Commit graph

258 commits

Author SHA1 Message Date
igneum-labs
7d09857f91 observer: a watchdog forces a reconnect after ten failed ticks (the live page went stale for an hour after a node restart)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:22:22 +00:00
igneum-labs
a96bcea470 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
addeb660fd Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
8b4b1e500a Merge origin/master (974805b) into release-0.3.9: fud-a round 6, the entity imprint, the conflict-marker check; docs/bench-log.md both entries, the site taken from master and rebuilt (519 links, 0 broken) 2026-10-05 16:48:00 +00:00
igneum-labs
974805b9df ci: no conflict markers in tracked files (check + pre-push hook that also builds the site)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:45:09 +00:00
igneum-labs
ee7cfa9c27 Merge entity: Igneum Labs LTD and the DIFC address as the entity and contact everywhere, repository public at the public testnet, ledger published with it, no team page
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/fud-ledger.md
#	site/bench.html
#	site/index.html
#	site/journey.json
2026-10-05 16:42:40 +00:00
igneum-labs
02b19ed761 Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
8703d9e731 Merge fud-a: ledger sweep round 6 (11 fixes closed with rollout evidence, M1/M11/M16/M21/P3/P9/P14/X5 measured, C4 finding, F16 options)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/bench-log.md
2026-10-05 16:33:15 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
ef3cbaf4f5 Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 16:30:47 +00:00
igneum-labs
3a96e7371c Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 16:28:21 +00:00
igneum-labs
24aaa0e254 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:24:35 +00:00
igneum-labs
142ca73731 Merge txgen: the devnet transaction generator, proving watch, exporter block reconstruction fix with node-plan fixtures, bench log and evidence
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:22:26 +00:00
igneum-labs
3be4e3ef2a txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
d9736b3c06 Merge testnet-infra: testnet seed profile, DNS and RPC installers, build-job watcher fix, docs/testnet, the go checklist
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:05:16 +00:00
igneum-labs
f2416a39de build-job.mjs: the watcher reads the SUMMARY wherever it sits in the report (the closing report starts with the app header; two finished builds showed as still running on 5 October 2026)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:02:47 +00:00
igneum-labs
e6a3f8bab1 FUD sweep round 6 (evening, 5 October): eleven rolled-out fixes moved to Fixed with live measurement lines, F21/F22 shipped but switch not thrown, M20 closed on the 0.3.5 merge; P14 one base-fee definition in spec 05; M16 recompute-attacker cost model; C4 overlay-against-GHOSTDAG runner
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:02:02 +00:00
igneum-labs
a015f67eac Merge public-release: token-free public downloads, site buttons with live versions, HiveOS 0.3.8 package, the faucet (prepared)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	site/index.html
#	site/miner.html
#	site/wallet.html
2026-10-05 16:01:08 +00:00
igneum-labs
53dae0ddf1 release-0.3.6 plan: the two finality tests under the parallel suite answered (fork 7003055b); build-job.mjs forwards --node-tests, --app-tests, --no-app
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:59 +00:00
igneum-labs
3551069c51 Public testnet launch, the public side: dl/public downloads path, site download buttons, HiveOS package, faucet
Downloads: packaging/ota/publish-public.sh publishes the current installers, the HiveOS package and the two signed
manifests into dl/public/ with no token in any URL, writes the four /public/ aliases as vercel.json rewrites and an
unsigned index for the site; publish-manifest.sh --public and ship-app.mjs --public run it on every release (dry run
and self-test cover it). Nothing removed from the token folders.

Site: the miner and wallet buttons link the public aliases and show the version and size from the index, read at
build time (site/downloads.json is the offline snapshot); TESTNET_OPEN in build.mjs drops the "Public testnet: not yet
open" line on the go; the HiveOS Flight Sheet install line on the miner page; /faucet page.

HiveOS: igneum-hive-0.3.8.tar.gz from the 0.3.8 node (2b6d23ef, PC build job) and the zig-built Linux workers.

Faucet: site/api/faucet.mjs (10 IGN per address and per IP per day, Neon table faucet_grants, EIP-1559 transfer signed
by site/lib/eth.mjs with no dependencies: keccak, RLP, secp256k1 with RFC 6979), FAUCET_KEY and FAUCET_RPC from the
Vercel env only; 15 unit tests with a fake database and node, run in CI.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:31 +00:00
igneum-labs
6cecbd4c67 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
72351e8270 Testnet seeds: NET=testnet profile for the seed scripts, seeds-testnet.tsv (3 Hetzner VMs), dns.sh (deSEC), the public RPC allowlist and nginx site, build-job.mjs forwards --node-tests
seed1.testnet nbg1 195.201.35.33, seed2.testnet ash 5.161.232.205, seed3.testnet sin 5.223.52.210 (5 October 2026). Ports 26810/26811/28810/26890
from seed.env; provision-seed.sh BUILD_WHERE=cross takes the PC build job's Linux igneumd from infra/cross/out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:46:22 +00:00
igneum-labs
9a204e2266 rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:37:02 +00:00
igneum-labs
7f1884290a ci: the pinned-guests check ignores comment lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:01:38 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
a0e092d109 Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
aa9b4da932 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
0f6fc2ead5 Merge rotation-2 (7c9a939) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
fc137257ed Merge origin/testnet-adopt (3be4501) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
2edc5f693c Merge job-wake: instant job wake-up (relay /wake long-poll, 2-minute fallback poll, publisher wake)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:26:07 +00:00
igneum-labs
7e0fc7da65 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
37c947beb9 lock: build slots open to new builds come from ~/.config/igneum/build-slots (1 to 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:19:52 +00:00
igneum-labs
fd07ef569f Merge origin/testnet-prep (28f6ccc) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
d791efd4be Merge origin/fud-consensus into release-0.3.5
bench-log.md: both appended entries kept (the round-4 consensus items and the red team next to the branch's own).
2026-10-05 02:19:41 +00:00
igneum-labs
e12f768e3c Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:56:28 +00:00
igneum-labs
90478b5cf4 Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:49:46 +00:00
igneum-labs
a32b10aad8 Merge branch 'redteam' into fud-consensus
# Conflicts:
#	docs/fud-ledger.md
2026-10-05 01:34:21 +00:00
igneum-labs
2cb3d88bca fud.mjs: node logs kept per scenario, pre-F24 refusal wording counted, reorg criterion as the rule promises; first-pass and control results kept
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:34:04 +00:00
igneum-labs
d80b384360 Merge remote-tracking branch 'origin/master' into release-0.3.5 2026-10-05 01:14:23 +00:00
igneum-labs
d9182273ce Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:12:27 +00:00
igneum-labs
be99cb3821 Lock: three run slots for functional runs; a measurement waits for all of them
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:10:17 +00:00
igneum-labs
4b26d04bc0 Red team 4 Oct 2026: every attack suite against the 0.3.4 finality-fixes build (rule v3 on, fast time); 30 scenarios, ledger F25 M30 M31 new, F21 F23 F24 measured
Report docs/review/redteam-2026-10-04.md: finality attacks s1-s8 plus 34% withholding, 50/50 long partition, F23 and
F24 custom runs, ordering harness, execution suite and EVM smoke, proving hostile tests and a proof flood, difficulty v2
timestamp forging in the simulator. New fails: the fast-time harnesses corrupt the u64::MAX sentinels of the override
(F25), a block or transaction flood grows the node by hundreds of MB in a minute (M30), the coinbase does not fit the
204-byte limit on mainnet, testnet and simnet parameters (M31). F23 and F24 reproduced on this build; F21's bound
measured at one window of the side's own DAA. Scenario scripts under tools/finality-attacks/redteam/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:03:08 +00:00
igneum-labs
af8ae429f8 Harness: port and data-dir overrides, per-load RSS deltas, cache-build counts; bench-log entry for ledger M30
tools/harness: IGNEUM_HARNESS_BASE_PORT and IGNEUM_HARNESS_TMP move the test
network's ports and data directory so two agents can run it at once; the u64
sentinel round-trip in overrideParams is fixed with the BigInt reviver from
tools/finality-attacks (ledger F25); s6 records rss_start, rss_delta and
cache_builds per load and reports per-load growth (the old row subtracted one
baseline taken before all three loads, which is how the mempool flood was
read as +270 MB); s7 counts "PoW cache built" lines beside every RSS sample;
--live-only skips the s7 simulator part.

docs/bench-log.md: the 4 October 2026 (night) entry: the floods' growth was
one 256 MiB PoW cache per epoch roll (the engine kept a cache per (epoch,
day) pair, KEEP 4), measured before and after the fork fix (fork branch
fud-memory, 796f758d): submit load +263/+257 MB with 1/1 builds before,
+9/+2 MB with 0/0 after; block flood 302 to 1,085 MB with 3/3 builds before,
300 to 315 MB with 0/0 after. Result JSON under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 00:38:33 +00:00
igneum-labs
22aa692779 Round-4 consensus items: the fud.mjs runner (digest, ban, reorg scenarios on the fast-time 3-node network, ports 29400+), per-node override files and --equivocate-at in the harness, spec 02 section 2.8, spec 03 C1/C4/3.6 and the 3.10 rows, spec 08 section 8.7
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 23:53:35 +00:00
igneum-labs
29e3a0c1d3 Merge origin/dev-fee (96270bd) into release-0.3.5
bench-log.md: both appended entries kept; the generated site pages rebuilt with node site/build.mjs.
2026-10-04 23:16:45 +00:00
igneum-labs
bfea36330e Dev fee: the test-network measurement in the bench log; run.mjs waits for the nodes and edits the override as text
9 fee blocks in the 785 blocks of the two fee-paying miners (1.15%, expected 1 in 100 templates), the miners' fee
counters equal the chain's count on both nodes, the control miner at --dev-fee 0 paid nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 23:15:27 +00:00
igneum-labs
7210fd4683 Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
cfb937b42d Merge origin/miner-reliability into release-0.3.5
Conflicts resolved keeping both: engine.rs carries the sweep state (miner-eff) and the node watchdog (reliability);
the STATUS line goes through watchdog::parse_status and still feeds the sweep's rate sample; main.rs declares both
modules; bench-log.md keeps both entries. site/build.mjs keeps master's partial-injected pages and adds the /miners
bench table through the same page() with active: 'miners'; the Miners link is in site/partials/nav.html; sitemap
gains /miners; every generated page rebuilt with node site/build.mjs.
2026-10-04 22:25:10 +00:00
igneum-labs
cad8aa0d96 Reliability measured: miner guards and the app watchdog on private test networks; M26, M27, X21 fixed in the ledger
docs/bench-log.md: the fake-worker measurements (slow start one trip and 2.0 s restart, fake-fast guard in under
0.1 s, exit 43 at 8.8 s, CPU re-check stop at 0.5 s, stall guard at 60.1 s with STATUS lines through the silence,
one prepare per epoch with refused retries held; app: zero-rate restart at 79.6 s and faulted at 75.4 s on the
repeat, no-status restart at 90.4 s, silent node restarted at 150.7 s and synced 7.2 s later; no double restart on
the miner's own worker restart). Two defects the harness found are named with their fork commits.
docs/fud-ledger.md and the round-4 review table: M26, M27, X21 Fixed with the commits.
engine.rs: the miner's restart note no longer hides the fault reason on the card.
tools/reliability: the harness matches the miner's stderr lines where they are printed there.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:22:16 +00:00
igneum-labs
ec843737c2 Merge origin/dev-fee into release-0.3.5
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
2026-10-04 21:48:04 +00:00
igneum-labs
1028c2579f Miner dev fee: app switch and UI line, HiveOS package, Linux worker cross-build, docs and public text
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.

- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
  "dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
  miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
  with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
  stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
  proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
  docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
  miner section note

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:46:41 +00:00
igneum-labs
1867a4819b Merge origin/build-job into release-0.3.5
Conflict resolved: publish-jobs.sh keeps master's verify command and --tries (the retrying live check) alongside the
build kind's arguments; the usage range covers the merged header.
2026-10-04 21:32:48 +00:00
igneum-labs
ca2ac6dfa8 Merge origin/miner-perf into release-0.3.5
Conflicts resolved: state.rs keeps both the sweep fields (miner-eff) and the race fields (miner-perf); bench-log.md
keeps both appended entries; publish-manifest.sh keeps master's --override implementation (8082576, the "every
height switch" rule, --verify-only, --tries, the retrying live check) and adds miner-perf's --tuning / --no-tuning
with the carry-over of consensus.override and tuning from the current manifest. One --override case, one parser.
2026-10-04 21:31:26 +00:00
igneum-labs
e24516934a Merge remote-tracking branch 'origin/app-ui' into release-0.3.5
# Conflicts:
#	app/igneum-app/ui/app.css
2026-10-04 21:28:59 +00:00
igneum-labs
cda444bbee READMEs: the console's Machines card as it is now (stale, stopped, OTA state, vendors), the parser tests, autosync's restart key and check mode, the observer's dependence on the app's node for proving
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:14:45 +00:00
igneum-labs
0d51aafee7 Observer: logs the seeded checkpoint states at start and names the earlier state when a lock is recorded over one (index 1319 re-recorded 14 min after its lock at the 20:15 restart)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:19:59 +00:00
igneum-labs
66c0bf2a6d Observer autosync: the restart key is observer.mjs and run.sh, not the whole tools/observer tree (an autosync.sh change restarted the observer for nothing)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:18:32 +00:00
igneum-labs
9f0c9036ea Build job: a PC builds the node and the app engine for Linux and Windows inside WSL2, mining untouched
New job kind `build` (jobs.rs, jobbuild.rs, jobrun.rs run_build): free-space check on both sides (20 GB), the
build-inputs zip by sha256, setup inside the distro as root (mingw-w64 posix, clang for bindgen, protoc, zstd, the
Windows rust target; idempotent), sources extracted with the target dir persisting under /root/igneum-build,
cargo build --release native and for x86_64-pc-windows-gnu, cargo test for the manifest's packages, binaries
zstd-compressed and sent to the relay (fn=upload, Blob PUT, fn=drop; 50 MB each) with sha256 in RESULT lines,
STAGE lines with UTC times, a 40-minute default budget and per-stage caps, the Linux side killed on a cap. The
app's runner stays serial (one Active at a time), so a build never overlaps a shard job; nothing stops the miners.
From this version an unknown job kind is skipped by the app (parse_lenient) instead of rejecting the whole file;
the signer stays strict.

Mac side: packaging/windows/push-build-inputs.sh packs a fork worktree, app/igneum-app, brand/icons and
proto-cuda with a manifest (branch, commit, dirty, builds, tests) and the sha256; publish-jobs.sh add --kind build;
tools/build-job.mjs packs, publishes, watches, fetches, checks both sha256 per file and the PE header of every exe
(plus verify-exe.py on igneum-app.exe), and places the binaries where push-inputs.sh, make-payload.sh and the
cloud-devnet scripts look. relay.mjs drop <file> --body carries the body.

Tested on the Mac: 33 app tests (6 new) and the signer's 21; cargo check for x86_64-pc-windows-gnu; the packer
(7.9 MB zip, no target dirs); the publisher against a scratch folder with the rebuilt signer, the old signer
refusing the kind, a bad job refused at signing; the fetch path against the live relay with a real exe (sha256
and PE pass, a wrong sha256 refused; test items deleted). Not run on a PC: the job itself. docs/plans/build-job.md
has the first job for PC 1 and the rollout order (0.3.4 must be on the PCs before a build job is published).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:17:55 +00:00
igneum-labs
2b3ce1c7e3 Observer autosync: a failed fast-forward names git's reason and the dirty files the incoming commits also touch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:14:21 +00:00
igneum-labs
b98a528c9a Merge branch 'master' of https://github.com/igneum-network/igneum 2026-10-04 20:06:13 +00:00
igneum-labs
7d30c5f160 Merge branch 'igneum-wt-finality'
# Conflicts:
#	docs/bench-log.md
2026-10-04 20:06:11 +00:00
igneum-labs
21ccb65f40 Console: a machine whose app logged a clean quit or an update, with no status line after it, shows 'stopped (quit|update) N ago' instead of 'silent' (parseAppTail moved to relay/lib/parse.mjs, test)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:04:18 +00:00
igneum-labs
2bb0728eb2 Finality rule v3 (ledger F21, F22): simulator scenario M, spec 03 Q4/Q5, cloud vote-timing analysis, v3 harness runner, fast-time profile, bench-log entry, devnet rollout plan
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:04:12 +00:00
igneum-labs
c924e9d30a Miner app UI: log drawer rebuilt (open state, scroll to newest, time jump, last error and swap, search, copy, drag height, virtualised), every screen on one scale, canvas and polling idle when hidden
Log drawer: the Logs button shows its open state (Close logs, chevron); a Newest button appears when the user scrolls
up and follow re-engages at the end; a time ruler with error and swap marks, an HH:MM:SS jump box, last error and last
swap buttons; substring search with a match count and highlights; copy the lines in view; the height drags from a grip
(140 px to 70% of the window, remembered); a window under 700 px tall opens a 180 px drawer. The list is virtualised
(19 px rows, only the rows in view in the DOM; up to 20,000 lines kept; wrap mode under 5,000 lines). Polling runs only
while the drawer is open and the window is visible.

Screens: one type scale and spacing scale in app.css, tabular figures everywhere, the bottom bar in pieces (machine name
truncates first, address always short, uptime dropped under 1100 px), tile captions carry their full text as a title,
syncing shows an ETA from the measured block rate, the engine-away state names itself on the node tile, short-window
rules, the key sheet scrolls on a short window, compact settings card rows on two lines, only a block that just arrived
flashes (not the whole strip on first paint).

Performance: the minute grid is drawn once into an offscreen layer; the strip redraws twice a second and at the display
rate only during a flash; nothing draws and the state poll drops to every 5 s while document.hidden. ?debug=1 prints a
budget line every 5 s and exposes window.__igneumBench.

tools/ui-mock: a stand-in engine (node tools/ui-mock/server.mjs) replaying recorded, scrubbed API responses with
scenarios (syncing, nodedown, nocards, integrated, clock, paused, biglog, fresh, job, nvidia), so UI work never
touches a running miner.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:51:22 +00:00
igneum-labs
4a32962417 Observer autosync restarts the observer whenever the checked-out tools/observer tree changes (marker + check mode); console stale mark at 180 s (one missed upload is not stale); bugs.md rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:48:45 +00:00
igneum-labs
8e243dfd3e Observer: one checkpoint_locked event per index (the poll claims the state before its first await; the FinalityLock notification path raced it and the live feed showed two locked lines 30 ms apart); a lock claimed by the notification gets its votes_seen from the next poll
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:34:57 +00:00
igneum-labs
df5f144642 Relay: secrets compared in constant time (relay/lib/auth.mjs, unit test in CI), HSTS header, tools/relay.mjs prints /r/<token> in list and watch (round 4, X28 and X24 part)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:31:22 +00:00
igneum-labs
a601321481 App engine: watchdog per card and per node, WORKER FAULT and mismatched= read from the miner; public GPU bench table and the reliability test harness
Review round 4 X21 and the project lead's levers 5 and 6 (4 October 2026 evening):
- src/watchdog.rs: CardWatch (no status line for 90 s, or hash rate 0 for 60 s while the node is synced: one
  restart, then the card is marked faulted with the reason in the UI and the log; the miner's own worker restarts
  suspend both rules until ready, so there are no double restarts; exit 43 counts as a watchdog restart) and
  NodeWatch (our node silent for 120 s is restarted in-process through the restart kind the remote jobs use, with a
  growing delay). State machines with no clock; 11 unit tests replay recorded STATUS and WORKER FAULT lines.
- engine.rs reads STATUS mismatched=, faults= and the WORKER FAULT lines onto the card (faults, mismatched, message);
  a faulted card is not restarted until the user changes its settings or resumes mining; other cards keep mining.
- site/miners.html (build.mjs, scrubbed like /bench, rows from site/miner-bench.json): card, generator version, best
  MH/s, MH per watt where measured, miner version, date, source, measured by the team or reported by the fleet. In the
  navigation beside the engineering log on every page and in the sitemap. One line says there is no other miner to
  compare with.
- tools/reliability: fake-worker.mjs (the serve protocol, misbehaving on command), run.mjs (miner guards on a private
  test network, ports 29950+) and app-run.mjs (the app watchdog end to end, ports 29960+).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:20:49 +00:00
igneum-labs
9915c883b1 Bug hunt: console cards for other/intel workers and a stale mark on old STATUS lines (relay/lib/parse.mjs + test in CI); publish-jobs verifies the live file with retries and named reasons, a verify command, a failed deploy stops, a collect command without $_ is refused; the dl token masked in printed URLs; docs/bugs.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:15:05 +00:00
igneum-labs
b06ba68a4d Lock: three build slots, exclusive measure, run mode, status command; replaced atomically
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:12:26 +00:00
igneum-labs
713fb56cf4 CI identity grep: .log files get the generic scrub too; the 4 October difficulty record carried a home path (every master run red since c01b954)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:09:09 +00:00
igneum-labs
fe3a3ab701 Fleet learning for the kernel race: the TUNING record, the aggregator, the manifest's tuning object, the PC 1 race job
The engine turns a worker's race line into one TUNING {json} line in the app log (card model as the worker names it,
driver, arch, program class loads and wide loads, every variant's MH/s, winner, gain, the card's power cap and
draw, MH per watt), which the existing intake receives; the card state carries the variant for the dashboard and
one event per race. tools/tuning.mjs aggregates the records from miner_logs per card model (median MH/s or MH per
watt, at least 3 samples, de-duplicated per race) and writes tuning.json; publish-manifest.sh --tuning puts it in
the signed manifest (and now takes --override for consensus.override; both are carried over from the current
manifest when not given, --no-tuning drops it); manifest.rs parses it; ota.rs writes <app data>/tuning.json and
removes it when the manifest drops it; procs::spawn takes an environment and every miner starts with
IGNEUM_TUNING_FILE, which its worker reads at every prepare. Dry run of the publisher against a scratch folder:
tuning and override written, carried over, dropped, signature verified.

docs/plans/miner-perf.md: the signed jobs for PC 1 (fetch the race build of the NVRTC worker, then
relay/playbooks/race-5090.ps1 with the miners stopped: 17 variants, 3 rounds, twice) with the exact publish
commands for the main session; not published by the agent.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:08:45 +00:00
igneum-labs
78f4213977 Lock: a 'run' mode for functional runs that lets builds continue; rule updated
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:08:36 +00:00
igneum-labs
665bb612f2 Jobs reader: error lines shown under a job's status
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:00:57 +00:00
igneum-labs
a36ea68b45 Jobs reader: the app's closing report counts as final and error lines are collected; prove-shard.sh fails the job when a stage fails
Three watchers never saw a job finish because the closing upload starts with the app header, not the SUMMARY line,
and a shard run whose stages failed still exited 0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:59:13 +00:00
igneum-labs
9f940a5ee8 Ship tool: one command cuts an Igneum Miner version (tools/ship-app.mjs)
the project lead, 4 Oct 2026: 0.3.1, 0.3.2 and 0.3.3 each took eight hand steps and an hour. The tool runs them in order, each
step idempotent and resumable (--from): preflight, bump (six version files, one function, read back), push-inputs,
commit and push, the windows.yml run polled with gh (auth switch before every call), fetch, DMG under the build lock,
copy, signed manifest, one deploy, HEAD/GET verification with sizes and sha256, one console item. --dry-run prints
the plan, --check compares the version files, --self-test bumps a scratch copy. Secrets never printed.

Found by --check: Igneum-Miner.iss and Info.plist were left at 0.3.2 when 0.3.3 was cut (CI passed -Version from
Cargo.toml, so the installer was right; the Mac bundle said 0.3.2 because build-dmg.sh's sed only matched 0.3.0).
Both aligned to 0.3.3; build-dmg.sh now stamps the version with plutil. fetch-ci-artifacts.sh: CONSOLE_SKIP=1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:29:21 +00:00
igneum-labs
63174a5b6a Relay: its own key (relay-key) replaces the intake key for the Mac tools and clients; relay token rotated 4 Oct 2026 (round 4, X23); prove package excludes cross-build folders
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:25:19 +00:00
igneum-labs
3d0c3faa38 Observer autosync: the shared checkout fast-forwards to origin and restarts the observer when its code or the public API changed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:19:12 +00:00
igneum-labs
771e00c3e1 Live page: shards per block (proving v0), three strips on one time axis (blocks, finality bar, proving), observer proof feed, hero glint
Observer (tools/observer/observer.mjs): reads the execution layer's JSON-RPC of a node on the proving build
(IGNEUM_EVM_RPC, default the Mac app's node 26800): every chain block's shard plan as it joins the chain
(igneum_getShardPlan by blockHash, one live_proofs row per shard, planned), the proof records of the chain
blocks of the last 10 minutes polled in rotation (igneum_getProofRecords, four in flight, 40 blocks per tick
while active, 10 before activation): proving (in the pool), verified (SP1 proof verified, or carried and checked
by consensus), paid (a carrying segment paid it), with the prover's id8, the carrier, lag in DAA and the payout.
live_state.proving = {supported, active, activation_daa, tip_daa, verifier, pool, blocks_10m,
blocks_fully_proven_10m, shards_proven_10m, shards_paid_10m, median_proof_lag_s, provers_10m}. A node without
the RPCs gives supported false (rechecked every 5 min); an unreachable endpoint is retried every 20 s. Events:
proving (activation, first paid shard), prover_seen. Additive schema (live_proofs, live_state.proving).

API (site/api/live.mjs): proving, and per block shards: [{i, n, state, prover, lag, payout (IGN), pgas}] and
proven; ?window=N (30 to 300 s) for the page's diagnostic long view; LIVE_TABLE_PREFIX reads a test observer's
tables.

Live page (site/live.html), the design change of 4 Oct 2026: three thin strips sharing one time axis, newest at
the right. BLOCKS keeps the per-miner lanes, chain path, blue/red/pending colouring, arrival glow and tooltips;
the lock ring, dashed lock line and final band leave it. FINALITY is an 18 px bar: ember wash = final (up to the
newest locked checkpoint on screen), molten tick = locked checkpoint, faint = proposed, one label at the newest
lock ("locked #522, 12 s ago"); while finality is not active it reads "finality paused: N% of weight silent" and
nothing else (R4.6.3). PROVING shows one cell per shard under each chain block, outline (planned), molten
(proving), prover colour (verified), tick (paid), a dashed "proofs land N s behind the tip" line, or the one
honest line before activation ("Proving layer: not yet activated on this devnet; activation at DAA N" / "node
without proving"). Header stats: on screen, chain, identities, last lock, proven. Legend: one line per strip.
Hover and tap tooltips on blocks and cells (block, shard, prover, lag, payout). Lanes snap on resize (they used
to ease from a zero-height layout). Phone width, no horizontal scroll; draw 0.6 ms avg, 1 ms max with 110 blocks
on screen (playwright, 1280 px).

Hero (site/index.html): a faint second glint behind a real block once every shard of it is verified, only while
the proving layer is active; pace and sampling untouched.

Verified on the private 3-node proving network (tools/proving-v0/run.mjs --network-only, activation 60) with a
CPU prover loop signing as v0/v1/v2: records relayed, verified on node 0, carried and paid (block 155 by 405,
lag 259 DAA, 0.634 IGN); screenshots in docs/design/live-proving (devnet before activation at 1280 and 375 px,
test network active, the ?window=300 view with paid cells). The live devnet shows the "not yet activated;
activation not set" line once the observer runs this build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 17:39:28 +00:00
igneum-labs
84c64d7aa3 Build and measurement lock for agents on the Mac; the standing rule in CLAUDE.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 16:58:56 +00:00
igneum-labs
3f23df38b7 Packaging for proving v0: the Mac DMG carries igneum-prove-host and igneum-prove-export, the Windows payload carries the Linux host and exporter under wsl2/bin with the WSL2 scripts and the fixtures; the prover probes the shipped WSL2 binaries first and runs helpers by absolute path; push-inputs takes IGNEUM_NODE_SRC; the test script's --network-only mode
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:36:59 +00:00
igneum-labs
9f7fe7ec85 Bench log: proving v0 end to end on the 3-node test network (CPU prover, 150.6 s, three nodes agree on the payout)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:26:41 +00:00
igneum-labs
072e736604 Proving v0: the app's prove setting, Proving tile and Set up hook; spec 7.7 (records, assignment, payout, activation as implemented); proving-v0 plan status; ledger P21 and P22; test script fixes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:09:32 +00:00
igneum-labs
d6d6153c9f Proving v0: payouts in the shard statement (fixture, ShardInput, executor), the empty-segment plan fix, host modes compressed and verify, exporter reads payouts; the app's prover service (src/prover.rs); the 3-node test network script (tools/proving-v0/run.mjs); proving_v0_activation_daa in the fast-time profile
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:06:26 +00:00
igneum-labs
552d5a30c2 Igneum console at the relay URL: Machines, Jobs, Builds, Chain, Work log, Results and the relay as tabs
relay/api/console.mjs reads the log intake (miner_logs) and console_items in Neon, the OTA manifest, the
CI json and the jobs file from the downloads host (DL_TOKEN in the project env, never in the client), and
igneum.network/api/live; 10 s cache per answer. tools/console.mjs: post --kind log|build|note, log, machines,
chain, jobs, builds, results, sync-bench, sync-dl, sync-hetzner, sync, url. The two Mac-side build scripts
post build events. Screenshots at 375 px and desktop in docs/design/console/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:53:33 +00:00
igneum-labs
cdb9b3a734 Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:52:45 +00:00
igneum-labs
5c471eab07 Public API: no peer addresses, no full key hashes, no payout addresses (R4.6.2, R4.6.8)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:47:39 +00:00
igneum-labs
344893ee11 Observer: decoupled ingest, lag metric, per-minute by header time, feed self-check, restart loop
After the 4 Oct 2026 stall (no block stored from 11:57 to 13:15 UTC, then 7,022
blocks in two minutes). Notifications only enqueue; a drain loop handles them
in bounded batches. Block flush, colour marking and certificate work each run
on their own timer and never wait on one another. Mergesets come from the
notification's verbose data (bounded cache); getBlock only on a miss, four at
a time. live_state gains observer_lag_s and queue_depth; the API serves them;
the page shows "observer N s behind" past 30 s instead of waiting for the
first block. blocks_per_minute and blocks_60s are bucketed by the block's own
timestamp and reseeded from the table on start, so a catch-up fills past
minutes instead of painting a spike. If no blockAdded arrives for 60 s while
the node's block_count advances, the observer resubscribes; after two failed
attempts it exits 2 and tools/observer/run.sh restarts it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:26:46 +00:00
igneum-labs
6b72c3b3e6 Fast time: the devnet at 60x for test networks (override-60x.json, --fast-time in both harnesses, proof script)
infra/fast-time/override-60x.json is the devnet with every clock-like consensus parameter divided by 60 and every
block count unchanged (finality window, ban and min_daa 120 DAA; merge depth 60; Kaspa finality depth 720; pruning
depth at the anticone bound 13,838; coinbase maturity 2; the hourly program epoch 60 blocks with a 10-block lead;
the dataset day 24 minutes). The epoch length, lead and day are consensus parameters of the node since devnet-v4
a5ef8b07, carried by the override file. README lists each field, why it scales or not, the flags and the numbers.

Measured (simnet.mjs, three devnet-v4 nodes, three vmine voters at 1 block/s, one real-hash CPU miner): next
epoch seed in the template at 56.1 s, program swap at 65.1 s wall (DAA 60), first finality lock at 185.5 s wall
(checkpoint 5, DAA 149). Both harnesses take --fast-time: finality-attacks s3 PASS in 113 s wall with 16 locks
per node (the devnet rule needs 20 min of warm-up at 6 blocks/s before any lock); harness s3 partition and heal
43 s wall for three cuts against 983 s for four on the devnet profile with the same binary. Bench-log entry.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:34:19 +00:00
igneum-labs
7717c4fdac Windows CI: the one-click app built on GitHub runners, no PC needed
windows.yml: parse job (every .ps1 through the Windows PowerShell 5.1 parser with a negative fixture, PSScriptAnalyzer
as warnings, parenthesis check of every .bat/.cmd with a negative fixture), build job (engine on the MSVC target,
window host through BUILD-APP.bat as it is, payload through make-payload.sh in Git Bash, installer through
build-installer.ps1, smoke run of both exes, launcher DRY_RUN, three artifacts for 90 days).
push-inputs.sh publishes payload-inputs.zip (node, miner, workers, NVRTC DLLs) to the downloads host from the Mac;
fetch-ci-artifacts.sh pulls the green run's installer and payload back into the downloads folder.
Host: --version and --help, version.h shared with host.rc. Launcher: DRY_RUN=1 prints the plan and starts nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:32:20 +00:00
igneum-labs
cbe003e38b tools/prove-fixtures: ignore node_modules
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:32 +00:00
igneum-labs
6671d88a95 Proving host: the setup line splits prover-client creation from the two key setups (ledger P20 gap); simnet export and generator results kept with the fixtures
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:10:26 +00:00
igneum-labs
b64a31c77f Proving fixtures: blocks of one, two and four shards at S_p from a private simnet, plus the v1 cut of the v0 blocks
tools/prove-fixtures: a one-node simnet on ports 29300+ and a generator that lands bursts of equal-sized modexp calls, transfers and Counter increments in one chain block (blocks 338, 341, 344: 0.90, 1.80 and 3.60 S_p). block-56-transfers-3shards is a test cut at 200 pgas for the Mac CPU multi-shard check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:05:05 +00:00
igneum-labs
53f7f55796 Relay: text, files and runnable tasks between the Mac, the PCs and the phone (relay.igneum.network)
New Vercel project igneum-relay from relay/: one function (api/relay.mjs) over Neon tables relay_items and relay_machines,
files in Vercel Blob store igneum-relay (50 MB client uploads, 4 MB through the function), phone-first web page at /r/<token>/
with the site tokens. Mac CLI tools/relay.mjs (feed, read, drop, task, run, watch, inbox, machines, role, name).
Windows clients send.bat/send.ps1 and the igneum-agent (registers hostname, role, GPUs, WSL, nvcc; runs queued PowerShell
scripts, posts results, reboot-continue via scheduled task + RunOnce), bash twins send.sh and agent.sh (verified live),
playbooks for WSL setup, prover setup, prove-block, miner v4, one-click placeholder. make-clients.sh bakes the secrets
into a zip; the repo copies hold placeholders. Screenshots under docs/design/relay.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:04:30 +00:00
igneum-labs
617d3b9682 Live DAG: side blocks carry their GHOSTDAG colour (blue paid, red excluded, pending)
Observer: additive live_blocks.color (pending by default). Every chain block's
mergeset marks its blues blue and its reds red, from the notification's verbose
data or getBlock for chain blocks learned via virtualChainChanged; a reorg puts
the removed chain blocks' mergesets back to pending. API serves color. Page:
blue side blocks filled in the miner's hue at 70% with the ring, pending the
faint outline, red a dark outline with a strike; tooltip and legend name the
state.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:03:28 +00:00
igneum-labs
70bed1065a CI on every push: igneum-pow tests, census build, simulator quick modes, site build + link check, identity grep
GitHub Actions workflow (.github/workflows/ci.yml) on push and pull_request with three jobs on the free runners:
igneum-pow `cargo test --release` and the igneum-census build; the two Python simulators' --quick modes under a
120-second timeout; the site build, an internal link check of site/*.html (tools/ci/link-check.mjs) and a gh-free
identity grep of the public export list (tools/ci/identity-check.sh over tools/ci/forbidden-strings.txt: machine
names, LAN and overlay addresses, home paths, local time zones, the log-intake key pattern; never a key or a name).
The node fork is too big for CI today and the workflow says so.

sim/finality_v2.py --quick is now a genuine smoke run (one day or hour per scenario, one partition and one eclipse
setting): 149 s at nice 19 on a loaded Mac, was 745 s. sim/difficulty/sim.py gains --quick (up50 and warmup-hard,
kaspa and igneum controllers, 36 s). One bench-log time-zone label reworded so the identity grep passes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 09:57:34 +00:00
igneum-labs
5962a655c1 Finality attacks: hostile test network of our own nodes, seven scenarios, bench-log entry
tools/finality-attacks: run.mjs drives a private igneum-devnet-800 network (ports 27800+,
/tmp/igneum-fin-attacks, skip_proof_of_work) with the test-only hostile flags of igneum-miner
(vmine, --equivocate, --sybil, --drop-votes, --pulse, fin-rpc-attack; worktree fin-attacks on
master c6d47547..2a00ff55). Seven scenarios in priority order 3,2,1,6,4,8,5 with a spec 03
criterion and a measured result each; README carries the catalogue, what needs a finality-aware
p2p probe, and a proposed diff for every FAIL.

Results (six voters): S3 dishonest aggregators PASS (35/35/35 locks, 0 conflicts, 1,018 ms);
S2 Sybil dust: weights PASS, aggregator sortition FAIL (per key, ledger F17); S1 equivocation
PASS (2/2/2 stripped, 0 conflicts); S6A 3/3 partition FAIL (floor is time-bounded, one side
crossed 56.7% at 84 s of a 90 s split, T* = 2F/13R, 9.2 days for a 50/50 split at mainnet
scale); S6B 4/2 PASS; S4 vote-dropping producer PASS (0 ms added); S8 malformed votes over
RPC PASS (9 cases, no crash); S5 pulse: no retarget amplification (ratio 0.999) PASS,
lock-alone FAIL (a 20 s burst locked checkpoints 1 to 10 alone on a young window, ledger F1,
spec 3.8 not implemented). S7 eclipse not run.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 23:50:02 +00:00
igneum-labs
72d7bff0ee exec-attacks: execution-layer attack suite (tools + bench log)
Adversarial robustness and conformance tests of the execution layer against a
throwaway 3-node simnet on ports 27600+. Six scenarios, each a runnable command
with a design-derived pass criterion and a measured result: malformed/boundary
txs, nonce games across parallel blocks, RPC fuzz, pgas exhaustion, reorgs under
execution, and developer-registry abuse. 98 checks, 0 failures, 0 node panics.

Two findings filed in the bench-log entry: the mempool admits txs with gas_limit
above B_e (low), and an over-pgas-budget tx is executed natively in full before
being skipped for no fee (medium, griefing).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:57:19 +00:00
igneum-labs
d4cd91f55f Light client v0: the browser verifies the latest certified checkpoint
site/verify/core.js recomputes every header hash (keyed BLAKE2b, the
node's field order), checks the parent links from the previous locked
checkpoint, hashes each voter's G1 key to its vote_key_hash, verifies the
BLS aggregate over "igneum-vote-v1/" || chain_id || 0 || index_le64 ||
checkpoint under the vote tag with the bitmap's keys, and applies Q3
(2/3 of active, 17/30 of total). verify.js drives it from /api/checkpoint
with @noble/hashes 2.4.0 and @noble/curves 2.4.0 pinned from jsdelivr and
fills the homepage card; the badge says LIVE only after a pass in the tab.

site/api/checkpoint.mjs ships the data: certificate bytes, voter table
with public keys, header chain. tools/observer stores every certificate a
block carries (new table live_certificates, voter table read at the lock,
selected-chain headers back to the previous lock, one-off backfill of the
newest lock on start) and keeps header nonces exact; the FinalityLock
write no longer fails on a missing votes_seen.

Tested on the igneum-devnet-7 test network: checkpoint 95 verifies in
Chrome in 103 ms; a flipped signature bit, a dropped voter, an altered key,
an altered header and a removed header all fail with the reason named.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:21:12 +00:00
igneum-labs
87df9eac9d Harness: consensus attack catalogue runner and first results
tools/harness runs the standard consensus-attack catalogue against a private
test network of our own igneumd nodes (127.0.0.1 ports 27200+, /tmp/igneum-harness,
never the live devnet or the PC node), with a pass criterion per scenario from the
spec and a measured result each. Built on the node fork's own crates
(igneum-harness-sim on kaspa_utils::sim as simpa does; igneum-p2p-probe for the
wire). Scenarios: 1 withholding, 2 timestamp edges and drift, 3 partition and heal,
4 eclipse, 5 malformed and boundary inputs on every p2p and RPC surface, 6 resource
exhaustion, 7 fast-miner flood. Finality and difficulty-controller scenarios are
stubs with their criteria written.

bench-log: one dated entry, a row per scenario (criterion, measured, pass or fail).
First run: 19 of 20 measured rows pass. Findings recorded in the entry: scenario 5
reproduces ledger M15 on HEAD (bogus past-day or DAA headers build a 256 MiB cache
before rejection; the r3-fixes branch removes it); scenario 1 at 45% hash with
burst withholding shows a selfish-mining blue-share gain (50.7% of blues), the one
failing row.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:17:37 +00:00
igneum-labs
585a9e7f0c Execution layer devnet v3: implementation notes, bench entry, viem smoke test
docs/design/execution-layer.md section 10: what the execution-layer branch implements
(D1 to D10, RPC, differential), the devnet rules fixed there, what is missing, the merge
plan with the finality branch. docs/bench-log.md: the 3-node simnet run with numbers.
tools/evm-smoke: viem 2.57 smoke test (fund, 50 transfers, duplicates in parallel blocks,
contract deploy and call, state roots across nodes, export for igneum-exec-diff) and the
solc build of DeveloperRegistry and the Counter test contract.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:05:33 +00:00
igneum-labs
51d61f0dca Finality v2: fork reading guide, spec implementation notes, bench entry, observer checkpoints, live page locks
- docs/fork-divergence.md: "Finality v2" table (every file, risk, merge note), decisions
- docs/spec/03-finality.md: section 3.10 implementation notes, clause by clause
- docs/bench-log.md: test-network results (72 of 72 steady locks, median 0.80 s; equivocation
  strip; partition: 0 locks at 39.6% of total with the floor binding, heal in 30 s), follower
- tools/observer: live_checkpoints table, FinalityLock subscription, "checkpoint N locked" events
- site: /api/live adds checkpoints and locked/final flags; /live draws the lock ring and final line

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 21:54:24 +00:00
igneum-labs
9cc195ddec Provenance: credit every borrowed component, upstream merge procedure, prover customer brief
docs/provenance.md: table of every component Igneum uses (origin, licence, what changed, why, how measured), what is new, what to adopt from upstream, own-code licence pending the project lead's decision. Licences verified on disk: rusty-kaspa ISC, chiavdf Apache-2.0, igneum-pow MIT, blake2b_simd MIT, blake3 CC0 or Apache-2.0, sha2 MIT or Apache-2.0, secp256k1 CC0, keccak Apache-2.0 or MIT. RandomX, SP1, revm, blst, ProgPoW, LWMA, Monero, GMP, sha3: approximate, not cloned.
site: litepaper gains the Built on the shoulders section and nav entry; index gains the two-line mention and footer link near the RandomX comparison; the block rate reads one block a second at launch, rising, where it read as permanent (litepaper diagram, index live section).
tools/upstream: README with the exact merge commands, expected conflict files from fork-divergence, the test list and the consensus-review rule; sync-upstream.sh fetches and opens the merge on a branch without committing. Not run against the fork.
docs/commercial/prover-customer-brief.md: one-page brief for a first proving customer at testnet, timeline from journey.json, risks, 10 candidates labelled approximate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 20:02:16 +00:00
igneum-labs
37d87d9420 Docs: the node binary is igneumd; rename table in fork-divergence
Records the 3 Oct 2026 rename pass in vendor/igneum-node (binary, process
name, user agent, data and log paths, env vars, address prefixes, DNS
seeders, default build set) and what stays Kaspa-named internally. The
Windows miner guide and the observer README now start igneumd.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 19:38:35 +00:00
igneum-labs
d93606554a Live devnet: observer, /api/live and the /live page
tools/observer: Node 22 observer on the node's wRPC JSON port (blockAdded and
virtualChainChanged subscriptions, 2 s state ticks) writing live_blocks,
live_state and live_events to Neon, miner address decoded from the coinbase
payload, events for new or quiet miners, peers and difficulty steps.
site/api/live.mjs: three indexed queries, max-age=1.
site/live.html: status strip, DAG stream with real parent edges and a lane per
miner, miners table, events feed, blocks-per-minute sparkline, OFFLINE freeze.
The homepage live path and the /api/live cache header went in with 408c968.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 19:22:06 +00:00
igneum-labs
3095fca303 Add the miner log intake, Windows uploader and Mac reader
POST /api/log stores a log snapshot in Neon table miner_logs over the HTTP SQL
endpoint with no dependencies. upload-log.bat posts the last 256 KB of a log from
Windows with the curl.exe that ships with it. tools/logs.mjs lists runs and prints
the latest lines on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 18:42:32 +00:00