From b0fec5d5e944ae016729ef76f1b63550f20b28cf Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Mon, 5 Oct 2026 20:37:51 +0000 Subject: [PATCH] Rig installer for Ubuntu 24.04: install-rig.sh, the six units (node, miner@card, prover, telemetry, update timer), rig-status, the signed-manifest and package checks, the self-test; console accepts linux labels packaging/linux: preflight (Ubuntu 24.04, NVIDIA driver 580 floor with libcuda and libnvrtc.so.12, AMD ROCm OpenCL ICD, Intel compute runtime, nvidia-smi and the OpenCL list printed, RAM, free disk, ports, ufw), the wallet and rig name asked once, the igneum system user, the Ed25519 check of dl/public/igneum-app-latest.json with the OTA public key (OpenSSL 3 pkeyutl -rawin, python3 cryptography fallback, never skipped), consensus.override written from the verified manifest and refreshed hourly (the HiveOS override rule without a package republish), the HiveOS package downloaded with size and sha256 checked (the signed linux entry when the manifest has one, else the .sha256 sidecar behind --allow-sidecar-sha256, said in capitals), releases under /opt/igneum with a current symlink and a 90-s rollback, one miner unit per card with CUDA_DEVICE_ORDER=PCI_BUS_ID and the OpenCL ordinal mapping, the integrated GPU and the BMC VGA excluded by the inventory, the prover unit as the proving-v1 loop in bash (12 GB gate, 20 GB mine-and-prove line with the card's miner paused per shard through a sudoers rule, idles in state setup while no Linux prover binary is published), telemetry in the app's line shapes with the relay upload under nodelog-linux/miner-/linux labels, the identities rule with its 8 GiB threshold. Tested on the Mac: shellcheck -x -S style clean, bash -n, check-units.sh (6 units, the systemd-analyze stand-in; no systemd or Docker here), the inventory on a fake sysfs tree, the rules, the live manifest verified by both verifiers and tampered copies refused, the installer dry run with the 0.3.9 package downloaded and verified. Untested until a rig exists: listed in README.md. Co-Authored-By: Claude Fable 5.1 --- packaging/linux/README.md | 136 ++++++++ packaging/linux/bin/igneum-gpus.sh | 63 ++++ packaging/linux/bin/igneum-miner.sh | 81 +++++ packaging/linux/bin/igneum-node.sh | 20 ++ packaging/linux/bin/igneum-prover.sh | 141 ++++++++ packaging/linux/bin/igneum-rig-lib.sh | 301 +++++++++++++++++ packaging/linux/bin/igneum-telemetry.sh | 129 ++++++++ packaging/linux/bin/igneum-update.sh | 90 +++++ packaging/linux/bin/rig-status | 34 ++ packaging/linux/check-units.sh | 80 +++++ packaging/linux/install-rig.sh | 307 ++++++++++++++++++ packaging/linux/selftest.sh | 106 ++++++ packaging/linux/units/igneum-miner@.service | 35 ++ packaging/linux/units/igneum-node.service | 31 ++ packaging/linux/units/igneum-prover.service | 34 ++ .../linux/units/igneum-telemetry.service | 28 ++ packaging/linux/units/igneum-update.service | 16 + packaging/linux/units/igneum-update.timer | 12 + relay/api/console.mjs | 5 +- relay/lib/parse.mjs | 6 +- relay/test/parse.test.mjs | 4 + 21 files changed, 1655 insertions(+), 4 deletions(-) create mode 100644 packaging/linux/README.md create mode 100755 packaging/linux/bin/igneum-gpus.sh create mode 100755 packaging/linux/bin/igneum-miner.sh create mode 100755 packaging/linux/bin/igneum-node.sh create mode 100755 packaging/linux/bin/igneum-prover.sh create mode 100755 packaging/linux/bin/igneum-rig-lib.sh create mode 100755 packaging/linux/bin/igneum-telemetry.sh create mode 100755 packaging/linux/bin/igneum-update.sh create mode 100755 packaging/linux/bin/rig-status create mode 100755 packaging/linux/check-units.sh create mode 100755 packaging/linux/install-rig.sh create mode 100755 packaging/linux/selftest.sh create mode 100644 packaging/linux/units/igneum-miner@.service create mode 100644 packaging/linux/units/igneum-node.service create mode 100644 packaging/linux/units/igneum-prover.service create mode 100644 packaging/linux/units/igneum-telemetry.service create mode 100644 packaging/linux/units/igneum-update.service create mode 100644 packaging/linux/units/igneum-update.timer diff --git a/packaging/linux/README.md b/packaging/linux/README.md new file mode 100644 index 000000000..99d1663a0 --- /dev/null +++ b/packaging/linux/README.md @@ -0,0 +1,136 @@ +# Igneum rig on Ubuntu 24.04 + +`install-rig.sh` turns an Ubuntu 24.04 machine with up to eight GPUs into an Igneum mining rig run by systemd: +one node, one miner per card (CUDA on NVIDIA, OpenCL on AMD and Intel), a prover unit, a telemetry unit, an hourly +signed-manifest update timer and a `rig-status` command. Built on 5 October 2026 from the HiveOS package +(`packaging/hive`: the hooks, the glibc ceiling, the consensus override rule, the stop path and the sync wait learnt +on PC 1 that night) for the rig the project lead is building (Threadripper PRO, 4 RTX 5090 or 4090, 2 RX 9070 XT, 2 Arc B580, +NVIDIA driver 580 or newer; HiveOS is out because its image's driver predates the RTX 50 series). + +**Mining works from the package as published. Proving does not yet: the HiveOS package carries `igneumd`, +`igneum-miner` and the two workers, no `igneum-prove-host`, no `igneum-prove-export`, and its `igneum-miner` has no +`key-hash` or `sign-record` subcommand. The prover unit installs, decides by the per-card rule below, and then idles +in state `setup` naming what is missing. Until a Linux prover build is published, a rig mines only and the proving +share is earned from the app machines.** The same sentence belongs on the miners page (`site/miner.html` says the +card mines and proves) until the package carries the prover. + +**Nothing here has run on a rig.** Everything below marked tested ran on this Mac (no systemd, no GPU, no Docker) on +5 October 2026; the "untested until a rig exists" list is the truth of the state. + +## What the project lead types + +``` +git clone && cd igneum +sudo packaging/linux/install-rig.sh --wallet 0x<40 hex> --name rig1 --allow-sidecar-sha256 \ + [--relay-key-file ~/log-intake-key] [--network devnet|testnet] [--prover auto|on|off] +rig-status +``` + +Asked once when not given: the payout wallet (0x and 40 hex, an EVM address he holds the key for; lower-cased and +stored) and the rig name (letters, digits, `-` and `_`, up to 32; it labels the rig's vote keys as `-`, +its payouts, and the console card as `-`). Everything else has a default in `/etc/igneum/rig.conf` +(the file is written once and kept on re-runs; edit it, then `systemctl restart igneum-node`, the miners follow). + +`--allow-sidecar-sha256` is needed today: the signed public manifest names only the mac and windows builds, so the +package's sha256 comes from `igneum-downloads.json` and the `.sha256` sidecar on the same TLS host, unsigned. The +installer says so in capitals. The follow-up that removes the flag: `packaging/ota/publish-public.sh --hive` adds a +`platforms.linux` entry (url, sha256, size, kind) to the public app manifest and re-signs it; the apps ignore the +extra key (`manifest.rs parse` reads mac and windows only), and `install-rig.sh` and `igneum-update.sh` already +prefer that entry when it exists. `--package-url --package-sha256 --package-size` is the hand path. + +`--relay-key-file` installs the log-intake key (the same upload-only key every app ships) so the rig's journals reach +the console every 60 s; without it nothing leaves the rig. `--preflight-only` runs the checks alone; `--dry-run` +prints every step and only downloads into a scratch folder. + +## What the installer assumes + +| Assumption | Why | Checked by the preflight | +|---|---|---| +| Ubuntu 24.04 on x86_64 with systemd, OpenSSL 3 (or python3-cryptography), curl, python3, tar, flock, pciutils | the units, the Ed25519 check, the package (built with `GLIBC=2.27`: igneumd 2.27, miner 2.25, workers 2.17, read from the ELFs of 0.3.9) | yes; `--force` goes on anyway | +| NVIDIA driver 580 or newer, `libcuda.so.1` and `libnvrtc.so.12` on the library path | the project lead's floor for the RTX 50 series; the CUDA worker dlopens NVRTC 12 and compiles the hourly program (`infra/cross/build-workers-linux.sh`); a CUDA 13 toolkit's `libnvrtc.so.13` does not satisfy it | yes, failure | +| AMD: amdgpu bound, `libOpenCL.so.1`, an AMD ICD in `/etc/OpenCL/vendors` (ROCm 6.4 or newer for RDNA 4, kernel 6.11 or newer; both approximate) | the OpenCL worker compiles through the ICD | ICD and library failure, versions warning | +| Intel: xe (or i915) bound, `intel-opencl-icd` from Intel's compute-runtime repository (a 2025 release for Battlemage, kernel 6.12 or newer; approximate) | same | ICD failure, kernel warning | +| 20 GB free on /var/lib and /opt; 8 GB RAM to mine, 16 GB to prove | chain data under /var/lib/igneum/node, releases under /opt/igneum; the SP1 host side measured 2.3 GB inside WSL2 on 5 October 2026 (approximate for bare Linux) | yes | +| Ports 26611 (devnet P2P) or 26811 (testnet) free; RPC 26610/26810 and EVM RPC 26790/26890 on loopback | the apps' port layout (`config.rs evm_port` = rpc + 180) | yes; ufw rule added when ufw is active | +| The integrated GPU is not a card: AMD APUs report under 2 GiB of VRAM carve-out, an Intel iGPU sits at `0000:00:02.0`, the BMC's ASPEED VGA is vendor 1a03 | the rule the app's telemetry uses (kind integrated) rebuilt from sysfs; approximate | printed as notes | +| CUDA device index = PCI bus order (`CUDA_DEVICE_ORDER=PCI_BUS_ID` in the units); OpenCL index = the card's position among its vendor's devices in `igneum-worker-opencl --list` | OpenCL lists no bus id; two identical AMD cards are told apart by list order only, as the app does | the list is printed at install | +| Vote keys are derived from labels (`VoteSecretKey::from_label`; `--identities N` gives `