Merge ship-docs-rule33 cdf790d8 into master (gate: green on 7334ed7e, recorded by tools/ci/pre-push.sh; landed on the build mirror)

This commit is contained in:
igneum-labs 2026-10-08 20:37:53 +00:00
commit ba1e4b89df

View file

@ -21,3 +21,5 @@ Every cut of the Igneum Miner app and its node runs under these. The dated plan
15. **The version bump is the release branch's first commit (7 October 2026, after the 0.3.23 miss).** When a release-0.3.N branch opens, its first commit moves the six version places (app/igneum-app/Cargo.toml and Cargo.lock, app/windows/version.h, app/igneum-app/resources/igneum-app.rc's four fields, packaging/mac/app/Info.plist, the installer's AppVersion), never left to the cut: release-0.3.23 opened at 4cdcab31 and carried 0.3.22 in every place until 21:26 BST, so the app exes and the window host crossed from its first closed tip read 0.3.22 and were void. Gate check: on a push to release-0.3.N the pre-push gate (tools/ci/release-version-check.sh, self-test on tonight's shape first) reads all six places against the branch name and goes red on any mismatch; the .rc was the second layer of the same miss (the box cross failed in build.rs at 21:30 BST).
16. **The public miner carries no remote execution; the fleet runs the lab build (the founder's ruling on review B F14, 8 October 2026, 19:57 UK).** From 2.0.2 the public build has no run-script, fetch, collect, restart or update-now jobs, no jobs feed, no wake listener and no relay client (cargo feature `lab`, off by default), and documents its least-privilege boundary; "automatic updates off" stays off for an urgent manifest (pause and notify only). Our fleet, PC 1, PC 2 and the mini run the lab build only (product "Igneum Miner Lab", channel `igneum-2.0-devnet-lab`; the kits Igneum-Miner-Lab-Setup-<v>.exe, the lab DMG, the lab hive; the per-PC combined exes wrap the lab Setup), which verifies its manifest and jobs feed against the lab root (~/.config/igneum/lab-signing on the Mac, never in the repo), separate from the OTA key; publish-manifest.sh and publish-jobs.sh sign the lab channel with the lab key and a public channel with the public key, never cross (`--lab` / `--channel lab`). The relay agent refuses to run anything beside a public engine, and the jobs publisher refuses a target whose last upload is not a lab build.
17. **No entry publishes without a fresh-install canary on the live network (rule 33, the founder's word of 8 October 2026, 21:2x UK, after the two chain hours of the 2.0.1 night).** Before any entry (Mac, HiveOS, Windows, the fleet kit) publishes, a canary runs on a box with no AVX-512 and an empty datadir, from the entry's own artefact, on the live network: install from the artefact, sync from genesis to the tip, mine for five minutes with zero template refusals and at least one accepted block, claim and prove one shard and see it paid or queued for the lock, quit within the bound, and every line read back from the box. The steward records it as the release-gate case (INT-07 and V6-12's clean-install test are this case), BLOCKED when the canary cannot run; the publish scripts refuse without the canary's record for that exact sha; the cut note carries the canary's lines. The two classes of the 2.0.1 night that a canary would have caught: the miner's base unit (a template with six merged subsidies, refused by every shipped miner) and the rejoin at block 3847 (a sync from an empty datadir across the outage's fork); both sat on the live devnet and no canary looked.
18. **A class gets a fix clock inside the hour and a canary test, never a list entry without a time (8 October 2026).** The lane that finds a class names the fix's owner, its clock inside the hour and the canary line that proves it, in the same message; "on the 2.0.2 list" without a time is refused by the shipper. The 3847 class was handed to the node lane at 20:03 and had no clock until 21:40.