Commit graph

243 commits

Author SHA1 Message Date
igneum-labs
0eabca7475 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
e4c76902fa Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 16:30:47 +00:00
igneum-labs
19358aa292 Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 16:28:21 +00:00
igneum-labs
eca6336704 release-0.3.6 plan: why the PC-built Windows node died at start, answered and fixed in the fork (static libstdc++); the stale comments on the Windows DLLs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:26:05 +00:00
igneum-labs
62efb63251 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:24:35 +00:00
igneum-labs
4d0de6d3da Merge txgen: the devnet transaction generator, proving watch, exporter block reconstruction fix with node-plan fixtures, bench log and evidence
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:22:26 +00:00
igneum-labs
fa6bbb0d5f txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
1f4be2f81d Merge testnet-infra: testnet seed profile, DNS and RPC installers, build-job watcher fix, docs/testnet, the go checklist
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:05:16 +00:00
igneum-labs
a2dcd798f6 docs/plans/testnet-go.md: the go checklist with the state of every line at 16:05 UTC, the final genesis, the cost
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:04:09 +00:00
igneum-labs
b23c4fc36b release-0.3.6 plan: the two finality tests under the parallel suite answered (fork 7003055b); build-job.mjs forwards --node-tests, --app-tests, --no-app
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:59 +00:00
igneum-labs
745b69d887 Testnet seeds: debian-13 images (the PC build's glibc 2.39), a glibc check before the upload, the final genesis in docs/testnet/README.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:58:18 +00:00
igneum-labs
81a1337d56 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
dbda6f0884 Merge fud-b: the conceded wording in the litepaper, site and ledger (31 entries)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:45:01 +00:00
igneum-labs
7fe071c41d fud-ledger: evening sweep paragraphs on the 31 conceded wording items, each naming where the honest sentence now lives
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:44:18 +00:00
igneum-labs
2fa4cbccb1 rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:37:02 +00:00
igneum-labs
5f0c78d27d release-0.3.8 plan: the cut, the proving rollout, the first cross-verified shard 2026-10-05 14:08:31 +00:00
igneum-labs
9cd5fe4645 Merge program-id: pinned shard and aggregator guests (elf/ + manifest), fast verify with the pinned key, CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	proving/igneum-prove/host/build.rs
2026-10-05 13:00:54 +00:00
igneum-labs
08bb0dc047 Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
885f2d022f Prover: the 5 October post-root assertion explained (stale build, empty-segment plan), fixture 58927, fixture test, source stamp
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.

The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit ed1cbb0 (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.

So the prover core needs no rule change: the fix is commit ed1cbb0, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:

- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
  statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
  segment's shard ends at the root after the rewards, never the pre-root. With the pre-ed1cbb0 rule put back
  the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
  untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
  printed on the first line of every run, so a stale build names itself in the log instead of in a line
  number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.

The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:50:40 +00:00
igneum-labs
fc8b90f027 Bench log: the first shards proven, verified and paid on the live devnet (5 October 2026)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:54:47 +00:00
igneum-labs
ffae0f47a1 Merge release-0.3.6 plan commits (0.3.7 results)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:36:39 +00:00
igneum-labs
52c82bea7c benchmarks: the vmmap captures carry no local timezone stamp (identity check)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:44 +00:00
igneum-labs
b7ff29b82c release-0.3.6 plan: every reachable machine on 0.3.7 with node state, the open items 2026-10-05 10:31:26 +00:00
igneum-labs
6761b368b5 release-0.3.6 plan: the three Windows machines on 0.3.7 with their nodes up 2026-10-05 10:29:19 +00:00
igneum-labs
8dc734a5cf release-0.3.6 plan: the Mac on 0.3.7 2026-10-05 10:27:46 +00:00
igneum-labs
88fdfa1215 release-0.3.6 plan: the update-now job's run times per machine 2026-10-05 10:27:34 +00:00
igneum-labs
05d16b23f0 release-0.3.6 plan: the jobs file mirrored into the NEXT folder by hand (publish-jobs.sh does not) 2026-10-05 10:22:37 +00:00
igneum-labs
43e7de615f release-0.3.6 plan: the 0.3.7 ship, both manifests compared, the update-now job, the baseline 2026-10-05 10:18:18 +00:00
igneum-labs
4661354b72 release-0.3.6 plan: the 0.3.7 cross-built exes, the -static-libstdc++ result 2026-10-05 10:10:01 +00:00
igneum-labs
88aec377e7 release-0.3.6 plan: the watch's end 2026-10-05 09:59:51 +00:00
igneum-labs
39eee4f54c release-0.3.6 plan: the PC-built Windows node dies at start even with matching DLLs; 0.3.7 ships the Mac cross-build; 0.3.8 open item 2026-10-05 09:56:22 +00:00
igneum-labs
cf002532ec release-0.3.6 plan: the OTA helper logs of the three machines 2026-10-05 09:50:32 +00:00
igneum-labs
ec98276c79 release-0.3.6 plan: PC 2 and the Mac after the publish, the node restart loop on the PCs 2026-10-05 09:50:05 +00:00
igneum-labs
48af50c6f8 release-0.3.6 plan: the 0.3.7 DMG 2026-10-05 09:49:51 +00:00
igneum-labs
4aebea48bd release-0.3.6 plan: section 9, the 0.3.6 Windows runtime incident and the 0.3.7 hotfix 2026-10-05 09:47:12 +00:00
igneum-labs
f3a091fccf release-0.3.6 plan: the machines after the publish, PC 1 first 2026-10-05 09:39:36 +00:00
igneum-labs
405d881a11 release-0.3.6 plan: verify and console steps, the ship's close 2026-10-05 09:35:53 +00:00
igneum-labs
67c7048d2b release-0.3.6 plan: the ship, the live manifest compared field by field 2026-10-05 09:35:31 +00:00
igneum-labs
3d1bd8014d release-0.3.6 plan: PC 1 take 2 binaries and hashes, the PC 2 pair read precisely, the finality test-isolation finding 2026-10-05 09:27:28 +00:00
igneum-labs
80a1c1ebdb release-0.3.6 plan: the DMG hash 2026-10-05 09:19:49 +00:00
igneum-labs
c5e79183a9 release-0.3.6 plan: PC 2 suite result (M30 pow-cache queue under full-suite parallelism), the two follow-up jobs, the DMG with the 0.3.5 prover 2026-10-05 09:19:14 +00:00
igneum-labs
3b20d2bd40 release-0.3.6 plan: the PC 1 build failure (cargo mtime freshness over the persistent target dir), the fix, take 3, the PC 2 suites job 2026-10-05 09:13:59 +00:00
igneum-labs
d46c64fc34 release-0.3.6 plan: section 8, the cut (merges, changes, tests, secrets, binaries, digest, live manifest) 2026-10-05 08:53:28 +00:00
igneum-labs
20bf44cdbb Merge rotation-2 (d5986d2) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
b63913f26c Merge proving-app (253fb15) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 68a3d50), tile shows the verifier 2026-10-05 08:33:13 +00:00
igneum-labs
df1064f63d Merge origin/testnet-adopt (2267d95) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
cd8d816727 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
253fb151a7 docs: release 0.3.6 done notes for the app-side proving items
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
2267d95eb9 release-0.3.6 plan: the fork results, miner-latency in after its three gates, the release dev-fee address
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:00 +00:00
igneum-labs
7be9ad661c docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:45:45 +00:00