release 0.3.14: the recovery on the shipped binary (the snapshot flag, the three traps), the two new items for the fix

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-06 16:19:50 +00:00
parent 5f23b03438
commit 7fecaf7d01

View file

@ -17,7 +17,10 @@ devnet's pruning point had moved from bb45cf0d (DAA 45,537) to eb2a5d70 (DAA 88,
|---|---|---|
| A deep reorg never replays from genesis on a pruned node: the follower unwinds through its persisted generations, else requests a peer's snapshot (protocol 16); a good snapshot is never overwritten by a tip-0 one | the proving agent's fix branch off bb43e9a8 | (pending) |
| A moved pruning point does not strand the anchor: a node keeps executing from its persisted state; the anchor is for a node with nothing | the same | (pending) |
| The six version files | (the bump commit) | |
| A flag file (`--igneum-exec-snapshot`) that cannot be read or whose sha does not match fails loudly at start (on the seed, as user igneum, a file under /root was ignored silently and the node replayed genesis, 16:16Z) | the proving agent's branch | (pending) |
| The p2p snapshot path refuses a snapshot at or below the node's own tip, below the restart, or at tip 0 (the seed pulled and loaded a 2,629-byte tip-0 snapshot from a fleet box at 16:16:30Z) | the same | (pending) |
| The hands' and the seed's restart scripts: `IGNEUMD_EXEC_SNAPSHOT` / `IGNEUMD_EXEC_SNAPSHOT_FILE` (the flag; on the seed the file installed for the igneum user under `/var/lib/igneum-v4`, the quoted `EXTRA_ARGS`) and `IGNEUM_EXEC_RESET` (the persisted exec files deleted after the stop); node 1 on its own eth port 26791 | 32e004f, 0585b9e, db1205b, dd9044e, 08ddee7 (this branch; `release-0.3.13` carries the 26791 line only) | in |
| The six version files | 4b25760 | in |
No re-pin of the anchor (the coordinator's decision). If the fix is code-only the object is CARRIED OVER (the thirteen-field one, digest
b18ed271... unchanged) and this is ONE publish; if a field changes, the 0.3.12 two-publish shape.
@ -38,4 +41,16 @@ object is carried over).
## 4. The rollout (to fill at the go)
## 4a. The recovery on the shipped binary (16:11 to 16:18Z), before this cut
The proving agent's export of node 1's copy (13:45Z: tip chain block 130,272, 4,612 blocks below the fork point, 114,830,936 bytes, sha256
ac101f13576179fd7d7f5e8ee902c9a7b6cc47730e3a3c069f389f0ca46d9221) loaded through `--igneum-exec-snapshot=<file>,0x<sha>` after the persisted
tip-0 files were deleted: the observer 16:11:18Z (`startedFrom snapshot`, `eth_blockNumber` 136,415 at 16:12:03Z and climbing, blocked null,
paidShards 1,482, paidWei 1825.699240038 IGN), node 1 16:11:32Z (136,459, on 26791), the seed 16:18:01Z (136,636). Three traps on the way:
the hands script's `pgrep -f` matched the caller's own shell when the pattern's text sat in the command (11 minutes lost; a rule: a
restart script's pattern never appears in the caller's command line, and `pgrep` excludes the caller); the seed's env file is sourced, so an
unquoted `EXTRA_ARGS` with a space ran the flag as a command and the unit crash-looped eight times (the seed off the air 16:14 to 16:16Z);
the unit's user could not read a file under `/root` and the flag did nothing, silently. The PCs and the fleet's boxes stay at 0 until this
cut or the same manual recovery (the fleet agent has the recipe; the PCs' app node takes no flag).
## 5. Owed