From a804866781ef532e0b5a862d0c3c96a794fcd4d3 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Tue, 6 Oct 2026 16:19:50 +0000 Subject: [PATCH] release 0.3.14: the recovery on the shipped binary (the snapshot flag, the three traps), the two new items for the fix Co-Authored-By: Claude Fable 5.1 --- docs/plans/release-0.3.14.md | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/docs/plans/release-0.3.14.md b/docs/plans/release-0.3.14.md index d396f1e27..8da45c1e2 100644 --- a/docs/plans/release-0.3.14.md +++ b/docs/plans/release-0.3.14.md @@ -17,7 +17,10 @@ devnet's pruning point had moved from bb45cf0d (DAA 45,537) to eb2a5d70 (DAA 88, |---|---|---| | A deep reorg never replays from genesis on a pruned node: the follower unwinds through its persisted generations, else requests a peer's snapshot (protocol 16); a good snapshot is never overwritten by a tip-0 one | the proving agent's fix branch off bb43e9a8 | (pending) | | A moved pruning point does not strand the anchor: a node keeps executing from its persisted state; the anchor is for a node with nothing | the same | (pending) | -| The six version files | (the bump commit) | | +| A flag file (`--igneum-exec-snapshot`) that cannot be read or whose sha does not match fails loudly at start (on the seed, as user igneum, a file under /root was ignored silently and the node replayed genesis, 16:16Z) | the proving agent's branch | (pending) | +| The p2p snapshot path refuses a snapshot at or below the node's own tip, below the restart, or at tip 0 (the seed pulled and loaded a 2,629-byte tip-0 snapshot from a fleet box at 16:16:30Z) | the same | (pending) | +| The hands' and the seed's restart scripts: `IGNEUMD_EXEC_SNAPSHOT` / `IGNEUMD_EXEC_SNAPSHOT_FILE` (the flag; on the seed the file installed for the igneum user under `/var/lib/igneum-v4`, the quoted `EXTRA_ARGS`) and `IGNEUM_EXEC_RESET` (the persisted exec files deleted after the stop); node 1 on its own eth port 26791 | 32e004f, 0585b9e, db1205b, dd9044e, 08ddee7 (this branch; `release-0.3.13` carries the 26791 line only) | in | +| The six version files | 4b25760 | in | No re-pin of the anchor (the coordinator's decision). If the fix is code-only the object is CARRIED OVER (the thirteen-field one, digest b18ed271... unchanged) and this is ONE publish; if a field changes, the 0.3.12 two-publish shape. @@ -38,4 +41,16 @@ object is carried over). ## 4. The rollout (to fill at the go) +## 4a. The recovery on the shipped binary (16:11 to 16:18Z), before this cut + +The proving agent's export of node 1's copy (13:45Z: tip chain block 130,272, 4,612 blocks below the fork point, 114,830,936 bytes, sha256 +ac101f13576179fd7d7f5e8ee902c9a7b6cc47730e3a3c069f389f0ca46d9221) loaded through `--igneum-exec-snapshot=,0x` after the persisted +tip-0 files were deleted: the observer 16:11:18Z (`startedFrom snapshot`, `eth_blockNumber` 136,415 at 16:12:03Z and climbing, blocked null, +paidShards 1,482, paidWei 1825.699240038 IGN), node 1 16:11:32Z (136,459, on 26791), the seed 16:18:01Z (136,636). Three traps on the way: +the hands script's `pgrep -f` matched the caller's own shell when the pattern's text sat in the command (11 minutes lost; a rule: a +restart script's pattern never appears in the caller's command line, and `pgrep` excludes the caller); the seed's env file is sourced, so an +unquoted `EXTRA_ARGS` with a space ran the flag as a command and the unit crash-looped eight times (the seed off the air 16:14 to 16:16Z); +the unit's user could not read a file under `/root` and the flag did nothing, silently. The PCs and the fleet's boxes stay at 0 until this +cut or the same manual recovery (the fleet agent has the recipe; the PCs' app node takes no flag). + ## 5. Owed