Merge remote-tracking branch 'box/master' into ci-steward-2

# Conflicts:
#	tools/ci/merge-to-master.sh
#	tools/ci/pre-push.sh
This commit is contained in:
igneum-labs 2026-10-07 18:57:47 +00:00
commit fccc89381e
37 changed files with 1155 additions and 77 deletions

View file

@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
| 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet |
| 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet |
| 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/funding.md` (the three lots) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the three cryptanalysis lots are the next test |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word |
| 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet |
| 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet |
| 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet |

View file

@ -20,7 +20,7 @@ The chip model. We price the strongest chip we can design against an RTX 5090 an
| When a stored-dataset chip pays for itself | at about USD 100 M of market cap in the first two years, not before | modelled, 7 October 2026 |
| The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class) | 5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x) | modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state |
What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is not ours: the cryptanalysis plan buys three external lots against the mixer, the chained cache and the acceptance rule.
What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.
## 3. The miner page's line
@ -30,4 +30,4 @@ Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 35
| # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification |
|---|---|---|---|---|---|---|---|
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/funding.md` (the three lots) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the three cryptanalysis lots are the next test |
| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word |

File diff suppressed because one or more lines are too long

View file

@ -64,3 +64,34 @@ sha256 279b1b690e854fc9, the string read back, pairing 8c728ca3 at byte 5. The d
**Three more in (16:2x BST):** update-return-21b a64c193f (the eGPU card kind from a USB4 or Thunderbolt router in the device's parent chain, the Power Helper's fault line and its stale-prefix fix; app 255 + 32 + 8, UI 76); first-block-21 at cc9141cb replacing 6e555d47 (main's "seen once": the first-block card waits until a window has shown it, POST api/card/seen, ladder.rs card_seen; app 255 + 32 + 8, UI 67); miner-reliability-21 at 018440ae (the register: MF-11 in the update-return lane's words, MF-12 the pool stall, MF-13 the Power Helper's stale count; code unchanged since 4a28eb59, CI success). UI tests on the merged tree 76 of 76; the app gate on build-2 at the merged tip below. GitHub refused pushes with "Internal Server Error" from about 15:25 to 16:18 BST, transient.
**The node order, final (16:3x BST):** on 55768f88: c631c64b first (the test-only fix of the two stale integration targets, 1026 → 1282; both green on build-2 at 15:34Z), then 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5; the tip's suite set runs the consensus crate whole (`-p kaspa-consensus` without `--lib`: the lib and both integration targets) beside consensus-core, the miner, kaspa-pow, the exec suite and the three checks (the suite rule from the 0.3.20 known-red finding). era-vdf-node 394a5902 is 0.3.22's.
## 6. The shape that ships: the 0.3.21 app tree over the field node c4459193 (main, 17:5x BST)
No node gate for 0.3.21: the app tree ships over the node already in the field (c4459193, the 0.3.20 pin, digest 4bbbe816 on the floor file). The 96161037 line (N15's numbering class, the bare-node proving ids) folds into 0.3.22 and later; its canary cells (kept-datadir ids BOTH PRESENT, wipe canary c22-1 synced in 42 minutes, 23 for 23, restart synced in 1 min 24 s) stand as readings, not as this release's gate.
**The exact tree:** release-0.3.21 at 44b63ac9 = scaling-21 b340b904 merged (c999a104), the windows.yml smoke fix 6c4686e7 (a direct call with the exit code read, in place of Start-Process -Wait -PassThru, which raced the version read-back on run 37653903394), and the node-source pin back to c4459193 (44b63ac9). App gate GREEN on build-2 on that tree at 18:05 BST: 257 + 32 + 8, rc 0. Payload inputs on the dl host at 18:04 BST: igneumd.exe 49502cc7, igneum-miner.exe b4871b5d (c4459193's Windows pair, the 0.3.20 release's bytes), igneum-worker-cuda.exe d7a413c7, igneum-worker-opencl-intel.exe af53f194, igneum-gpu-telemetry 0d68d06e, the Linux prover pair.
**The GitHub exception window, from 18:02 BST:** GitHub answers "Your account was suspended" (403) to every call from the igneum-labs login, API and git; the windows.yml dispatch at 18:04 BST was that 403 and no run started. Main's ruling: no lane pushes, fetches or polls GitHub, not even a retry; the box mirror /srv/igneum.git on build-1 and build-2 is origin for every lane; the box gate stamp replaces merge-to-master.sh's CI wait; the window and its start are recorded here and closed by a row when the login is restored. release-0.3.21 44b63ac9 reached both mirrors at 18:12 BST; master a4bca198 was fast-forwarded onto the mirrors (they had sat at 83977817) so every lane's origin carries a current master.
**Windows without windows.yml:** the 0.3.10 shape. igneum-app.exe cross-built on build-1 from 44b63ac9 (GNU target, 151803c7, 4,232,704 B; igneum-ota-sign.exe ddfd9444; igneum-prove-verify.exe dbda5323), the payload zip igneum-windows-app-0.3.21-44b63ac9.zip 586beedd and the installer kit installer-kit-44b63ac9.zip 6d0b5437 on the dl host; the window host (MSVC, WebView2) and the installer (Inno Setup, rcedit) only build on a Windows box, so a signed job on PC 2 (run-20261007-172000, woken 18:20 BST) builds both, reads --version off the three exes and posts the installer back through the relay; the smoke (install silent, --version read, the app starts and exits clean) runs on PC 2 by a following signed job and is the gate line. PC 2's agent polled the relay at 18:23 BST while its app, node and miners had been down since 17:27 BST (the Intel driver install), so the jobs reach it; no job on PC 1.
**The Mac:** Igneum-Miner-0.3.21.dmg rebuilt under the build lock at 18:15 BST with c4459193's Mac node pair (igneumd-mac b306baba, igneum-miner-mac deb4d263, the 0.3.20 release's bytes): 490919d9, 44,538,877 bytes, version 0.3.21 build 202610071714. The earlier fb517a11 (96161037's Mac node) never ships.
**Publish reading:** about 19:15 BST on the smoke's green; the staging in a scratch copy with the live floor file and the 0.3.20 hive package unchanged; the apps on the pollers, the Mac first.
## 7. LIVE on the Mac, 18:41:50 BST (main's ruling: the Mac entry now, Windows as its own entry)
Deploy runbook r0321/deploy.sh --mac-only --go (preflight: the staged manifest equals the live one on consensus.override, floor 900000, 16 fields, interface 1.0.1; the DMG present and read back). Copied into the live folder at 18:40:44 BST, Vercel deploy, the live manifest read back at 18:41:50 BST: version 0.3.21, channel devnet, mac Igneum-Miner-0.3.21-c4459193.dmg 490919d9 (44,538,877 bytes), windows none, floor 900000, ui 1.0.1; the DMG from the live URL 490919d9. The 0.3.20 hive package and the floor file unchanged. The Mac poller takes it within the hour or on Check now. The Windows entry lands as its own entry when an installer passes PC 2's smoke: (2a) a per-user Inno Setup 6 install on PC 2 by job (unelevated, fail clean) and (2b) the window host by mingw on the box run in parallel; a PC 1 build job (MSVC) wins over (2b) if the project lead allows one; (2c) windows.yml when GitHub returns is the last resort. Testnet re-arm line (the node lane, 18:38 BST): fork 6ed56f63 on release-0.3.22-node, digest 87d103b6 with no file, genesis 52a3e6a9 (5 October 00:00Z, past), every gate green on the exact commit; Devnet 3's digest on that binary still 83eb50cd. The 0.3.22 node pin candidate: N15 dfae08e5 as 34a2dbaa on 6ed56f63, gates running from 18:39 BST. Signing bonus (for the project lead, the node lane): supply unchanged, only who is paid (a silent producer 72 and the pool 28 instead of 80 and 20; fees untouched); waits for 0.3.23 whatever the decision (c7ea1e21 silent_split missing).
**scene-parity-21-sizing in (15:0x BST):** 7e15bf2f on 3dc0832a: live-dag.js 2.0.4 (the box's height follows the lanes through onSize and autoHeight, for /live; the app passes neither, its frames byte-identical, the parity test equal on every comparison); scene/, site/ and the app copy byte-equal; no Rust change, the app gate of 20c9153b stands; pre-push 56 green. The same 2.0.4 is on master at b9017422 and served by igneum.network.
**pool-finish-21 in (15:0x BST):** 2eea335f (the ten pool commits rebased onto 3dc0832a, no conflict; the pool-fee sentence in site/miner.html). Lines at that tip on build-2: igneum-pool 28; the app gate 229 + 32 + 8. Merged after scene-parity-21-sizing (JS only, so the Rust gate stands). The app side of 0.3.21 now carries: driver-check, miner-reliability-21 (cbd6f3a4), gpu-logos-21 with the Prove switch fix, earnings-tidy-21, scene-parity-21 and its sizing (live-dag.js 2.0.4), pool-finish-21; still mine: the under-12 GB prove-instead switch (section 2). The app gate on the final tree runs on build-2 about 19:30 BST or as soon as the switch lands.
**N15 rides 0.3.21's node line (the node lane, 15:1x BST):** branch numbering-fix at d8bceca5 (a6864e36 then d8bceca5, from 52e96c94): chain_path checks the first added block's selected parent against the tip record before anything is appended and hands the orphan records above the fork point to the reorg unwind (the shape that left p1-5090 two high: a reorg's removed list one short at 15:51Z on 6 October); a start-time self-check once per process walks the records from the restart pin against the DAG's selected parents, names the first break, unwinds above it and lets the follower re-walk (the shape that left p2-3090-3 46 high from a snapshot carrying its source's break); recordsContinuous and continuityBreak on igneum_getProvingStatus and igneum_getExecStatus (null, true, or false with the break's block), box-prover claiming only on true. The number is canonical by construction from the pin; the carrier's refusal by number stands (the statement binds the number). Two unit tests known-failed first; the exec suite 35 and the kaspad check green on build-2 at 14:13Z; the live line is the fleet's restart of p1-5090 and p2-3090-3 on the 0.3.21 candidate (the self-check naming #155958 and #158875, the unwind, offset 0 after). The 0.3.21 node order, final, on byte 5: 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5.
**update-return-21 in (15:3x BST):** 9d838ae5, one commit on b4289c4a (the app half: ota.rs, engine.rs, jobrun.rs, ember.rs, platform.rs, main.rs, bootcheck.rs; app/windows/host.cpp; Igneum-Miner.iss /IGNOTA=2; one round, main.rs's mod list by union). Lines on the tree: build-2 app tests 247 + 32 + 8; UI 74; the Windows cross green on build-1 (igneum-app.exe 4,172,288 B sha256 5b0598ad…, system DLLs only). host.cpp compiles in the cut's windows.yml run: the named gate line. The relay half stays on update-return for the relay lane's line through master.
**first-block-21 in (16:0x BST):** 6e555d47 on 064fb02b (ladder.rs: first_block_shown persisted in ladder.json, Ladder::start_run; engine.rs start_run at load and started_at on the state; app.js staleCard, firstWait, the first rung reading the flag; the ui-mock secondblock scenario). Lines: build-2 app gate 254 + 32 + 8 (seven new ladder tests); UI 67 (view 46, one new known-failed first); pre-push 56. No installer, node or host change. Captures ~/Desktop/igneum-previews-2026-10-07/first-block/01 and 02.
**Three more in (16:2x BST):** update-return-21b a64c193f (the eGPU card kind from a USB4 or Thunderbolt router in the device's parent chain, the Power Helper's fault line and its stale-prefix fix; app 255 + 32 + 8, UI 76); first-block-21 at cc9141cb replacing 6e555d47 (main's "seen once": the first-block card waits until a window has shown it, POST api/card/seen, ladder.rs card_seen; app 255 + 32 + 8, UI 67); miner-reliability-21 at 018440ae (the register: MF-11 in the update-return lane's words, MF-12 the pool stall, MF-13 the Power Helper's stale count; code unchanged since 4a28eb59, CI success). UI tests on the merged tree 76 of 76; the app gate on build-2 at the merged tip below. GitHub refused pushes with "Internal Server Error" from about 15:25 to 16:18 BST, transient.
**The node order, final (16:3x BST):** on 55768f88: c631c64b first (the test-only fix of the two stale integration targets, 1026 → 1282; both green on build-2 at 15:34Z), then 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5; the tip's suite set runs the consensus crate whole (`-p kaspa-consensus` without `--lib`: the lib and both integration targets) beside consensus-core, the miner, kaspa-pow, the exec suite and the three checks (the suite rule from the 0.3.20 known-red finding). era-vdf-node 394a5902 is 0.3.22's.

View file

@ -0,0 +1,71 @@
# Release 0.3.22: Devnet 3 (ordered 7 October 2026, 17:2x BST; genesis by 18:30 BST on the project lead's word)
Main's order (17:26 BST): Devnet 3 goes now, not after 0.3.21. 0.3.22's node = the release-0.3.21-node worktree on build-1 (96161037, both node gates PASS) + the sub-version 3 igneum-pow pin (the 017e7037 line, byte 7, pairing id a785001687d8688a; the Counter lane's handoff by 17:40 BST, else the node lane takes it from the audit-freeze-2026-10-07 tag) + the igneum-devnet-3 network object (its own network id and p2p port, every activation at 0: program_class_v4, difficulty_v2, finality_v3, fees_v1, proving_v1, latency_ladder rung 0; the genesis cut; NO override file on the new chain) + era VDF f2ecf452 only if its merge is clean and green in the same run (else 0.3.23 by an activation height; era_vdf_activation_daa stays at never on devnet-3 unless main's object names it). Built as an incremental on build-1's lease ahead of the 0.3.21 app gate.
Gates before genesis: the box suite on the exact commit (the consensus crate whole, consensus-core, the miner against sub-version 3's packs, kaspa-pow, the exec suite, the three checks); from the build on the fleet's pods: the empty-datadir canary, the fresh-genesis digest agreement on two fleet boxes from empty (the same digest and the first lock between them), the late joiner's sync from them, the shutdown under 1 s, the proving ids present on a bare node. After genesis on the live chain: the relay cases (with a relay kept synced before the window, the warm rule) and the hands. Genesis on green with the fleet's two genesis boxes (the standing-fleet shape: supervisor, kill file, vote key, miner); the old devnet keeps running until Devnet 3 has 24 hours; the apps move by signed update after that. The genesis is reported as a clock reading.
Staged (the build-server lane, 17:27 BST): the Devnet 3 seed on build-1 as a bare process (p2p 0.0.0.0:26631, gRPC 27630, JSON 27632, EVM 27810, empty datadir /home/build/dn3seed); the hands' second instances node1-dn3 (p2p 26651, rpc 26650, json 28650, evm 26830, --enable-unsynced-mining, peers the seed) and observer-dn3 (p2p 127.0.0.1:26661, rpc 26660, json 28660, evm 26860); ufw allows 26631 and 26651 since 17:27 BST; provision.sh's P2P_PORTS carries both; infra/build-server/devnet3/devnet3.{env,sh} with the NET_FLAGS placeholder until the node lane names the flag; read-back by the first log line, the commit-string count, the digest line, the "[igneum-exec] genesis <hash> executed" line and the server lines. The hands' nodes take no vote key (the miner's label is the key). The fleet: four gate pods on separate hosts renting with DESTROY=0; the fresh-genesis form, dn3_ tables, pay-by-key on the new chain and the no-stop cutover script follow; the capacity plan (a second node per standing box or a parallel set, the Devnet 3 hub) by 19:00 BST.
The app side: the app must start its node on igneum-devnet-3 (the network flag the node lane names; the manifest's channel; no override object), the chain scene and the ladder reading the new chain's facts, the first-block and earnings rows from zero: 0.3.22's app cut after the node is live, by signed update when Devnet 3 has 24 hours.
Era VDF (the era lane, 17:3x BST): f2ecf452 on 96161037, one round; the consensus crate whole 120 + 1 + 1, consensus-core 142, kaspa-pow 7; with the fields unset the digest is unchanged (the pinned devnet digest c562d70e read with the fields present; era_vdf_fields_enter_the_digest_only_when_set); at 0 it costs a node nothing for 180 days, then one core for an hour once; O-4.10 owed before any era 1.
**The frozen sub-version 3 object (the Counter lane, 17:3x BST, handed to the node lane):** igneum-pow 017e70376489251e18564c0abce7e466e606c8b3 on ca3-v4-amend (the audit-freeze-2026-10-07 tag; 2a111fb1 and 6941da1d above it are docs only). Object byte 7, PROGRAM_SUBVERSION_V4 = 3, the devnet epoch-0 program id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3); the kit packs-ca3-v4-sub3 zip sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154 (eight packs); fingerprints equal on Metal, Apple OpenCL, the fleet's 5090 (Linux CUDA) and PC 2 (Windows CUDA): mx8-devnet-epoch0 90f794dd556f7a3b (the v3 control), v4-devnet-epoch0 e370fb2080b7dbb1, era-0 b7237555d31fc3cf, era-1 b6b167fa15dfe2c9, era-2 28bdf65eff33f2c4, era-3 e26d38c46f3f1b16, era-4 dd8fdf6ff4f59eed, era-5 8bf40f5cb858d835. Both attack-pass gates GREEN on 017e7037 (the 64-seed hot-set census at 2^24: 60 of 64 under 1.2x; the exhaustion gate by construction and 0 of 24,631 chain-shaped seeds, max attempt 29); suite 103 of 103; CI success. Open, stated as open: the four-seed tail (p10 1.50x, p8 1.38x, p34 1.25x, p4 1.22x; main's ruling: the window model's unattributed residue with nil chip consequence; attribution for 0.3.23); the 10^6 chain-path count runs on as a strengthening line; the epoch draw costs about two attempts at 2.2 s once an hour; the owed measurements (G2, G3, the ladder, AMD on PC 1, the 2019-class core) do not gate Devnet 3. No further hash change rides 0.3.22. Devnet 3's object sets program_class_v4_activation_daa 0 and signals byte 7 from genesis.
## 1. The candidate: release-0.3.22-node = fa7f854f (16:37:50Z, 17:37 BST)
Three commits on 96161037: bd710a36 the sub-version 3 re-pin (byte 7, igneum-pow 017e7037, epoch-0 id a785001687d8688a, must-differ c120d796 / 1a423069 / a7886616); aded4620 era VDF (the era lane's f2ecf452, clean); fa7f854f the Devnet 3 object. The object: network igneum-devnet-3, flag `--devnet --devnet-suffix=3`, default p2p 26631 (ten above the previous suffix; gRPC, JSON and EVM on the devnet defaults unless passed); genesis 2026-10-07T00:00:00Z, payload "igneum-devnet-3 | 2026-10-07 | every upgrade on from block zero | coins here have no value | resets are announced", hash a6fa348e2a0fc6a5fa0ae3cb080160f5e2be865af71bac0068ca2fb8d1fcfd7b, bits 0x1d100000 (the DAA takes over after 600 blocks); active from DAA 0: difficulty v2, proving v0 and v1 (8 blocks a segment, 600 DAA, aggregator 1,000 bps, the fresh rule), finality v3, program class v3 and v4 (byte 7 from genesis, a one-day signal window), the latency ladder at rung 0, calibrated v1 fees, era VDF (main's ruling); at never (as on the live devnet, not in main's list): difficulty v3, the finality DAA-seconds rule, fork gate, peer directory, signing bonus, finality leave, pool split, consensus proof verify, exec restart (the chain executes from genesis). The node refuses --override-params-file on igneum-devnet-3 (mainnet, testnet, devnet suffixes 3 to 99; harness suffixes above 99 keep the file) and prints the digest with no file. Not in it: the N15 kept-datadir numbering class (p12-vast and pool-1 off by 2), 0.3.23's, the release note names it. Gates from 16:38Z: the release build on build-1 (gate priority); on build-2 the consensus crate whole, consensus-core, kaspa-pow with 017e7037's packs, the miner, the exec suite; then from the build the empty-datadir canary, the fresh-genesis digest agreement on two boxes, the late joiner, the shutdown under 1 s, the proving ids on a bare node.
**build-1 for Devnet 3 (the build-server lane and the fleet, reconciled 17:40 BST), nothing started:** the seed a bare process on p2p 0.0.0.0:26631 (rpc 27630, json 27632, evm 27810, empty datadir /home/build/dn3seed); the observer node on Devnet 3 is the fleet's instance (/srv/hands/bin/run-observer-node-dn3.sh, appdir /srv/hands/observer-node-dn3, rpc 26650, json 28650, p2p 26651, evm 26850, its observer.mjs on dn3_ tables running); the second node1 on p2p 0.0.0.0:26671 (rpc 26670, json 28670, evm 26870, appdir /srv/hands/node1-dn3, --enable-unsynced-mining); ufw allows 26631, 26651 and 26671; four units installed and DISABLED (igneum-observer-node-dn3, igneum-observer-dn3, igneum-hash-origin-dn3.service and .timer at 08:30 UTC with --prefix dn3_). On the go, in order: the 0.3.22 pairs under /srv/artefacts/0322-fa7f854f/ with the evm-types read, devnet3.env and dn3.env pointed at that igneumd, then seed --go, node1 --go, observer-node --go, each read back by the first log line, the string count, the devnet-3 digest line, the genesis line and the server lines.
**Main (17:4x BST):** fa7f854f accepted; the nine switches at never stay at never for the genesis (nothing untested flips under this clock); Devnet 3 is the chain they go live on by activation height, one at a time, each after its own gate, no further reset; consensus proof verify stays off until the proven share reads one. After genesis: the table of the nine (built and gated, built and ungated, not built; the owning lane; the earliest height) for the project lead.
**The fleet's Devnet 3 set, STANDING at 16:44Z:** five boxes on five hosts (the hive package, the kill file, box-dn3.sh, a vote key each, the binary slot empty until the artefact lands): dn3-g1 RunPod 3070 (64.119.209.250, p2p mapped 21703) = the Devnet 3 HUB and default peer; dn3-g2 Vast 3070 Utah (154.64.230.67, p2p 27017) = the second genesis node; dn3-j1 Vast 3060 12 GB = the late joiner from empty; dn3-c1 Vast 3060 12 GB = the empty-datadir canary (12 GB, so the prover statement reads there); dn3-x1 Vast 3060 12 GB = spare and second joiner; hairpin checked (every Vast box reaches dn3-g1's mapped port and build-1's 26631). The cutover dn3-genesis.py (per box: the binary with its sha read back, box-dn3.sh with --devnet --devnet-suffix=3, appdir /root/fleet/dn3, no override, FRESH=1, UNSYNCED=1 on the two genesis boxes only, seeds dn3-g1, dn3-g2, build-1's 26631 and 26671; read back the string, the devnet-3 digest, the genesis hash line, synced, the first lock; nothing named on the old devnet), dry-tested. The gate dn3-gate.py: digest agreement g1/g2, the same first lock on both, the late joiner synced from them, the canary mining ten minutes with its blocks held by dn3-g1 and 0 rejects, shutdown under 1 s then the restart on the kept datadir, the proving ids on a bare node; one line per check with its UTC time, DN3 GATE PASS/FAIL. hub-1's second node staged (36610/36611/36790, outbound only, FRESH, MINE=0). Pay-by-key on the new chain through dn3-g1. The watcher on /srv/artefacts/0322-*/ starts the gate within the minute of the binary. Capacity for day one: a SECOND NODE PER STANDING BOX (box-dn3.sh on 36610/36611/36790, FRESH from empty, the box's existing key label on the new chain, MINE=1 with a second miner on the same card), rolled in three waves of 5/5/4 after the genesis pair locks, nothing stopped on the old chain; plus the five gate boxes and hub-1's and build-1's second nodes: about 22 voters; cost USD 9.2/day for the five gate boxes, the second nodes USD 0, the 0.3.21 warm set 11.52/day; the fallback a parallel set of fourteen 3070 pods (USD 44/day) only if the first wave shows card contention (the read: the live miner's rate and the dn3 node's template timing). Spend at 16:40Z: 406.49 of 1,000.
**The 0.3.21 set, running on:** c22-1's wipe in IBD; the warm-set cases' window running; N15's live line: p2-4090-1b's kept snapshot tips were side-tip blocks on the hub's DAG, the node refused them rightly and loaded the hub's snapshot, healthy, no discontinuity line (the node lane holds the reading); p1-5090 now; roll lines p2-3090-2 2.3314 and p2-3090-3 2.8553 IGN verified by key.
**Main (17:4x BST): yes to the second node per standing box**, three waves of 5/5/4 after the genesis pair locks, nothing stopped on the old chain, with two conditions: (1) a 24-hour exception to the one-miner-per-GPU rule, not a new rule: when the apps move to Devnet 3 and the old chain's miners stop, each box is back to one miner (written as an exception with its end in the fleet notes); (2) the contention read on wave 1 decides the fallback mechanically: a live miner's rate on any of the five down more than 10 percent against its hour-before mean, or the dn3 node's template latency above the 0.3.20 gate figure, takes the 3070 set for the remaining waves without asking; spend under the USD 1,000 ceiling either way.
**The app side of 0.3.22 (the shipper):** the app's node starts on igneum-devnet-3 through its packaged config (Runtime.network "devnet" with devnet_suffix 3, read from igneum-app.json in the 0.3.22 package; the OTA update replaces the package, so the signed 0.3.22 update is the move), with node_dir devnet-3 (a fresh datadir beside devnet-v4, the old chain's kept for the way back), the node_override_file None on a suffixed devnet (the node refuses the file; the OTA manifest's consensus.override is ignored with a log line on devnet-3), the chain scene, the ladder, first-block and earnings reading the new chain from zero, the prover on the new chain's records; the manifest for the 0.3.22 publish carries channel "devnet-3". Cut after the genesis on its own branch release-0.3.22 off release-0.3.21's tip; published by signed update when Devnet 3 has 24 hours (main's clock).
## 5. The genesis: 69d1b56e, 18:06:19 BST
**The timestamp fault and the fix:** fa7f854f and 21d8f454 carried a genesis timestamp of 2026-10-08T00:00:00Z, so every block read "too far into the future"; the node lane's 69d1b56e sets 2026-10-07T00:00:00Z (genesis hash 4020cb4382e3fe4b…b925, test `every_compiled_genesis_lies_in_the_past_of_the_clock`). ab9af79f is void with it; the igneum-devnet-3 digest with no override file on 69d1b56e is 83eb50cdf2eda4cb…22b2.
**Gates on 69d1b56e, every one green:** build-1 release build 18:03:03 BST; box suites on build-2 (kaspa-consensus whole 120 + 1 + 1 at 18:02:17, igneum-exec 36 at 18:03:09, kaspa-consensus-core 152 at 18:03:40, kaspa-pow 17 at 18:04:31, igneum-miner 25 at 18:05:22 against the sub-version 3 packs); the canary set from the artefact (object 7 / 1794, era VDF from 0, ladder rung 0, fees v1, shutdown 677 ms after SIGTERM, the override file refused exit 1 while the shared devnet still takes it, two empty nodes handshaking with equal digests, the shared-devnet node rejected with the network mismatch); the pack gate PASS by construction on dn3-g1 (miner c29f33bb = the pair's, the pack exported on the box, the hive 0.3.20 miner 4050c255 refused); the program id read back fce15bf61030be57 (see the correction below).
**The pairs:** node-lane pair igneumd 0751598f (57,816,736 B) and igneum-miner c29f33bb under /srv/artefacts/0322-69d1b56e/node-lane/; the build-server lane's hands pair igneumd efb54938 (57,817,120 B, GLIBC_2.39) and igneum-miner 07246920 under /hands/, seed pair fb15cecf and f8c40e1c under /seed/ (the miners byte-identical to 21d8f454's: the miner does not embed the genesis). The shipper's ruling: the node-lane bytes stand as the genesis pair on dn3-g1 and dn3-g2; the hands pair goes on the joiners, hub-1 and build-1.
**The genesis reading:** dn3-g1 (the Devnet 3 hub, 64.119.209.250:21703) up 18:04:55 BST, "igneumd/2.1.0-69d1b56e", digest 83eb50cd, "genesis 4020cb43… executed: chain id 4463", miner from 18:05:19, FIRST BLOCK ACCEPTED 18:06:19.920 BST ("PoW accepted c313ddac… by igneum-lottery-v2-bound, daa 0, epoch seed 4020cb43…"), 85 of 85 GPU blocks by 18:10, 287 by 18:14, 0 rejected. dn3-g2 (154.64.230.67:27017) up 18:17:58 BST on the same pair, synced from g1 (639 blocks at 18:18:52), mining from 18:18:15; 702 blocks, daa 702 at 18:19:08, 0 rejected on either; finality checkpoints 20 (985353b4…), 21 (e788fac0…, blue score 631), 22 (f45336bd…, blue score 660) identical on both logs. The genesis declared on that agreement at 18:25 BST (main noted it at 18:18 BST). The object's finality window is 7,200 DAA, so no checkpoint can lock before about 20:10 BST; the first lock is a follow-up line, not a gate (the fleet's check 2 re-lettered to "first common lock within 30 minutes of DAA 7200"). The go to build-1's seed (26631), node1-dn3 (26671) and the observer unit on the hands pair went at 18:24 BST; the joiners dn3-j1, dn3-c1 (ten-minute canary) and dn3-x1 place on the hands pair. Nothing in the go path reads GitHub (both lanes confirmed: /srv/artefacts, the box mirror for the observer clone, the dl host for the hive package and the kit zip). The executor on a fresh devnet-3 node logs "waiting for consensus to sync before the executor starts (the sink is 61,000 s old)" until the first block, then executes genesis: expected (the genesis is 17 hours old by design), not a fault; runbook row.
**Program id correction (the Counter lane, 18:1x BST):** Devnet 3's epoch-0 class v4 program id is fce15bf61030be57 (read in the 0.3.22 miner's "cache ready" line on build-1 at 18:10:39 BST and on dn3-g1); a785001687d8688a is the SHARED devnet's epoch-0 id (genesis edc4fa84) and the kaspa-pow pairing pin, which is unchanged because the id follows the seed. Every Devnet 3 box's gate wants fce15bf61030be57 at epoch 0 and stops the miner on 1a4230699a6b9c60 or a785001687d8688a; the per-epoch form (the miner's line equals the node's seed-derived id, read each 3,600 DAA) is for after tonight. Both paired miners on dn3-g1 printed fce15bf61030be57, so the node drew Devnet 3's seed and the record is right.
**The nine switches:** recorded as section 6.11 of docs/plans/counter-asic-3-node.md (branch ca3-v4-node e70535fc on the box mirror, 18:15 BST), one row per switch with state, owner, gate and the earliest Devnet 3 height; signing bonus is not gateable on 69d1b56e (c7ea1e21 silent_split missing) and is 0.3.23's; every height reads as lock time + DAA seconds at 1 block/s.
**Found by the 0.3.21 wipe canary, fixed 18:14:35 BST:** the Hetzner live seed 188.245.5.161:26611 was still on the old sixteen-field object (digest eada4bda) one hour forty after the 0.3.20 sweep; it was never in a wave (the 15:56 go listed the hands and bps-seed, not it). Per tier: fleet voters, hub and pool-1 unaffected (they peer on the hub); every 0.3.20 app on the floor file saw a reject line at each dial of the seed and synced through the hub and node1 instead (c22-1 did); a fresh joiner configured with only the seed could not join. The build-server lane (infra/devnet/restart-seed.sh over the ops key) installed the c4459193 seed-class igneumd 4a2d8a8d and the floor file 294f1f80, unit igneumd-v4 down about 3 s, read-back "igneumd/2.1.0-c4459193", digest 4bbbe816 MATCH, 278 blocks accepted in the first minute. Rule 5 now names the seeds with a read-back line.
## 6. After the genesis: the clocks, the rulings, the 0.3.22 tree (18:3x to 18:5x BST)
**DN3 GATE PASS (the fleet, 18:36 BST):** digest and checkpoint agreement on dn3-g1/g2 (checkpoints 20 to 29 identical, lock line 855414eb identical), late joiner twice (dn3-j1, 911 then 1,099 blocks), canary blocks held (dn3-c1, 15 of dn3-g1's last 900), shutdown 589 ms, bare-node proving ids present; two of the six lines read by hand after script faults of the fleet's (inspect arguments reversed; a token read broken by spaces), both fixed and recorded. Eight nodes on five hosts plus build-1's seed, node1-dn3 and observer, all on 83eb50cd, about 1,900 blocks at 18:36 BST. The relay set dn3-relay, dn3-poison, dn3-twin rented for the cases. The first finality lock at DAA 7,200, about 20:10 BST; the second-node wave 1 on the standing boxes starts on that line (main's two conditions).
**The two clocks (main):** the 0.3.22 apps publish at 18:30 BST on 8 October on green (the 24-hour line is 18:06 BST); the first Discord card (Devnet 3 + 0.3.22) publishes after the fleet's relay run on Devnet 3 reads CASES END with the relay cell read AND the 0.3.22 apps are out; the card names the first-block time, the chain id and the launch-first chip line from master 9b996d06, no prize; staged at scratchpad/r0322/discord-card-devnet3-0322.md, main reads it after the relay run.
**The 0.3.22 app tree and its order (accepted by main):** release-0.3.22 at 27ab317e on the box mirror = release-0.3.21 44b63ac9 merged (7f07a37f) + driver-check 46cc41e9 (27ab317e; the eGPU driver-install hold and warning); app gate GREEN on build-2 at 18:33 BST (259 + 33 + 8, pre-push 56). Missing, in closing order: (a) the node pin = N15 dfae08e5 rebased onto 69d1b56e on release-0.3.22-node, gated, plus whichever switch heights are green by the cut; (b) the Windows node pair from build-1's cross and the payload inputs, the installer by the PC 2 job shape while GitHub is out, the Mac node pair and DMG on the Mac under the lock; (c) the hive 0.3.22 package with the sub-version 3 kit inside; (d) the manifest on channel devnet-3, KEEPING the floor file for the 0.3.20 and 0.3.21 apps until the intake shows no app below 0.3.22 for 24 hours (main's ruling; the 0.3.22 app ignores the file by construction); (e) the app's vote key hash to the intake and the publisher's --public ui arm; (f) node_peers adds dn3-g1 64.119.209.250:21703 and dn3-g2 154.64.230.67:27017 beside build-1.
**the project lead's ruling on the nine switches (through main, 18:4x BST), executed by the node lane on Devnet 3 by activation height, each with its gate line and a read-back on every node, no reset, one at a time:** (1) peer directory, pool split, fork gate ON in that order, each height set the moment its 6.11 condition reads true; (2) difficulty v3, the finality DAA-seconds rule, finality leave up: mid-chain crossing tests on the fast-time harness tonight, each height set as its test goes green; (3) signing bonus: one paragraph for the project lead on whether it changes total minted supply or only who is paid, with the number; (4) mandatory proof verification ON after 24 hours of every Devnet 3 block proven on the hash-origin report, the fleet's provers on Devnet 3 from tonight, the share reported hourly; (5) exec restart never. **Mechanics (main):** a height is a constant in the igneum-devnet-3 Params of a node commit, rolled out by the sweep (one box at a time, commit string and height line read back, the hub first); never a file, no new signed-record mechanism; one commit may carry several heights staggered so the chain crosses them one at a time; a node that misses the commit forks off at the height, as designed, which is the test; each commit is a release of the node line (0.3.22, 0.3.23) and reaches the apps by the signed update. Recorded in 6.11 by the node lane as heights are set; each height to main as a clock reading.
**Testnet re-arm (main, through the build-server lane):** the arming on fork e6dd3afd (digest 4fbb2152, genesis 01294fd3) is void (old object; a go on it hard-forks at sub-version 3). The node lane cuts a testnet genesis object on release-0.3.22-node in the Devnet 3 shape (byte 7 from genesis, every activation at 0 that Devnet 3 has at 0, era VDF at 0, a past genesis timestamp with the future-genesis test beside it, no override file, the testnet's seeds and chain id as they are); the build-server lane builds the seed-class pair under /srv/artefacts/testnet-<commit>/seed/ and dry-runs wave1-0320.sh against seed1/2/3 at height 0; nothing onto a seed and nothing mines before the project lead's word (not before 15 October, LG-2).
**0.3.21 Windows, the toolchain finding (18:37 BST):** PC 2's installer job (take 2, 68 s) verified the payload (igneum-app.exe 151803c7 prints "igneum-app 0.3.21", igneumd.exe 49502cc7 "igneumd 2.1.0") and stopped on PC 2's toolchain: no MSVC (no window host "Igneum Miner.exe", whose host.cpp changed in update-return-21) and no Inno Setup 6 (no installer; winget refused by the job as told). Three shapes put to main at 18:45 BST: the Mac entry now and Windows later (the manifest carries a platform that lands later; 0.3.20 Windows apps do nothing until their entry arrives); winget Inno Setup on PC 2 (still no 0.3.21 host); the host by mingw on the box (dry compile asked) or Windows held until GitHub returns and windows.yml runs. deploy.sh carries --mac-only for shape (1); the full preflight stands for the Windows entry.
**Proving on Devnet 3 opens (the fleet, 18:45 BST):** dn3-x1's first segment 1024..1031 claimed 18:44:23 BST and SUBMITTED 18:45:49 (8 of 8 shards accepted, proof 1,272,909 bytes, 86.1 s end to end, peak 8,534 MiB on a 3060 12 GB); its record waits in dn3-g1's pool for a carrier; the paid-by-key line opens the 24-hour window for the project lead's mandatory-verification rule. Sizing: about 42 segments an hour per 12 GB card against 450 an hour made, so 11 cards reach a share of one; 14 more 3060 pods renting (about USD 0.85/h together, 20 a day). The 0.3.21 warm cases (CASES-W21 END rc 0, 18:47 BST, on 96161037): the target refused every version-1026 block (44,081 seen, 0 accepted), restarted back at the tip, the hub holds 900 of its last 900; the relay cell again reads the target's own refusal, not a relayed poison block, so Devnet 3's relay run (relay on the hands pair synced before the window, the twin peered to the relay alone) is where that cell gets read, and its CASES END is the card's gate.
## 7. the project lead moves the apps to Devnet 3 tonight (19:1x BST): the pin, the tree, the clock
**the project lead's word (through main, 19:10 BST):** the apps and the site's live page move to Devnet 3 now, not tomorrow. The clock: the 0.3.22 node pin at 19:15 BST; the Mac entry about 20:15 BST on channel devnet-3 (the floor file kept in the manifest for the 0.3.20 and 0.3.21 apps until the intake shows none below 0.3.22 for 24 hours); the Windows entry as its own entry when PC 2's smoke runs, about 21:00 BST, the 0.3.21 Windows entry skipped in its favour (said in the notes); the hive 0.3.22 package with the sub-version 3 kit published with the pin, the fleet's standing boxes moving in waves after the first lock; the site's live page pointed at the dn3 observer on build-1 after the first lock (about 20:10 BST), deployed from the box with the Vercel CLI as a site-only deploy of master's live tree (GitHub dark), edge time to main. Heights ride 0.3.23, set from the 0.3.23 sweep's finish with a two-hour margin (plan: 12:00 BST 8 October, difficulty v3 at the first multiple of 7,200 DAA at or after 14:00 BST, the other two 7,200 apart).
**The pin: release-0.3.22-node = 34a2dbaa at 19:15 BST, no heights** (69d1b56e + the testnet object 6ed56f63 + the N15 kept-datadir fix dfae08e5; igneum-devnet-3 digest 83eb50cd unchanged, igneum-testnet-1 87d103b6 on the same binary). Gates on the exact commit: build-1 build 18:40:26 BST (igneumd bc25693c, node-lane pair under /srv/artefacts/0322-34a2dbaa/node-lane/); build-2 suites consensus 122, exec 37 (the new scan test), pow 17, miner 25, core 152 by 18:42:51; canary set green (shutdown 567 ms, override refused, handshake, mismatch rejection). The Devnet 3 join-and-restart read is the fleet's. Crossing cases on the fast-time harness: difficulty v3 pass GREEN 19:08 BST and known-failed FAIL as expected; the DAA-seconds rule and finality leave green on the chain's reading but the harness's checkpoint read used the wrong RPC parameter, rerun by 19:22 BST; no heights commit could carry gates by 19:15, so every height rides 0.3.23 (0.3.23 line: 18473645 = 43360992 + d840537b subsidy_per_block, gates green, digest edit list 25; daa61847 rebased by the genesis-forward lane).
**The 0.3.22 app tree at 19:15 BST, release-0.3.22 c977786b on the box mirror:** 27ab317e (release-0.3.21 44b63ac9 + driver-check 46cc41e9) + pool-finish-21 8f2aae75 (the Devnet 3 split-read tool) + signing-22 e1b01654 (vote on by default pinned by test; Overview and Cards rows read signing or silent with the reason) + key-22 6501558f (scene/live-dag.js 2.0.5 legend, the app's chain card renders it, the site untouched) + c977786b (node_peers adds dn3-g1 64.119.209.250:21703 and dn3-g2 154.64.230.67:27017; self-test reads four). App gate on build-2 GREEN at every step (last 259 + 33 + 8, rc 0); pre-push 56 on each push. Riding if on the mirror by 19:45 BST, else 0.3.23: boot-start-22 (the engine starts at boot without a logon on Windows; a headless engine never reads a closed stdin as the host leaving), the export-wait reliability item (a worker never waits on the export past one retry interval), the driver-check hold-every-card-of-the-vendor rule, the UI lane's shard words. The Mac node pair builds on 34a2dbaa under the lock from 19:12 BST (r0322/mac-node-34a2dbaa.sh), then the DMG.
**PC 2 tonight:** the take-4 0.3.21 installer (mingw host, run-20261007-175020) was picked up at 18:51:57 BST before its removal deployed and the runner's abort ended the install in its first second (the build-server lane's fault, two rules added to the job tooling: an installs-app job is never removable without --force; never remove a published job without reading the machine's latest line); the update-return lane re-ran the kept installer at 19:07:56 BST and the 0.3.21 engine then restarted four times a minute apart and died ("quit requested by the window host went away (stdin closed)" 3 s after the node start: an engine started by a parent whose stdin closes at once); the project lead reinstalled PC 2 by hand with the public 0.3.20 installer (45b2f3fb, the MSVC host; the public alias confirmed as that file by hash at 19:12:54 BST). PC 2 is read-only for every lane until its app uploads as 0.3.20; then the 0.3.22 installer job (--installs-app) and the smoke, one job at a time; then the Intel lane's driver retry with the minidump copy folded in (one UAC click). PC 1: released to the Counter lane's queue at 19:04:37 BST (the 0.3.21 MSVC host e223db18 built there in 9 s, collected by the relay Blob); one slot for the 0.3.22 host (app/windows/version.h moved to 0.3.22, host.cpp untouched).

View file

@ -9,7 +9,7 @@ Every cut of the Igneum Miner app and its node runs under these. The dated plan
4c. **The proving ids gate (main, 7 October 2026, after the 0.3.20 blocker).** On every candidate, a node started on the LIVE override file reports both proving ids (the shard program id and the aggregator id) on its proving v1 start line, and a prover's first statement against it is accepted; a zero-id statement is the known-failed shape. It runs beside the kept-datadir read, since both share the warm pod. Why: c4459193 read the ids as unknown, built statements with zeros and refused every proof; a sweep would have stopped every prover's pay.
4a. **Every gate starts on every candidate the moment its binary builds, never after the pin (the project lead, 7 October 2026).** The digest and mixed-version gates, the kept-datadir start, the relay and poison cases and the wipe canary all begin on each candidate binary as it lands; a struck candidate's runs are stopped and its successor's begin. The post-pin wait is then the longest single form (about 80 minutes, the wipe), not the sum.
4b. **Warm pods per gate class (the project lead, 7 October 2026, ordered to the fleet lane).** The fleet keeps synced pods warm for each gate class so a case form's target starts at the tip (a kept copy of the live line, caught up), never from a kept copy far behind it; the wipe canary is the only full IBD in the set.
5. **Rollout in waves, each box read back (the project lead, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK).
5. **Rollout in waves, each box read back (the project lead, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). The wave list is written, not remembered: every sweep's first wave names each Hetzner seed by address (188.245.5.161:26611 for the shared devnet; the testnet seeds when they move) beside the hands and the fleet, and the seed's row closes only on its own read-back line (string, digest, first accepted block) from the lane that holds its key (the build-server lane, infra/devnet/restart-seed.sh). Added 7 October 2026 after the 0.3.20 sweep left the seed on the old object for one hour forty, found by the 0.3.21 wipe canary's reject lines.
6. **Read-back is by commit string plus digest plus engine:** on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees `strings igneumd | grep -c igneum-pow/src/` above zero. The miner embeds no commit string; its pairing is the build line and the sha.
7. **igneum-pow pairing:** a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file).
8. **glibc classes:** HiveOS 2.31 (`--ship hive`, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (`--ship seed`), fleet 24.04 boxes native 2.39.

View file

@ -135,3 +135,15 @@ Added by the launch-pack lane (branch `launch-pack`) from `docs/analysis/mission
| LG-11 A signed proving customer | One customer paying for proofs at a published rate, or a signed letter of intent with a volume, before mainnet (the owner, 7 October 2026: a mainnet gate, not a testnet gate; the weight of the Devnet 2 gate: mainnet does not open without it) | the contract or the letter in the entity's records, a redacted copy linked from `docs/evidence.md`, the rate on the site; for the paying case the job market's payout contract shows a paid job for that customer; `grep -c "rollup signs for testnet" site/journey.json` is 0 after the handoff lands | M | NOT DONE: Taiko is named as the first customer and nothing is signed; the brief and the pilot progression are ledger X13 | the owner (the signature), the execution engineer (the paid job) |
| LG-12 Hash origin daily for 90 days | The report posts every day for the first 90 days from the go, with no gap | `SELECT count(*) FROM hash_origin_reports WHERE day >= '<go date>'` reaches 90 with consecutive days; the timer's journal on the box shows a run per day | C | The job and its `--go <date>` flag exist; the timer is OWED (section 3 of the pack) | build-server lane (timer), the report |
| LG-13 The disclosure prize | USD 50,000 for a reproduced break of the published hash class, paid in fiat by Igneum Labs LTD, announced only when escrowed and only when the entity's registered address exists on its documents and the owner gives the publish word | `docs/plans/funding.md` rule 3 (escrow before announcement); the staged text in docs/plans/cryptanalysis.md 3.3 on branch `cryptanalysis` (43d9700b, not on master yet); until the word, `grep -ci "50,000" site/*.html` is 0 | M (the announcement may come earlier, on the word) | APPROVED by the owner at 09:5x UK on 7 October 2026; STAGED; nothing public mentions it | the owner (escrow, the word), the cryptanalysis lane (the announcement) |
## LG-2 waived by the owner (7 October 2026, 19:5x BST)
Launch gate LG-2 (seven daily hash-origin reports before the testnet) is waived by the owner, 7 October 2026 19:5x BST; the report
still runs daily from Devnet 3 (igneum-hash-origin-dn3.timer on build-1, 08:30 UTC, `--prefix dn3_`, DN3_GO_DATE 2026-10-07) and
from the testnet from its go. The testnet gate is now: the 24-hour proven window closed on Devnet 3 (about 19:00 BST on 8 October),
the 0.3.23 heights crossed on every Devnet 3 node, the launch text (LG-5) on the site, the seeds on the 0.3.22 object with the dry
run clean (done: fork 6ed56f63, digest 87d103b6, genesis 52a3e6a9, seed-class pair under /srv/artefacts/testnet-6ed56f63/seed/ on
build-1, three-seed dry run clean at height 0 at 18:44 BST), and the owner's word. The seeds stay armed for a go as early as the
evening of 8 October: `infra/build-server/wave1-0320.sh seeds --igneumd <that igneumd> --sha256 80932b18… --miner <that miner>
--digest 87d103b6… --commit 6ed56f63 --wipe-genesis --genesis 52a3e6a9… --go` on the word, nothing before.

View file

@ -0,0 +1,17 @@
# Devnet 3 on igneum-build-1 (0.3.22, main's order on the project lead's word, 7 October 2026): the network flag and the ports every script here
# reads. NET_FLAGS is a PLACEHOLDER until the node lane names the object's flag in its commit (igneum-devnet-3: own network id and
# p2p port, every activation at 0, no override file). Ports follow the box's pattern (devnet 266x1 p2p; Devnet 2 seed 27610/27612/27790):
NET_FLAGS="--devnet --devnet-suffix=3" # PLACEHOLDER: replace with the node lane's flag for igneum-devnet-3
IGNEUMD="/srv/artefacts/0322-69d1b56e/hands/igneumd" # the 0.3.22 candidate 69d1b56e (genesis timestamp fix; built 18:04 BST, 7 Oct 2026)
# the seed (a bare process beside the Devnet 2 one, run as build, empty datadir)
DN3_SEED_APPDIR=/home/build/dn3seed
DN3_SEED_P2P=26631 # ufw: opened 7 Oct 2026 (provision.sh P2P_PORTS carries it)
DN3_SEED_RPC=27630; DN3_SEED_JSON=27632; DN3_SEED_EVM=27810
DN3_SEED_LOG=/home/build/dn3seed.log
# the hands' SECOND instances (the old devnet runs on for a day, so these run beside node1 and observer-node, not instead).
# Reconciled with the fleet lane's staging of 17:37 BST: ITS observer-node-dn3 (/srv/hands/bin/run-observer-node-dn3.sh, unit
# igneum-observer-node-dn3, rpc 26650, wrpc json 28650, p2p 26651, evm 26850, appdir /srv/hands/observer-node-dn3, peers from
# /srv/hands/dn3/dn3.env) is the observer instance; this lane runs the seed and node1-dn3 (p2p 26671, ufw open since 16:39Z).
DN3_NODE1_APPDIR=/srv/hands/node1-dn3; DN3_NODE1_P2P=26671; DN3_NODE1_RPC=26670; DN3_NODE1_JSON=28670; DN3_NODE1_EVM=26870
DN3_OBS_APPDIR=/srv/hands/observer-node-dn3; DN3_OBS_P2P=26651; DN3_OBS_RPC=26650; DN3_OBS_JSON=28650; DN3_OBS_EVM=26850
DN3_OBS_SCRIPT=/srv/hands/bin/run-observer-node-dn3.sh # the fleet lane's; devnet3.sh observer-node starts its unit, not a copy

View file

@ -9,21 +9,24 @@
# lines. No unit yet: the processes are detached (setsid nohup) under the build user like the Devnet 2 seed; units follow once the
# network is green. The old devnet's node1 and observer-node are not touched.
set -euo pipefail
HERE=$(cd "$(dirname "$0")" && pwd); . "$HERE/devnet3.env"
HERE=$(cd "$(dirname "$0")" && pwd); . "$HERE/devnet3.conf"
KEY="${IGNEUM_BUILD_KEY:-$HOME/.ssh/igneum_ed25519}"; HOST=$(head -1 "${IGNEUM_BUILD_HOST_FILE:-$HOME/.config/igneum/build-server}" | tr -d '[:space:]')
SSH=(ssh -i "$KEY" -o BatchMode=yes -o ConnectTimeout=15 "$HOST")
say() { echo "$(TZ=Europe/London date '+%H:%M:%S %Z') devnet3: $*" >&2; }
mode="${1:-}"; shift || true; GO=0; [ "${1:-}" = --go ] && GO=1
case "$NET_FLAGS" in *suffix=3*) say "NET_FLAGS is still the placeholder ($NET_FLAGS): the node lane's flag goes into devnet3.env first" ;; esac
case "$NET_FLAGS" in *suffix=3*) say "NET_FLAGS is still the placeholder ($NET_FLAGS): the node lane's flag goes into devnet3.conf first" ;; esac
case "$IGNEUMD" in *PLACEHOLDER*) [ "$mode" = status ] || { say "IGNEUMD is the placeholder: the 0.3.22 candidate's build fills it"; [ "$GO" = 0 ] || exit 1; } ;; esac
start_one() { # <name> <appdir> <p2p bind> <rpc> <json> <evm> <log> [extra args...]
local name="$1" appdir="$2" p2p="$3" rpc="$4" json="$5" evm="$6" log="$7"; shift 7
local args="$NET_FLAGS --appdir=$appdir --rpclisten=127.0.0.1:$rpc --rpclisten-json=127.0.0.1:$json --evm-rpclisten=127.0.0.1:$evm --listen=$p2p --nodnsseed --disable-upnp --nologfiles --yes $*"
if [ "$GO" = 0 ]; then say "DRY $name: $IGNEUMD $args > $log"; return 0; fi
"${SSH[@]}" bash -s -- "$name" "$IGNEUMD" "$appdir" "$log" "$args" <<'REMOTE'
set -euo pipefail; name="$1"; bin="$2"; appdir="$3"; log="$4"; args="$5"
# ssh flattens its arguments into one remote command line, so the argument string travels base64-encoded (the first --go at
# 18:22 BST lost everything after the first flag: the seed started on the OLD devnet with digest c562d70e and port 26611)
"${SSH[@]}" bash -s -- "$name" "$IGNEUMD" "$appdir" "$log" "$(printf '%s' "$args" | base64 | tr -d '\n')" <<'REMOTE'
set -euo pipefail; name="$1"; bin="$2"; appdir="$3"; log="$4"; args="$(printf '%s' "$5" | base64 -d)"
[ -x "$bin" ] || { echo "no binary $bin"; exit 1; }
mkdir -p "$appdir"; [ -z "$(ls -A "$appdir")" ] || echo "note: $appdir is not empty"
mkdir -p "$appdir"; [ -z "$(ls -A "$appdir")" ] || echo "note: $appdir is not empty: $(ls "$appdir" | tr '\n' ' ')"
case "$args" in *--devnet-suffix=3*) ;; *) echo "REFUSED: the argument line lacks --devnet-suffix=3: $args"; exit 1 ;; esac
cd "$(dirname "$log")"; setsid nohup "$bin" $args > "$log" 2>&1 < /dev/null & pid=$!; sleep 8
echo "$name pid $pid alive=$(kill -0 $pid 2>/dev/null && echo yes || echo NO) commit-strings=$(grep -a -c "$(echo "$bin" | grep -oE '[0-9a-f]{8}' | tail -1)" /proc/$pid/exe 2>/dev/null || echo ?)"
head -1 "$log" | cut -c1-120; grep -oE "Consensus params digest: [0-9a-f]+" "$log" | head -1
@ -35,7 +38,9 @@ REMOTE
case "$mode" in
seed) start_one dn3-seed "$DN3_SEED_APPDIR" "0.0.0.0:$DN3_SEED_P2P" "$DN3_SEED_RPC" "$DN3_SEED_JSON" "$DN3_SEED_EVM" "$DN3_SEED_LOG" --maxinpeers=128 --outpeers=8 ;;
node1) start_one node1-dn3 "$DN3_NODE1_APPDIR" "0.0.0.0:$DN3_NODE1_P2P" "$DN3_NODE1_RPC" "$DN3_NODE1_JSON" "$DN3_NODE1_EVM" /srv/hands/node1-dn3.log --enable-unsynced-mining --addpeer=127.0.0.1:$DN3_SEED_P2P --maxinpeers=128 --outpeers=8 ;;
observer-node) start_one observer-dn3 "$DN3_OBS_APPDIR" "127.0.0.1:$DN3_OBS_P2P" "$DN3_OBS_RPC" "$DN3_OBS_JSON" "$DN3_OBS_EVM" /srv/hands/observer-dn3.log --addpeer=127.0.0.1:$DN3_NODE1_P2P --addpeer=127.0.0.1:$DN3_SEED_P2P ;;
status) "${SSH[@]}" "for l in $DN3_SEED_LOG /srv/hands/node1-dn3.log /srv/hands/observer-dn3.log; do [ -f \$l ] && { echo \"== \$l\"; head -1 \$l | cut -c1-100; grep -oE 'Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed' \$l | head -2; tail -1 \$l | cut -c1-120; }; done; ss -ltn | awk '{print \$4}' | grep -E ':(26631|26651|26661|27630|26650|26660)\$' | tr '\n' ' '; echo" ;;
observer-node) # the fleet lane's instance: its unit (installed 16:39Z, disabled); IGNEUMD_DN3 and DN3_PEERS come from /srv/hands/dn3/dn3.env
if [ "$GO" = 0 ]; then say "DRY observer-node: sudo systemctl enable --now igneum-observer-node-dn3 (reads $DN3_OBS_SCRIPT; dn3.env IGNEUMD_DN3 must name the 0.3.22 artefact)"; "${SSH[@]}" 'grep -E "^(IGNEUMD_DN3|DN3_PEERS|DN3_LISTEN)=" /srv/hands/dn3/dn3.env'; else
ssh -i "$KEY" -o BatchMode=yes "root@${HOST#*@}" 'systemctl enable --now igneum-observer-node-dn3 && sleep 8 && systemctl is-active igneum-observer-node-dn3 && journalctl -u igneum-observer-node-dn3 --since "-60 s" --no-pager | grep -oE "igneumd/[^ ]+|Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed|P2P Server starting on: [^ ]+" | head -4'; fi ;;
status) "${SSH[@]}" "for l in $DN3_SEED_LOG /srv/hands/node1-dn3.log; do [ -f \$l ] && { echo \"== \$l\"; head -1 \$l | cut -c1-100; grep -oE 'Consensus params digest: [0-9a-f]+|genesis [0-9a-f]+ executed' \$l | head -2; tail -1 \$l | cut -c1-120; }; done; ss -ltn | awk '{print \$4}' | grep -E ':(26631|26651|26671|27630|26650|26670)\$' | tr '\n' ' '; echo" ;;
*) sed -n '2,12p' "$0" | sed 's/^# \{0,1\}//'; exit 2 ;;
esac

View file

@ -33,13 +33,13 @@ bs_route() { # <class: gate|build|check|suite|bench|prove|attack|other> -> the
}
# Spill-over (the project lead, 7 October 2026, 15:02 UK: build-1 at load 139 with a queue of 1 h 40 min while build-2 read 4.5 with both
# slots free). The class is a PREFERENCE, not a pin: a job goes to its class's box unless that box has no free slot or its 1-minute
# load is above BS_SPILL_LOAD (64), in which case it goes to the other box when THAT one has a free slot under the same load
# load is above BS_SPILL_LOAD (80 since 19:4x BST, was 64), in which case it goes to the other box when THAT one has a free slot under the same load
# line; when neither qualifies it queues on its own box. The alternate of box 1 is box 2, of box 2 box 1, of box 3 box 1; a box
# without a host file is never chosen. The decision is one line on the Mac (bs_log) and travels to the box in BR_ROUTE_* for the
# JSONL row ("route": preferred, box, spilled, reason), so the dashboard shows it per job. A box is read with one ssh
# (bs_box_state: free slots of the slot count, load1); BS_ROUTE_STATE_<n> in the environment replaces the ssh for the self-test
# (tools/ci/route-spill-check.sh), "down" standing for an unreachable box.
BS_SPILL_LOAD="${BS_SPILL_LOAD:-64}"
BS_SPILL_LOAD="${BS_SPILL_LOAD:-80}" # the project lead, 7 Oct 2026 19:4x BST: both boxes to near max; was 64
bs_box_state() { # <box> -> "free=<n> slots=<n> load1=<x>" | "absent" | "down"
local b="$1" v f h
v=$(eval "printf '%s' \"\${BS_ROUTE_STATE_$b:-}\""); if [ -n "$v" ]; then printf '%s' "$v"; return 0; fi

View file

@ -190,10 +190,10 @@ if [ "${1:-}" = --self-test-slots ]; then
after() { python3 -c "import sys; sys.exit(0 if float(open(sys.argv[1]).read()) >= float(open(sys.argv[2]).read()) else 1)" "$1" "$2"; }
# 1. two concurrent builds: 45 jobs each
fake a 6 & fake b 6 & wait
[ "$(cat "$t/a.jobs")" = JOBS=45 ] && [ "$(cat "$t/b.jobs")" = JOBS=45 ] || fail "two concurrent builds got $(cat "$t/a.jobs" "$t/b.jobs" | tr '\n' ' ') (want JOBS=45 JOBS=45)"
[ "$(cat "$t/a.jobs")" = JOBS=44 ] && [ "$(cat "$t/b.jobs")" = JOBS=44 ] || fail "two concurrent builds got $(cat "$t/a.jobs" "$t/b.jobs" | tr '\n' ' ') (want JOBS=44 JOBS=44)"
# 2. one build alone: 90
fake c 1
[ "$(cat "$t/c.jobs")" = JOBS=90 ] || fail "a lone build got $(cat "$t/c.jobs") (want JOBS=90)"
[ "$(cat "$t/c.jobs")" = JOBS=88 ] || fail "a lone build got $(cat "$t/c.jobs") (want JOBS=88)"
# 3. a quiet measurement blocks an unbounded build (it starts only after the quiet ended) and lets a bounded suite run beside it
fake m 9 1 & sleep 0.5; fake d 1 & BR_CORES=1 BR_NICE=10 fake s 1 & wait # the quiet holds 9 s: longer than a slot take plus the 3 s settle
after "$t/d.start" "$t/m.end" || fail "an unbounded build started while a quiet measurement held the box (build start $(cat "$t/d.start"), quiet end $(cat "$t/m.end"))"
@ -214,8 +214,8 @@ if [ "${1:-}" = --self-test-slots ]; then
grep -q 'self-test f' "$t/locks/build-0" || fail "the holder line of the busy slot build-0 was lost when another build probed it: '$(cat "$t/locks/build-0")'"
wait
# 6. the log carries the job count and the measure flag
grep -q '"jobs":45' "$t/log/builds.jsonl" && grep -q '"measure":true' "$t/log/builds.jsonl" || fail "builds.jsonl lacks jobs or measure fields"
echo "self-test-slots: two concurrent builds 45 each, a lone build 90, a quiet blocks an unbounded build and not a bounded suite, a quiet is refused beside a slot or a lease, a run keeps off leased cores, a probe keeps the holder line, the log carries jobs and measure"; exit 0
grep -q '"jobs":44' "$t/log/builds.jsonl" && grep -q '"measure":true' "$t/log/builds.jsonl" || fail "builds.jsonl lacks jobs or measure fields"
echo "self-test-slots: two concurrent builds 44 each, a lone build 88, a quiet blocks an unbounded build and not a bounded suite, a quiet is refused beside a slot or a lease, a run keeps off leased cores, a probe keeps the holder line, the log carries jobs and measure"; exit 0
fi
# One run per worktree directory at a time (6 October 2026, 19:51:09 UK: two runs of one worktree started in the same second;
@ -318,7 +318,7 @@ PY
SLOTS_DIR="$IGNEUM_BUILD_SLOTS_DIR"
slots=$(cat "$SLOTS_DIR/slots" 2>/dev/null || echo 1); [ "$slots" -ge 1 ] 2>/dev/null || slots=1
JOBS_ALONE="${JOBS_ALONE:-90}"; JOBS_SHARED="${JOBS_SHARED:-45}"
JOBS_ALONE="${JOBS_ALONE:-88}"; JOBS_SHARED="${JOBS_SHARED:-44}" # the project lead, 7 Oct 2026: 88 of 96 cores, 8 reserved for the release builds, the seed and the observers
holder_line() { printf 'pid %s since %sZ waited %s s: %s\n' "$BR_PID" "$(date -u +%H:%M:%S)" "$1" "$BR_LABEL"; }
give_up() { # <what>
echo "build-remote: gave up waiting for $1 after 2 h" >&2
@ -469,6 +469,9 @@ BR_RUN_LOG="$RUN_LOG_DIR/$BR_HOST-$BR_T0-$BR_PID.log"; export BR_RUN_LOG
# (since the third slot on build-2, 7 Oct 2026: a bounded run takes the band its SLOT owns, counted from the top: slot 0 the last N
# cores, slot 1 the N below, slot 2 the N below that, so three bounded runs never share a core; a band below core 0 falls back to
# the last N)
# (the project lead, 7 Oct 2026 19:4x BST, both boxes to near max: a bounded run takes the LAST N cores, N = 88 by default, leaving the first 8
# to the release builds, the seed and the observer processes; with N above half the box the slots share the band, and nice 10 plus
# the per-slot jobs rule keep two suites fair; a smaller N (IGNEUM_BOUND_CORES) returns to disjoint bands per slot when it fits)
ncpu=$(nproc); cores_str="0-$((ncpu - 1))"
if [ "${BR_CORES:-0}" -gt 0 ] && [ "${BR_CORES}" -lt "$ncpu" ]; then
band=0; case "${got:-}" in ''|measure) ;; *) band=$got ;; esac

View file

@ -93,6 +93,7 @@
"sig_scheme_activation_daa": 18446744073709551615,
"finality_succession_activation_daa": 18446744073709551615,
"latency_ladder_cache_rung": {"mib": 512, "admissible": false},
"latency_ladder_cache_rung_activation_daa": 18446744073709551615,
"fees": {"pgas": {"version": 1, "cycles_per_pgas": 1000, "intrinsic_pgas_per_tx": 300, "modexp_base": 10, "modexp_per_byte_numer": 1, "modexp_per_byte_denom": 10}, "block_proving_gas_limit": 120000, "shard_proving_gas_budget": 30000, "min_execution_base_fee_wei": 100000000000, "min_proving_base_fee_wei": 10000000000000, "initial_execution_base_fee_wei": 100000000000, "initial_proving_base_fee_wei": 10000000000000, "base_fee_change_denominator": 8},
"peer_directory_activation_daa": null
}

View file

@ -82,6 +82,16 @@ Stats JSON (what Hive reads from `$stats`): `hs` (kH/s per GPU), `hs_units` (`kh
digest on the downloads page; a different one means the override is stale and the node is refused.
- Ports: the bundled node listens on 26611 (p2p) and answers RPC on 127.0.0.1:26610 only.
## Shipped packs (0.3.22)
`make-hive-package.sh --kit <zip>` (repeatable) puts program-pack kits under `packs/` in the archive: the class v4 sub-version 3
kit (eight packs, program_id `a785001687d8688a` for the shared devnet's epoch 0) and Devnet 3's epoch-0 pack
`v4-devnet3-epoch0` (program_id `fce15bf61030be57`, exported under igneum-pow 017e7037 over genesis `4020cb43` as epoch and
era seed, day bytes for 7 October UTC). They are the rig's FIRST-START convenience: `h-run.sh` seeds `packs/devnet` from the
shipped pack only when the node's own export left nothing, so a rig mines from its first start; the pack is dated, and a rig
starting after epoch 0 (3,600 DAA) re-exports from its own node as before. The shipped pack is never the authority; the
pack-id gate reads `program.json`'s `program_id`.
## Building the package
infra/cross/build-linux.sh # igneumd and igneum-miner for Linux (cargo-zigbuild), into infra/cross/out

View file

@ -73,7 +73,17 @@ say "GPUs: $nv NVIDIA, $amd AMD (worker setting: $WORKER)"
# 3. the hourly program pack from the node (the workers read it with --pack; the miner writes the next one to packs/prepare)
export_pack() { [[ "$NODE_URL" == "none" ]] && return 0; rm -rf "$HERE/packs/devnet"; "$BIN/igneum-miner" export-pack "$NODE_URL" "$HERE/packs/devnet" >> "$MAIN" 2>&1; }
# a shipped pack (packs/<name>/program.json, from make-hive-package.sh --kit; 0.3.22) seeds packs/devnet ONLY when the node's own
# export left nothing: the rig's first-start convenience, never the authority (a rig starting after epoch 0 re-exports from its node;
# the miner's --prepare-packs and exit 42 keep it on the chain's program as before). SHIPPED_PACK names the directory under packs/
# (h-config.sh or the Flight Sheet; default v4-devnet3-epoch0 when it exists).
seed_pack() {
[[ -d "$HERE/packs/devnet" && -f "$HERE/packs/devnet/program.json" ]] && return 0
local sp="${SHIPPED_PACK:-v4-devnet3-epoch0}"
if [[ -f "$HERE/packs/$sp/program.json" ]]; then rm -rf "$HERE/packs/devnet"; cp -R "$HERE/packs/$sp" "$HERE/packs/devnet"; say "first start: packs/devnet seeded from the shipped pack $sp (program_id $(sed -n 's/.*"program_id" *: *"\{0,1\}\([0-9a-fx]*\)"\{0,1\}.*/\1/p' "$HERE/packs/$sp/program.json" | head -1)); the node's export replaces it"; fi
}
export_pack || say "pack export failed; the miners retry"
seed_pack
# 4. one miner per GPU, restarted on exit (exit 42 = the program changed and the worker cannot prepare: re-export the pack)
run_gpu() {

View file

@ -4,6 +4,8 @@
# and infra/cross/out-workers (the two GPU workers, build-workers-linux.sh)
# NODE_OUT=... WORKERS_OUT=... VERSION=... OUT=... other inputs; VERSION defaults to the igneumd version in version.txt
# --fake stub binaries instead (the self-test; never ship it)
# --kit <zip> (repeatable) program-pack kit(s) unpacked under packs/ in the tar (0.3.22: the sub-version 3
# kit and Devnet 3's epoch-0 pack); the rig's first-start convenience, see h-run.sh
# Output: packaging/hive/build/igneum-hive-<version>.tar.gz with the directory igneum/ inside (what Hive expects:
# the archive name carries the version, the directory does not), plus its sha256 and the Flight Sheet lines.
set -euo pipefail
@ -12,7 +14,12 @@ REPO="$(cd "$HERE/../.." && pwd)"
NODE_OUT="${NODE_OUT:-$REPO/infra/cross/out-v2}"
WORKERS_OUT="${WORKERS_OUT:-$REPO/infra/cross/out-workers}"
OUT="${OUT:-$HERE/build}"
FAKE=0; [[ "${1:-}" == "--fake" ]] && FAKE=1
# --kit <zip> (repeatable; 0.3.22, 7 October 2026): a program-pack kit unpacked under packs/ in the tar (the class v4 sub-version 3
# packs and Devnet 3's epoch-0 pack, from the hash lane), the rig's FIRST-START convenience: h-run.sh seeds packs/devnet from a
# shipped pack only when the node's own export leaves nothing, and a rig starting after epoch 0 re-exports from its own node as
# before; the shipped pack is never the authority. The pack-id gate reads program.json's program_id.
FAKE=0; KITS=()
while [[ $# -gt 0 ]]; do case "$1" in --fake) FAKE=1; shift ;; --kit) KITS+=("$2"); shift 2 ;; *) echo "unknown argument $1" >&2; exit 2 ;; esac; done
log() { printf '%s %s\n' "$(date -u +%H:%M:%S)" "$*"; }
die() { log "ERROR: $*" >&2; exit 1; }
stage="$OUT/igneum"; rm -rf "$stage"; mkdir -p "$stage/bin"
@ -34,6 +41,18 @@ else
VERSION="${VERSION:-$(head -1 "$NODE_OUT/version.txt" | awk '{print $2}')}"
fi
[[ -n "$VERSION" ]] || die "no version (VERSION=... or a version.txt with 'igneumd <version>')"
if [[ ${#KITS[@]} -gt 0 ]]; then
mkdir -p "$stage/packs"
for k in "${KITS[@]}"; do
[[ -f "$k" ]] || die "no kit zip at $k"
unzip -q -o "$k" -d "$stage/packs" || die "kit $k does not unzip"
log "kit $(basename "$k") sha256 $(shasum -a 256 "$k" 2>/dev/null | awk '{print $1}' || sha256sum "$k" | awk '{print $1}') unpacked under packs/"
done
# every pack directory holds program.json; its program_id is what the pack-id gate reads
n=0; while IFS= read -r pj; do d="$(dirname "$pj")"; id="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1])).get("program_id",""))' "$pj" 2>/dev/null || true)"; log "pack ${d#"$stage/packs/"}: program_id ${id:-?}"; n=$((n+1)); done < <(find "$stage/packs" -name program.json | sort)
[[ $n -gt 0 ]] || die "the kit(s) hold no pack (no program.json found)"
printf 'packs: %s pack(s) from %s (first-start convenience; the rig re-exports from its own node)\n' "$n" "$(for k in "${KITS[@]}"; do basename "$k"; done | tr '\n' ' ')" >> "$stage/version.txt"
fi
cp "$HERE/h-config.sh" "$HERE/h-run.sh" "$HERE/h-stats.sh" "$HERE/README.md" "$stage/"
sed "s/^CUSTOM_VERSION=.*/CUSTOM_VERSION=$VERSION/" "$HERE/h-manifest.conf" > "$stage/h-manifest.conf"
chmod +x "$stage"/h-*.sh "$stage"/bin/*

View file

@ -54,7 +54,7 @@ KIND="" TARGET="" PLATFORM="" REQUIRES="" REQUIRES_SET=0 ID="" TITLE="" EXPIRES_
SCRIPT="" SHELL_KIND="" ELEVATED=0 STOP_MINERS=0 TIMEOUT_MIN="" CARDS_OFF=""
FILE="" URL="" SHA="" SIZE="" DIR="" TO="" EXTRACT=0 EXTRACT_DIR="" FRESH=0
GLOBS=() COMMAND="" WHAT=""
ZIP="" FIXTURES="" CAP_MIN="" DISTRO="" WSL_USER="" REMOVE_ID=""
ZIP="" FIXTURES="" CAP_MIN="" DISTRO="" WSL_USER="" REMOVE_ID="" FORCE="" INSTALLS_APP=0
TARGETS="" BUDGET_MIN="" STAGE_MIN="" MIN_FREE_GB="" TESTS=1 RELAY_URL="" NICE="" CARGO_JOBS=""
case "$CMD" in
remove) REMOVE_ID="${1:-}"; [ -n "$REMOVE_ID" ] || { echo "remove <id>" >&2; exit 2; }; shift ;;
@ -67,6 +67,8 @@ while [ $# -gt 0 ]; do
--requires) REQUIRES="$2"; REQUIRES_SET=1; [ "$REQUIRES" = none ] && REQUIRES=""; shift 2 ;;
--id) ID="$2"; shift 2 ;;
--title) TITLE="$2"; shift 2 ;;
--force) FORCE="$2"; shift 2 ;; # remove: override the running-job refusal, with the reason (7 Oct 2026)
--installs-app) INSTALLS_APP=1; shift ;; # add --kind run: the script installs over the app; never removed without --force
--expires-hours) EXPIRES_H="$2"; shift 2 ;;
--script) SCRIPT="$2"; shift 2 ;;
--shell) SHELL_KIND="$2"; shift 2 ;;
@ -227,8 +229,8 @@ if [ "$CMD" = list ]; then
[ -f "$JOBS" ] || { echo "no jobs file in $DEST"; exit 0; }
"$SIGNER" verify-jobs "$PUB" "$JOBS" "$JOBS.sig" || { echo "the file in $DEST does not verify; run: $0 sign" >&2; exit 1; }
if [ -f "$SIGNED" ]; then "$SIGNER" verify-signed-jobs "$PUB" "$SIGNED" >/dev/null || { echo "the envelope in $DEST does not verify; run: $0 sign" >&2; exit 1; }; else echo "(no igneum-jobs.signed.json yet; the next write makes one)"; fi
python3 - "$JOBS" <<'PY'
import json, sys, datetime
INSTALLS_APP="$INSTALLS_APP" python3 - "$JOBS" <<'PY'
import json, sys, datetime, os
f = json.load(open(sys.argv[1]))
now = datetime.datetime.now(datetime.timezone.utc)
for j in f.get("jobs", []):
@ -353,17 +355,36 @@ except Exception: print("")' "${ZIP%.zip}.json" 2>/dev/null || true)"
esac
[ -n "$PLATFORM" ] || PLATFORM=any
[ -n "$ID" ] || ID="$KIND-$(date -u +%Y%m%d-%H%M%S)"
NEW_JOB="$(python3 -c 'import json,sys,datetime
NEW_JOB="$(INSTALLS_APP="$INSTALLS_APP" python3 -c 'import json,sys,datetime,os
a=sys.argv
now=datetime.datetime.now(datetime.timezone.utc)
t={"machine_ids": "all" if a[2]=="all" else [x.strip().lower() for x in a[2].split(",") if x.strip()], "platform": a[3]}
if os.environ.get("INSTALLS_APP")=="1" and a[5]=="run": t.setdefault("params",{})["installs_app"]=True
if a[4]: t["requires"]=[x.strip() for x in a[4].split(",") if x.strip()]
print(json.dumps({"id": a[1], "kind": a[5], "title": a[6], "created_at": now.strftime("%Y-%m-%dT%H:%M:%SZ"), "expires_at": (now+datetime.timedelta(hours=float(a[7]))).strftime("%Y-%m-%dT%H:%M:%SZ"), "target": t, "params": json.loads(a[8]), "report": "log-intake"}))' "$ID" "$TARGET" "$PLATFORM" "$REQUIRES" "$KIND" "$TITLE" "$EXPIRES_H" "$PARAMS")"
fi
# ---- the removal guard (7 October 2026, 18:53 BST: a removal reached PC 2 one second after its job had launched a silent
# installer over the running app; the runner's abort-on-removal ended the process tree and the app went dark). A remove refuses
# when any target's latest report for the id has started and carries no final line (the job is running), or when the job was
# published with --installs-app; `--force "<reason>"` overrides, and the reason is printed. The read is tools/jobs.mjs <id>.
# REMOVE_GUARD_READ=<file> replaces the read for the self-test (tools/ci/publish-jobs-check.sh).
if [ -n "$REMOVE_ID" ]; then
read_out="$( if [ -n "${REMOVE_GUARD_READ:-}" ]; then cat "$REMOVE_GUARD_READ"; else node "$ROOT/tools/jobs.mjs" "$REMOVE_ID" 2>/dev/null || true; fi )"
running="$(printf '%s\n' "$read_out" | grep -cE '^(job [^ ]+ \(.*\) on .* started|== running the)' || true)"
final="$(printf '%s\n' "$read_out" | grep -cE '^(SUMMARY: |job [^ ]+: (done|failed|aborted|timeout))' || true)"
jobs_now="$JOBS"; [ -f "$DEST/igneum-jobs.json" ] && jobs_now="$DEST/igneum-jobs.json" # the file at the destination this run writes
installs="$(python3 -c 'import json,sys; j=[x for x in json.load(open(sys.argv[1])).get("jobs",[]) if x.get("id")==sys.argv[2]]; print(1 if j and "\"installs_app\": true" in json.dumps(j[0]) else 0)' "$jobs_now" "$REMOVE_ID" 2>/dev/null || echo 0)"
if [ -z "$FORCE" ]; then
if [ "$running" -gt 0 ] && [ "$final" = 0 ]; then echo "remove refused: $REMOVE_ID has started on a machine and has no final line yet (a removal ends the running job's process tree); wait for its SUMMARY, or --force \"<reason>\"" >&2; exit 3; fi
if [ "$installs" = 1 ]; then echo "remove refused: $REMOVE_ID was published with --installs-app (it installs over the app); --force \"<reason>\" to remove it anyway" >&2; exit 3; fi
else
echo "remove: --force given ($FORCE); running=$running final=$final installs_app=$installs"
fi
fi
# ---- merge: current jobs minus expired (minus a removed id), plus the new one; canonical JSON ---------------------
NEW="$JOBS.new"
python3 - "$JOBS" "$NEW" "$NEW_JOB" "$REMOVE_ID" <<'PY'
INSTALLS_APP="$INSTALLS_APP" python3 - "$JOBS" "$NEW" "$NEW_JOB" "$REMOVE_ID" <<'PY'
import json, sys, datetime, os
cur, out, new_job, remove = sys.argv[1:5]
now = datetime.datetime.now(datetime.timezone.utc)

View file

@ -1,5 +1,9 @@
/* Igneum DAG / Ember 2.0 (the EMBER 02 renderer pack, 7 Oct 2026). THE SHARED SOURCE: scene/live-dag.js; site/live-dag.js and
* app/igneum-app/ui/live-dag.js are byte-equal copies written by tools/scene/sync.mjs (the gate refuses a drifted copy). Edit here.
* 2.0.6 (7 Oct 2026): IgneumDag.shardWords(block, nowMs) is the one shard sentence (tooltip, /live inspector, app inspector); the
* empty case reads from the block's facts (loading, excluded, not yet ordered, off the chain) instead of one fixed sentence.
* 2.0.5 (key-22, 7 Oct 2026): IgneumDag.legend({mine}) and renderLegend(el,{mine}) are the one key both pages render; the app's
* Included swatch had been ember while the scene draws included blocks in --included, and "pending" lower-case.
* 2.0.4 (7 Oct 2026): the box's height follows the lanes. laneHeight (default 46 px, 40 on a phone, 26 compact) times the lanes
* shown (at most maxLanes, narrowLanes on a phone, never under 2) plus the axis and padding is the scene's wanted height;
* onSize(heightPx, {lanes, laneHeight, narrow, compact}) reports it whenever it changes, so a page can size the box, and with
@ -301,13 +305,13 @@
function paint(){if(destroyed||!W||!H)return;var t=performance.now();draw(t);lastPaint=t;}
function redraw(){if(destroyed||raf||doc.hidden||!visible)return;lastPaint=-Infinity;raf=requestAnimationFrame(frame);}
function stopFrame(){if(raf)cancelAnimationFrame(raf);raf=0;}
function words(b){
function words(b,nowMs){
if(!b)return {title:'No block selected',lines:[]};
var inclusion=b.color==='blue'?'included':b.color==='red'?'excluded':'pending';
var bits=[inclusion];if(b.chain)bits.push('selected chain');if(b.proven)bits.push('proven');if(b.locked)bits.push('locked checkpoint');if(b.final)bits.push('final');
return {title:b.hash+' '+bits.join(' / '),lines:[(own(b)?'Your block / ':'')+'miner key '+b.miner,
'Blue score '+fmt(b.blue_score===undefined?b.blue:b.blue_score)+' / DAA '+fmt(b.daa),b.parents.length+' parent'+(b.parents.length===1?'':'s'),
'Shards: '+(b.shards.length?b.shards.map(function(s){return s.state;}).join(', '):'no shard plan yet')]};
'Shards: '+shardWords(b,nowMs).summary]};
}
function showTip(b){
if(!tip)return;
@ -377,5 +381,46 @@
getSnapshot:function(){return {ok:true,state:{stale:state!=='live'},blocks:blocks.map(cloneBlock),finality:{checkpoints:cps.map(function(c){return Object.assign({},c);})}};}};
instances.set(canvas,api);if(chip)chip.hidden=true;theme();size();emit('onState',state,reason);if(opts.poll!==false)poll();redraw();return api;
}
root.IgneumDag={mount:mount,version:'2.0.4'};
// the shard sentence, once (7 Oct 2026, the fixed sentence the site's animation showed on every planless block): from the
// block's own facts. No shards: an excluded block has nothing to prove, a pending block is not yet ordered, a blue block off
// the selected chain gets no plan, a chain block under 10 s old is loading its plan, an older one says how long it has waited.
// With shards: a planned shard with no prover is awaiting one (with the block's age), assigned, proving, verified, paid.
function ageWord(sec){sec=Math.max(0,Math.round(sec));return sec<90?sec+' s':sec<5400?Math.round(sec/60)+' min':Math.round(sec/3600)+' h';}
function shardWords(b,nowMs){
var now=finite(nowMs)?nowMs:Date.now(),age=b&&finite(b.ts)?Math.max(0,(now-b.ts)/1000):0,sh=(b&&b.shards)||[];
if(!sh.length){
if(!b)return {summary:'',items:[],state:'none'};
if(b.color==='red')return {summary:'excluded, nothing to prove',items:[],state:'excluded'};
if(b.color!=='blue')return {summary:'not yet ordered',items:[],state:'pending'};
if(!b.chain)return {summary:'off the selected chain, no shards planned',items:[],state:'none'};
if(age<10)return {summary:'shard plan loading',items:[],state:'loading'};
return {summary:'no shard plan after '+ageWord(age),items:[],state:'late'};
}
var items=sh.map(function(x,i){var st=x.state,w=st==='planned'?(x.prover?'assigned to '+x.prover:'awaiting a prover · '+ageWord(age)):st==='proving'?'proving'+(x.prover?' by '+x.prover:''):st==='verified'?'verified':st==='paid'?'paid'+(finite(x.payout)?' '+x.payout+' IGN':''):'unknown';return {i:i,state:st,word:w};});
var n={paid:0,verified:0,proving:0,assigned:0,awaiting:0};
sh.forEach(function(x){if(x.state==='planned'){if(x.prover)n.assigned++;else n.awaiting++;}else if(n[x.state]!==undefined)n[x.state]++;});
var parts=[];if(n.paid)parts.push(n.paid+' paid');if(n.verified)parts.push(n.verified+' verified');if(n.proving)parts.push(n.proving+' proving');if(n.assigned)parts.push(n.assigned+' assigned');if(n.awaiting)parts.push(n.awaiting+' awaiting a prover · '+ageWord(age));
return {summary:parts.join(', '),items:items,state:n.awaiting?'awaiting':n.proving?'proving':'done'};
}
// key-22 (7 October 2026, the app's key against /live): THE key, once. Entries in the order both
// pages show them, each naming the token the scene draws that state with and the swatch's shape; the app passes
// {mine:true} and gets "Your blocks" (ringed, molten) first. tools/scene/legend.test.mjs fails when a page's key or a
// drawn colour drifts from this list. Shapes: square (outlined), circle (the checkpoint ring), tick (the proof mark),
// ringed (the own-block halo); faded dims the swatch as the scene dims excluded blocks.
function legend(o){
var own={id:'you',label:'Your blocks',token:'--molten',shape:'ringed'};
var list=[{id:'pending',label:'Pending',token:'--ash',shape:'square'},{id:'included',label:'Included',token:'--included',shape:'square'},
{id:'excluded',label:'Excluded',token:'--excluded',shape:'square',faded:true},{id:'chain',label:'Selected chain',token:'--ember',shape:'square',fill:'--ember-12'},
{id:'proven',label:'Proven',token:'--bone',shape:'tick'},{id:'locked',label:'Locked checkpoint',token:'--ember',shape:'circle'}];
return (o&&o.mine?[own]:[]).concat(list);
}
// renders the key into el: <span><i class="lg <shape> [faded]" style="--lg:var(token)"></i>Label</span>…, keeping any
// children the page already placed there (the app's source line) after the entries
function renderLegend(el,o){
if(!el)return [];var entries=legend(o),doc=el.ownerDocument,keep=Array.prototype.slice.call(el.childNodes).filter(function(n){return !(n.getAttribute&&n.getAttribute('data-lg'));});
while(el.firstChild)el.removeChild(el.firstChild);
entries.forEach(function(e){var sp=doc.createElement('span');sp.setAttribute('data-lg',e.id);var i=doc.createElement('i');i.className='lg '+e.shape+(e.faded?' faded':'');i.style.setProperty('--lg','var('+e.token+')');if(e.fill)i.style.setProperty('--lg-fill','var('+e.fill+')');sp.appendChild(i);sp.appendChild(doc.createTextNode(e.label));el.appendChild(sp);});
keep.forEach(function(n){el.appendChild(n);});return entries;
}
root.IgneumDag={mount:mount,legend:legend,renderLegend:renderLegend,shardWords:shardWords,version:'2.0.6'};
})(window);

View file

@ -411,16 +411,49 @@ for (const [file, active] of PAGES) {
}
// the public bench table (/miners): one row per card, generator version and miner version, from site/miner-bench.json
// (the bench-log numbers that exist today, and rows later jobs append); rendered through the same scrub as /bench
// (the bench-log numbers that exist today, and rows later jobs append); rendered through the same scrub as /bench.
// 7 October 2026 (the project lead): the CURRENT class (rows measured on the class v4 program, or class v3 rows re-measured with their
// class v4 cost, 6 October on) is the table; the earlier classes (the genesis program, the hourly program, class v3 before
// the shadow) sit collapsed below so no reader compares a 228 MH/s genesis row with a 136 MH/s class v3 row as one thing.
// Every header sorts on a click (default MH per watt, high first); the sort is a few lines of script in the page.
{
const bj = JSON.parse(readFileSync(join(here, 'miner-bench.json'), 'utf8'));
const rows = bj.rows.slice().sort((a, b) => (a.card < b.card ? -1 : a.card > b.card ? 1 : a.generator < b.generator ? -1 : a.generator > b.generator ? 1 : b.mh_s - a.mh_s));
const isCurrent = (r) => r.generator === 'v2' && r.date >= '2026-10-06';
const byMhW = (a, b) => ((b.mh_per_w ?? -1) - (a.mh_per_w ?? -1)) || (b.mh_s - a.mh_s) || (a.card < b.card ? -1 : 1);
const cur = bj.rows.filter(isCurrent).sort(byMhW);
const earlier = bj.rows.filter(r => !isCurrent(r)).sort((a, b) => (a.card < b.card ? -1 : a.card > b.card ? 1 : a.generator < b.generator ? -1 : a.generator > b.generator ? 1 : b.mh_s - a.mh_s));
const rows = bj.rows;
const fmt = (n) => Number(n).toLocaleString('en-GB', { maximumFractionDigits: 1 });
const cell = (r) => [
r.card, r.generator, fmt(r.mh_s), r.mh_per_w == null ? 'not measured' : fmt(r.mh_per_w), r.miner, r.date, r.source, r.by + (r.note ? '. ' + r.note : ''),
const fmt3 = (n) => Number(n).toLocaleString('en-GB', { maximumFractionDigits: 3 });
const heads = [
['Card', 'card', 'text'], ['Generator', 'generator', 'text'], ['Best MH/s', 'mh_s', 'num'], ['Watts', 'watts', 'num'], ['MH per watt', 'mh_per_w', 'num'],
['Class v4 cost', 'v4_cost', 'text'], ['Tuned', 'tuned', 'text'], ['Miner', 'miner', 'text'], ['Date', 'date', 'text'], ['Source', 'source', 'text'], ['Who measured it', 'by', 'text'],
];
const table = '<div class="tbl"><table><thead><tr>' + ['Card', 'Generator', 'Best MH/s', 'MH per watt', 'Miner', 'Date', 'Source', 'Who measured it'].map(h => `<th>${h}</th>`).join('') + '</tr></thead><tbody>' +
rows.map(r => '<tr>' + cell(r).map(c => `<td>${esc(String(c))}</td>`).join('') + '</tr>').join('') + '</tbody></table></div>';
const cells = (r) => [
[r.card, r.card], [r.generator, r.generator], [fmt(r.mh_s), r.mh_s], [r.watts == null ? 'not read' : fmt(r.watts), r.watts ?? -1], [r.mh_per_w == null ? 'not measured' : fmt3(r.mh_per_w), r.mh_per_w ?? -1],
[r.v4_cost || 'not measured', r.v4_cost || ''], [r.tuned || 'stock, mining', r.tuned || ''], [r.miner + (r.driver_os ? ' (' + r.driver_os + ')' : ''), r.miner], [r.date, r.date], [r.source, r.source], [r.by + (r.note ? '. ' + r.note : ''), r.by],
];
const render = (list, id) => '<div class="tbl"><table class="sortable" id="' + id + '"><thead><tr>' +
heads.map(([h, k, t], i) => `<th data-key="${k}" data-type="${t}" aria-sort="${k === 'mh_per_w' ? 'descending' : 'none'}"><button type="button" class="sort">${h}</button></th>`).join('') +
'</tr></thead><tbody>' + list.map(r => '<tr>' + cells(r).map(([c, v]) => `<td data-v="${esc(String(v))}">${esc(String(c))}</td>`).join('') + '</tr>').join('') + '</tbody></table></div>';
const table = render(cur, 'bench-current');
const earlierTable = render(earlier, 'bench-earlier');
const sortScript = `<script>
(function(){
// header sort on the bench tables: a click sorts by that column (numbers by value, text by locale), a second click flips it
document.querySelectorAll('table.sortable').forEach(function(t){
var ths=t.querySelectorAll('th'),tb=t.querySelector('tbody');
ths.forEach(function(th,i){th.querySelector('button').addEventListener('click',function(){
var cur=th.getAttribute('aria-sort'),dir=cur==='descending'?'ascending':'descending',num=th.getAttribute('data-type')==='num';
ths.forEach(function(o){o.setAttribute('aria-sort','none');});th.setAttribute('aria-sort',dir);
var rows=Array.prototype.slice.call(tb.querySelectorAll('tr'));
rows.sort(function(a,b){var x=a.children[i].getAttribute('data-v'),y=b.children[i].getAttribute('data-v');var c=num?(parseFloat(x)-parseFloat(y)):x.localeCompare(y,'en');return dir==='descending'?-c:c;});
rows.forEach(function(r){tb.appendChild(r);});
});});
});
})();
</script>`;
const sortStyle = '<style>th .sort{all:unset;cursor:pointer;font:inherit;color:inherit}th .sort::after{content:" \\2195";opacity:.45}th[aria-sort="descending"] .sort::after{content:" \\2193";opacity:1}th[aria-sort="ascending"] .sort::after{content:" \\2191";opacity:1}details.earlier{margin:var(--s-4) 0}details.earlier summary{cursor:pointer;color:var(--bone)}</style>';
// Ember Tune's fleet priors (site/miner-priors.json, tools/tuning.mjs --priors --site): one row per card model,
// driver major and program class; a row under the sample floor shows its count and no point
const pj = JSON.parse(readFileSync(join(here, 'miner-priors.json'), 'utf8'));
@ -437,14 +470,21 @@ for (const [file, active] of PAGES) {
prows.map(r => '<tr>' + pcell(r).map(c => `<td>${esc(String(c))}</td>`).join('') + '</tr>').join('') + '</tbody></table></div>'
: '<p>No tune reports yet. The first rows appear once five machines with the same card model have reported.</p>';
const body = scrubBench([
sortStyle,
'<h2 id="table">The table</h2>',
'<p>One row per card, generator version and miner version. The rate is the best one measured. Integrated GPUs are not listed. Prototype rows are bench numbers from before the devnet and say so in the miner column.</p>',
'<p>One row per card on the current class: the class v4 program (the latency-shadow block over the class v3 hash), or a class v3 row re-measured with its class v4 cost on 6 October 2026 or later. Click a column header to sort; the table opens by MH per watt. Integrated GPUs are not listed. The earlier classes sit below, collapsed.</p>',
'<p><strong>Why the rate fell from the first bench to today.</strong> The genesis program did 104 dependent random 4-byte loads per hash over a 1 GiB dataset; the hourly program and class v3 do 128, with the mixer between them; class v4 adds about 100,000 integer operations per hash that ride in the memory wait. So the hash is bound by random-read bandwidth by design, and a card\'s MH/s is a relative number: the difficulty follows it, and the same card earns the same share of blocks at 136 MH/s on class v3 as it did at 228 MH/s on the genesis program. What a miner compares is hash per watt, and what the chain cares about is the chip edge, which the shadow work is there to cut.</p>',
table,
`<p>Rows on the current class: ${cur.length}. Each row names the engineering log entry or the job it came from.</p>`,
'<details class="earlier"><summary>Earlier classes (the genesis program, the hourly program, class v3 before the shadow): ' + earlier.length + ' rows, not comparable with the table above</summary>',
'<p>These rows are the bench numbers of 3 and 4 October 2026: the genesis program (104 loads per hash), the hourly program and the first class v3 miner. A higher MH/s here is a different hash, not a faster card.</p>',
earlierTable,
'</details>',
'<h2 id="how">How a row gets here</h2>',
'<p>Every row names the engineering log entry or the job it came from. "Measured by the team" means our own hardware and our own log. "Reported by the fleet" means a machine we do not own, read from the status lines its miner uploads.</p>',
'<p>MH per watt needs the card\'s power draw during the run. The app reads it on NVIDIA cards through the driver. Rows get the figure when a run records it.</p>',
'<p>Every row names the engineering log entry or the job it came from. "Measured by the team" means our own hardware and our own log. "Reported by the fleet" or "measured by the fleet" means a machine we rent or do not own, read from the status lines its miner uploads or from a bench run on it.</p>',
'<p>MH per watt needs the card\'s power draw during the run. The app reads it on NVIDIA cards through the driver. Rows get the figure when a run records it. The class v4 cost column is what the latency-shadow work costs that card against the class v3 control, in watts and rate, where it was measured. The tuned column is the card\'s state at the row: a full Ember Tune names its point; stock means the card as it came, bench only or mining.</p>',
'<p>There is no other Igneum miner to compare with yet, so this table compares cards, not miners. The app that produces these rows: <a href="/miner">the miner page</a>.</p>',
`<p>Rows: ${rows.length}. Each row names the engineering log entry it came from.</p>`,
sortScript,
'<h2 id="priors">Fleet tuning priors</h2>',
'<p>Ember Tune runs on every card the app mines with: the power limit and the core clock are stepped on the live program and the card keeps the point with the best MH per watt within 1% of its top rate. Every finished tune is reported back without anything that identifies the owner, and the fleet\'s median point per card model, driver major and program class comes back down inside the signed update manifest as the starting point for the next card of that model. A model needs ' + pj.min_samples + ' reports before its prior is used.</p>',
ptable,

View file

@ -218,7 +218,7 @@
<div class="derived"><p>Here are the limits, stated before anyone else states them.</p>
<ul>
<li><strong>A proof in seconds.</strong> Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.</li>
<li><strong>A chip is impossible.</strong> No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). The published model (5 October 2026) prices the strongest chip we can name, one with the whole cache on-die computing dataset items on the fly, at 0.92x the hash rate of an RTX 5090 per unit of silicon with a 3x fixed-function allowance, approximate. The same model, drawn out to the chip that stores the dataset (6 October 2026): The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090. A memory-controller chip that stores the whole dataset reaches 1.2x per chip and, in our model, 5x to 9x per joule; the Ethash chips of this class reached 2.1x to 4.8x. The lever against it, program work in the latency shadow, is measured and in its gates: it brings the chip to 2.1x to 3.9x, the range running from a chip core as costly per operation as the GPU’s (k = 1) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x. Sources: the chip model analysis (6 October 2026); the Ethash rows of the ASIC history (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022); Counter ASIC 3.0 item 8 (100,000 ops per hash: the chip's per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at a chip core equal to the GPU's (k = 1) and to 3.9x at the X9’s claimed core (k about 0.33, never measured), the 5090 at 0.2% less rate, gates G1 to G6 in progress). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.</li>
<li><strong>A chip is impossible.</strong> No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as the GPU’s (k = 1, modelled on measured card watts, 6 October 2026) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.9x at the X9’s claimed core, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.</li>
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.</li>
<li><strong>A memory-hard prototype on every vendor.</strong> Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.</li>
<li><strong>Finality in the first month.</strong> No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.</li>

View file

@ -250,7 +250,7 @@ td.mono{font-family:var(--f-mono);font-size:12.5px;min-width:180px}td.iv{color:v
<tr data-status="tested by the team"><td class="n">14</td><td class="claim">Ethereum bytecode runs unchanged, with the documented differences of spec 7.1<div class="where">Homepage Build card; litepaper Building</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">as row 13; fixes <code>F-exec-A</code>, <code>F-exec-B</code> (spec 7.5)</td><td><code>tools/evm-smoke/smoke.mjs</code>: deploy via viem, <code>increment</code>, <code>hashLoop</code>, <code>eth_estimateGas</code>, <code>eth_getLogs</code>; <code>tools/exec-attacks</code> scenarios 1 and 3; bench-log "execution layer attack fixes"</td><td>Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The <code>Prover</code> precompile, proof records and the shard planner are not in the node</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">15</td><td class="claim">Every block is proven, with the proof landing within about a minute at launch<div class="where">Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>d7e1f89</code> (GPU proof), <code>e01a3cc</code>, <code>292e800</code>, <code>eedd136</code> (<code>proving/igneum-prove</code>: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6</td><td><code>proving/windows-wsl2</code> (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; <code>igneum-prove-host --mode block</code> on <code>proving/fixtures/</code>; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"</td><td>First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture <code>block-78-increment</code> (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in <code>docs/benchmarks/proving-e2e.md</code>. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on the RTX 5090 Windows rig in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind <code>proving_v1_activation_daa</code> (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">16</td><td class="claim">A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)<div class="where">Litepaper Proving ("The proving budget"); roadmap gate 2</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.1 (Target), 7.6 (<code>S_p</code> provisional, 7,500,000 pgas = <code>B_p</code> / 4)</td><td><code>PROVE-SHARD.bat</code> on the RTX 5090 (pending); the end-to-end standard in <code>docs/benchmarks/proving-e2e.md</code>; bench-log "proving: devnet v4 shards"</td><td>Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional <code>S_p</code> is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)<div class="where">the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line</div></td><td><span class="st st-0">tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured</span></td><td class="mono"><code>docs/analysis/chip-model-v3.md</code> 5 and 6; <code>docs/analysis/latency-shadow-2026-10-06.md</code>; <code>docs/plans/counter-asic-3-status.md</code>; <code>docs/analysis/attack-pass/f8-uniform.md</code>, <code>f4-weakday.md</code>, <code>docs/analysis/ca3-v4-uniform.md</code>; <code>docs/design/class-v5-stored-state.md</code>; the H100 and market-cap rows of 7 October; <code>docs/plans/funding.md</code> (the three lots)</td><td>the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses <code>tools/attack/f8-uniform</code> and the F4 census; the verifier by <code>igneum-pow bench</code></td><td>136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1</td><td class="iv">none yet; the three cryptanalysis lots are the next test</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)<div class="where">the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line</div></td><td><span class="st st-0">tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured</span></td><td class="mono"><code>docs/analysis/chip-model-v3.md</code> 5 and 6; <code>docs/analysis/latency-shadow-2026-10-06.md</code>; <code>docs/plans/counter-asic-3-status.md</code>; <code>docs/analysis/attack-pass/f8-uniform.md</code>, <code>f4-weakday.md</code>, <code>docs/analysis/ca3-v4-uniform.md</code>; <code>docs/design/class-v5-stored-state.md</code>; the H100 and market-cap rows of 7 October; <code>docs/plans/cryptanalysis/in-house-pass.md</code> (the internal adversarial pass)</td><td>the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses <code>tools/attack/f8-uniform</code> and the F4 census; the verifier by <code>igneum-pow bench</code></td><td>136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1</td><td class="iv">none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word</td></tr>
<tr data-status="tested by the team"><td class="n">18</td><td class="claim">The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache<div class="where">Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">readwidth e752fc7 (<code>docs/plans/read-width.md</code>), ca2-era 78c0ee4, ca2-cache 2de19e5 (<code>docs/plans/hot-table.md</code>)</td><td>The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load</td><td>Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">19</td><td class="claim">The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors<div class="where">Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">ca2-mixer 1ab8b21 (<code>tests/mixer.rs</code>, <code>tests/scratch.rs</code>), ca2-era 78c0ee4, ca2-soundness a465881 (<code>docs/analysis/scratch-soundness.md</code>), <code>igneum-pow/tests/packs.rs</code></td><td>The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card</td><td>Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT) job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">20</td><td class="claim">No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)<div class="where">Homepage stats and Economics tiles; litepaper Supply, Economics</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>6ac80a3</code>; fork "igneum-node devnet v0"; <code>consensus/core/src/igneum.rs</code>, <code>coinbase.rs</code></td><td><code>cargo test -p kaspa-consensus-core igneum</code> (8 pass: subsidy table, ramp, split, cap) and <code>cargo test -p kaspa-consensus coinbase</code> (8 pass); <code>igneum-miner inspect 40</code>; bench-log "igneum-node devnet v0"</td><td>Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the <code>igneum-proving-pool-v0</code> output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened</td><td class="iv">none yet</td></tr>

17
site/leaderboard.js Normal file
View file

@ -0,0 +1,17 @@
/* The /live weight leaderboard's rows (7 October 2026): the top 10 by default, a toggle "Show top 20" then "Show all N" (the
count live), then back to the ten; the viewer's own key is always visible, as its row inside the ten or as a pinned extra
row below them with its true rank. A classic script (window.IgneumLeaderboard) for live.html; module.exports for the test. */
(function (root) {
var L = {};
L.rows = function (keys, show, mine) {
keys = (keys || []).slice(); var total = keys.length, n = Math.min(show || 10, total);
var rows = keys.slice(0, n).map(function (k, i) { return Object.assign({}, k, { rank: i + 1, you: !!mine && k.id === mine }); });
var pinned = null;
if (mine) { var idx = -1; for (var i = 0; i < keys.length; i++) if (keys[i].id === mine) { idx = i; break; } if (idx >= n) pinned = Object.assign({}, keys[idx], { rank: idx + 1, you: true }); }
var toggle = null;
if (total > 10) { if (n <= 10 && total > 20) toggle = { label: 'Show top 20', next: 20 }; else if (n < total) toggle = { label: 'Show all ' + total, next: total }; else toggle = { label: 'Show top 10', next: 10 }; }
return { rows: rows, pinned: pinned, toggle: toggle, total: total, shown: n };
};
root.IgneumLeaderboard = L;
if (typeof module === 'object' && module && module.exports) module.exports = L;
})(typeof window !== 'undefined' ? window : globalThis);

View file

@ -0,0 +1,28 @@
// node --test site/lib/leaderboard.test.mjs (the /live weight leaderboard, 7 October 2026: top 10 by default, a toggle
// "Show top 20" then "Show all N", the viewer's own key pinned below the ten when it sits outside them)
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { readFileSync } from 'node:fs';
import { fileURLToPath } from 'node:url';
import { dirname, join } from 'node:path';
const here = dirname(fileURLToPath(import.meta.url));
const load = (p) => { const mod = { exports: {} }; new Function('module', 'window', readFileSync(p, 'utf8'))(mod, undefined); return mod.exports; };
const L = load(join(here, '../leaderboard.js'));
const keys = Array.from({ length: 41 }, (_, i) => ({ id: 'k' + String(i + 1).padStart(2, '0'), blocks: 1000 - i * 20, voter: true, participation: 1 }));
test('top 10 by default, the toggle reads Show top 20, then Show all 41 with the live count, then back to Show top 10', () => {
const a = L.rows(keys, 10, null);
assert.equal(a.rows.length, 10); assert.equal(a.rows[0].rank, 1); assert.equal(a.rows[9].rank, 10); assert.equal(a.pinned, null);
assert.equal(a.toggle.label, 'Show top 20'); assert.equal(a.toggle.next, 20);
const b = L.rows(keys, 20, null); assert.equal(b.rows.length, 20); assert.equal(b.toggle.label, 'Show all 41'); assert.equal(b.toggle.next, 41);
const c = L.rows(keys, 41, null); assert.equal(c.rows.length, 41); assert.equal(c.toggle.label, 'Show top 10'); assert.equal(c.toggle.next, 10);
assert.equal(L.rows(keys.slice(0, 8), 10, null).toggle, null, 'no toggle when the ten hold everyone');
assert.equal(L.rows(keys.slice(0, 15), 10, null).toggle.label, 'Show all 15', 'between 10 and 20 the second step is the whole list');
});
test('the viewer\'s own key is always visible: inside the ten as its row, outside them as a pinned extra row with its true rank', () => {
const inside = L.rows(keys, 10, 'k03'); assert.equal(inside.pinned, null); assert.ok(inside.rows.some((r) => r.id === 'k03' && r.you));
const outside = L.rows(keys, 10, 'k27'); assert.equal(outside.rows.length, 10); assert.equal(outside.pinned.id, 'k27'); assert.equal(outside.pinned.rank, 27); assert.equal(outside.pinned.you, true);
assert.equal(L.rows(keys, 41, 'k27').pinned, null, 'shown in the full list, so not pinned twice');
assert.equal(L.rows(keys, 10, 'zz').pinned, null, 'a key not in the table pins nothing');
});

View file

@ -445,7 +445,7 @@ body.all .pager{display:none}
<tr><td>When a stored-dataset chip pays for itself</td><td>at about USD 100 M of market cap in the first two years, not before</td><td>modelled, 7 October 2026</td></tr>
<tr><td>The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class)</td><td>5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x)</td><td>modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state</td></tr>
</tbody></table></div>
<p>What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is not ours: the cryptanalysis plan buys three external lots against the mixer, the chained cache and the acceptance rule.</p>
<p>What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.</p>
<p>No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: <a href="/bench#counter-asic-2-0-the-numbers">the numbers</a>; the claim is tested by paid independent cryptanalysis and the public benchmark. Monero has run on RandomX since 2019 (approximate) with no chip shipped. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. A box with about a 2x per joule edge over the best CPUs, and about 3x over a desktop, was withdrawn rather than face a RandomX re-tune of 1.5x or more. That is the band Igneum’s class v4 model sits in (2.1x to 3.9x over an RTX 5090), and the defence that held was a maintained algorithm with a credible upgrade path, which is what the ladder is.</p>
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.</p>
</section>
@ -802,7 +802,7 @@ body.all .pager{display:none}
<p>Here are the limits, stated before anyone else states them.</p>
<ul>
<li><strong>A proof in seconds.</strong> Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.</li>
<li><strong>A chip is impossible.</strong> No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). The published model (5 October 2026) prices the strongest chip we can name, one with the whole cache on-die computing dataset items on the fly, at 0.92x the hash rate of an RTX 5090 per unit of silicon with a 3x fixed-function allowance, approximate. The same model, drawn out to the chip that stores the dataset (6 October 2026): The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090. A memory-controller chip that stores the whole dataset reaches 1.2x per chip and, in our model, 5x to 9x per joule; the Ethash chips of this class reached 2.1x to 4.8x. The lever against it, program work in the latency shadow, is measured and in its gates: it brings the chip to 2.1x to 3.9x, the range running from a chip core as costly per operation as the GPU’s (k = 1) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x. Sources: the chip model analysis (6 October 2026); the Ethash rows of the ASIC history (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022); Counter ASIC 3.0 item 8 (100,000 ops per hash: the chip's per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at a chip core equal to the GPU's (k = 1) and to 3.9x at the X9’s claimed core (k about 0.33, never measured), the 5090 at 0.2% less rate, gates G1 to G6 in progress). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.</li>
<li><strong>A chip is impossible.</strong> No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as the GPU’s (k = 1, modelled on measured card watts, 6 October 2026) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.9x at the X9’s claimed core, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.</li>
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.</li>
<li><strong>A memory-hard prototype on every vendor.</strong> Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.</li>
<li><strong>Finality in the first month.</strong> No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.</li>

View file

@ -1,5 +1,9 @@
/* Igneum DAG / Ember 2.0 (the EMBER 02 renderer pack, 7 Oct 2026). THE SHARED SOURCE: scene/live-dag.js; site/live-dag.js and
* app/igneum-app/ui/live-dag.js are byte-equal copies written by tools/scene/sync.mjs (the gate refuses a drifted copy). Edit here.
* 2.0.6 (7 Oct 2026): IgneumDag.shardWords(block, nowMs) is the one shard sentence (tooltip, /live inspector, app inspector); the
* empty case reads from the block's facts (loading, excluded, not yet ordered, off the chain) instead of one fixed sentence.
* 2.0.5 (key-22, 7 Oct 2026): IgneumDag.legend({mine}) and renderLegend(el,{mine}) are the one key both pages render; the app's
* Included swatch had been ember while the scene draws included blocks in --included, and "pending" lower-case.
* 2.0.4 (7 Oct 2026): the box's height follows the lanes. laneHeight (default 46 px, 40 on a phone, 26 compact) times the lanes
* shown (at most maxLanes, narrowLanes on a phone, never under 2) plus the axis and padding is the scene's wanted height;
* onSize(heightPx, {lanes, laneHeight, narrow, compact}) reports it whenever it changes, so a page can size the box, and with
@ -301,13 +305,13 @@
function paint(){if(destroyed||!W||!H)return;var t=performance.now();draw(t);lastPaint=t;}
function redraw(){if(destroyed||raf||doc.hidden||!visible)return;lastPaint=-Infinity;raf=requestAnimationFrame(frame);}
function stopFrame(){if(raf)cancelAnimationFrame(raf);raf=0;}
function words(b){
function words(b,nowMs){
if(!b)return {title:'No block selected',lines:[]};
var inclusion=b.color==='blue'?'included':b.color==='red'?'excluded':'pending';
var bits=[inclusion];if(b.chain)bits.push('selected chain');if(b.proven)bits.push('proven');if(b.locked)bits.push('locked checkpoint');if(b.final)bits.push('final');
return {title:b.hash+' '+bits.join(' / '),lines:[(own(b)?'Your block / ':'')+'miner key '+b.miner,
'Blue score '+fmt(b.blue_score===undefined?b.blue:b.blue_score)+' / DAA '+fmt(b.daa),b.parents.length+' parent'+(b.parents.length===1?'':'s'),
'Shards: '+(b.shards.length?b.shards.map(function(s){return s.state;}).join(', '):'no shard plan yet')]};
'Shards: '+shardWords(b,nowMs).summary]};
}
function showTip(b){
if(!tip)return;
@ -377,5 +381,46 @@
getSnapshot:function(){return {ok:true,state:{stale:state!=='live'},blocks:blocks.map(cloneBlock),finality:{checkpoints:cps.map(function(c){return Object.assign({},c);})}};}};
instances.set(canvas,api);if(chip)chip.hidden=true;theme();size();emit('onState',state,reason);if(opts.poll!==false)poll();redraw();return api;
}
root.IgneumDag={mount:mount,version:'2.0.4'};
// the shard sentence, once (7 Oct 2026, the fixed sentence the site's animation showed on every planless block): from the
// block's own facts. No shards: an excluded block has nothing to prove, a pending block is not yet ordered, a blue block off
// the selected chain gets no plan, a chain block under 10 s old is loading its plan, an older one says how long it has waited.
// With shards: a planned shard with no prover is awaiting one (with the block's age), assigned, proving, verified, paid.
function ageWord(sec){sec=Math.max(0,Math.round(sec));return sec<90?sec+' s':sec<5400?Math.round(sec/60)+' min':Math.round(sec/3600)+' h';}
function shardWords(b,nowMs){
var now=finite(nowMs)?nowMs:Date.now(),age=b&&finite(b.ts)?Math.max(0,(now-b.ts)/1000):0,sh=(b&&b.shards)||[];
if(!sh.length){
if(!b)return {summary:'',items:[],state:'none'};
if(b.color==='red')return {summary:'excluded, nothing to prove',items:[],state:'excluded'};
if(b.color!=='blue')return {summary:'not yet ordered',items:[],state:'pending'};
if(!b.chain)return {summary:'off the selected chain, no shards planned',items:[],state:'none'};
if(age<10)return {summary:'shard plan loading',items:[],state:'loading'};
return {summary:'no shard plan after '+ageWord(age),items:[],state:'late'};
}
var items=sh.map(function(x,i){var st=x.state,w=st==='planned'?(x.prover?'assigned to '+x.prover:'awaiting a prover · '+ageWord(age)):st==='proving'?'proving'+(x.prover?' by '+x.prover:''):st==='verified'?'verified':st==='paid'?'paid'+(finite(x.payout)?' '+x.payout+' IGN':''):'unknown';return {i:i,state:st,word:w};});
var n={paid:0,verified:0,proving:0,assigned:0,awaiting:0};
sh.forEach(function(x){if(x.state==='planned'){if(x.prover)n.assigned++;else n.awaiting++;}else if(n[x.state]!==undefined)n[x.state]++;});
var parts=[];if(n.paid)parts.push(n.paid+' paid');if(n.verified)parts.push(n.verified+' verified');if(n.proving)parts.push(n.proving+' proving');if(n.assigned)parts.push(n.assigned+' assigned');if(n.awaiting)parts.push(n.awaiting+' awaiting a prover · '+ageWord(age));
return {summary:parts.join(', '),items:items,state:n.awaiting?'awaiting':n.proving?'proving':'done'};
}
// key-22 (7 October 2026, the app's key against /live): THE key, once. Entries in the order both
// pages show them, each naming the token the scene draws that state with and the swatch's shape; the app passes
// {mine:true} and gets "Your blocks" (ringed, molten) first. tools/scene/legend.test.mjs fails when a page's key or a
// drawn colour drifts from this list. Shapes: square (outlined), circle (the checkpoint ring), tick (the proof mark),
// ringed (the own-block halo); faded dims the swatch as the scene dims excluded blocks.
function legend(o){
var own={id:'you',label:'Your blocks',token:'--molten',shape:'ringed'};
var list=[{id:'pending',label:'Pending',token:'--ash',shape:'square'},{id:'included',label:'Included',token:'--included',shape:'square'},
{id:'excluded',label:'Excluded',token:'--excluded',shape:'square',faded:true},{id:'chain',label:'Selected chain',token:'--ember',shape:'square',fill:'--ember-12'},
{id:'proven',label:'Proven',token:'--bone',shape:'tick'},{id:'locked',label:'Locked checkpoint',token:'--ember',shape:'circle'}];
return (o&&o.mine?[own]:[]).concat(list);
}
// renders the key into el: <span><i class="lg <shape> [faded]" style="--lg:var(token)"></i>Label</span>…, keeping any
// children the page already placed there (the app's source line) after the entries
function renderLegend(el,o){
if(!el)return [];var entries=legend(o),doc=el.ownerDocument,keep=Array.prototype.slice.call(el.childNodes).filter(function(n){return !(n.getAttribute&&n.getAttribute('data-lg'));});
while(el.firstChild)el.removeChild(el.firstChild);
entries.forEach(function(e){var sp=doc.createElement('span');sp.setAttribute('data-lg',e.id);var i=doc.createElement('i');i.className='lg '+e.shape+(e.faded?' faded':'');i.style.setProperty('--lg','var('+e.token+')');if(e.fill)i.style.setProperty('--lg-fill','var('+e.fill+')');sp.appendChild(i);sp.appendChild(doc.createTextNode(e.label));el.appendChild(sp);});
keep.forEach(function(n){el.appendChild(n);});return entries;
}
root.IgneumDag={mount:mount,legend:legend,renderLegend:renderLegend,shardWords:shardWords,version:'2.0.6'};
})(window);

View file

@ -158,6 +158,9 @@
.three{display:grid;grid-template-columns:repeat(3,minmax(0,1fr));gap:var(--s-4);margin-top:var(--s-4)}
.two{display:grid;grid-template-columns:minmax(0,1.4fr) minmax(0,1fr);gap:var(--s-4);margin-top:var(--s-4)}
.lb table td,.lb table th{white-space:nowrap}.lb .you td{color:var(--molten-text)}
/* the leaderboard (7 October 2026): ten rows by default in a box of fixed height, so the page below never jumps when the toggle opens; the
extra rows scroll inside; the viewer's pinned row sits under a dashed rule */
.tbl.lb{height:432px;overflow:auto}.lb .pinned td{border-top:1px dashed var(--line-2)}.lb-more{margin:8px 0 0;font-size:12px}.lb-more .linkish{color:var(--ash)}
@media (max-width:900px){.two{grid-template-columns:1fr}}
@media (max-width:1000px){.three{grid-template-columns:1fr}}
.dp{border:var(--hair);border-radius:16px;background:var(--row);padding:25px;min-width:0}
@ -460,6 +463,7 @@ details.tablebar summary{display:flex;align-items:center}
<thead><tr><th class="num">Rank</th><th>Key</th><th class="num">Blocks in window</th><th class="num">Presence</th><th>Last block</th></tr></thead>
<tbody id="w-body"><tr><td colspan="5">Waiting for the first read.</td></tr></tbody>
</table></div>
<p class="lb-more"><button type="button" class="linkish" id="w-toggle" hidden>Show top 20</button></p>
<p class="note" style="margin-top:14px;font-size:12px" id="w-note">Weight is blue blocks over the window, never hashrate: a card that arrived today sits at the bottom. The dust line and the window are read from the node.</p>
</div>
<div class="dp">
@ -548,6 +552,7 @@ details.tablebar summary{display:flex;align-items:center}
</script>
<!-- footer:end -->
<script src="/leaderboard.js"></script>
<script src="/live-dag.js" defer></script>
<script src="/proof-core.js" defer></script>
<script>
@ -569,8 +574,9 @@ details.tablebar summary{display:flex;align-items:center}
(function(){var w=fn&&fn.weights,keys=w&&w.keys?w.keys.slice():[],p=fn&&fn.params||{};keys.sort(function(a,b){return (b.blocks||0)-(a.blocks||0);});
var seen={};(d.miners||[]).forEach(function(m){seen[m.id]=m;});
$('w-tag').textContent=keys.length?keys.length+' keys · window '+fmtN(p.weightWindow)+' DAA · dust '+fmtN(p.dust):'30-day weight';
$('w-body').innerHTML=keys.length?keys.slice(0,24).map(function(k,i){var m=seen[k.id],last=m&&m.last_seen?Math.max(0,Math.round((now-new Date(m.last_seen).getTime())/1000))+' s ago':'not in 10 min';
return '<tr'+(mine&&k.id===mine?' class="you"':'')+'><td class="num">'+(i+1)+'</td><td class="mono">'+esc(k.id)+(mine&&k.id===mine?' (you)':'')+'</td><td class="num">'+fmtN(k.blocks)+'</td><td class="num">'+(!k.voter?(k.stripped_until_daa?'stripped':'under dust'):k.participation===null||k.participation===undefined?'pending':Math.round(k.participation*100)+'%')+'</td><td>'+last+'</td></tr>';}).join('')+(keys.length>24?'<tr><td colspan="5">and '+(keys.length-24)+' more keys</td></tr>':''):'<tr><td colspan="5">No weights in the reply.</td></tr>';
$('w-body').innerHTML=keys.length?(function(){var LB=window.IgneumLeaderboard,r=LB?LB.rows(keys,lbShow,mine):{rows:keys.slice(0,24).map(function(k,i){return Object.assign({},k,{rank:i+1,you:!!mine&&k.id===mine});}),pinned:null,toggle:null};var tg=$('w-toggle');if(tg){tg.hidden=!r.toggle;if(r.toggle){tg.textContent=r.toggle.label;tg.dataset.next=r.toggle.next;}}
return r.rows.concat(r.pinned?[Object.assign({},r.pinned,{pin:true})]:[]).map(function(k){var m=seen[k.id],last=m&&m.last_seen?Math.max(0,Math.round((now-new Date(m.last_seen).getTime())/1000))+' s ago':'not in 10 min';
return '<tr'+(k.you?(k.pin?' class="you pinned"':' class="you"'):'')+'><td class="num">'+k.rank+'</td><td class="mono">'+esc(k.id)+(k.you?' (you)':'')+'</td><td class="num">'+fmtN(k.blocks)+'</td><td class="num">'+(!k.voter?(k.stripped_until_daa?'stripped':'under dust'):k.participation===null||k.participation===undefined?'pending':Math.round(k.participation*100)+'%')+'</td><td>'+last+'</td></tr>';}).join('');})():'<tr><td colspan="5">No weights in the reply.</td></tr>';
var tot=(d.miners||[]).length,voters=keys.filter(function(k){return k.voter;}).length,signing=keys.filter(function(k){return k.voter&&k.participation>=.9;}).length,lock=null;(fn&&fn.checkpoints||[]).forEach(function(c){if(c.state==='locked'&&(!lock||c.index>lock.index))lock=c;});
var rows=[['Keys with a block in 10 min',tot,tot],['Voters above the dust line',voters,keys.length||tot],['Voters signing 90% of points or more',signing,voters],['Weight signing at the last lock',lock&&lock.fraction_total!==null&&lock.fraction_total!==undefined?Math.round(lock.fraction_total*100)+'%':'pending',null]];
$('census').innerHTML=rows.map(function(r){var pc=r[2]&&typeof r[1]==='number'?r[1]/r[2]*100:(typeof r[1]==='string'&&/%$/.test(r[1])?parseFloat(r[1]):0);return '<div class="id-row"><span class="name"><i class="sw"></i>'+r[0]+'</span><span class="pct">'+(typeof r[1]==='number'?fmtN(r[1])+(r[2]&&r[2]!==r[1]?' of '+fmtN(r[2]):''):r[1])+'</span><span class="bar"><i style="width:'+Math.min(100,pc).toFixed(1)+'%"></i></span></div>';}).join('');})();
@ -611,8 +617,9 @@ details.tablebar summary{display:flex;align-items:center}
$('i-title').textContent=b.locked?'Checkpoint locked':b.proven?'Proof complete':(b.shards||[]).some(function(x){return x.state==='proving';})?'Proof in progress':'Block observed';
$('i-hash').textContent=b.hash+(b.number?' · #'+fmtN(b.number):'');
var sh=b.shards||[],done=sh.filter(function(x){return x.state==='verified'||x.state==='paid';}).length;
$('i-shard-count').textContent=sh.length?done+' / '+sh.length+' complete':'no shard plan yet';$('i-track').innerHTML=sh.map(function(x){return '<i class="'+esc(x.state)+'"></i>';}).join('');
$('i-shards').innerHTML=sh.length?sh.map(function(x,i){return '<li class="'+esc(x.state)+'"><span>Shard '+String(i+1).padStart(2,'0')+'</span><span>'+esc(x.state.charAt(0).toUpperCase()+x.state.slice(1))+'</span></li>';}).join(''):'<li class="muted">'+(b.chain?'No shard plan yet.':'Not a chain block: no shards.')+'</li>';
var sw=window.IgneumDag&&IgneumDag.shardWords?IgneumDag.shardWords(b,Date.now()):{summary:sh.length?'':'no shard plan',items:sh.map(function(x){return {word:x.state};})},cap=function(s){return s.replace(/^./,function(c){return c.toUpperCase();});};
$('i-shard-count').textContent=sh.length?done+' / '+sh.length+' complete':sw.summary;$('i-track').innerHTML=sh.map(function(x){return '<i class="'+esc(x.state)+'"></i>';}).join('');
$('i-shards').innerHTML=sh.length?sh.map(function(x,i){return '<li class="'+esc(x.state)+'"><span>Shard '+String(i+1).padStart(2,'0')+'</span><span>'+esc(cap(sw.items[i]?sw.items[i].word:x.state))+'</span></li>';}).join(''):'<li class="muted">'+esc(cap(sw.summary))+'.</li>';
$('i-incl').textContent=(b.color==='blue'?'Included':b.color==='red'?'Excluded':'Pending')+(b.chain?' / selected chain':'');
$('i-miner').textContent=b.miner+(mineB?' (you)':'');$('i-blue').textContent=fmtN(b.blue_score);$('i-daa').textContent=fmtN(b.daa);
$('i-parents').textContent=(b.parents||[]).length+' observed'+((b.parents||[]).length?': '+b.parents.join(', '):'');$('i-time').textContent=hms(b.ts)+' UTC';
@ -629,6 +636,7 @@ details.tablebar summary{display:flex;align-items:center}
// the Proven tile reads its own 600 s window every 10 s (provenTile below): proofs land minutes after the block, so the scene's short window would read zero
$('m-cp').textContent=cp?(cp.state==='locked'?'Locked':'Pending'):'None';$('m-cp-w').textContent=cp&&cp.fraction_total!==null&&cp.fraction_total!==undefined?Math.round(cp.fraction_total*100)+'% weight':'';$('m-cp-note').textContent=cp?'#'+fmtN(cp.index)+' · blue score '+fmtN(cp.blue_score):'no checkpoint in the reply';
$('c-count').textContent=st.blocks+' blocks';var r=dag.getViewRange(),lo=null,hi=null;dag.getBlocks().forEach(function(b){if(b.ts>=r.start&&b.ts<=r.end){if(lo===null||b.blue_score<lo)lo=b.blue_score;if(hi===null||b.blue_score>hi)hi=b.blue_score;}});$('blue-range').textContent=lo===null?'blue score pending':'blue score '+fmtN(lo)+' to '+fmtN(hi);}
var lbShow=10;document.getElementById('w-toggle').addEventListener('click',function(){lbShow=parseInt(this.dataset.next,10)||10;if(lastD)render(lastD);});
function mountDag(){if(dag||!window.IgneumDag)return;
dag=IgneumDag.mount($('dag'),{poll:false,window:60,fps:60,mine:mine||undefined,tooltip:$('dag-tip'),chip:$('dag-chip'),pauseButton:$('dag-pause'),
onWindow:function(w){$('z-pct').textContent=w+' s';if(lastD)render(lastD);},

View file

@ -1,5 +1,5 @@
{
"_about": "Rows of the public bench table at /miners (site/build.mjs). One row per card, generator version and miner version: the best measured rate. Later jobs append rows. Fields: card, generator (v1 | v2), mh_s (best measured MH/s), mh_per_w (MH per watt, null when the power was not measured), miner (the miner or package version), date (YYYY-MM-DD), source (the docs/bench-log.md heading, or the job id), by ('measured by the team' | 'reported by the fleet'), note (short, optional). No machine names, no addresses, no owner names: the build scrubs the page and fails on any that survive.",
"_about": "Rows of the public bench table at /miners (site/build.mjs). One row per card, generator version and miner version: the best measured rate. Later jobs append rows. Fields: card, generator (v1 | v2), mh_s (best measured MH/s), mh_per_w (MH per watt, null when the power was not measured), miner (the miner or package version), date (YYYY-MM-DD), source (the docs/bench-log.md heading, or the job id), by ('measured by the team' | 'reported by the fleet'), note (short, optional), watts (board power at the rate, null when not read), v4_cost (what the class v4 shadow costs this card against the class v3 control: watts and rate, measured; 'not measured' when not), tuned (the card's tune state at the row: 'full Ember Tune: <point>' | 'clock lock <MHz>, cap <W>' | 'stock, bench only' | 'stock, mining'), driver_os (driver and OS where known). No machine names, no addresses, no owner names: the build scrubs the page and fails on any that survive.",
"rows": [
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -10,7 +10,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090, memory-hard dataset (pack igneum-genesis-mh)",
"by": "measured by the team",
"note": "genesis program, 104 loads per hash, 1 GiB dataset"
"note": "genesis program, 104 loads per hash, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -21,7 +25,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090 first run, dataset sweep and second program",
"by": "measured by the team",
"note": "hourly program, 128 loads per hash, 1 GiB dataset"
"note": "hourly program, 128 loads per hash, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
@ -32,7 +40,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, the gfx1036 worker fault and what the Mac could and could not reproduce",
"by": "measured by the team",
"note": "live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected"
"note": "live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
@ -43,7 +55,11 @@
"date": "2026-10-03",
"source": "bench log: 3 October 2026, RTX 5090 first run (the Apple row of the same table)",
"by": "measured by the team",
"note": "genesis program, 1 GiB dataset"
"note": "genesis program, 1 GiB dataset",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, bench only"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
@ -54,7 +70,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, first hourly program swap on the live devnet: compile-ahead, no pause, two cards",
"by": "measured by the team",
"note": "live devnet v4, unbroken through the hour boundary"
"note": "live devnet v4, unbroken through the hour boundary",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "Apple silicon laptop (model not reported)",
@ -65,7 +85,11 @@
"date": "2026-10-04",
"source": "bench log: 4 October 2026, first outside machine on the devnet: an Apple silicon laptop through the Igneum Miner app",
"by": "reported by the fleet",
"note": "21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks"
"note": "21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks",
"watts": null,
"v4_cost": "not measured",
"driver_os": "",
"tuned": "stock, mining"
},
{
"card": "NVIDIA RTX 5060 Ti (16 GB)",
@ -76,7 +100,461 @@
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the first 16 GB card: an RTX 5060 Ti in a Thunderbolt enclosure (run b)",
"by": "measured by the team",
"note": "class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure"
"note": "class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure",
"watts": 114.8,
"v4_cost": "0.1 percent of rate, measured 7 October 2026",
"driver_os": "NVIDIA driver, Windows 11",
"tuned": "stock, bench only (180 W default cap, never tuned)"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
"generator": "v2",
"mh_s": 136.1,
"watts": 350,
"mh_per_w": 0.389,
"miner": "igneum-worker-cuda bench, class v3 program (mx8-devnet-epoch0)",
"date": "2026-10-06",
"source": "bench log: 6 October 2026, Counter ASIC 3.0 item 8, the 5090 rows (the control row)",
"by": "measured by the team",
"note": "the control; 290 W in the app on the same card",
"v4_cost": "about +80 W for 0.2 percent of rate at the unlocked 2,850 MHz core, measured 6 October 2026; the efficiency pass (clock and voltage under class v4) runs 7 October",
"tuned": "stock, bench only (unlocked core)",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "NVIDIA RTX 5090 (32 GB)",
"generator": "v2",
"mh_s": 127.71,
"watts": 226.8,
"mh_per_w": 0.563,
"miner": "Igneum Miner 0.3.13 + Ember Tune kit 6 (mining, class v3 program)",
"date": "2026-10-06",
"source": "bench log: 6 October 2026, 16:01Z, Ember run 6 (ember-tune-pc1-6)",
"by": "measured by the team",
"note": "against 127.9 MH/s at 311.0 W untuned (0.411 MH/W): 84 W saved for 0.15 percent of rate; the ladder's floor, not yet its optimum",
"v4_cost": "as the row above",
"tuned": "full Ember Tune: 1,854 MHz core lock at the 100 percent cap",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "NVIDIA RTX 4070 (12 GB)",
"generator": "v2",
"mh_s": 30.95,
"watts": 79.5,
"mh_per_w": 0.389,
"miner": "igneum-worker-cuda bench (installed worker), class v3 control",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the RTX 4070 rows (job run-ca3-pc1-4070-shadow-20261006)",
"by": "measured by the team",
"note": "79.3 to 79.8 W at the tune point; 28.78 MH/s at 75.6 W (0.381) in Ember run 6 mining",
"v4_cost": "+30 W (79 to 109 W) for +0.4 percent of rate at 102,100 ops per hash, measured 6 October 2026",
"tuned": "full Ember Tune: 1,860 MHz core lock, 160 W cap (Ember run 6: 1,863 MHz at the 50 percent cap, 75.6 W)",
"driver_os": "NVIDIA driver, Windows 11"
},
{
"card": "AMD Radeon RX 9070 XT (16 GB)",
"generator": "v2",
"mh_s": 18.92,
"watts": 199,
"mh_per_w": 0.095,
"miner": "igneum-worker-opencl bench (installed worker), class v3 control",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the RX 9070 XT rows (job run-ca3-pc1-amd-g1-shadow-20261006); watts from the app's telemetry read of 5 October 2026 (the job's ADLX sample parsed 0 rows)",
"by": "measured by the team",
"note": "the card sits at 87 to 95 percent of its dependent random-read ceiling (2.42 to 2.68 G loads/s), in a Thunderbolt enclosure; AMD OpenCL 3683.0",
"v4_cost": "+2 percent of rate (19.29 against 18.92 MH/s) at 102,100 ops per hash, watts owed, measured 6 October 2026",
"tuned": "stock, bench only (the AMD tune pass runs 7 October: set only if the ADLX tune line reads, else measure-only)",
"driver_os": "Adrenalin 26.9.2, Windows 11"
},
{
"card": "Apple M5 Max (40 GPU cores, Metal)",
"generator": "v2",
"mh_s": 27.0,
"watts": 21,
"mh_per_w": 1.29,
"miner": "igneum-miner Metal worker, class v3 program",
"date": "2026-10-06",
"source": "Counter ASIC 3.0 status: item 8, the Mac rows (IOReport GPU and DRAM watts)",
"by": "measured by the team",
"note": "GPU plus DRAM watts, not wall",
"v4_cost": "+16 W for 1.5 percent of rate at 102,100 ops per hash, measured 6 October 2026",
"tuned": "no lever on Apple silicon (no clock or power control exposed); stock",
"driver_os": "macOS, Metal"
},
{
"card": "Intel Arc B580 (12 GB)",
"generator": "v2",
"mh_s": 11.0,
"watts": null,
"mh_per_w": null,
"miner": "igneum-worker-opencl bench, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the Intel Arc B580 (eGPU equals slot)",
"by": "measured by the team",
"note": "the same rate in the Thunderbolt enclosure and the slot; watts not read on this run",
"v4_cost": "0.1 percent of rate, measured 7 October 2026",
"tuned": "stock, bench only",
"driver_os": "Intel driver, Windows 11"
},
{
"card": "NVIDIA H100 SXM (80 GB)",
"generator": "v2",
"mh_s": 248.7,
"watts": 385.6,
"mh_per_w": 0.645,
"miner": "igneum-worker-cuda bench (Linux), class v3 control",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep, a rented card)",
"by": "measured by the fleet",
"note": "424.0 W maximum; 98 percent of its random-read ceiling like the 5090; 1.78x the 5090's hash at 1.15x the tuned 5090's hash per watt and a third of the hash per rented dollar",
"v4_cost": "not measured",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.126.09, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5080 (16 GB)",
"generator": "v2",
"mh_s": 71.16,
"watts": 143.4,
"mh_per_w": 0.496,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "148.6 W maximum; the team's own 5080 on a dock reads 60 MH/s warming and gets its full Ember Tune on 7 October",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3070 Ti (8 GB)",
"generator": "v2",
"mh_s": 38.98,
"watts": 178.3,
"mh_per_w": 0.219,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 595.71.05, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3070 (8 GB)",
"generator": "v2",
"mh_s": 33.66,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's 0.3.21 wipe canary (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "the 0.3.21 wipe canary's status line, 17:07Z, beside its node; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3080 (10 GB)",
"generator": "v2",
"mh_s": 43.72,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026) and the sweep's hands row",
"by": "reported by the fleet",
"note": "a standing voter's status line, 18:00Z; the hands row of the sweep reads 40.82 MH/s at 204.9 W; 10 GB, no prover",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3080 Ti (12 GB)",
"generator": "v2",
"mh_s": 58.95,
"watts": 267.3,
"mh_per_w": 0.221,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "283.0 W maximum",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3090 (24 GB)",
"generator": "v2",
"mh_s": 50.04,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voters (status lines, 7 October 2026)",
"by": "reported by the fleet",
"note": "the best of four standing voters this hour (42.2 to 50.0 MH/s) beside their provers; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3090 Ti (24 GB)",
"generator": "v2",
"mh_s": 61.95,
"watts": 249.5,
"mh_per_w": 0.248,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.65.06, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4090 (24 GB)",
"generator": "v2",
"mh_s": 52.25,
"watts": 183.1,
"mh_per_w": 0.285,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, the RTX 4090 hands row",
"by": "measured by the fleet",
"note": "the hands row: the card mines and proves (17.4 GB peak while proving); the standing 4090 voters read 44.5 to 50.8 MH/s this hour beside their provers",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5090 (32 GB), fleet",
"generator": "v2",
"mh_s": 100.6,
"watts": 308,
"mh_per_w": 0.327,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "a standing voter's status beside its prover, 18:00Z; 122 MH/s at 308 W earlier in the day (0.396 MH/W); the team's own 5090 rows above",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3060 (12 GB)",
"generator": "v2",
"mh_s": 26.89,
"watts": 111.6,
"mh_per_w": 0.241,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "114.5 W maximum; the Devnet 3 boxes read 23.7 to 25.7 MH/s beside their nodes",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580.126.09, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 3060 Ti (8 GB)",
"generator": "v2",
"mh_s": 33.1,
"watts": 129.5,
"mh_per_w": 0.256,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4060 Ti (8 GB)",
"generator": "v2",
"mh_s": 20.1,
"watts": 77.5,
"mh_per_w": 0.259,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 4070 Ti (12 GB)",
"generator": "v2",
"mh_s": 31.26,
"watts": 107.3,
"mh_per_w": 0.291,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5060 (8 GB)",
"generator": "v2",
"mh_s": 31.27,
"watts": 75.4,
"mh_per_w": 0.415,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5070 (12 GB)",
"generator": "v2",
"mh_s": 52.01,
"watts": 102.8,
"mh_per_w": 0.506,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX 5070 Ti (16 GB)",
"generator": "v2",
"mh_s": 78.43,
"watts": 145.6,
"mh_per_w": 0.539,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX A5000 (24 GB)",
"generator": "v2",
"mh_s": 47.64,
"watts": null,
"mh_per_w": null,
"miner": "hive package 0.3.20 igneum-miner, class v4 program",
"date": "2026-10-07",
"source": "the fleet's standing voter (status line, 7 October 2026)",
"by": "reported by the fleet",
"note": "a standing voter's status line, 18:00Z; watts not read",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, mining",
"driver_os": "NVIDIA driver, Ubuntu 24.04"
},
{
"card": "NVIDIA L40S (48 GB)",
"generator": "v2",
"mh_s": 56.36,
"watts": 240.7,
"mh_per_w": 0.234,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA A100 PCIe (80 GB)",
"generator": "v2",
"mh_s": 154.97,
"watts": 299.6,
"mh_per_w": 0.517,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA A100 SXM (80 GB)",
"generator": "v2",
"mh_s": 138.39,
"watts": 266.3,
"mh_per_w": 0.52,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA H200 SXM (141 GB)",
"generator": "v2",
"mh_s": 313.04,
"watts": 432.9,
"mh_per_w": 0.723,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA B200 (180 GB)",
"generator": "v2",
"mh_s": 416.35,
"watts": 855.6,
"mh_per_w": 0.487,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
},
{
"card": "NVIDIA RTX PRO 6000 Blackwell (96 GB)",
"generator": "v2",
"mh_s": 130.49,
"watts": 288.7,
"mh_per_w": 0.452,
"miner": "hive package 0.3.20 igneum-worker-cuda, class v4 program",
"date": "2026-10-07",
"source": "bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)",
"by": "measured by the fleet",
"note": "",
"v4_cost": "not measured (class v4 program only)",
"tuned": "stock, bench only (rented, not tuned)",
"driver_os": "NVIDIA driver 580, Ubuntu 24.04"
}
]
}

File diff suppressed because one or more lines are too long

View file

@ -110,7 +110,7 @@ case "${CARGO_ARGS[0]:-build}" in
*) SCHED_CLASS=build ;;
esac
if [ "$PRIORITY" = gate ]; then BR_NICE=0; BR_CORES=0; BR_JOBS_CAP=0
elif [ "$SCHED_CLASS" = suite ] || [ "$SCHED_CLASS" = bench ]; then BR_NICE=10; BR_CORES=32; BR_JOBS_CAP=32; fi
elif [ "$SCHED_CLASS" = suite ] || [ "$SCHED_CLASS" = bench ]; then BR_NICE=10; BR_CORES="${IGNEUM_BOUND_CORES:-88}"; BR_JOBS_CAP="${IGNEUM_BOUND_CORES:-88}"; fi # the project lead, 7 Oct 2026 19:4x BST: load both boxes to near max; 88 of 96, 8 reserved
# an explicit --jobs above the bounded class's cap is clamped (main's rule: bounded unless a priority flag; 7 Oct 2026: two suites
# ran at -j 90 on a box at load 190 because their callers passed --jobs 90)
if [ "$BR_JOBS_CAP" -gt 0 ] && [ -n "$JOBS" ] && [ "$JOBS" -gt "$BR_JOBS_CAP" ]; then bs_log "--jobs $JOBS clamped to $BR_JOBS_CAP for a $SCHED_CLASS (pass --priority gate for the full set)"; JOBS=$BR_JOBS_CAP; fi
@ -132,7 +132,7 @@ bs_context
if [ "$BS_CRATE_REL" = proving/igneum-prove ] && [ -z "${BOX_GIVEN:-}" ] && [ "$PRIORITY" != gate ]; then bs_route_spill prove; [ "$BS_ROUTE_BOX" != "$BOX" ] && { BOX=$BS_ROUTE_BOX; bs_host "$BOX"; }; fi
# box 2 keeps the suites' numbers: everything that lands there runs at the bounded class (nice 10, a 32-core band, -j 32), builds
# and gates included (main, 7 Oct 2026); a gate still takes its slot ahead of queued suites
if [ "$BOX" = 2 ] && [ "$BR_CORES" = 0 ]; then BR_NICE=10; BR_CORES=32; BR_JOBS_CAP=32; export BR_NICE BR_CORES BR_JOBS_CAP; bs_log "bounded on box 2 (nice 10, a 32-core band, -j 32) so a suite beside it keeps its number"; fi
if [ "$BOX" = 2 ] && [ "$BR_CORES" = 0 ]; then BR_NICE=10; BR_CORES="${IGNEUM_BOUND_CORES:-88}"; BR_JOBS_CAP="${IGNEUM_BOUND_CORES:-88}"; export BR_NICE BR_CORES BR_JOBS_CAP; bs_log "bounded on box 2 (nice 10, the ${BR_CORES}-core band, -j $BR_JOBS_CAP) so a suite beside it keeps its number"; fi
if [ "$BR_JOBS_CAP" -gt 0 ] && [ -n "$JOBS" ] && [ "$JOBS" -gt "$BR_JOBS_CAP" ]; then bs_log "--jobs $JOBS clamped to $BR_JOBS_CAP on box $BOX"; JOBS=$BR_JOBS_CAP; fi
bs_log "box $BOX ($BS_HOST) for class $SCHED_CLASS, priority $PRIORITY$( [ "${BR_ROUTE_SPILLED:-0}" = 1 ] && echo ", SPILLED from box $BR_ROUTE_PREF")"
@ -255,6 +255,9 @@ if [ "$FETCH" = 1 ] && [ -n "$ARTEFACTS" ]; then
bs_log "artefact $dest: $(bs_size "$dest") bytes, sha256 $(bs_sha256 "$dest"), $(file -b "$dest" | cut -c1-60)"
# the commit-string gate (rule of 6 October 2026): a node binary without its commit in its strings fails the run
case "$BS_KIND:$(basename "$dest")" in node:igneumd) "$HERE/ci/commit-string-check.sh" "$dest" "$BS_SHA" || bs_die "commit-string gate failed for $a" ;; esac # only kaspad depends on kaspa-build-info
# the engine gate (7 Oct 2026, the Devnet 3 start): igneumd and igneum-miner must carry igneum-pow/src/ paths; a commit string
# alone does not prove the engine (a stub-engine 21d8f454 rejected every mined block on the fleet's hub)
case "$BS_KIND:$(basename "$dest")" in node:igneumd|node:igneum-miner) [ "${IGNEUM_ALLOW_STUB:-}" = 1 ] || "$HERE/ci/engine-check.sh" "$dest" || bs_die "engine gate failed for $a (IGNEUM_ALLOW_STUB=1 to fetch a stub-engine binary on purpose)" ;; esac
# the glibc ceiling of anything that ships (main, 7 Oct 2026): a seed or a rig refuses a binary needing more than 2.36
if [ "$SHIP" = 1 ]; then "$HERE/ci/glibc-ceiling-check.sh" "$dest" "$GLIBC" || bs_die "glibc ceiling gate failed for $a"; fi
done

View file

@ -1,6 +1,6 @@
#!/usr/bin/env bash
# The scheduling classes of tools/build-remote.sh (main, 7 October 2026, the load-190 night): a build-remote call WITHOUT a priority
# flag must put every suite (cargo test) and bench (cargo bench) into the bounded class, nice 10 on 32 cores with -j 32, while a
# flag must put every suite (cargo test) and bench (cargo bench) into the bounded class, nice 10 on 88 cores with -j 88 (the project lead, 7 Oct 2026 19:4x BST: both boxes to near max, 8 cores reserved), while a
# build keeps the box's own jobs rule and --priority gate gives nice 0 on the full set. This check runs the tool's --plan mode (no box,
# no crate) for the four shapes and compares the resolved class; a change that lets a bare `cargo test` run unbounded again fails it.
#
@ -14,8 +14,8 @@ expect() { # <expected line> <args...>
if [ "$got" = "$want" ]; then echo "build-kind: [$*] -> $got"; else echo "build-kind: [$*] resolved to '$got', expected '$want'" >&2; return 1; fi
}
fail=0
expect 'kind=suite nice=10 cores=32 jobs=32 priority=normal' -- test -p kaspa-consensus-core --lib || fail=1
expect 'kind=bench nice=10 cores=32 jobs=32 priority=normal' -- bench -p igneum-pow || fail=1
expect 'kind=suite nice=10 cores=88 jobs=88 priority=normal' -- test -p kaspa-consensus-core --lib || fail=1
expect 'kind=bench nice=10 cores=88 jobs=88 priority=normal' -- bench -p igneum-pow || fail=1
expect 'kind=build nice=0 cores=96 jobs=box priority=normal' -- build --release -p kaspad || fail=1
expect 'kind=gate nice=0 cores=96 jobs=box priority=gate' --priority gate -- test -p igneum-app || fail=1
expect 'kind=check nice=0 cores=96 jobs=box priority=normal' -- check || fail=1

32
tools/ci/engine-check.sh Executable file
View file

@ -0,0 +1,32 @@
#!/usr/bin/env bash
# The engine gate (7 October 2026, the Devnet 3 start): a 21d8f454 igneumd with its commit string twice but ZERO igneum-pow/src/
# paths was placed in the artefact folder by a build outside the app tree; the fleet's hub ran it, the igneum-pow miner's blocks
# were every one rejected (Reject(BlockInvalid)), the go stopped. The commit-string gate cannot see this: the string comes from the
# fork's own git, the engine from the igneum-pow tree the build sat next to. So every igneumd and igneum-miner that
# tools/build-remote.sh fetches must carry igneum-pow source paths in its strings (rustc embeds the panic locations of the engine
# crate it compiled in: igneum-pow/src/..., or igneum-pow-amend/src/... when the fork pairs through its paths override); none means
# the stub engine or no paired tree, and the fetch refuses; the matched directory name is printed so the pairing is visible.
#
# tools/ci/engine-check.sh <binary> # exit 0 with the count, exit 1 "no igneum-pow/src/ path in <binary>"
# tools/ci/engine-check.sh --self-test # a fixture with the paths passes, one without fails
set -euo pipefail
if [ "${1:-}" = --self-test ]; then
t=$(mktemp -d); trap 'rm -rf "$t"' EXIT
printf 'binary junk\0/srv/builds/x/igneum-pow/src/lib.rs\0more junk\0igneum-pow/src/lottery.rs\0' > "$t/good"
printf 'binary junk\0/srv/builds/x/igneum-pow-amend/src/lib.rs\0igneum-pow-amend/src/lottery.rs\0' > "$t/amend"
printf 'binary junk\0/srv/builds/x/consensus/pow/src/stub.rs\0commit 21d8f454\0' > "$t/bad"
out=$("$0" "$t/good") || { echo "engine-check self-test: a binary WITH igneum-pow/src/ paths was refused"; exit 1; }
case "$out" in *"igneum-pow/src/ 2 paths"*) ;; *) echo "engine-check self-test: the matched directory is not printed: $out"; exit 1 ;; esac
out=$("$0" "$t/amend") || { echo "engine-check self-test: a binary paired through igneum-pow-amend/src/ was refused"; exit 1; }
case "$out" in *"igneum-pow-amend/src/ 2 paths"*) ;; *) echo "engine-check self-test: the amend directory is not printed: $out"; exit 1 ;; esac
if "$0" "$t/bad" >/dev/null 2>&1; then echo "engine-check self-test: a binary WITHOUT igneum-pow paths passed"; exit 1; fi
echo "engine-check self-test: igneum-pow/src/ and igneum-pow-amend/src/ pass with the directory named, a binary without is refused"; exit 0
fi
f="${1:-}"; [ -f "$f" ] || { echo "engine-check: no file '$f'" >&2; exit 2; }
# any directory name beginning igneum-pow and ending /src/ (the fork pairs its pow through a paths override that may name the tree
# igneum-pow-amend, the archive of 017e7037; the shipper, 7 Oct 2026); the matched name is printed so the pairing is visible
dirs=$(LC_ALL=C grep -a -oE 'igneum-pow[A-Za-z0-9._-]*/src/' "$f" | sort | uniq -c | awk '{printf "%s %s paths; ", $2, $1}')
n=$(LC_ALL=C grep -a -c -E 'igneum-pow[A-Za-z0-9._-]*/src/' "$f" || true)
if [ "${n:-0}" -gt 0 ]; then echo "engine-check: $(basename "$f") paired: ${dirs% }"; exit 0; fi
echo "engine-check: no igneum-pow*/src/ path in $(basename "$f"): the stub engine or no paired igneum-pow tree (the commit string alone does not prove the engine; 7 Oct 2026 Devnet 3)" >&2
exit 1

View file

@ -13,12 +13,13 @@
# it is the fix (--fixes-master). Record: era-vdf's tip 0e2d6b1c was merged with no ci run; master's igneum-pow suite was red from
# 16:31 UK and five docs-only merges landed green over it. The pre-push hook holds the same rule (pre-push.sh master_ci_ok).
#
# tools/ci/merge-to-master.sh [<branch>] [--tries N] [--ci-wait MIN] [--fixes-master] default: the current branch, 6 tries
# tools/ci/merge-to-master.sh [<branch>] [--tries N] [--ci-wait MIN] [--fixes-master] [--remote <name>] default: the current branch, 6 tries, origin
# MERGE_REMOTE=box tools/ci/merge-to-master.sh ... the same as --remote box (the box mirror /srv/igneum.git while GitHub is suspended, 7 October 2026)
# tools/ci/merge-to-master.sh --self-test the CI verdicts, with a fake ci-state: green goes, red refuses, master red refuses
# unless --fixes-master, none pushes the branch, pending waits then goes
set -euo pipefail
ROOT=$(git rev-parse --show-toplevel); cd "$ROOT"
BRANCH="$(git rev-parse --abbrev-ref HEAD)"; TRIES=6; CI_WAIT_MIN="${CI_WAIT_MIN:-25}"; FIXES_MASTER=0; SELF_TEST=0; REMOTE=origin
BRANCH="$(git rev-parse --abbrev-ref HEAD)"; TRIES=6; CI_WAIT_MIN="${CI_WAIT_MIN:-25}"; FIXES_MASTER=0; SELF_TEST=0; REMOTE="${MERGE_REMOTE:-origin}"
while [ $# -gt 0 ]; do case "$1" in --tries) TRIES="$2"; shift 2 ;; --ci-wait) CI_WAIT_MIN="$2"; shift 2 ;; --fixes-master) FIXES_MASTER=1; shift ;; --remote) REMOTE="$2"; shift 2 ;; --self-test) SELF_TEST=1; shift ;; -*) echo "unknown option $1" >&2; exit 2 ;; *) BRANCH="$1"; shift ;; esac; done
# --remote <name>: land on another remote's master (a box mirror, build@<box>:/srv/igneum.git, while GitHub is unreachable; main's
# ruling of 7 October 2026, 19:5x UK). CI runs on GitHub only, so the CI rule binds the origin remote; on a mirror the box gate

View file

@ -104,6 +104,7 @@ tree_checks() {
run "pinned guest programs match their manifest" bash tools/ci/pinned-guests-check.sh
run "root prover playbooks kill the GPU server and unlink its socket" bash tools/ci/prover-socket-check.sh
run "commit-string gate self-test" bash tools/ci/commit-string-check.sh --self-test
run "engine gate self-test (igneumd and igneum-miner must carry igneum-pow/src/ paths)" bash tools/ci/engine-check.sh --self-test
run "build server remote checkout self-test" bash infra/build-server/remote-run.sh --self-test
run "a slot holder keeps its own line for the whole run (the watcher-trust rule)" bash infra/build-server/remote-run.sh --self-test-keeper
run "the remote checkout resets the mirror's tree before the branch checkout (the stale-overlay class)" bash -c 'bash tools/ci/mirror-reset-check.sh --self-test && bash tools/ci/mirror-reset-check.sh'
@ -113,6 +114,7 @@ tree_checks() {
run "the class router is a preference with spill-over (a held or overloaded box hands the job to the other one)" bash tools/ci/route-spill-check.sh
run "per-core leases, the quiet class and the reaper pass on the box (lease.sh and remote-run.sh self-tests over ssh; skipped on a runner with no box; one retry)" bash tools/ci/retry-once.sh box-locks bash tools/ci/box-locks-check.sh $( [ "$MODE" = ci ] && echo --ci )
run "the simulators job runs on master and release-* pushes and pull requests into them only" bash tools/ci/sims-branch-check.sh
run "publish-jobs.sh never removes a running or installs-app job without --force (the PC 2 abort class)" bash tools/ci/publish-jobs-check.sh
run "no shell assignment hides behind a trailing comment (the swallowed-defaults class)" bash -c 'bash tools/ci/defaults-line-check.sh --self-test && bash tools/ci/defaults-line-check.sh'
run "no script kills or finds a process by a plain name or a file name (pgrep/pkill -f literals, ps | grep)" bash -c 'bash tools/ci/kill-by-name-check.sh --self-test && bash tools/ci/kill-by-name-check.sh'
run "the identity check's own self-test (excluded research path passes, exported leak fails)" bash tools/ci/identity-check.sh --self-test
@ -123,10 +125,10 @@ tree_checks() {
run "the home hero's loop never idles in view, stops hidden, resumes without a jump" node tools/site-redesign/tests/hero-loop-test.cjs
run "chain scene: the site's and the app's copies are scene/ byte for byte, the palette tokens live once (self-test, then the tree)" bash -c 'node tools/scene/sync.mjs --self-test && node tools/scene/sync.mjs --check'
run "chain scene: a push paints with the document hidden and no animation frame (the blank /live of 7 Oct 2026; known-failed first)" node tools/scene/paint-test.cjs
run "chain scene: the live feed contract (the recorded reply validates; a rewritten miner, a float now, a stray key refused)" node --test tools/scene/feed-contract.test.mjs
run "chain scene: the live feed contract (the recorded reply validates; a rewritten miner, a float now, a stray key refused)" node --test tools/scene/feed-contract.test.mjs tools/scene/legend.test.mjs tools/scene/shard-words.test.mjs
run "chain scene parity: one recorded feed through the home fold, /live and the app's Inspect view on build-2, three frames each pixel-equal apart from the app's own-key overlay (a changed token fails first; skipped with no box and no Playwright; one retry)" bash tools/ci/retry-once.sh scene-parity bash tools/scene/parity-remote.sh
run "no text overlaps: every served page at 390 to 1600 px, light and dark, the hero at each step (self-test first; IGNEUM_OVERLAP_APPS=1 adds the miner and wallet UIs)" overlap_sweep
run "explorer, emission and public stats unit tests" node --test site/lib/explorer.test.mjs site/lib/emission.test.mjs site/lib/money.test.mjs site/api/public-stats.test.mjs
run "explorer, emission and public stats unit tests" node --test site/lib/explorer.test.mjs site/lib/emission.test.mjs site/lib/money.test.mjs site/lib/leaderboard.test.mjs site/api/public-stats.test.mjs
run "ship tool self-test" node tools/ship-app.mjs --self-test
run "relay unit tests" node --test relay/test/parse.test.mjs relay/test/auth.test.mjs relay/test/wake.test.mjs relay/test/ember.test.mjs
run "miner app notice strip and update card tests" node --test app/igneum-app/ui/notices.test.mjs app/igneum-app/ui/update-card.test.mjs app/igneum-app/ui/view.test.mjs app/igneum-app/ui/tune-line.test.mjs

30
tools/ci/publish-jobs-check.sh Executable file
View file

@ -0,0 +1,30 @@
#!/usr/bin/env bash
# The removal guard of packaging/ota/publish-jobs.sh (7 October 2026, 18:53 BST: a removal reached PC 2 one second after its job had
# launched a silent installer over the running app; the runner's abort-on-removal ended the process tree and the app went dark).
# A remove must refuse while any target's report shows the job started with no final line, and refuse a job published with
# --installs-app; --force "<reason>" overrides. The check runs the script against a scratch destination (--dest) with the
# machine read replaced by a fixture (REMOVE_GUARD_READ), so nothing is published and no machine is read.
#
# tools/ci/publish-jobs-check.sh # exit 1 with the case that resolved wrongly (the check IS its self-test)
set -euo pipefail
cd "$(dirname "$0")/../.."
t=$(mktemp -d); trap 'rm -rf "$t"' EXIT
mkdir -p "$t/dest"; export IGNEUM_DLSITE="$t/site"; mkdir -p "$t/site/dl/testtoken"
P="packaging/ota/publish-jobs.sh"
# the real OTA key signs into the scratch --dest (as packaging/ota/test-publish-jobs.sh does; nothing is deployed, the downloads
# folder is untouched); a machine without the key or the signer skips the check as not applicable
[ -f "$HOME/.config/igneum/ota-signing-key" ] && [ -x app/igneum-app/target/release/igneum-ota-sign ] || { echo "publish-jobs-check: no OTA key or signer here; skipped as not applicable"; exit 0; }
printf 'echo hi\n' > "$t/s.ps1"
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-run --title t --requires none --dest "$t/dest" >/dev/null 2>&1 || { echo "publish-jobs-check: add failed"; exit 1; }
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-install --installs-app --title t --requires none --dest "$t/dest" >/dev/null 2>&1 || { echo "publish-jobs-check: add --installs-app failed"; exit 1; }
grep -q '"installs_app":true' "$t/dest/igneum-jobs.json" || { echo "publish-jobs-check: --installs-app did not write the param"; exit 1; }
fail=0
printf 'job guard-run (run) on PC machine 0000000100000000 run job-guard-run-00000001, started 2026-10-07T18:00:00Z\n== running the powershell script (cap 40 min) ==\nRESULT start\n' > "$t/running.txt"
printf 'SUMMARY: done exit 0, started 2026-10-07T18:00:00Z, finished 2026-10-07T18:00:09Z, 9 s: script finished, exit 0\njob guard-run: done (exit 0) after 9 s: script finished\n' > "$t/done.txt"
if REMOVE_GUARD_READ="$t/running.txt" bash "$P" remove guard-run --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: a RUNNING job was removed"; fail=1; else echo "publish-jobs-check: a running job's removal is refused"; fi
if REMOVE_GUARD_READ="$t/running.txt" bash "$P" remove guard-run --dest "$t/dest" --force "test" >/dev/null 2>&1; then echo "publish-jobs-check: --force removes a running job (with the reason)"; else echo "publish-jobs-check: --force did not remove"; fail=1; fi
if REMOVE_GUARD_READ="$t/done.txt" bash "$P" remove guard-install --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: an --installs-app job was removed without --force"; fail=1; else echo "publish-jobs-check: an --installs-app job's removal is refused"; fi
bash "$P" add --kind run --target 00000001 --script "$t/s.ps1" --id guard-run2 --title t --requires none --dest "$t/dest" >/dev/null 2>&1
if REMOVE_GUARD_READ="$t/done.txt" bash "$P" remove guard-run2 --dest "$t/dest" >/dev/null 2>&1; then echo "publish-jobs-check: a finished job's removal passes"; else echo "publish-jobs-check: a finished job's removal was refused"; fail=1; fi
[ "$fail" = 0 ] && echo "publish-jobs-check: a running or installs-app job is never removed without --force; a finished one is"
exit $fail

View file

@ -1,7 +1,7 @@
#!/usr/bin/env bash
# The spill-over router of tools/build-remote.sh (lib.sh bs_route_spill; the project lead, 7 October 2026, 15:02 UK: build-1 at load 139 with a
# queue of 1 h 40 min while build-2 sat at 4.5 with free slots). The class is a preference: a job goes to its class's box unless
# that box has no free slot or its 1-minute load is above 64, in which case it goes to the other box when that one qualifies, else
# that box has no free slot or its 1-minute load is above 80 (was 64), in which case it goes to the other box when that one qualifies, else
# it queues on its own box. This check feeds the router fixed box states through BS_ROUTE_STATE_<n> (no ssh) and host files in a
# scratch directory, and compares the chosen box and the spilled flag for the known cases: a held build-1 selects build-2, a free
# build-1 selects build-1, an overloaded build-1 spills, a held build-2 sends a suite to build-1, two full boxes queue on the
@ -22,17 +22,18 @@ expect() { # <case> <class> <want box> <want spilled> ; the states come from t
}
BS_ROUTE_STATE_1="free=0 slots=2 load1=30" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a held build-1 selects build-2" build 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=20" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a free build-1 selects build-1" build 1 0
BS_ROUTE_STATE_1="free=2 slots=2 load1=70" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "an overloaded build-1 spills" build 2 1
BS_ROUTE_STATE_1="free=2 slots=2 load1=95" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "an overloaded build-1 spills" build 2 1
BS_ROUTE_STATE_1="free=0 slots=2 load1=30" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a gate spills like a build" gate 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=0 slots=3 load1=10" expect "a held build-2 sends a suite to build-1" suite 1 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=1 slots=3 load1=90" expect "an overloaded build-2 sends a bench away" bench 1 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=1 slots=3 load1=120" expect "an overloaded build-2 sends a bench away" bench 1 1
BS_ROUTE_STATE_1="free=2 slots=2 load1=5" BS_ROUTE_STATE_2="free=2 slots=3 load1=10" expect "a free build-2 keeps its suite" suite 2 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=80" BS_ROUTE_STATE_2="free=0 slots=3 load1=90" expect "two full boxes queue a build on build-1" build 1 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=80" BS_ROUTE_STATE_2="free=0 slots=3 load1=90" expect "two full boxes queue a suite on build-2" suite 2 0
BS_ROUTE_STATE_1="down" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a build-1 that is down spills" build 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=5" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a proving class with no box 3 prefers box 1" prove 1 0
BS_ROUTE_STATE_1="free=0 slots=2 load1=5" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "a proving class spills to box 2 when box 1 is held" prove 2 1
BS_ROUTE_STATE_1="free=1 slots=2 load1=64" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load exactly 64 is under the line" build 1 0
BS_ROUTE_STATE_1="free=1 slots=2 load1=80" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load exactly 80 is under the line" build 1 0
BS_ROUTE_STATE_1="free=2 slots=2 load1=70" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load 70 stays on build-1 (the line is 80)" build 1 0
# the ssh path itself under the hook's shell (/bin/bash is 3.2 on the Mac; the pool lane found `BS_SSH_OPTS[@]: unbound variable`
# at the first unpinned route, 7 Oct 2026): a host file pointing at a port nothing answers on must read "down" in a few seconds,
# not die on an unset array

View file

@ -0,0 +1,70 @@
// node --test tools/scene/legend.test.mjs (key-22, the project lead's screenshot of the app's chain key against /live, 7 October 2026)
// The key is ONE export: IgneumDag.legend({ mine }) in scene/live-dag.js (entries, order, token names, shapes); the app's
// chain card and the site's /live key render from it, so they cannot drift. This test fails when either key's entries,
// order or tokens differ from the export, and when a colour the scene draws on blocks has no key entry.
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { readFileSync, existsSync } from 'node:fs';
import { fileURLToPath } from 'node:url';
import { dirname, join } from 'node:path';
import { execSync } from 'node:child_process';
const here = dirname(fileURLToPath(import.meta.url)), root = join(here, '../..');
const src = readFileSync(join(root, 'scene/live-dag.js'), 'utf8');
const win = { document: { hidden: false, addEventListener() {}, createElement: () => ({ style: {} }) }, addEventListener() {}, matchMedia: () => ({ matches: false, addEventListener() {} }), getComputedStyle: () => ({ getPropertyValue: () => '' }), devicePixelRatio: 1, innerWidth: 1280 };
new Function('window', 'document', src)(win, win.document);
const Dag = win.IgneumDag;
const SITE_ORDER = ['Pending', 'Included', 'Excluded', 'Selected chain', 'Proven', 'Locked checkpoint'];
// the entries a page's markup carries today, from its literal spans (a hard-coded key) or none (a rendered key)
const literal = (html, tag) => [...html.matchAll(new RegExp('<span><i class="' + tag + '[^>]*></i>([^<]+)</span>', 'g'))].map((m) => m[1].trim());
test('the export: Pending first, Included, Excluded, Selected chain, Proven, Locked checkpoint; the app adds Your blocks first; every entry names its token and shape (known-failed on 0.3.22)', () => {
assert.ok(Dag && typeof Dag.legend === 'function', 'IgneumDag.legend exists');
const site = Dag.legend({ mine: false }), app = Dag.legend({ mine: true });
assert.deepEqual(site.map((e) => e.label), SITE_ORDER);
assert.deepEqual(app.map((e) => e.label), ['Your blocks'].concat(SITE_ORDER));
for (const e of app) { assert.match(e.token, /^--[a-z-]+$/, e.label + ' token'); assert.ok(['square', 'circle', 'tick', 'ringed'].includes(e.shape), e.label + ' shape'); assert.ok(e.id); }
assert.equal(app[0].token, '--molten'); assert.equal(app[0].shape, 'ringed');
assert.equal(site.find((e) => e.label === 'Included').token, '--included', 'the key draws Included in the colour the scene draws it');
assert.equal(site.find((e) => e.label === 'Excluded').token, '--excluded');
assert.equal(site.find((e) => e.label === 'Locked checkpoint').shape, 'circle');
assert.equal(site.find((e) => e.label === 'Proven').shape, 'tick');
assert.equal(typeof Dag.renderLegend, 'function', 'one renderer for both pages');
});
test('every colour the scene draws on a block or a band has a key entry', () => {
const tokens = new Set(Dag.legend({ mine: true }).map((e) => e.token));
// the renderer's palette read: col={ember:c('--ember',…), …, blue:c('--included',…), red:c('--excluded',…)}
const read = [...src.matchAll(/c\('(--[a-z0-9-]+)'/g)].map((m) => m[1]);
const drawn = ['--included', '--excluded', '--ember', '--molten', '--bone', '--ash'];
for (const t of drawn) { assert.ok(read.includes(t), 'the scene reads ' + t); assert.ok(tokens.has(t), 'the key has an entry in ' + t); }
});
// the /live key as ruled (7 October 2026): Included, Excluded, Selected chain, Proven, Locked checkpoint; no Pending and no
// Your blocks (the site has no "you"). The exceptions are the ruling's; every entry the two surfaces share must carry the
// same wording and the same token as the export, so the swatches cannot drift apart again.
const SITE_RULED = SITE_ORDER.filter((l) => l !== 'Pending');
// the site deploys from master alone and a release-* branch carries site/ frozen as it was cut (tools/scene/sync.mjs's scope
// rule), so the site half binds on master (or SCENE_SYNC_SCOPE=site, or a site/live.html passed as SITE_LIVE_HTML) and is a
// diagnostic on a release branch
const branch = (() => { try { return execSync('git rev-parse --abbrev-ref HEAD', { cwd: root, stdio: ['ignore', 'pipe', 'ignore'] }).toString().trim(); } catch (e) { return ''; } })();
const siteBinds = process.env.SCENE_SYNC_SCOPE === 'site' || !!process.env.SITE_LIVE_HTML || branch === 'master';
// the app lives on the release branches (master carries no app/igneum-app/ui/live-dag.js), so the app half binds where that copy exists
const appBinds = existsSync(join(root, 'app/igneum-app/ui/live-dag.js'));
const siteEntries = (html) => [...html.matchAll(/<span><i class="lgi([^"]*)"(?: style="([^"]*)")?><\/i>([^<]+)<\/span>/g)].map((m) => { const tok = /var\((--[a-z0-9-]+)\)/.exec(m[2] || ''); return { label: m[3].trim(), token: tok ? tok[1] : (/\btick\b/.test(m[1]) ? '--bone' : ''), shape: /\btick\b/.test(m[1]) ? 'tick' : /border-radius:50%/.test(m[2] || '') ? 'circle' : 'square' }; });
test('the app key is the export, not a hand-written list; the site key is the export minus the ruled exceptions (Pending, Your blocks), same wording and tokens on every shared entry', (t) => {
const app = readFileSync(join(root, 'app/igneum-app/ui/index.html'), 'utf8'), site = readFileSync(process.env.SITE_LIVE_HTML || join(root, 'site/live.html'), 'utf8');
const appLit = literal(app, 'lg');
if (appBinds) { assert.ok(/data-legend="mine"/.test(app), 'the app legend renders from IgneumDag.legend({ mine: true })'); assert.deepEqual(appLit, [], 'hand-written entries in the app key: ' + appLit.join(', ')); }
else t.diagnostic('no app scene copy in this tree (master): the app half binds on the release branches');
const got = siteEntries(site), exp = Dag.legend({ mine: false }).filter((e) => e.label !== 'Pending'), problems = [];
if (JSON.stringify(got.map((e) => e.label)) !== JSON.stringify(SITE_RULED)) problems.push('the /live key reads ' + got.map((e) => e.label).join(', ') + ', ruled: ' + SITE_RULED.join(', '));
for (const e of exp) { const g = got.find((x) => x.label === e.label); if (!g) continue; if (g.token !== e.token) problems.push(e.label + ' token on /live is ' + g.token + ', the export says ' + e.token); if (g.shape !== e.shape) problems.push(e.label + ' shape on /live is ' + g.shape + ', the export says ' + e.shape); }
if (got.some((e) => /your/i.test(e.label))) problems.push('the site shows Your block; the ruling has none');
if (siteBinds) assert.deepEqual(problems, [], 'the /live key against the export:\n' + problems.join('\n'));
else if (problems.length) t.diagnostic('site/live.html on this release branch is the frozen cut (' + problems.join('; ') + '); the check binds on master, where the site deploys from');
// the app's source line stays
if (appBinds) assert.match(readFileSync(join(root, 'app/igneum-app/ui/app.js'), 'utf8'), /From Igneum’s observer\. Your blocks are ringed\./);
// the copies are the source (the sync gate says the same; this fails first when a legend edit misses the sync)
if (appBinds) assert.equal(readFileSync(join(root, 'app/igneum-app/ui/live-dag.js'), 'utf8'), src, 'the app copy of live-dag.js is the scene source');
});

View file

@ -0,0 +1,54 @@
// node --test tools/scene/shard-words.test.mjs (7 October 2026: "why does the animation on site say no shard plan yet?")
// IgneumDag.shardWords(block, nowMs) is the one source of the shard sentence the scene's tooltip, the site's /live
// inspector and the app's inspector print. The empty case says what the block's own facts say: a block under 10 s old
// with no shards is loading its plan, an excluded block has nothing to prove, a pending block is not yet ordered, a
// blue block off the selected chain gets no plan; a planned shard with no prover is awaiting one, with the block's age;
// proving, verified and paid as before.
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { readFileSync, existsSync } from 'node:fs';
import { fileURLToPath } from 'node:url';
import { dirname, join } from 'node:path';
import { execSync } from 'node:child_process';
const here = dirname(fileURLToPath(import.meta.url)), root = join(here, '../..');
const src = readFileSync(join(root, 'scene/live-dag.js'), 'utf8');
const win = { document: { hidden: false, addEventListener() {}, createElement: () => ({ style: {} }) }, addEventListener() {}, matchMedia: () => ({ matches: false, addEventListener() {} }), getComputedStyle: () => ({ getPropertyValue: () => '' }), devicePixelRatio: 1, innerWidth: 1280 };
new Function('window', 'document', src)(win, win.document);
const Dag = win.IgneumDag;
const NOW = 1_791_378_800_000;
// the site deploys from master alone and a release-* branch carries site/ frozen as it was cut, so the site inspector's
// check binds on master (or SCENE_SYNC_SCOPE=site) and is a diagnostic on a release branch
const branch = (() => { try { return execSync('git rev-parse --abbrev-ref HEAD', { cwd: root, stdio: ['ignore', 'pipe', 'ignore'] }).toString().trim(); } catch (e) { return ''; } })();
const siteBinds = process.env.SCENE_SYNC_SCOPE === 'site' || branch === 'master';
const appBinds = existsSync(join(root, 'app/igneum-app/ui/live-dag.js')); // the app lives on the release branches
const block = (over) => ({ hash: 'ab12', ts: NOW - 42_000, color: 'blue', chain: true, miner: 'k1', parents: [], blue_score: 1, daa: 1, shards: [], locked: false, final: false, proven: false, ...over });
test('the four empty cases (known-failed on 2.0.5): loading under 10 s, excluded, not yet ordered, off the selected chain; an old chain block with no plan says how long', () => {
assert.ok(Dag && typeof Dag.shardWords === 'function', 'IgneumDag.shardWords exists');
assert.equal(Dag.shardWords(block({ ts: NOW - 4_000 }), NOW).summary, 'shard plan loading');
assert.equal(Dag.shardWords(block({ color: 'red', chain: false }), NOW).summary, 'excluded, nothing to prove');
assert.equal(Dag.shardWords(block({ color: 'pending', chain: false }), NOW).summary, 'not yet ordered');
assert.equal(Dag.shardWords(block({ chain: false }), NOW).summary, 'off the selected chain, no shards planned');
assert.equal(Dag.shardWords(block(), NOW).summary, 'no shard plan after 42 s');
for (const s of [Dag.shardWords(block({ ts: NOW - 4_000 }), NOW), Dag.shardWords(block({ color: 'red' }), NOW)]) assert.deepEqual(s.items, []);
assert.equal(/no shard plan yet/.test(src), false, 'the old words are gone from the scene');
});
test('a planned shard with no prover is awaiting one, with the block age; assigned, proving, verified and paid as before', (t) => {
const sh = [{ i: 0, n: 4, state: 'planned', prover: null }, { i: 1, n: 4, state: 'planned', prover: 'faa34a1a' }, { i: 2, n: 4, state: 'proving', prover: 'b2' }, { i: 3, n: 4, state: 'paid', prover: 'c3', payout: 4.5532 }];
const w = Dag.shardWords(block({ shards: sh }), NOW);
assert.deepEqual(w.items.map((x) => x.word), ['awaiting a prover · 42 s', 'assigned to faa34a1a', 'proving by b2', 'paid 4.5532 IGN']);
assert.equal(w.summary, '1 paid, 1 proving, 1 assigned, 1 awaiting a prover · 42 s');
const old = Dag.shardWords(block({ ts: NOW - 400_000, shards: [{ state: 'planned', prover: null }] }), NOW);
assert.equal(old.items[0].word, 'awaiting a prover · 7 min'); assert.equal(old.summary, '1 awaiting a prover · 7 min');
const done = Dag.shardWords(block({ shards: [{ state: 'verified' }, { state: 'paid', payout: 1 }] }), NOW);
assert.equal(done.summary, '1 paid, 1 verified'); assert.deepEqual(done.items.map((x) => x.word), ['verified', 'paid 1 IGN']);
// the tooltip line uses it (words() is an instance method, so the source line is the check)
assert.match(src, /'Shards: '\+shardWords\(b,nowMs\)\.summary/, 'the tooltip takes the shared sentence');
// both inspectors use it: no hand-written shard sentence left
const live = readFileSync(join(root, 'site/live.html'), 'utf8'), siteOk = !/no shard plan yet/i.test(live) && /IgneumDag\.shardWords\(/.test(live);
if (siteBinds) assert.ok(siteOk, 'the site inspector still carries its own shard sentence');
else if (!siteOk) t.diagnostic('site/live.html on this release branch is the frozen cut; the inspector check binds on master, where the site deploys from');
if (appBinds) { const app = readFileSync(join(root, 'app/igneum-app/ui/app.js'), 'utf8'); assert.equal(/no shard plan yet/i.test(app), false, 'the app inspector'); assert.match(app, /IgneumDag\.shardWords\(/, 'the app inspector takes the shared sentence'); }
else t.diagnostic('no app scene copy in this tree (master): the app half binds on the release branches');
});

View file

@ -33,6 +33,8 @@ createServer(async (req, res) => {
if (p.startsWith('/api/')) {
const name = p.slice(5).replace(/[^a-z0-9_-]/gi, '');
if (!existsSync(join(site, 'api', name + '.mjs'))) { res.statusCode = 404; return res.end('no such function'); }
// IGNEUM_LIVE_FIXTURE=<path>: answer /api/live from a recorded reply with its clock moved to now (captures and tests off the database)
if (name === 'live' && process.env.IGNEUM_LIVE_FIXTURE) { const f = JSON.parse(readFileSync(process.env.IGNEUM_LIVE_FIXTURE, 'utf8')); const shift = Date.now() - new Date(f.now).getTime(); f.now = new Date().toISOString(); for (const b of f.blocks || []) b.ts += shift; res.setHeader('Content-Type', 'application/json'); return res.end(JSON.stringify(f)); }
try { const h = await api(name); return await h({ method: req.method, url: req.url, headers: req.headers, query: Object.fromEntries(url.searchParams), socket: req.socket }, shim(res)); }
catch (e) { res.statusCode = 500; return res.end(String(e.stack || e)); }
}