From fb6f84e3e2fc71eb160165bf099f16c5ec95d948 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 15:42:20 +0000 Subject: [PATCH] Site reset to Igneum 2.0, second pass: the reference apps and the deploy smoke pins follow the Igneum 2.0 devnet - /light, /receipt and the offline receipt verifier say "devnet, no value" (bundle and source), the reference-app test page names no devnet number, the faucet API's closed message names no testnet - /oracle drops the earlier-oracle history sentence - tools/site-deploy-from-mirror.sh: the served-page pins no longer expect "Devnet 3 faucet" or the class v5 floor history; they expect the Igneum 2.0 devnet faucet title and igneum-devnet-4 on /build Co-Authored-By: Claude Fable 5.1 --- site/api/faucet.mjs | 2 +- site/lc/app.js | 12 ++++++------ site/lc/test.html | 4 ++-- site/lc/verify-receipt.js | 10 +++++----- site/oracle.html | 2 +- tools/reference-apps/receipt/verify-receipt.src.mjs | 2 +- tools/site-deploy-from-mirror.sh | 2 +- 7 files changed, 17 insertions(+), 17 deletions(-) diff --git a/site/api/faucet.mjs b/site/api/faucet.mjs index a92243a8e..7ee001437 100644 --- a/site/api/faucet.mjs +++ b/site/api/faucet.mjs @@ -59,7 +59,7 @@ export function createHandler({ env = process.env, sql, rpc } = {}) { const key = env.FAUCET_KEY, rpcUrl = env.FAUCET_RPC; const chainId = Number(env.FAUCET_CHAIN_ID || 4463); if (!key || !/^0x[0-9a-fA-F]{64}$/.test(key) || !rpcUrl) { - return res.status(503).json({ ok: false, error: 'The faucet is not open yet. It opens with the public testnet.' }); + return res.status(503).json({ ok: false, error: 'The faucet is not open yet.' }); } let body; try { body = await readBody(req); } catch { return res.status(400).json({ ok: false, error: 'bad json' }); } diff --git a/site/lc/app.js b/site/lc/app.js index c722b6c0c..1f4b7cdc3 100644 --- a/site/lc/app.js +++ b/site/lc/app.js @@ -53,11 +53,11 @@ export async function runLight(address) { const res = verifyBalance(cp, proof, deps); window.__igneumLight = { cp, proof, neg, res }; const top = res.verified - ? `
Proven balance · Devnet 3, no value
${esc(formatIgn(res.balance_wei))} IGN
+ ? `
Proven balance · devnet, no value
${esc(formatIgn(res.balance_wei))} IGN

${esc(res.balance_wei)} wei at chain block ${res.block}, under checkpoint ${res.checkpoint} (locked ${esc(ago(Number(proof.headers[proof.headers.length - 1].timestamp)))}). Verified here in ${res.ms} ms, ${res.headers} headers checked.

` - : `
Not verified · Devnet 3, no value

${esc(res.reason)}

`; + : `
Not verified · devnet, no value

${esc(res.reason)}

`; out.innerHTML = top + negativeHtml('a copy of this proof with one byte of a trie node altered', neg) + stepsHtml(res) - + `

Data served by ${esc(API)} (a read service in front of a Devnet 3 node). Nothing it answered was taken on trust: the certificate, every header hash and parent link, the coinbase inclusion, the segment record's signature and the account proof were recomputed in this tab. What is trusted: that the aggregator's statement is the true execution result (every node checks it natively before paying the record; the SP1 proof behind it is verified by nodes, not in this tab yet), and the voter list with weights, which came from the node (spec 10.1).

`; + + `

Data served by ${esc(API)} (a read service in front of a devnet node). Nothing it answered was taken on trust: the certificate, every header hash and parent link, the coinbase inclusion, the segment record's signature and the account proof were recomputed in this tab. What is trusted: that the aggregator's statement is the true execution result (every node checks it natively before paying the record; the SP1 proof behind it is verified by nodes, not in this tab yet), and the voter list with weights, which came from the node (spec 10.1).

`; setStatus(res.verified ? 'verified' : 'refused', res.verified ? 'ok' : 'bad'); return res; } @@ -81,12 +81,12 @@ export async function runReceipt(tx) { const t = res.tx || {}; const when = new Date(Number(res.block_time || 0)).toISOString().replace('T', ' ').slice(0, 19) + ' UTC'; const top = res.verified - ? `
Transaction inclusion receipt · included and finalised · Devnet 3, no value
${esc(formatIgn(t.value || '0'))} IGN
+ ? `
Transaction inclusion receipt · included and finalised · devnet, no value
${esc(formatIgn(t.value || '0'))} IGN
To
${esc(t.to || 'contract creation')}
From
${esc(receipt.tx_as_reported.from)} (as the node reports it; the signature is the chain's check)
Transaction
0x${esc(receipt.tx_hash)}
Block
${esc(res.block)} at ${esc(when)}, DAA ${esc(res.block_daa)}
Finality
checkpoint ${res.checkpoint}, ${esc(res.certificate)}; ${res.headers} headers from the block to the checkpoint, verified here in ${res.ms} ms
${receipt.execution ? `
Executed
status ${receipt.execution.status === '0x1' ? 'success' : 'failed'}, gas ${parseInt(receipt.execution.gas_used, 16)}, ${receipt.execution.logs} log(s) (as the node reports it: executed is reported, not authenticated by this receipt; a payment receipt would authenticate the outcome)
` : ''}
` - : `
Not verified · Devnet 3, no value

${esc(res.reason)}

`; + : `
Not verified · devnet, no value

${esc(res.reason)}

`; out.innerHTML = top + negativeHtml('a copy of this receipt with one nibble of the raw transaction altered', neg) + stepsHtml(res) + (res.verified ? `

The file carries the raw transaction, the including block's header and merkle path, every header up to the certified checkpoint, the certificate and the voter table. Anyone re-verifies it offline with the one-file verifier: node verify-receipt.js receipt.json (verify-receipt.js, plain JavaScript, no npm, no network). A tampered file fails there the same way the copy above failed here.

` : ''); @@ -111,7 +111,7 @@ function wire() { if (!ok) { setStatus(kind === 'light' ? 'an address is 0x and 40 hex digits' : 'a transaction hash is 0x and 64 hex digits', 'bad'); return; } form.querySelector('button').disabled = true; try { if (kind === 'light') await runLight(v); else await runReceipt(v); } - catch (err) { setStatus(String(err.message || err), 'bad'); $('[data-result]').innerHTML = `
Could not fetch · Devnet 3, no value

${esc(String(err.message || err))}

`; } + catch (err) { setStatus(String(err.message || err), 'bad'); $('[data-result]').innerHTML = `
Could not fetch · devnet, no value

${esc(String(err.message || err))}

`; } finally { form.querySelector('button').disabled = false; } }); if (input.value) form.requestSubmit(); diff --git a/site/lc/test.html b/site/lc/test.html index 496cdb4d1..29c0032c1 100644 --- a/site/lc/test.html +++ b/site/lc/test.html @@ -8,8 +8,8 @@ -

Igneum reference apps: the negative cases, in this tab (Devnet 3, no value)

-

Each row runs site/lc/core.js on live Devnet 3 data from . A tampered case must read refused; the genuine case must read verified. The same cases run under Node in tools/reference-apps/light-service/verify.test.mjs. Parameters: ?api= (the read service), ?address= (the balance to prove; default: the miner of the latest block), ?tx= (a transaction; default: one in a recent block).

+

Igneum reference apps: the negative cases, in this tab (devnet, no value)

+

Each row runs site/lc/core.js on live devnet data from . A tampered case must read refused; the genuine case must read verified. The same cases run under Node in tools/reference-apps/light-service/verify.test.mjs. Parameters: ?api= (the read service), ?address= (the balance to prove; default: the miner of the latest block), ?tx= (a transaction; default: one in a recent block).

Receipt

caseresultmsreason

Balance

diff --git a/site/lc/verify-receipt.js b/site/lc/verify-receipt.js index 5c92158fd..6eb21755b 100644 --- a/site/lc/verify-receipt.js +++ b/site/lc/verify-receipt.js @@ -2121,8 +2121,8 @@ var ScalarMultiplier = class { } /** * Implements ec multiplication using precomputed signed fixed-window wNAF tables. - * Constant-time: fixed window count with one table addition per window — zero digits feed - * the fake accumulator — and no doublings; the lookup scans the whole window slice. + * Constant-time: fixed window count with one table addition per window, zero digits feed + * the fake accumulator, and no doublings; the lookup scans the whole window slice. * Scalar bounds are validated by the public entry points ({@link ScalarMultiplier.mulCT}, * {@link ScalarMultiplier.mulCTBlinded}, {@link ScalarMultiplier.mulUnsafe}); * signedWindowDigits throws if `n` exceeds the table. @@ -2209,7 +2209,7 @@ var ScalarMultiplier = class { * A cached wNAF table only pays off when reused; a flat 2^FW_WINDOW table (`size-1` adds) is * far cheaper to build for a single use. The point-operation sequence is independent of `n`: * build the table, then per window exactly FW_WINDOW doublings, a data-oblivious scan over - * every table entry, and one addition (adds the identity when the window digit is 0 — never + * every table entry, and one addition (adds the identity when the window digit is 0, never * skipped). * * `n` must be `< 2^bits`. Assumes complete addition (adding the identity costs the same as any @@ -2217,7 +2217,7 @@ var ScalarMultiplier = class { * projective form (no normalizeZ): normalizing this small a table costs more than the * mixed-add savings it would buy for a single multiply. * @returns real point `p`; `f` duplicates it only to match {@link wnafCachedCT}'s return shape - * (this path needs no fake accumulator — its op-count is already scalar-independent). + * (this path needs no fake accumulator, its op-count is already scalar-independent). */ fixedWindowCT(point, n, bits) { const W = FW_WINDOW; @@ -5313,7 +5313,7 @@ if (args.includes("--tamper")) { if (t2.verified) process.exit(1); } var r = verifyReceipt(receipt, deps); -console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (Devnet 3, no value)`); +console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (devnet, no value)`); console.log("What this file authenticates: that the signed transaction is included in a block that is finalised. What it does not: the execution outcome (status, gas), which is carried as the node reported it. A payment receipt, which authenticates the transfer outcome, is a different file."); print(r); if (!r.verified) { diff --git a/site/oracle.html b/site/oracle.html index 790010c9a..65f41565d 100644 --- a/site/oracle.html +++ b/site/oracle.html @@ -257,7 +257,7 @@

On Sepolia

-
Oracle
0x3ad71d4660d8a8d2f92248b9c286392dd76a3ab6 IgneumStateOracle, deployed 8 October 2026 on the shared verifier (tx 0x16312cf8…4e2a, block 11870855); its trust() names the two unchecked items below; accepts statements with chain id 4463 or 4464. The earlier oracle 0xefe9879d…a1b2 (stand-in verifier at first) stays as deployed.
+
Oracle
0x3ad71d4660d8a8d2f92248b9c286392dd76a3ab6 IgneumStateOracle, deployed 8 October 2026 on the shared verifier (tx 0x16312cf8…4e2a, block 11870855); its trust() names the two unchecked items below; accepts statements with chain id 4463 or 4464.
Verifier
0xAf74f3F512081291D663Bb1d6b6d37E99e37D744 the shared IgneumCertificateVerifier (the DEX lane's, a real BLS12-381 check on chain through the EIP-2537 precompiles, voter table installed at checkpoint 2127), set by setVerifier on 8 October 2026 (tx 0xd679bb65…db8e); the stand-in 0xa197ef31…a6f6 served until then
Chain
Sepolia, chain id 11155111; the Igneum 2.0 devnet (igneum-devnet-4), no value
Proven roots
Certificate 2232 (0xf056c26e…, 29 voters, signed weight 4,988 of 7,164) recorded on the shared verifier with a real BLS check, tx 0x1794b785…1e8a, 792,677 gas. Devnet chain block 28439, post_root 0x6e6d2fc8… stored on this oracle with a 6-header path, tx 0xcdb24dbc…ee5fc, 1,624,984 gas; provenBalance read 721.451608 IGN for 0xcaed79d8…c087 on Sepolia, equal to the devnet node's eth_getProof.
diff --git a/tools/reference-apps/receipt/verify-receipt.src.mjs b/tools/reference-apps/receipt/verify-receipt.src.mjs index 39c3ec853..c79a1232a 100644 --- a/tools/reference-apps/receipt/verify-receipt.src.mjs +++ b/tools/reference-apps/receipt/verify-receipt.src.mjs @@ -25,7 +25,7 @@ if (args.includes('--tamper')) { if (t.verified) process.exit(1); } const r = verifyReceipt(receipt, deps); -console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (Devnet 3, no value)`); +console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (devnet, no value)`); console.log('What this file authenticates: that the signed transaction is included in a block that is finalised. What it does not: the execution outcome (status, gas), which is carried as the node reported it. A payment receipt, which authenticates the transfer outcome, is a different file.'); print(r); if (!r.verified) { console.log(`REFUSED: ${r.reason}`); process.exit(1); } diff --git a/tools/site-deploy-from-mirror.sh b/tools/site-deploy-from-mirror.sh index 69cc700a6..9f57ff122 100755 --- a/tools/site-deploy-from-mirror.sh +++ b/tools/site-deploy-from-mirror.sh @@ -18,7 +18,7 @@ LIVE_NETWORK="${LIVE_NETWORK:-igneum-devnet-3}" INDEX_STRINGS=("At launch the strongest chip in our public model" "git.igneum.network/igneum-network/") LEGAL_PAGE="${LEGAL_PAGE:-/litepaper}"; LEGAL_STRING="Not legal advice" # the legal line lives on the litepaper in master's tree (22:16 UK: no commit put it on the index) MINERS_MIN_ROWS="${MINERS_MIN_ROWS:-20}" # the current-class table alone (the datacentre rows sit in their own table since 8 Oct 2026) -SERVED_PAGES=(swap "faucet|Devnet 3 faucet" "faucet|chain id 4464 since its class v5 floor" "build|Built to prove every block" "build|since its class v5 floor" "grants|Not legal advice." proving tx/0x0 "light|" "receipt|<title>" "oracle|<title>" "lc/test|<title>" "explorer|Source since 12:25 UTC" lc/app.js lc/core.js lc/verify-receipt.js "economics|Not legal advice." "income|The calculator" "income|/income-calc.js" "income|id=\"income-data\"" income-calc.js) # clean URLs every deploy must answer 200 (8 Oct 2026: the DEX lane's /swap, the builder lane's /faucet; /light /receipt /oracle /build /grants join as they land) +SERVED_PAGES=(swap "faucet|Igneum 2.0 devnet faucet" "build|Built to prove every block" "build|igneum-devnet-4" "grants|Not legal advice." proving tx/0x0 "light|<title>" "receipt|<title>" "oracle|<title>" "lc/test|<title>" "explorer|Source since 12:25 UTC" lc/app.js lc/core.js lc/verify-receipt.js "economics|Not legal advice." "income|The calculator" "income|/income-calc.js" "income|id=\"income-data\"" income-calc.js) # clean URLs every deploy must answer 200 (8 Oct 2026: the DEX lane's /swap, the builder lane's /faucet; /light /receipt /oracle /build /grants join as they land) SITE="${SITE_URL:-https://igneum.network}" # the /miners row count: the rows of the current-class table (table#bench-current, the regrouped bench of 8 Oct 2026; the datacentre # and earlier tables sit under their own ids); known-failed: an empty table reads 0