$final" = 0 ]; then echo "remove refused: $REMOVE_ID has started on a machine and has no final line yet (a removal ends the running job's process tree); wait for its SUMMARY, or --force \"<reason>\"" >&2; exit 3; fi
if [ "$installs" = 1 ]; then echo "remove refused: $REMOVE_ID was published with --installs-app (it installs over the app); --force \"<reason>\" to remove it anyway" >&2; exit 3; fi
else
echo "remove: --force given ($FORCE); running=$running final=$final installs_app=$installs"
fi
fi
# ---- merge: current jobs minus expired (minus a removed id), plus the new one; canonical JSON ---------------------
NEW="$JOBS.new"
python3 - "$JOBS" "$NEW" "$NEW_JOB" "$REMOVE_ID" <<'PY'
INSTALLS_APP="$INSTALLS_APP" python3 - "$JOBS" "$NEW" "$NEW_JOB" "$REMOVE_ID" <<'PY'
import json, sys, datetime, os
cur, out, new_job, remove = sys.argv[1:5]
now = datetime.datetime.now(datetime.timezone.utc)

View file

@ -416,10 +416,11 @@ for (const [file, active] of PAGES) {
const bj = JSON.parse(readFileSync(join(here, 'miner-bench.json'), 'utf8'));
const rows = bj.rows.slice().sort((a, b) => (a.card < b.card ? -1 : a.card > b.card ? 1 : a.generator < b.generator ? -1 : a.generator > b.generator ? 1 : b.mh_s - a.mh_s));
const fmt = (n) => Number(n).toLocaleString('en-GB', { maximumFractionDigits: 1 });
const fmt3 = (n) => Number(n).toLocaleString('en-GB', { maximumFractionDigits: 3 });
const cell = (r) => [
r.card, r.generator, fmt(r.mh_s), r.mh_per_w == null ? 'not measured' : fmt(r.mh_per_w), r.miner, r.date, r.source, r.by + (r.note ? '. ' + r.note : ''),
r.card, r.generator, fmt(r.mh_s), r.watts == null ? 'not read' : fmt(r.watts), r.mh_per_w == null ? 'not measured' : fmt3(r.mh_per_w), r.v4_cost || 'not measured', r.tuned || 'stock, mining', r.miner + (r.driver_os ? ' (' + r.driver_os + ')' : ''), r.date, r.source, r.by + (r.note ? '. ' + r.note : ''),
];
const table = '<div class="tbl"><table><thead><tr>' + ['Card', 'Generator', 'Best MH/s', 'MH per watt', 'Miner', 'Date', 'Source', 'Who measured it'].map(h => `<th>${h}</th>`).join('') + '</tr></thead><tbody>' +
const table = '<div class="tbl"><table><thead><tr>' + ['Card', 'Generator', 'Best MH/s', 'Watts', 'MH per watt', 'Class v4 cost', 'Tuned', 'Miner', 'Date', 'Source', 'Who measured it'].map(h => `<th>${h}</th>`).join('') + '</tr></thead><tbody>' +
rows.map(r => '<tr>' + cell(r).map(c => `<td>${esc(String(c))}</td>`).join('') + '</tr>').join('') + '</tbody></table></div>';
// Ember Tune's fleet priors (site/miner-priors.json, tools/tuning.mjs --priors --site): one row per card model,
// driver major and program class; a row under the sample floor shows its count and no point
@ -442,7 +443,7 @@ for (const [file, active] of PAGES) {
table,
'<h2 id="how">How a row gets here</h2>',
'<p>Every row names the engineering log entry or the job it came from. "Measured by the team" means our own hardware and our own log. "Reported by the fleet" means a machine we do not own, read from the status lines its miner uploads.</p>',
'<p>MH per watt needs the card\'s power draw during the run. The app reads it on NVIDIA cards through the driver. Rows get the figure when a run records it.</p>',
'<p>MH per watt needs the card\'s power draw during the run. The app reads it on NVIDIA cards through the driver. Rows get the figure when a run records it. The class v4 cost column is what the latency-shadow work costs that card against the class v3 control, in watts and rate, where it was measured. The tuned column is the card\'s state at the row: a full Ember Tune names its point; stock means the card as it came, bench only or mining.</p>',
'<p>There is no other Igneum miner to compare with yet, so this table compares cards, not miners. The app that produces these rows: <a href="/miner">the miner page</a>.</p>',
`<p>Rows: ${rows.length}. Each row names the engineering log entry it came from.</p>`,
'<h2 id="priors">Fleet tuning priors</h2>',

View file

@ -250,7 +250,7 @@ td.mono{font-family:var(--f-mono);font-size:12.5px;min-width:180px}td.iv{color:v
<tr data-status="tested by the team"><td class="n">14</td><td class="claim">Ethereum bytecode runs unchanged, with the documented differences of spec 7.1<div class="where">Homepage Build card; litepaper Building</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">as row 13; fixes <code>F-exec-A</code>, <code>F-exec-B</code> (spec 7.5)</td><td><code>tools/evm-smoke/smoke.mjs</code>: deploy via viem, <code>increment</code>, <code>hashLoop</code>, <code>eth_estimateGas</code>, <code>eth_getLogs</code>; <code>tools/exec-attacks</code> scenarios 1 and 3; bench-log "execution layer attack fixes"</td><td>Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The <code>Prover</code> precompile, proof records and the shard planner are not in the node</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">15</td><td class="claim">Every block is proven, with the proof landing within about a minute at launch<div class="where">Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>d7e1f89</code> (GPU proof), <code>e01a3cc</code>, <code>292e800</code>, <code>eedd136</code> (<code>proving/igneum-prove</code>: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6</td><td><code>proving/windows-wsl2</code> (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; <code>igneum-prove-host --mode block</code> on <code>proving/fixtures/</code>; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"</td><td>First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture <code>block-78-increment</code> (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in <code>docs/benchmarks/proving-e2e.md</code>. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on the RTX 5090 Windows rig in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind <code>proving_v1_activation_daa</code> (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">16</td><td class="claim">A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)<div class="where">Litepaper Proving ("The proving budget"); roadmap gate 2</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.1 (Target), 7.6 (<code>S_p</code> provisional, 7,500,000 pgas = <code>B_p</code> / 4)</td><td><code>PROVE-SHARD.bat</code> on the RTX 5090 (pending); the end-to-end standard in <code>docs/benchmarks/proving-e2e.md</code>; bench-log "proving: devnet v4 shards"</td><td>Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional <code>S_p</code> is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)<div class="where">the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line</div></td><td><span class="st st-0">tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured</span></td><td class="mono"><code>docs/analysis/chip-model-v3.md</code> 5 and 6; <code>docs/analysis/latency-shadow-2026-10-06.md</code>; <code>docs/plans/counter-asic-3-status.md</code>; <code>docs/analysis/attack-pass/f8-uniform.md</code>, <code>f4-weakday.md</code>, <code>docs/analysis/ca3-v4-uniform.md</code>; <code>docs/design/class-v5-stored-state.md</code>; the H100 and market-cap rows of 7 October; <code>docs/plans/funding.md</code> (the three lots)</td><td>the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses <code>tools/attack/f8-uniform</code> and the F4 census; the verifier by <code>igneum-pow bench</code></td><td>136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1</td><td class="iv">none yet; the three cryptanalysis lots are the next test</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)<div class="where">the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line</div></td><td><span class="st st-0">tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured</span></td><td class="mono"><code>docs/analysis/chip-model-v3.md</code> 5 and 6; <code>docs/analysis/latency-shadow-2026-10-06.md</code>; <code>docs/plans/counter-asic-3-status.md</code>; <code>docs/analysis/attack-pass/f8-uniform.md</code>, <code>f4-weakday.md</code>, <code>docs/analysis/ca3-v4-uniform.md</code>; <code>docs/design/class-v5-stored-state.md</code>; the H100 and market-cap rows of 7 October; <code>docs/plans/cryptanalysis/in-house-pass.md</code> (the internal adversarial pass)</td><td>the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses <code>tools/attack/f8-uniform</code> and the F4 census; the verifier by <code>igneum-pow bench</code></td><td>136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1</td><td class="iv">none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word</td></tr>
<tr data-status="tested by the team"><td class="n">18</td><td class="claim">The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache<div class="where">Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">readwidth e752fc7 (<code>docs/plans/read-width.md</code>), ca2-era 78c0ee4, ca2-cache 2de19e5 (<code>docs/plans/hot-table.md</code>)</td><td>The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load</td><td>Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">19</td><td class="claim">The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors<div class="where">Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">ca2-mixer 1ab8b21 (<code>tests/mixer.rs</code>, <code>tests/scratch.rs</code>), ca2-era 78c0ee4, ca2-soundness a465881 (<code>docs/analysis/scratch-soundness.md</code>), <code>igneum-pow/tests/packs.rs</code></td><td>The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card</td><td>Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT) job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">20</td><td class="claim">No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)<div class="where">Homepage stats and Economics tiles; litepaper Supply, Economics</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>6ac80a3</code>; fork "igneum-node devnet v0"; <code>consensus/core/src/igneum.rs</code>, <code>coinbase.rs</code></td><td><code>cargo test -p kaspa-consensus-core igneum</code> (8 pass: subsidy table, ramp, split, cap) and <code>cargo test -p kaspa-consensus coinbase</code> (8 pass); <code>igneum-miner inspect 40</code>; bench-log "igneum-node devnet v0"</td><td>Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the <code>igneum-proving-pool-v0</code> output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened</td><td class="iv">none yet</td></tr>

View file

@ -445,7 +445,7 @@ body.all .pager{display:none}
<tr><td>When a stored-dataset chip pays for itself</td><td>at about USD 100 M of market cap in the first two years, not before</td><td>modelled, 7 October 2026</td></tr>
<tr><td>The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class)</td><td>5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x)</td><td>modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state</td></tr>
</tbody></table></div>
<p>What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is not ours: the cryptanalysis plan buys three external lots against the mixer, the chained cache and the acceptance rule.</p>
<p>What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.</p>
<p>No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: <a href="/bench#counter-asic-2-0-the-numbers">the numbers</a>; the claim is tested by paid independent cryptanalysis and the public benchmark. Monero has run on RandomX since 2019 (approximate) with no chip shipped. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. A box with about a 2x per joule edge over the best CPUs, and about 3x over a desktop, was withdrawn rather than face a RandomX re-tune of 1.5x or more. That is the band Igneum’s class v4 model sits in (2.1x to 3.9x over an RTX 5090), and the defence that held was a maintained algorithm with a credible upgrade path, which is what the ladder is.</p>
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.</p>
</section>

View file

@ -1,5 +1,5 @@
{
"_about": "Rows of the public bench table at /miners (site/build.mjs). One row per card, generator version and miner version: the best measured rate. Later jobs append rows. Fields: card, generator (v1 | v2), mh_s (best measured MH/s), mh_per_w (MH per watt, null when the power was not measured), miner (the miner or package version), date (YYYY-MM-DD), source (the docs/bench-log.md heading, or the job id), by ('measured by the team' | 'reported by the fleet'), note (short, optional). No machine names, no addresses, no owner names: the build scrubs the page and fails on any that survive.",
"_about": "Rows of the public bench table at /miners (site/build.mjs). One row per card, generator version and miner version: the best measured rate. Later jobs append rows. Fields: card, generator (v1 | v2), mh_s (best measured MH/s), mh_per_w (MH per watt, null when the power was not measured), miner (the miner or package version), date (YYYY-MM-DD), source (the docs/bench-log.md heading, or the job id), by ('measured by the team' | 'reported by the fleet'), note (short, optional), watts (board power at the rate, null when not read), v4_cost (what the class v4 shadow costs this card against the class v3 control: watts and rate, measured; 'not measured' when not), tuned (the card's tune state at the row: 'full Ember Tune: <point>' | 'clock lock <MHz>, cap <W>' | 'stock, bench only' | 'stock, mining'), driver_os (driver and OS where known). No machine names, no addresses, no owner names: the build scrubs the page and fails on any that survive.",
"rows": [
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -10,7 +10,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090, memory-hard dataset (pack igneum-genesis-mh)",
"by": "measured by the team",
"note": "genesis program, 104 loads per hash, 1 GiB dataset"
"note": "genesis program, 104 loads per hash, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -21,7 +25,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090 first run, dataset sweep and second program",
"by": "measured by the team",
"note": "hourly program, 128 loads per hash, 1 GiB dataset"
"note": "hourly program, 128 loads per hash, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -32,7 +40,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, the gfx1036 worker fault and what the Mac could and could not reproduce",
"by": "measured by the team",
"note": "live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected"
"note": "live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
@ -43,7 +55,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090 first run (the Apple row of the same table)",
"by": "measured by the team",
"note": "genesis program, 1 GiB dataset"
"note": "genesis program, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
@ -54,7 +70,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, first hourly program swap on the live devnet: compile-ahead, no pause, two cards",
"by": "measured by the team",
"note": "live devnet v4, unbroken through the hour boundary"
"note": "live devnet v4, unbroken through the hour boundary",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "Apple silicon laptop (model not reported)",
@ -65,7 +85,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, first outside machine on the devnet: an Apple silicon laptop through the Igneum Miner app",
"by": "reported by the fleet",
"note": "21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks"
"note": "21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "NVIDIA RTX 5060 Ti (16 GB)",
@ -76,7 +100,461 @@
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the first 16 GB card: an RTX 5060 Ti in a Thunderbolt enclosure (run b)",
"by": "measured by the team",
"note": "class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure"
"note": "class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure",
"watts": 114.8,
"v4_cost": "0.1 percent of rate, measured 7 October 2026",
"driver_os": "NVIDIA driver, Windows 11",
"tuned": "stock, bench only (180 W default cap, never tuned)"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
"generator": "v2",
"mh_s": 136.1,
"watts": 350,
"mh_per_w": 0.389,
"miner": "igneum-worker-cuda bench, class v3 program (mx8-devnet-epoch0)",
"date": "2026-10-06",
"source": "bench log: 6 October 2026, Counter ASIC 3.0 item 8, the 5090 rows (the control row)",
"by": "measured by the team",
"note": "the control; 290 W in the app on the same card",
"v4_cost": "about +80 W for 0.2 percent of rate at the unlocked 2,850 MHz core, measured 6 October 2026; the efficiency pass (clock and voltage under class v4) runs 7 October",
"tuned": "stock, bench only (unlocked core)",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
"generator": "v2",
"mh_s": 127.71,
"watts": 226.8,
"mh_per_w": 0.563,
"miner": "Igneum Miner 0.3.13 + Ember Tune kit 6 (mining, class v3 program)",
"date": "2026-10-06",
"source": "bench log: 6 October 2026, 16:01Z, Ember run 6 (ember-tune-pc1-6)",
"by": "measured by the team",
"note": "against 127.9 MH/s at 311.0 W untuned (0.411 MH/W): 84 W saved for 0.15 percent of rate; the ladder's floor, not yet its optimum",
"v4_cost": "as the row above",
"tuned": "full Ember Tune: 1,854 MHz core lock at the 100 percent cap",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "NVIDIA RTX 4070 (12 GB)",
"generator": "v2",
"mh_s": 30.95,
"watts": 79.5,
"mh_per_w": 0.389,
"miner": "igneum-worker-cuda bench (installed worker), class v3 control",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the RTX 4070 rows (job run-ca3-pc1-4070-shadow-20261006)",
"by": "measured by the team",
"note": "79.3 to 79.8 W at the tune point; 28.78 MH/s at 75.6 W (0.381) in Ember run 6 mining",
"v4_cost": "+30 W (79 to 109 W) for +0.4 percent of rate at 102,100 ops per hash, measured 6 October 2026",
"tuned": "full Ember Tune: 1,860 MHz core lock, 160 W cap (Ember run 6: 1,863 MHz at the 50 percent cap, 75.6 W)",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "AMD Radeon RX 9070 XT (16 GB)",
"generator": "v2",
"mh_s": 18.92,
"watts": 199,
"mh_per_w": 0.095,
"miner": "igneum-worker-opencl bench (installed worker), class v3 control",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the RX 9070 XT rows (job run-ca3-pc1-amd-g1-shadow-20261006); watts from the app's telemetry read of 5 October 2026 (the job's ADLX sample parsed 0 rows)",
"by": "measured by the team",
"note": "the card sits at 87 to 95 percent of its dependent random-read ceiling (2.42 to 2.68 G loads/s), in a Thunderbolt enclosure; AMD OpenCL 3683.0",
"v4_cost": "+2 percent of rate (19.29 against 18.92 MH/s) at 102,100 ops per hash, watts owed, measured 6 October 2026",
"tuned": "stock, bench only (the AMD tune pass runs 7 October: set only if the ADLX tune line reads, else measure-only)",
"driver_os": "Adrenalin 26.9.2, Windows 11"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
"generator": "v2",
"mh_s": 27.0,
"watts": 21,
"mh_per_w": 1.29,
"miner": "igneum-miner Metal worker, class v3 program",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the Mac rows (IOReport GPU and DRAM watts)",
"by": "measured by the team",
"note": "GPU plus DRAM watts, not wall",
"v4_cost": "+16 W for 1.5 percent of rate at 102,100 ops per hash, measured 6 October 2026",
"tuned": "no lever on Apple silicon (no clock or power control exposed); stock",
"driver_os": "macOS, Metal"
},
{
"card": "Intel Arc B580 (12 GB)",
"generator": "v2",
"mh_s": 11.0,
"watts": null,
"mh_per_w": null,
"miner": "igneum-worker-opencl bench, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the Intel Arc B580 (eGPU equals slot)",
"by": "measured by the team",
"note": "the same rate in the Thunderbolt enclosure and the slot; watts not read on this run",
"v4_cost": "0.1 percent of rate, measured 7 October 2026",
"tuned": "stock, bench only",
"driver_os": "Intel driver, Windows 11"
},
{
"card": "NVIDIA H100 SXM (80 GB)",
"generator": "v2",
"mh_s": 248.7,
"watts": 385.6,
"mh_per_w": 0.645,
"miner": "igneum-worker-cuda bench (Linux), class v3 control",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep, a rented card)",
"by": "measured by the fleet",
"note": "424.0 W maximum; 98 percent of its random-read ceiling like the 5090; 1.78x the 5090's hash at 1.15x the tuned 5090's hash per watt and a third of the hash per rented dollar",
"v4_cost": "not measured",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.126.09, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5080 (16 GB)",
"generator": "v2",
"mh_s": 71.16,
"watts": 143.4,
"mh_per_w": 0.496,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "148.6 W maximum; the team's own 5080 on a dock reads 60 MH/s warming and gets its full Ember Tune on 7 October",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3070 Ti (8 GB)",
"generator": "v2",
"mh_s": 38.98,
"watts": 178.3,
"mh_per_w": 0.219,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 595.71.05, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3070 (8 GB)",
"generator": "v2",
"mh_s": 33.66,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's 0.3.21 wipe canary (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "the 0.3.21 wipe canary's status line, 17:07Z, beside its node; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3080 (10 GB)",
"generator": "v2",
"mh_s": 43.72,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026) and the sweep's hands row",
"by": "reported by the fleet",
"note": "a standing voter's status line, 18:00Z; the hands row of the sweep reads 40.82 MH/s at 204.9 W; 10 GB, no prover",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3080 Ti (12 GB)",
"generator": "v2",
"mh_s": 58.95,
"watts": 267.3,
"mh_per_w": 0.221,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "283.0 W maximum",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3090 (24 GB)",
"generator": "v2",
"mh_s": 50.04,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voters (status lines, 7 October 2026)",
"by": "reported by the fleet",
"note": "the best of four standing voters this hour (42.2 to 50.0 MH/s) beside their provers; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3090 Ti (24 GB)",
"generator": "v2",
"mh_s": 61.95,
"watts": 249.5,
"mh_per_w": 0.248,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4090 (24 GB)",
"generator": "v2",
"mh_s": 52.25,
"watts": 183.1,
"mh_per_w": 0.285,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the RTX 4090 hands row",
"by": "measured by the fleet",
"note": "the hands row: the card mines and proves (17.4 GB peak while proving); the standing 4090 voters read 44.5 to 50.8 MH/s this hour beside their provers",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5090 (32 GB), fleet",
"generator": "v2",
"mh_s": 100.6,
"watts": 308,
"mh_per_w": 0.327,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "a standing voter's status beside its prover, 18:00Z; 122 MH/s at 308 W earlier in the day (0.396 MH/W); the team's own 5090 rows above",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3060 (12 GB)",
"generator": "v2",
"mh_s": 26.89,
"watts": 111.6,
"mh_per_w": 0.241,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "114.5 W maximum; the Devnet 3 boxes read 23.7 to 25.7 MH/s beside their nodes",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.126.09, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3060 Ti (8 GB)",
"generator": "v2",
"mh_s": 33.1,
"watts": 129.5,
"mh_per_w": 0.256,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4060 Ti (8 GB)",
"generator": "v2",
"mh_s": 20.1,
"watts": 77.5,
"mh_per_w": 0.259,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4070 Ti (12 GB)",
"generator": "v2",
"mh_s": 31.26,
"watts": 107.3,
"mh_per_w": 0.291,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5060 (8 GB)",
"generator": "v2",
"mh_s": 31.27,
"watts": 75.4,
"mh_per_w": 0.415,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5070 (12 GB)",
"generator": "v2",
"mh_s": 52.01,
"watts": 102.8,
"mh_per_w": 0.506,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5070 Ti (16 GB)",
"generator": "v2",
"mh_s": 78.43,
"watts": 145.6,
"mh_per_w": 0.539,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX A5000 (24 GB)",
"generator": "v2",
"mh_s": 47.64,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "a standing voter's status line, 18:00Z; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA L40S (48 GB)",
"generator": "v2",
"mh_s": 56.36,
"watts": 240.7,
"mh_per_w": 0.234,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA A100 PCIe (80 GB)",
"generator": "v2",
"mh_s": 154.97,
"watts": 299.6,
"mh_per_w": 0.517,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA A100 SXM (80 GB)",
"generator": "v2",
"mh_s": 138.39,
"watts": 266.3,
"mh_per_w": 0.52,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA H200 SXM (141 GB)",
"generator": "v2",
"mh_s": 313.04,
"watts": 432.9,
"mh_per_w": 0.723,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA B200 (180 GB)",
"generator": "v2",
"mh_s": 416.35,
"watts": 855.6,
"mh_per_w": 0.487,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX PRO 6000 Blackwell (96 GB)",
"generator": "v2",
"mh_s": 130.49,
"watts": 288.7,
"mh_per_w": 0.452,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
}
]
}

File diff suppressed because one or more lines are too long

View file

@ -110,7 +110,7 @@ case "${CARGO_ARGS[0]:-build}" in
*) SCHED_CLASS=build ;;
esac
if [ "$PRIORITY" = gate ]; then BR_NICE=0; BR_CORES=0; BR_JOBS_CAP=0
elif [ "$SCHED_CLASS" = suite ] || [ "$SCHED_CLASS" = bench ]; then BR_NICE=10; BR_CORES=32; BR_JOBS_CAP=32; fi
elif [ "$SCHED_CLASS" = suite ] || [ "$SCHED_CLASS" = bench ]; then BR_NICE=10; BR_CORES="${IGNEUM_BOUND_CORES:-88}"; BR_JOBS_CAP="${IGNEUM_BOUND_CORES:-88}"; fi # the project lead, 7 Oct 2026 19:4x BST: load both boxes to near max; 88 of 96, 8 reserved
# an explicit --jobs above the bounded class's cap is clamped (main's rule: bounded unless a priority flag; 7 Oct 2026: two suites
# ran at -j 90 on a box at load 190 because their callers passed --jobs 90)
if [ "$BR_JOBS_CAP" -gt 0 ] && [ -n "$JOBS" ] && [ "$JOBS" -gt "$BR_JOBS_CAP" ]; then bs_log "--jobs $JOBS clamped to $BR_JOBS_CAP for a $SCHED_CLASS (pass --priority gate for the full set)"; JOBS=$BR_JOBS_CAP; fi
@ -132,7 +132,7 @@ bs_context
if [ "$BS_CRATE_REL" = proving/igneum-prove ] && [ -z "${BOX_GIVEN:-}" ] && [ "$PRIORITY" != gate ]; then bs_route_spill prove; [ "$BS_ROUTE_BOX" != "$BOX" ] && { BOX=$BS_ROUTE_BOX; bs_host "$BOX"; }; fi
# box 2 keeps the suites' numbers: everything that lands there runs at the bounded class (nice 10, a 32-core band, -j 32), builds
# and gates included (main, 7 Oct 2026); a gate still takes its slot ahead of queued suites
if [ "$BOX" = 2 ] && [ "$BR_CORES" = 0 ]; then BR_NICE=10; BR_CORES=32; BR_JOBS_CAP=32; export BR_NICE BR_CORES BR_JOBS_CAP; bs_log "bounded on box 2 (nice 10, a 32-core band, -j 32) so a suite beside it keeps its number"; fi
if [ "$BOX" = 2 ] && [ "$BR_CORES" = 0 ]; then BR_NICE=10; BR_CORES="${IGNEUM_BOUND_CORES:-88}"; BR_JOBS_CAP="${IGNEUM_BOUND_CORES:-88}"; export BR_NICE BR_CORES BR_JOBS_CAP; bs_log "bounded on box 2 (nice 10, the ${BR_CORES}-core band, -j $BR_JOBS_CAP) so a suite beside it keeps its number"; fi
if [ "$BR_JOBS_CAP" -gt 0 ] && [ -n "$JOBS" ] && [ "$JOBS" -gt "$BR_JOBS_CAP" ]; then bs_log "--jobs $JOBS clamped to $BR_JOBS_CAP on box $BOX"; JOBS=$BR_JOBS_CAP; fi
bs_log "box $BOX ($BS_HOST) for class $SCHED_CLASS, priority $PRIORITY$( [ "${BR_ROUTE_SPILLED:-0}" = 1 ] && echo ", SPILLED from box $BR_ROUTE_PREF")"
@ -255,6 +255,9 @@ if [ "$FETCH" = 1 ] && [ -n "$ARTEFACTS" ]; then
bs_log "artefact $dest: $(bs_size "$dest") bytes, sha256 $(bs_sha256 "$dest"), $(file -b "$dest" | cut -c1-60)"
# the commit-string gate (rule of 6 October 2026): a node binary without its commit in its strings fails the run
case "$BS_KIND:$(basename "$dest")" in node:igneumd) "$HERE/ci/commit-string-check.sh" "$dest" "$BS_SHA" || bs_die "commit-string gate failed for $a" ;; esac # only kaspad depends on kaspa-build-info
# the engine gate (7 Oct 2026, the Devnet 3 start): igneumd and igneum-miner must carry igneum-pow/src/ paths; a commit string
# alone does not prove the engine (a stub-engine 21d8f454 rejected every mined block on the fleet's hub)
case "$BS_KIND:$(basename "$dest")" in node:igneumd|node:igneum-miner) [ "${IGNEUM_ALLOW_STUB:-}" = 1 ] || "$HERE/ci/engine-check.sh" "$dest" || bs_die "engine gate failed for $a (IGNEUM_ALLOW_STUB=1 to fetch a stub-engine binary on purpose)" ;; esac
# the glibc ceiling of anything that ships (main, 7 Oct 2026): a seed or a rig refuses a binary needing more than 2.36
if [ "$SHIP" = 1 ]; then "$HERE/ci/glibc-ceiling-check.sh" "$dest" "$GLIBC" || bs_die "glibc ceiling gate failed for $a"; fi
done

View file

@ -1,6 +1,6 @@
#!/usr/bin/env bash
# The scheduling classes of tools/build-remote.sh (main, 7 October 2026, the load-190 night): a build-remote call WITHOUT a priority
# flag must put every suite (cargo test) and bench (cargo bench) into the bounded class, nice 10 on 32 cores with -j 32, while a
# flag must put every suite (cargo test) and bench (cargo bench) into the bounded class, nice 10 on 88 cores with -j 88 (the project lead, 7 Oct 2026 19:4x BST: both boxes to near max, 8 cores reserved), while a
# build keeps the box's own jobs rule and --priority gate gives nice 0 on the full set. This check runs the tool's --plan mode (no box,
# no crate) for the four shapes and compares the resolved class; a change that lets a bare `cargo test` run unbounded again fails it.
#
@ -14,8 +14,8 @@ expect() { # <expected line> <args...>
if [ "$got" = "$want" ]; then echo "build-kind: [$*] -> $got"; else echo "build-kind: [$*] resolved to '$got', expected '$want'" >&2; return 1; fi
}
fail=0
expect 'kind=suite nice=10 cores=32 jobs=32 priority=normal' -- test -p kaspa-consensus-core --lib || fail=1
expect 'kind=bench nice=10 cores=32 jobs=32 priority=normal' -- bench -p igneum-pow || fail=1
expect 'kind=suite nice=10 cores=88 jobs=88 priority=normal' -- test -p kaspa-consensus-core --lib || fail=1
expect 'kind=bench nice=10 cores=88 jobs=88 priority=normal' -- bench -p igneum-pow || fail=1
expect 'kind=build nice=0 cores=96 jobs=box priority=normal' -- build --release -p kaspad || fail=1
expect 'kind=gate nice=0 cores=96 jobs=box priority=gate' --priority gate -- test -p igneum-app || fail=1
expect 'kind=check nice=0 cores=96 jobs=box priority=normal' -- check || fail=1

32
tools/ci/engine-check.sh Executable file
View file

@ -0,0 +1,32 @@
#!/usr/bin/env bash
# The engine gate (7 October 2026, the Devnet 3 start): a 21d8f454 igneumd with its commit string twice but ZERO igneum-pow/src/
# paths was placed in the artefact folder by a build outside the app tree; the fleet's hub ran it, the igneum-pow miner's blocks
# were every one rejected (Reject(BlockInvalid)), the go stopped. The commit-string gate cannot see this: the string comes from the
# fork's own git, the engine from the igneum-pow tree the build sat next to. So every igneumd and igneum-miner that
# tools/build-remote.sh fetches must carry igneum-pow source paths in its strings (rustc embeds the panic locations of the engine
# crate it compiled in: igneum-pow/src/..., or igneum-pow-amend/src/... when the fork pairs through its paths override); none means
# the stub engine or no paired tree, and the fetch refuses; the matched directory name is printed so the pairing is visible.
#
# tools/ci/engine-check.sh <binary> # exit 0 with the count, exit 1 "no igneum-pow/src/ path in <binary>"
# tools/ci/engine-check.sh --self-test # a fixture with the paths passes, one without fails
set -euo pipefail
if [ "${1:-}" = --self-test ]; then
t=$(mktemp -d); trap 'rm -rf "$t"' EXIT
printf 'binary junk\0/srv/builds/x/igneum-pow/src/lib.rs\0more junk\0igneum-pow/src/lottery.rs\0' > "$t/good"
printf 'binary junk\0/srv/builds/x/igneum-pow-amend/src/lib.rs\0igneum-pow-amend/src/lottery.rs\0' > "$t/amend"
printf 'binary junk\0/srv/builds/x/consensus/pow/src/stub.rs\0commit 21d8f454\0' > "$t/bad"
out=$("$0" "$t/good") || { echo "engine-check self-test: a binary WITH igneum-pow/src/ paths was refused"; exit 1; }
case "$out" in *"igneum-pow/src/ 2 paths"*) ;; *) echo "engine-check self-test: the matched directory is not printed: $out"; exit 1 ;; esac
out=$("$0" "$t/amend") || { echo "engine-check self-test: a binary paired through igneum-pow-amend/src/ was refused"; exit 1; }
case "$out" in *"igneum-pow-amend/src/ 2 paths"*) ;; *) echo "engine-check self-test: the amend directory is not printed: $out"; exit 1 ;; esac
if "$0" "$t/bad" >/dev/null 2>&1; then echo "engine-check self-test: a binary WITHOUT igneum-pow paths passed"; exit 1; fi
echo "engine-check self-test: igneum-pow/src/ and igneum-pow-amend/src/ pass with the directory named, a binary without is refused"; exit 0
fi
f="${1:-}"; [ -f "$f" ] || { echo "engine-check: no file '$f'" >&2; exit 2; }
# any directory name beginning igneum-pow and ending /src/ (the fork pairs its pow through a paths override that may name the tree
# igneum-pow-amend, the archive of 017e7037; the shipper, 7 Oct 2026); the matched name is printed so the pairing is visible
dirs=$(LC_ALL=C grep -a -oE 'igneum-pow[A-Za-z0-9._-]*/src/' "$f" | sort | uniq -c | awk '{printf "%s %s paths; ", $2, $1}')
n=$(LC_ALL=C grep -a -c -E 'igneum-pow[A-Za-z0-9._-]*/src/' "$f" || true)
if [ "${n:-0}" -gt 0 ]; then echo "engine-check: $(basename "$f") paired: ${dirs% }"; exit 0; fi
echo "engine-check: no igneum-pow*/src/ path in $(basename "$f"): the stub engine or no paired igneum-pow tree (the commit string alone does not prove the engine; 7 Oct 2026 Devnet 3)" >&2
exit 1

View file

@ -96,6 +96,7 @@ tree_checks() {
run "pinned guest programs match their manifest" bash tools/ci/pinned-guests-check.sh
run "root prover playbooks kill the GPU server and unlink its socket" bash tools/ci/prover-socket-check.sh
run "commit-string gate self-test" bash tools/ci/commit-string-check.sh --self-test
run "engine gate self-test (igneumd and igneum-miner must carry igneum-pow/src/ paths)" bash tools/ci/engine-check.sh --self-test
run "build server remote checkout self-test" bash infra/build-server/remote-run.sh --self-test
run "a slot holder keeps its own line for the whole run (the watcher-trust rule)" bash infra/build-server/remote-run.sh --self-test-keeper
run "the remote checkout resets the mirror's tree before the branch checkout (the stale-overlay class)" bash -c 'bash tools/ci/mirror-reset-check.sh --self-test && bash tools/ci/mirror-reset-check.sh'
@ -105,6 +106,7 @@ tree_checks() {
run "the class router is a preference with spill-over (a held or overloaded box hands the job to the other one)" bash tools/ci/route-spill-check.sh
run "per-core leases, the quiet class and the reaper pass on the box (lease.sh and remote-run.sh self-tests over ssh)" bash tools/ci/box-locks-check.sh $( [ "$MODE" = ci ] && echo --ci )
run "the simulators job runs on master and release-* pushes and pull requests into them only" bash tools/ci/sims-branch-check.sh
run "publish-jobs.sh never removes a running or installs-app job without --force (the PC 2 abort class)" bash tools/ci/publish-jobs-check.sh
run "no shell assignment hides behind a trailing comment (the swallowed-defaults class)" bash -c 'bash tools/ci/defaults-line-check.sh --self-test && bash tools/ci/defaults-line-check.sh'
run "no script kills or finds a process by a plain name or a file name (pgrep/pkill -f literals, ps | grep)" bash -c 'bash tools/ci/kill-by-name-check.sh --self-test && bash tools/ci/kill-by-name-check.sh'
run "the identity check's own self-test (excluded research path passes, exported leak fails)" bash tools/ci/identity-check.sh --self-test

30
tools/ci/publish-jobs-check.sh Executable file
View file

@ -0,0 +1,30 @@
#!/usr/bin/env bash
# The removal guard of packaging/ota/publish-jobs.sh (7 October 2026, 18:53 BST: a removal reached PC 2 one second after its job had
# launched a silent installer over the running app; the runner's abort-on-removal ended the process tree and the app went dark).
# A remove must refuse while any target's report shows the job started with no final line, and refuse a job published with
# --installs-app; --force "<reason>" overrides. The check runs the script against a scratch destination (--dest) with the
# machine read replaced by a fixture (REMOVE_GUARD_READ), so nothing is published and no machine is read.
#
# tools/ci/publish-jobs-check.sh # exit 1 with the case that resolved wrongly (the check IS its self-test)
set -euo pipefail
cd "$(dirname "$0")/../.."
t=$(mktemp -d); trap 'rm -rf "$t"' EXIT
mkdir -p "$t/dest"; export IGNEUM_DLSITE="$t/site"; mkdir -p "$t/site/dl/testtoken"
P="packaging/ota/publish-jobs.sh"
# the real OTA key signs into the scratch --dest (as packaging/ota/test-publish-jobs.sh does; nothing is deployed, the downloads
# folder is untouched); a machine without the key or the signer skips the check as not applicable
[ -f "$HOME/.config/igneum/ota-signing-key" ] && [ -x app/igneum-app/target/release/igneum-ota-sign ] || { echo "publish-jobs-check: no OTA key or signer here; skipped as not applicable"; exit 0; }
printf 'echo hi\n' > "$t/s.ps1"
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-run --title t --requires none --dest "$t/dest" >/dev/null 2>&1 || { echo "publish-jobs-check: add failed"; exit 1; }
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-install --installs-app --title t --requires none --dest "$t/dest" >/dev/null 2>&1 || { echo "publish-jobs-check: add --installs-app failed"; exit 1; }
grep -q '"installs_app":true' "$t/dest/igneum-jobs.json" || { echo "publish-jobs-check: --installs-app did not write the param"; exit 1; }
fail=0
printf 'job guard-run (run) on PC machine 0000000100000000 run job-guard-run-00000001, started 2026-10-07T18:00:00Z\n== running the powershell script (cap 40 min) ==\nRESULT start\n' > "$t/running.txt"
printf 'SUMMARY: done exit 0, started 2026-10-07T18:00:00Z, finished 2026-10-07T18:00:09Z, 9 s: script finished, exit 0\njob guard-run: done (exit 0) after 9 s: script finished\n' > "$t/done.txt"
if REMOVE_GUARD_READ="$t/running.txt" bash "$P" remove guard-run --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: a RUNNING job was removed"; fail=1; else echo "publish-jobs-check: a running job's removal is refused"; fi
if REMOVE_GUARD_READ="$t/running.txt" bash "$P" remove guard-run --dest "$t/dest" --force "test" >/dev/null 2>&1; then echo "publish-jobs-check: --force removes a running job (with the reason)"; else echo "publish-jobs-check: --force did not remove"; fail=1; fi
if REMOVE_GUARD_READ="$t/done.txt" bash "$P" remove guard-install --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: an --installs-app job was removed without --force"; fail=1; else echo "publish-jobs-check: an --installs-app job's removal is refused"; fi
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-run2 --title t --requires none --dest "$t/dest" >/dev/null 2>&1
if REMOVE_GUARD_READ="$t/done.txt" bash "$P" remove guard-run2 --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: a finished job's removal passes"; else echo "publish-jobs-check: a finished job's removal was refused"; fail=1; fi
[ "$fail" = 0 ] && echo "publish-jobs-check: a running or installs-app job is never removed without --force; a finished one is"
exit $fail

View file

@ -1,7 +1,7 @@
#!/usr/bin/env bash
# The spill-over router of tools/build-remote.sh (lib.sh bs_route_spill; the project lead, 7 October 2026, 15:02 UK: build-1 at load 139 with a
# queue of 1 h 40 min while build-2 sat at 4.5 with free slots). The class is a preference: a job goes to its class's box unless
# that box has no free slot or its 1-minute load is above 64, in which case it goes to the other box when that one qualifies, else
# that box has no free slot or its 1-minute load is above 80 (was 64), in which case it goes to the other box when that one qualifies, else
# it queues on its own box. This check feeds the router fixed box states through BS_ROUTE_STATE_<n> (no ssh) and host files in a
# scratch directory, and compares the chosen box and the spilled flag for the known cases: a held build-1 selects build-2, a free
# build-1 selects build-1, an overloaded build-1 spills, a held build-2 sends a suite to build-1, two full boxes queue on the
@ -22,17 +22,18 @@ expect() { # <case> <class> <want box> <want spilled> ; the states come from t
}
BS_ROUTE_STATE_1="free=0 slots=2 load1=30" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a held build-1 selects build-2" build 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=20" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a free build-1 selects build-1" build 1 0
BS_ROUTE_STATE_1="free=2 slots=2 load1=70" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "an overloaded build-1 spills" build 2 1
BS_ROUTE_STATE_1="free=2 slots=2 load1=95" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "an overloaded build-1 spills" build 2 1
BS_ROUTE_STATE_1="free=0 slots=2 load1=30" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a gate spills like a build" gate 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=0 slots=3 load1=10" expect "a held build-2 sends a suite to build-1" suite 1 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=1 slots=3 load1=90" expect "an overloaded build-2 sends a bench away" bench 1 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=1 slots=3 load1=120" expect "an overloaded build-2 sends a bench away" bench 1 1
BS_ROUTE_STATE_1="free=2 slots=2 load1=5" BS_ROUTE_STATE_2="free=2 slots=3 load1=10" expect "a free build-2 keeps its suite" suite 2 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=80" BS_ROUTE_STATE_2="free=0 slots=3 load1=90" expect "two full boxes queue a build on build-1" build 1 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=80" BS_ROUTE_STATE_2="free=0 slots=3 load1=90" expect "two full boxes queue a suite on build-2" suite 2 0
BS_ROUTE_STATE_1="down" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a build-1 that is down spills" build 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a proving class with no box 3 prefers box 1" prove 1 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=5" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a proving class spills to box 2 when box 1 is held" prove 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=64" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load exactly 64 is under the line" build 1 0
BS_ROUTE_STATE_1="free=1 slots=2 load1=80" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load exactly 80 is under the line" build 1 0
BS_ROUTE_STATE_1="free=2 slots=2 load1=70" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load 70 stays on build-1 (the line is 80)" build 1 0
# the ssh path itself under the hook's shell (/bin/bash is 3.2 on the Mac; the pool lane found `BS_SSH_OPTS[@]: unbound variable`
# at the first unpinned route, 7 Oct 2026): a host file pointing at a port nothing answers on must read "down" in a few seconds,
# not die on an unset array