Relay: its own key (relay-key) replaces the intake key for the Mac tools and clients; relay token rotated 4 Oct 2026 (round 4, X23); prove package excludes cross-build folders

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-04 18:25:19 +00:00
parent 3d0c3faa38
commit 63174a5b6a
5 changed files with 7 additions and 9 deletions

View file

@ -10,7 +10,7 @@ STAGE="$(mktemp -d)/igneum-prove-wsl2"
PKG="$STAGE/package"
mkdir -p "$PKG/proving" "$PKG/vendor/igneum-node-exec/igneum"
cp "$HERE/SETUP-PROVER.bat" "$HERE/setup-prover.ps1" "$HERE/setup-wsl.sh" "$HERE/prove-block.sh" "$HERE/PROVE-BLOCK.bat" "$HERE/prove-shard.sh" "$HERE/PROVE-SHARD.bat" "$HERE/README.txt" "$STAGE/"
rsync -a --exclude target --exclude Cargo.lock "$ROOT/proving/igneum-prove" "$PKG/proving/"
rsync -a --exclude "target*" --exclude Cargo.lock "$ROOT/proving/igneum-prove" "$PKG/proving/"
cp "$ROOT/proving/igneum-prove/Cargo.lock" "$PKG/proving/igneum-prove/" 2>/dev/null || true
rsync -a "$ROOT/proving/fixtures" "$PKG/proving/"
rsync -a --exclude target "$ROOT/vendor/igneum-node-exec/igneum/evm-types" "$PKG/vendor/igneum-node-exec/igneum/"

View file

@ -4,8 +4,6 @@ Text, files and tasks between the project lead's devices without Gmail: the Mac,
**Scope since 4 October 2026 (afternoon):** the relay stays for the Mac and for humans (notes, files, tasks for a person or a Claude session on a PC). Commands and files for the PCs themselves go over the line to the Igneum Miner app instead: signed jobs published next to the update manifest (`packaging/ota/publish-jobs.sh`, read back with `tools/jobs.mjs`, documented in `packaging/ota/README.md`, "Remote jobs"). The app jobs replace the PC agent (`igneum-agent.bat`): PC 2 has no Claude session and nobody at the keyboard, and both PCs report the same hostname (DESKTOP-KMCV30N), which the relay's registration cannot tell apart; the app's per-install machine id can. The playbooks under `relay/playbooks/` stay as the relay form of the same runs (`shard-test.ps1` is the model for a `run` job) and are parse-checked by `windows.yml`.
**Scope since 4 October 2026 (afternoon):** the relay stays for the Mac and for humans (notes, files, tasks for a person or a Claude session on a PC). Commands and files for the PCs themselves go over the line to the Igneum Miner app instead: signed jobs published next to the update manifest (`packaging/ota/publish-jobs.sh`, read back with `tools/jobs.mjs`, documented in `packaging/ota/README.md`, "Remote jobs"). The app jobs replace the PC agent (`igneum-agent.bat`): PC 2 has no Claude session and nobody at the keyboard, and both PCs report the same hostname (DESKTOP-KMCV30N), which the relay's registration cannot tell apart; the app's per-install machine id can. The playbooks under `relay/playbooks/` stay as the relay form of the same runs (`shard-test.ps1` is the model for a `run` job) and are parse-checked by `windows.yml`.
## The console
| Tab | Shows | Source |
@ -35,7 +33,7 @@ The web page lives at `/r/<token>/` and every API call sits under `/r/<token>/ap
| Items (text, title, who, kind, flags, read and done marks) | Neon table `relay_items` (database `igneum`) | body 1 MB |
| Machines (name, hostname, role, GPU and WSL facts, last seen) | Neon table `relay_machines` | |
| Files | Vercel Blob store `igneum-relay` (public URLs with random path and suffix, London) | 50 MB per file through a client token; 4 MB when pushed through the function |
| The token and key | `~/.config/igneum/relay-token`, `~/.config/igneum/log-intake-key`; project env | never in the repo |
| The token and key | `~/.config/igneum/relay-token`, `~/.config/igneum/relay-key` (the relay's own key since 4 October 2026, round 4 X23; the log-intake key no longer opens the relay); project env | never in the repo |
Kinds: `text` (a note), `file`, `task` (for a person or a Claude session on a PC), `run` (a script the agent executes), `result` (what a task produced, linked by `task_id`). Roles: `miner`, `prover`, `bench`, `mac`, `phone`.

View file

@ -5,7 +5,7 @@ set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
CFG="$HOME/.config/igneum"
URL="$(cat "$CFG/relay-url" 2>/dev/null | tr -d '\n' || true)"; URL="${URL:-https://relay.igneum.network}"
KEY="$(tr -d '\n' < "$CFG/log-intake-key")"; TOKEN="$(tr -d '\n' < "$CFG/relay-token")"
KEY="$(tr -d '\n' < "$CFG/relay-key")"; TOKEN="$(tr -d '\n' < "$CFG/relay-token")"
OUT="${1:-$HOME/Desktop}"; mkdir -p "$OUT"
STAGE="$(mktemp -d)/igneum-relay-clients"; mkdir -p "$STAGE"
for f in send.bat send.ps1 send.sh igneum-agent.bat igneum-agent.ps1 agent.sh CLAUDE-PC.md; do

View file

@ -10,7 +10,7 @@
// node tools/console.mjs sync-hetzner push the newest infra/cloud-devnet/results/ summary
// node tools/console.mjs sync all three syncs
// node tools/console.mjs url the console URL
// Reads ~/.config/igneum/relay-token (the URL secret), log-intake-key (x-igneum-key), relay-url (optional),
// Reads ~/.config/igneum/relay-token (the URL secret), relay-key (x-igneum-key), relay-url (optional),
// dl-token and dlsite-dir (sync-dl). Zero dependencies.
import { readFileSync, readdirSync, statSync, existsSync } from 'node:fs';
import { homedir } from 'node:os';
@ -20,7 +20,7 @@ import { fileURLToPath } from 'node:url';
process.stdout.on('error', e => { if (e.code === 'EPIPE') process.exit(0); throw e; });
const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..');
const cfg = n => { try { return readFileSync(join(homedir(), '.config', 'igneum', n), 'utf8').trim(); } catch { return ''; } };
const TOKEN = cfg('relay-token'); const KEY = cfg('log-intake-key');
const TOKEN = cfg('relay-token'); const KEY = cfg('relay-key'); // the relay's own key since 4 Oct 2026 (round 4, X23)
const BASE = (cfg('relay-url') || 'https://relay.igneum.network').replace(/\/$/, '');
if (!TOKEN) { console.error('no ~/.config/igneum/relay-token'); process.exit(1); }
const API = `${BASE}/r/${TOKEN}/c/`;

View file

@ -10,7 +10,7 @@
// node tools/relay.mjs inbox <machine> [--ack] what that machine has not read yet
// node tools/relay.mjs machines | role <name> <miner|prover|bench|mac|phone> | name <hostname> <name>
// node tools/relay.mjs ack <id> | done <id> | rm <id> | url
// Reads ~/.config/igneum/relay-token (the URL secret), log-intake-key (x-igneum-key), dl-token (for __DL_BASE__ in
// Reads ~/.config/igneum/relay-token (the URL secret), relay-key (x-igneum-key), dl-token (for __DL_BASE__ in
// playbooks) and relay-url (optional, default https://relay.igneum.network). Zero dependencies.
import { readFileSync, writeFileSync, mkdirSync, existsSync, statSync } from 'node:fs';
import { homedir, tmpdir, hostname } from 'node:os';
@ -18,7 +18,7 @@ import { basename, join, resolve } from 'node:path';
process.stdout.on('error', e => { if (e.code === 'EPIPE') process.exit(0); throw e; });
const cfg = n => { try { return readFileSync(join(homedir(), '.config', 'igneum', n), 'utf8').trim(); } catch { return ''; } };
const TOKEN = cfg('relay-token'); const KEY = cfg('log-intake-key'); const DL = cfg('dl-token');
const TOKEN = cfg('relay-token'); const KEY = cfg('relay-key'); const DL = cfg('dl-token'); // relay-key is the relay's own key since 4 Oct 2026 (round 4, X23); the intake key no longer opens the relay
const BASE = (cfg('relay-url') || 'https://relay.igneum.network').replace(/\/$/, '');
if (!TOKEN) { console.error('no ~/.config/igneum/relay-token'); process.exit(1); }
const API = `${BASE}/r/${TOKEN}/api/`;