tools/scene/parity.mjs serves site/ (tools/site-serve.mjs) and the app's UI (tools/ui-mock/server.mjs) on a build box, answers
every page's /api/live from scene/fixtures/live-2026-10-07.json, freezes the clock at the fixture's instant (Date, timers,
requestAnimationFrame) and reads each scene canvas at 900 by 420 px at the first push and the next two polls: the read is the
push's own synchronous paint, so a frame depends on the fake time alone, never on how long a fetch took. Known-failed first: the
app with --included moved by one unit must differ from /live at every instant (it does: 1,549 / 1,282 / 1,157 px). Then home
fold = /live, app Inspect = /live, app with this machine's key = /live with the same key (the overlay is the same picture), and
the app's overlay frame differs from its base frame (the overlay is drawn). The compact card is rendered and reported, not
compared. A RED line names the differing pixels and their box. tools/scene/parity-remote.sh carries the files to the box
(~/.config/igneum/build-server-2 by default) under this lane's prefix and runs it there; a plain CI runner with no box and no
Playwright prints a skip line. One new line in tools/ci/pre-push.sh.
First run on build-2 at 15:4x UK, release-0.3.21 tree plus scene-parity: every comparison equal at T+0, T+2 and T+4 s.
Found on the way and fixed in the harness, not the renderer: lane order keeps the history of earlier layouts (the scene must be
at the compared size before its first layout); the app's recorded mock card is a real devnet key (cleared for the base case).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 4102c935e518e83eba39d880daad1a57b77c3bf8)
The drift the app carried against the site's home fold and /live, and what moved:
- renderer: both were 2.0.2 byte for byte; the app now takes the shared scene/live-dag.js 2.0.3 (paint on push whatever the
document's visibility says: the blank /live; the phone rule on the viewport width) and proof-core.js through tools/scene/sync.mjs,
and the gate refuses a drifted copy.
- palette: the dark tokens were equal; the light theme's --ember was #E04A14 and --ember-hi #F2541B against the brand package's
#D0420D / #E04A14. The fourteen scene tokens now sit in the scene-tokens block app.css takes from scene/tokens.css (dark,
[data-theme="light"], prefers-color-scheme light) and are defined nowhere else in the file.
- phone rule: the app passed narrow: window.innerWidth < 720 at mount time and never again; the site keyed it on the canvas
width (a 640 px hero on a laptop rendered as a phone). Both now leave it to the renderer: the viewport, live on resize.
- feed window: the app asked the engine for 120 s, the site 300 s; both 300 now, so the viewer can pan the same range.
- Inspect view: 360 px tall against /live's 420 (five lanes against seven); 420 now.
- feed shape: the engine rewrote this machine's blocks to miner: "you" (a word the observer never emits) and its node-only
fallback carried now as a float of seconds, rows with timestamp_ms / is_chain_block / vote_key_hash / timestamp_source and no
number or rx, miners as {id, vote_key_hash, blocks_10m}, no proving, a finality with checkpoints alone. live.rs now passes the
observer's rows through untouched (state.you_blocks counts them; the UI's mine function marks the lane from the card ids, which
is the overlay: own blocks glow, the lane reads YOUR KEY) and node_only_reply builds the fallback in the contract's shape
(every key of scene/feed-contract.json, null where the node cannot know, partial: true, state.source "node", ISO now). The
test the_node_only_reply_has_the_contract_shape reads the contract file itself (include_str!), so the Rust side and
tools/scene/feed-contract.mjs cannot drift.
App gate on build-2 (test --release, --priority gate): 228 + 32 + 8 passed. Parity on build-2: app Inspect = /live = home fold
at T+0, T+2, T+4 s, the overlay identical when both surfaces know the key.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The blank /live (the project lead, 14:3x UK): IgneumDag 2.0.2 painted only from a requestAnimationFrame loop gated on document.hidden and
the IntersectionObserver, so a page that loaded with document.hidden true (the desktop pane, a background tab) and whose embedder
never fired visibilitychange took every push, reported live and never drew a frame. 2.0.3 paints the current picture synchronously
on push, size and theme change; the motion loop alone waits for a visible document and an intersecting canvas. Confirmed headless
on build-2 against the live feed: hidden document 0 lit pixels before, 110,007 after; the never-intersecting observer repaints
on every push. Known-failed test tools/scene/paint-test.cjs (the 2.0.2 renderer draws nothing in the same world).
The second 2.0.3 change: the phone rule (30 s window, four lanes) keys on the viewport width, not the canvas width; a 640 px hero
on a 1,440 px laptop was rendering as a phone while the app's card beside it was not.
scene/ is the one source: live-dag.js, proof-core.js, tokens.css (the fourteen palette tokens, the brand package's values, dark and
light), feed-contract.md and .json (one JSON shape for the observer's /api/live and the app's api/live), a recorded reply as the
fixture. tools/scene/sync.mjs writes the copies and the scene-tokens block into site.css and app.css; --check is the gate line
(byte-equal scripts, an equal block, the names defined nowhere else, a print block excepted), --self-test fails five known cases
first. The site's token definitions move out of the package's :root line into the block; no value changes on the site.
tools/scene/feed-contract.mjs validates a reply against the key lists; its test refuses a miner rewritten to "you", a float now,
a stray key. Three new lines in tools/ci/pre-push.sh. The app side (branch scene-parity, for 0.3.21) takes the same folder.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit f774353461)
A node before the exec RPC bounds fix (every 0.3.17 node) dies when a method that resolves a block number or indexes the record vector is asked while its exec follower holds no record; PC 1 crash-looped on two callers in one night (eth_getBlockByNumber from the clock sample, then igneum_getAssignedShards from the prover loop: 'panicked at igneum/exec/src/rpc.rs:808:35: range start index 1 out of range for slice of length 0'). Every caller (prover.rs's evm_rpc, update.rs's clock sample, extnode's rpc for chainfacts and the external-node probe) now goes through execrpc::call: SAFE_ON_EMPTY methods go out, GATED ones wait for igneum_getExecStatus's executedTipHash, an unclassified method is refused. The test every_caller_goes_through_the_gate scans src/ for JSON-RPC requests built elsewhere and for unclassified exec method names.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/miner-faults.md: MF-1 to MF-7, each with its rule, test and gate line.
- MF-1/MF-2: a worker starts and is judged only when the node is READY (synced and igneum_getExecStatus reports an
executed tip; execrpc::probe every 5 s off the engine thread); the node watchdog never counts the catch-up (settled
once read synced; 30 min cap before that; any RPC answer is a sign of life); the watchdog restarts on a ladder 10 s,
30 s, 2 min, 5 min, then every 5 min for ever (watchdog::RETRY_LADDER_S); the faulted state and the one-restart
budget are gone (tools/ci/permanent-fault-check.sh in the gate); a node-caused restart resets the ladder at sync.
- MF-3: the hot-plug pass starts a recovered or revived card's worker (unchanged rule, now in the register).
- MF-4: the status clock starts at ready (program loaded), loading bounded by 300 s; a self-test failure holds the
card 30 min with the reason on its row, released on a driver change; a crash loop climbs the ladder; the pack is
exported once a minute for every card (a refused pack forces one).
- MF-5: the app reads template_wait=, template_ms=, identities_active= from the 0.3.20 miner's STATUS; waiting on
the node is never the card's fault; the row says node slow; every node-wait label clears on the first rate.
- MF-6: a miners hold belongs to the job that took it and releases when that job is gone or at its own cap.
- MF-7: the engine owns every igneum-miner it started: an untracked one on this engine's node RPC is killed at start,
after every stop and every minute, one line and one fault report per kill; a restart kills the old process first.
- Every fault line posts one FAULT line to the log intake (label fault-<id8>, app and node version, 60/h cap).
- The signed cards job kind (per card enabled, identities, power_pct; refused for a card the machine lacks; applied
through the app's own card path, persisted, read back): packaging/ota/publish-jobs.sh add --kind cards.
- LG-4 as a job: relay/playbooks/first-share.ps1 and tools/fleet/first-share-gate.mjs (no Windows box yet).
- tools/reliability: the fault injector with one step per class (catch-up, card-appears, own-restart, zero-ladder,
no-status, node-silent, one-card-fails, orphan-miner); fake-worker.mjs lists devices and fails self-tests on command.
- master's build tooling (97255a4e) and release-0.3.20's igneum-pow taken into the worktree for the box routes.
Box: app 198 + 27 + 8 tests green on igneum-build-2; the tree gate green (33 checks).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>