src/driverinstall.rs: RIGHT = ("driver-install-task", ...) for boot-start-22's rights::RIGHTS; register_script = the Power Helper task with a two-hour run limit (no second task, no new firewall rule); the helper's command file takes "<seq> driver <vendor>" with a vendor WORD only, and the elevated helper resolves the file, size, sha256 and Authenticode signer from the signed table itself (Intel Corporation, NVIDIA Corporation or Advanced Micro Devices, and the row's own signer), runs the row's silent arguments with the heartbeat kept (cap 45 min), and writes "<seq> <vendor> exit <code> reboot <0|1>" to driver-result.txt; a restart-required exit is the Restart now button, never a restart by the app. drivers::start_install takes the helper route when the task is registered and keeps the one-prompt path otherwise. Tests known-failed first (the helper knew no driver verb: red on build-2, then green; the refusal of a file that is not the table's or not a vendor's; the right's id and the protocol round trip). Box gate 263 + 34 + 8. Plan 3d is the step as a table for the rights lane.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The Intel row's min_version is 32.0.101.6733 (Windows' inbox driver, on which the worker mines at 11.0 MH/s with the Intel rotate rewrite); 9034 stays the version on offer for a card with no driver. Test known-failed first (the shipped table demanded 9034 of an Arc on 6733; red on build-2, then green). The mock's offer scenario shows an older 6600 so the Install row still renders. Plan 3c: the install path moves onto the app's Power Helper task next; the minidump waits for the same path.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
drivertable::install_hold_keys holds every enabled card of the vendor being installed (the other vendors' cards keep mining; a card already off has nothing to stop); the row says so before the click and while it runs, with the enclosure warning kept on an external row; the toast and the engine's event name the vendor. The x1 gen1 link signature is not on the card state and was not added. Test known-failed first (the 5090 inside the case was not held for an NVIDIA install; red on build-2, then green); box gate 259 + 33 + 8; UI 51.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PC 2, 7 October 2026 18:34 BST: two rows sat on "exporting this hour's program" for 18 minutes while a third card
mined. The export ran on a thread per card under one lock with no bound on the wait, and a result that never came
left the slot in the building state for ever.
- watchdog::export_wait: inside one interval (the ladder rung, at least 30 s) the row keeps its word; past it the row
names what blocks the export; past two intervals the wait ends and the worker retries on its own interval.
- engine: EXPORT_HOLDER names the card whose export holds the pack lock and for how long, EXPORT_LAST_ERROR the last
failure (the node not at the epoch, no seeds.txt); export_blocker() reads them for the row; build_seq ignores a
late result after the wait ended; a failed export retries on the ladder, never a flat five minutes.
- docs/plans/miner-faults.md: MF-14 with rule, test and gate line.
Test known-failed first: an export that never returns is named at one interval and given up at two.
Gates: app tests 260 + 33 + 8 green on igneum-build-2; the tree gate GREEN, 56 checks.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The rule (drivertable::install_hold_keys): a driver install on a card the app reads as external (the eGPU kind from update-return-21b) stops that card's worker before the installer starts, through the cards path with the restore choice kept (the --cards-off shape); the vendor's cards inside the case and every other vendor's card keep mining. The row says so before the click and while it runs (the display reset can take the machine for a minute and may need a restart; save your work first). When the installer ends the held card goes back as it was; a card the install took away comes back when the card does (driver_release_held on the detection that lists it again). The app never restarts the machine.
Tests: the known-failed rule test first (an install on an eGPU card with the worker still running held nothing: red on build-2, then green), the view test for the two sentences; box gate 258 + 33 + 8 (test --release on build-2). Mock scenarios drivers-egpu and drivers-egpu-running; captures 13 to 16 (light and dark). Branch rebased onto release-0.3.21, which already carries the driver-check commits; the earlier tip is kept as driver-check-0320.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Pool-0: welcome carries software_dev_fee_percent beside the pool fee, the page's Fees row and site/miner.html say pool-0 charges the same 1 percent as the solo dev fee; jobs and seeds carry the latency ladder's rung for 0.3.19.
TLS (pool/src/tls.rs): --tls-cert/--tls-key or --tls-self-signed (a P-256 pair under the data dir, the certificate pin printed at start); the binding is the member's BLS signature over this connection's exporter (label EXPORTER-igneum-pool-binding, context the chain id), refused on any other connection; testnet and mainnet refuse the clear without --allow-plain. HiveOS: pools:// and POOL_PIN.
Page rows: node state in words (Q68), one formatter set and luck in MiningPoolStats' convention (Q69), samples and check costs persisted (Q70), payments under the lookup (Q71), hourly history with a sparkline, --alert-webhook, /metrics, /health on the node (Q72), the network's finality state beside "payouts follow blue confirmation, not finality" (Q73).
The open pool (pool/src/sidechain.rs, open.rs, p2p.rs; igneum-pool --open): the member's own node and daemon, no payout key, no balance; every coinbase carries the member's own address, the share chain's parent (IGNS) and the window's split (IGNP); templates re-stamped on a new chain tip without a node call; shares gossiped and checked by every member (structure, the node's seeds, the PoW); heaviest work wins, a fork's loser is stale; the dev fee as one split entry; shares.log and verify-share for the drop proof; the gate harness pool/tools/open-gate.mjs. The node side (the executor's split from pool_split_activation_daa) is on the fork branch pool-finish-node.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 3e5271ba6a)
pm-1, 7 October 2026: the member was idle for four intervals while its worker compiled, the first-phase idle easing
set first_done, and the measured 190 shares a second then walked down one step per 30 s for 5.5 minutes (the share
check at 10 to 11 ms on pool-1's cores). The sized correction now stays owed through idle easings (test
an_idle_easing_does_not_consume_the_sized_first_correction). Section 9.3: 207 found / 144 confirmed / 56 own orphans
under 2f6c0358, the residual as the node's 1 to 1.6 s template latency (a node-lane row), the member findings.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 98bef42ca4)
7 October 2026, 06:01Z and 06:12:55Z on pool-1: confirm_loop restarted its chain walk from the pruning point on any
failed getVirtualChainFromBlock and then fetched every chain block since (about 120,000) over the one connection the
templates used; one timed-out request under four parallel template fetches started it, every template request after it
timed out, no job was issued, 105 blocks on stale templates were orphans. Now: a second GrpcClient (pool.walker) for the
walk and the network numbers; a failed chain call keeps its cursor (the sink only when the node no longer knows it;
cursor_after_failure, node::walk_tests); at most 600 chain blocks per tick with a line saying so; a start with pending
blocks walks from the sink and says that older ones resolve by the orphan rule. docs/plans/pool.md section 9.2: the
re-run's record (the class question closed on pm-1 and pm-2, 71,240 shares, 0 mismatches), the cause, what stays open.
Suite 24 of 24 on igneum-build-1. Protocol and API unchanged.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit bacc407f17)