Commit graph

10 commits

Author SHA1 Message Date
igneum-labs
7eed16a29a Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).

The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.

Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:39:50 +00:00
igneum-labs
847211c7c2 Relay: the X23 tree on master (the signed and tagged run, lib/handler.mjs, guard, the per-machine secret), the start-app kind, the v3 agent as the per-user logon task IgneumRelayService with install-agent.ps1 and the hidden loop, the per-install hostname on registration, the signing tools/relay.mjs so no lane posts an unsigned run (the live relay refuses one since the 7 October 2026 deploy), tools/console.mjs and build-job.mjs on the header tier (X24), the playbooks on RELAY_DL_BASE (X26) and wsl-setup's sudo for apt-get and dpkg only (X28), the new playbooks (start-app, agent-install, pc2-crash-collect, boot-check, freeze-check), and the deploy record with the rollback line (docs/plans/relay-deploy-2026-10-07.md: production igneum-relay-iabqarnby, previous bgy767z40)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 14:47:59 +00:00
igneum-labs
53a4496dd9 Console: the job-channel ping (MF-11, 7 October 2026). Every 0.3.21 app names itself on its wake long-poll (machine, version, last job); /wake records one row per machine in relay_wake_seen before it holds; the Machines tab reads "job channel polled N ago, last job X" and, after 15 minutes without a poll, "job channel silent since <time>, last job X" in red, whatever the uploads say (PC 2 lost power at 10:46Z and nothing said so until a person read the intake). Tests in relay/test/wake.test.mjs.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 14:10:59 +00:00
igneum-labs
0550f58857 relay: /wake long-poll for the apps' remote jobs (public GET held 45 s, authenticated POST of the stamp)
GET /wake?since=<stamp> is public (the apps hold no token) and rate limited (30 a minute per IP). It holds up to
45 s, re-reading the stamp every 2 s, and answers {stamp, at, added, changed, held_ms} the moment the stored stamp
differs from since, else the unchanged stamp at the deadline. POST /r/<token>/wake {stamp, added} (the relay's
auth, also x-relay-token or x-igneum-key on /wake) records a stamp; one row per stamp in relay_wake, created by the
first POST. maxDuration 60 s for api/wake.mjs in vercel.json. api/relay.mjs is untouched.

The handler lives in lib/wake.mjs with its dependencies injected; relay/test/wake.test.mjs drives it with a fake
database, a fake clock and a fake sleep (the hold, the change, the deadline, the rate limit, the hold cap, auth, a
database error). CI's site job runs it with the other relay tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
cda444bbee READMEs: the console's Machines card as it is now (stale, stopped, OTA state, vendors), the parser tests, autosync's restart key and check mode, the observer's dependence on the app's node for proving
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:14:45 +00:00
igneum-labs
63174a5b6a Relay: its own key (relay-key) replaces the intake key for the Mac tools and clients; relay token rotated 4 Oct 2026 (round 4, X23); prove package excludes cross-build folders
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:25:19 +00:00
igneum-labs
1446d012cf Site build: the bench scrub is self-contained Node (runs on Vercel and CI), fails on any private string
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:54:16 +00:00
igneum-labs
552d5a30c2 Igneum console at the relay URL: Machines, Jobs, Builds, Chain, Work log, Results and the relay as tabs
relay/api/console.mjs reads the log intake (miner_logs) and console_items in Neon, the OTA manifest, the
CI json and the jobs file from the downloads host (DL_TOKEN in the project env, never in the client), and
igneum.network/api/live; 10 s cache per answer. tools/console.mjs: post --kind log|build|note, log, machines,
chain, jobs, builds, results, sync-bench, sync-dl, sync-hetzner, sync, url. The two Mac-side build scripts
post build events. Screenshots at 375 px and desktop in docs/design/console/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:53:33 +00:00
igneum-labs
cdb9b3a734 Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:52:45 +00:00
igneum-labs
53f7f55796 Relay: text, files and runnable tasks between the Mac, the PCs and the phone (relay.igneum.network)
New Vercel project igneum-relay from relay/: one function (api/relay.mjs) over Neon tables relay_items and relay_machines,
files in Vercel Blob store igneum-relay (50 MB client uploads, 4 MB through the function), phone-first web page at /r/<token>/
with the site tokens. Mac CLI tools/relay.mjs (feed, read, drop, task, run, watch, inbox, machines, role, name).
Windows clients send.bat/send.ps1 and the igneum-agent (registers hostname, role, GPUs, WSL, nvcc; runs queued PowerShell
scripts, posts results, reboot-continue via scheduled task + RunOnce), bash twins send.sh and agent.sh (verified live),
playbooks for WSL setup, prover setup, prove-block, miner v4, one-click placeholder. make-clients.sh bakes the secrets
into a zip; the repo copies hold placeholders. Screenshots under docs/design/relay.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:04:30 +00:00