Commit graph

149 commits

Author SHA1 Message Date
igneum-labs
0f3b23d7a7 Counter ASIC 3.0 items 6 and 7: proposed reserve order and spec text (docs/plans/counter-asic-3-reserve.md), the vendor-share section on the benchmark page, the observer README row 2026-10-06 07:40:41 +00:00
igneum-labs
42abffe015 Counter ASIC 3.0 items 6 and 7: tools/observer/vendor-share.mjs (fleet-reported and chain-attributed hash rate by vendor), node:test on fabricated rows, one 60-s hook and live_state.vendor_share in the observer 2026-10-06 07:36:46 +00:00
igneum-labs
ea141f2a94 Counter ASIC 3.0 items 6 and 7: family step-cost probes (Metal, CUDA), the PC 2 playbook, the M5 Max rows in the bench-log 2026-10-06 07:36:12 +00:00
igneum-labs
d3b44141d1 prover-floor: the three other PC 2 scripts test their kit file before the first use (C32)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:06:38 +00:00
igneum-labs
34b2fa0ff6 prover-floor: pc2-floor-sweep3-miner.ps1 tests its kit file before the first use (the kit-path check, C32)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:04:52 +00:00
igneum-labs
0059f12c98 Merge prover-floor (8e2686d) into release-0.3.11: docs and standalone probe sources the evidence rows cite (C38); nothing a built artefact reads 2026-10-05 23:03:46 +00:00
igneum-labs
b584e41e31 CI on the merged 0.3.11 tree: MacBook reworded in the analysis prose (the identity check's hostname pattern), a presence check before the kit's first use in the three proving-v1 PC 2 scripts (C32), pc1-cpu-prove.ps1 on the socket check's allow list (the CPU path starts no GPU server)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:44:09 +00:00
igneum-labs
8e2686d008 Prover floor: the beside-the-miner sweep playbook (sweep 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:42:31 +00:00
igneum-labs
830efc63e1 Prover floor patch v2: every trace buffer sized to its padded need (setup keys and shards), the sweep-2 points
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:41:37 +00:00
igneum-labs
8ad50d119b Merge branch 'bash-body-check' into release-0.3.11
# Conflicts:
#	.github/workflows/ci.yml
#	tools/ci/prover-socket-check.sh
2026-10-05 22:40:22 +00:00
igneum-labs
75a56182b2 Merge commit 'a2f08e3' into release-0.3.11
# Conflicts:
#	docs/bench-log.md
#	docs/evidence.md
#	site/litepaper.html
2026-10-05 22:39:34 +00:00
igneum-labs
629157b388 Merge branch 'ca2-coord' into release-0.3.11
# Conflicts:
#	docs/bench-log.md
2026-10-05 22:39:12 +00:00
igneum-labs
b2e6d6159e CI: run jobs test their fetched kit before use (the wiped-jobs-folder class)
The app's install clears the jobs folder on a PC, so a run job whose kit was fetched by an earlier fetch job finds
nothing after an update and fails in seconds (5 October 2026, 21:49Z, the AMD kit; bench-log 4df339f). Rule: a run
playbook that reaches a path under the jobs folder other than its own tests the kit is there before its first use,
and the fetch is republished under a new id after any app update.

tools/ci/kit-path-check.sh reads every *.ps1 under relay/playbooks/ and tools/. A kit root is a path derived from
the jobs folder (`$jobs = Split-Path $env:IGNEUM_JOB_DIR` then `Join-Path $jobs '<fetch id>'`, the race-5090.ps1
shape) or one carrying a literal `jobs\` (the amd-card-test.ps1 shape); every path built from it belongs to that kit.
A presence check (Test-Path, [IO.File]::Exists, [IO.Directory]::Exists, Get-Item or Get-ChildItem with -ErrorAction)
on the root or anything under it covers the whole kit. A use before that line fails with "kit path used before a
presence check: republish the fetch after any app update", as does a literal jobs\ path in a command with no check.
The job's own folder ($env:IGNEUM_JOB_DIR) is not a kit path.

Fixtures: kit-path-ok.ps1 (both shapes, checked; a sibling pack file covered by the worker's check) and
kit-path-unchecked.ps1 (the worker run before its check, a literal never checked); --self-test asserts the lines.
Wired into ci.yml after the bash-body step, and into publish-jobs.sh add --kind run beside the other two checks;
test-publish-jobs.sh gains the refusal (34 passed, 0 failed). The current tree: race-5090.ps1 is the one playbook
with a kit, checked before use. README-ship.md: the rule.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:37:29 +00:00
igneum-labs
19b30e31f0 Merge remote-tracking branch 'origin/master' into ca2-v3
# Conflicts:
#	docs/bench-log.md
#	proto-opencl/host.c
2026-10-05 22:34:07 +00:00
igneum-labs
393a8f831f Prover floor: the build recipe as it ran (Go pinned, the binary's sha256 and targets), the RISC Zero contingency figures with their source, playbook fixes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:33:31 +00:00
igneum-labs
2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
igneum-labs
1402989cdd Prover floor: SP1 6.8.1 GPU server memory model from source (the 24 GB panic, the threshold-sized trace buffers), the floor patch for sp1-gpu, the PC 2 toolchain, build and sweep playbooks
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:11:24 +00:00
igneum-labs
c4da08d302 App: the resume path re-arms every stopped card, re-exports its pack and checks 90 s later that every enabled card mines (PC 2 at 21:25:11Z and the Mac that afternoon stayed at 0 MH/s after resume); the PC 2 socket-fix job
The known-failed case, from PC 2's 0.3.9 log (run win-1ccfe586-20261005-200114): 1791234223 pause -> 'stopping the
miners (paused)' (every slot's restart_at cleared, the 5090 'off'); 1791235511 '[ok] mining resumed'; then
'0.00 MH/s, waiting' at every 30-s status line until the 0.3.10 restart at 21:49:41Z. Cause: Cmd::Resume re-armed
only slots whose watchdog said faulted; the 5090's slot was healthy and stopped, so nothing restarted it. The test
the_pc2_resume_of_21_25_11z_restarts_under_the_new_rule_and_not_the_old encodes that slot (faulted false, live
false): the old rule returns [] (the defect), the new rule [0]. cargo test -p igneum-app resume: 3 passed;
provedefault: 6 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:56:20 +00:00
igneum-labs
a5533177d3 CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class)
Twice on 5 October 2026 a PowerShell job script carried a bash body inside a string, a quote was lost on the way
through PowerShell, and bash refused the body: pc1-cpu-prove.ps1 (first version) reported exit 0 having done
nothing, the 0.3.10 installer job failed in 4 s. tools/amd-prove/check-job-bash.sh covered only its own here-string.

tools/ci/bash-body-check.sh reads every *.ps1 under relay/playbooks/ and tools/, finds each bash body however it is
handed over (bash -c "...", bash -lc '...', bash -c $var, a + concatenation in parentheses, the Start-Process argument
list, a here-string written to a file that is later run with bash), unescapes it the way PowerShell would (backtick
escapes and "" in double-quoted strings, '' in single-quoted strings, here-strings verbatim; $var left as-is, a $(...)
subexpression replaced by ${PS_SUBEXPR}), and runs bash -n on it. One line per body with the file line of the error.
A body it sees but cannot read is "unextractable body" and fails too: a skip would be a hole in the class check.
bash 3.2 compatible; python3 for the extractor.

--self-test runs three fixtures under tools/ci/fixtures/: the correct shapes (8 bodies, must pass), the lost quotes
(the awk apostrophe, a dropped closing quote in a literal and in a variable; must fail with the line), and three
unreadable bodies (must fail). Wired into ci.yml next to the copied-sources check, self-test first. The current tree:
7 inline bodies in 3 playbooks, all parse. packaging/README-ship.md: the job-script rule (body to a file, bash <file>).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:38:41 +00:00
igneum-labs
54132959be Merge origin/master (the explorer pages, the public API check, the CLAUDE.md note) into release-0.3.10; docs, site, observer and ci.yml only 2026-10-05 21:32:17 +00:00
igneum-labs
36c5f13a5f fast-time: the proving v1 fields and pow_genesis_dataset_log2 in both override files (the fork's every-field test), README rows; class-v3.mjs reports the build time per epoch; docs/plans/counter-asic-2-node.md (the node side of Counter ASIC 2.0, gate result pending)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:04:39 +00:00
igneum-labs
ffa2633845 docs/analysis/amd-proving.md: no zkVM proves on AMD (SP1, RISC Zero, Jolt, OpenVM, ICICLE cited), the SP1 CPU prover measured on PC 1 beside the miners (282 s a shard at any size, 30 GB RSS: no CPU tier), the tier consequences and the public line; PC 1 job scripts with the bash -n gate; bench-log entry
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:02:59 +00:00
igneum-labs
28635b165f Metal worker compiles a class v3 program from the pack a prepare line names; igneum-pow chain_dataset_day seam; pow_genesis_dataset_log2 in the override files
main.swift: servePackProgram reads program.h with the packfile.h checks (generator 2 or 3, the class line against
the generator, the seed bytes, IGNEUM_SEEDW_INIT against attempt_words, class and era against the line) and
compiles program_bound.metal; the program store keys on (seed, class, era); a v3 job with no resident v3 pack
program answers need + error; v2 lines unchanged (Swift generation, the variant race); a pack program never races.
verify.rs: Epoch::chain_dataset_day(day, class, days_since_genesis, genesis_dataset_log2) and days_since_genesis,
the entry the node builds every day cache through (the ca2-mixer growth rule fills the body).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:51:24 +00:00
igneum-labs
574cccd456 fast-time: program_class_v3_activation_daa in both override files (never), the README row, and class-v3.mjs, the rollout gate G4 script
class-v3.mjs: a 3-node private network (ports 29600 and up, igneum-devnet-960) on override-60x.json merged with
a CPU genesis difficulty (0x1f010000) and the class switch a few epochs ahead (default 150: inside epoch 2 at
60 DAA per epoch, so the switch rounds up to epoch 3 at DAA 180); one real CPU miner per node; reports blocks on
each side of the boundary, the class and program id of every epoch, rejected blocks (miners and nodes), the
sinks and block counts of every node, and every node's switch line; exit 0 when every check passes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:40:30 +00:00
igneum-labs
344cba8e8c Proving v1: the memory sweep and the miner-on peaks, the root-socket class fix (cleanup lines, tools/ci/prover-socket-check.sh in CI), the host's --budget re-plan and the S_p curve job, the RAM and aggregation-card gates, N = 8 in the fast-time file and spec 7.4
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:35:13 +00:00
igneum-labs
d4848453ae Proving v1: the chain of 8 on the 5090 measured (N = 2, 4, 8: 32.6, 66.8, 135.6 s; chained aggregation 9.7 s a block on a mining card), the fleet table re-cut on the measured rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
470b6a884f pc2-chain.ps1: the export goes through curl.exe to a file (Invoke-WebRequest's Content is a string; the first run failed on WriteAllBytes)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
3fcf4f705c Proving v1: the harness passes (21 checks), the bench-log entry with the step 1 GPU memory, RAM and SM-target numbers, the CPU chain of 2 and verify-segment
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
55ea10cc26 Proving v1: prover on by default, the aggregated segment record, host modes chain, aggregate and verify-segment, the app's aggregator step, spec 7.8, the fast-time harness and the coverage tool
Step 1: app/igneum-app/src/provedefault.rs decides once per install (NVIDIA 12 GB or more, WSL2 answering on
Windows, Linux native, Apple silicon off until measured), never switching an explicit on back off; the Settings
switch line and the tile line say why (5 unit tests). tools/proving-v1/pc2-prover-cost.ps1 is the PC 2 job
(5 min mining alone, 5 min with the prover, GPU memory and host RAM peaks, the sp1-gpu-server's SM targets).

Step 2: the host gains --mode chain (consecutive fixtures, each block aggregated with the previous block's
proof by recursion), --mode aggregate (the live aggregator over shard proof files, a run of blocks in one
process) and --mode verify-segment (the node's verifier against the pinned aggregator key); the app's prover
loop gains aggregate_once (spec 7.8). Eight consecutive live fixtures (blocks 81046 to 81053, node 1's export
at tip 81076) under proving/fixtures/chain/. tools/proving-v1/pc2-chain.ps1 is the PC 2 job (held).

Steps 3 and 4: tools/proving-v1/coverage.mjs (the proven-block share and the on-chain latency from one node's
RPC), tools/proving-v1/net.mjs (the fast-time 3-node harness on 29950+ with the known-finished and
known-failed cases of the chain rule and the unproven rule), the four proving_v1 fields in
infra/fast-time/override-60x.json. Spec 7.8, the 7.4 rows, the 5.3 sentence, docs/plans/proving-v1.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:04 +00:00
igneum-labs
84d6d28253 Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI
Fed by /api/explorer from the observer's tables. Latest blocks (hash, number, DAA, blue score, miner, txs, proof
records, time); a block's header, parents, children, mergeset, coinbase outputs, EVM transactions, shards, checkpoint
and certificate; an address's blocks, what they earned, vote keys and balance (eth_getBalance when EXPLORER_EVM_RPC is
set). Same tokens as live.html. vercel.json rewrites /block/:id and /address/:addr; the footer links the explorer; the
link checker skips template literals and resolves /api/<name> to its function. node tools/site-serve.mjs previews the
site with the functions in-process.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
48d987cfb4 Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check
The numbers profitability sites and pool software read (WhatToMine's form: explorer or pool with an API, the halving
schedule, a source for total coins). Reward and supply from the emission rule at the node's DAA score; the halving table
(33 rows), the 30-day ramp and the observer's coinbase check. Cached 10 s, CORS open. FIELDS in each handler is the
contract; public-stats.test.mjs checks it from a fixture, tools/ci/public-api-check.mjs checks a deployment.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
8ffcdd2182 Observer: explorer detail per block from the notification, chain block number from the shard plan, RPC load counter, hourly coinbase check against spec 2.5
site/lib/emission.mjs is the emission rule as igneum.rs computes it (block_subsidy, launch_ramp, an exact floor-sum for
minted-so-far); its tests reproduce the node's own test values and a devnet coinbase (block 2622db76: payload 454,486,399
at DAA 125,064, outputs 454,485,299 = E(125,063), what the merged parent declared). Every live_blocks row gains tx_count,
evm_miner (the IGNA tag, else the vote key's low 20 bytes), proof_records (IGNP section), subsidy_sompi, paid_sompi,
selected_parent, number, detail. No extra RPC per block: measured 282 against 283 wRPC and 785 against 776 EVM calls
per minute before and after. live_state.rpc_load and live_state.supply_check are new.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
18f244bcfb Merge miner-ui-2 (6acfaed) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
cbe031b39c Merge gpu-hotplug (bd21f2a) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
b36beeee5d Merge gpu-hotplug (bd21f2a) into release-0.3.10: cards re-enumerated every minute and on WM_DEVICECHANGE, one row per physical GPU, Code 43 cards marked, integrated GPUs off by default, the cards line in the console 2026-10-05 18:21:07 +00:00
igneum-labs
d905730d45 Merge c4-fix (3e129ee) into release-0.3.10: the certificate-driven reorg in spec 3.5, 3.2, 3.10, 3.11.7, ledger C4, bench-log; c4.mjs v2 mode; the signer never piped into head (signer-pipe-check); one build-inputs zip per job
# Conflicts:
#	docs/bench-log.md
2026-10-05 18:20:50 +00:00
igneum-labs
3e129eeb5c C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning)
Fork: vendor/igneum-node-c4 branch c4-fix on release-0.3.6 a24ab01a.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:17:36 +00:00
igneum-labs
948e20f2d0 Merge tx-gossip (fe635ed) into release-0.3.10: the EVM relay design note, rows 463 and 9 closed, the 3-node relay harness and its evidence 2026-10-05 18:00:03 +00:00
igneum-labs
135f67ab2a Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 17:55:57 +00:00
igneum-labs
fe635edcfb EVM transaction relay: design doc 1.4 "Relay", rows 463 and 9 closed, bench-log entry, 3-node relay harness
Fork tx-gossip e242acd0 adds the inventory relay of EVM transactions (protocol version 14) and replaces the
4-second hand-out cooldown with the hold on block-added. Here: the relay paragraph in execution-layer.md 1.4,
the 10.2 table row (hand-out cooldown, now the block-added hold) and 10.3 item 9 updated, the bench-log entry
with the PC 2 suites (igneum-exec 15 of 15, kaspa-p2p-flows 33 of 33), the digest check (unchanged,
9409dedac4bf...) and the 3-node fast-time run (A - B - C, generator on A at 2/s: 240 of 240 included, B 151
and C 105 over two hops, p50 1.5 s, 0 skipped copies, pools equal on all three nodes at every sample), the
result JSON under docs/benchmarks/evm-relay-2026-10-05/, and tools/txgen/relay-net.mjs (the harness: three
nodes in a chain on the fast-time profile, vmine on B and C paid to throwaway keys, txgen on A, inclusion
counted by miner from A's executed chain).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:53:07 +00:00
igneum-labs
d7049fdfda app: GPU hot-plug (re-detection every minute, WM_DEVICECHANGE on Windows), faulty cards listed with the problem code, integrated GPUs off by default, the card list in the console
5 October 2026: an RX 9070 XT went into PC 1 through a Sonnet USB4 box while the app ran and nothing noticed; the
app detected cards once at start. Now src/hotplug.rs compares every enumeration with the list (key, else vendor +
name when unique; a card whose tool did not answer is never called removed): a new usable card starts a worker,
enabled by default like a card at start, with "New card: <name>, mining" on the strip and in the log; a card
Windows lists with a problem code (Win32_VideoController Status / ConfigManagerErrorCode) is shown as "<name>: not
usable (Code 43)" with the reboot-or-reinstall hint and no worker; a card that disappears has its worker stopped
(quit, 8 s) and its row says removed for five minutes, then hides; an unchanged list touches nothing. The Windows
host sends "detect" on WM_DEVICECHANGE; the engine polls every 60 s (300 s on macOS, no GPU hot-plug there).

detect.rs: the Ryzen iGPU is "gfx1036" to the OpenCL worker, so the APU gfx codes count as integrated, plus the
adapter row's Intel processor string and a dedicated memory under 1 GB; integrated defaults to off with "integrated
GPU, off by default (2 to 3 MH/s for 30 W)" on the row, and the user's choice is kept across re-detections and
restarts (settings, found by key or by vendor + name when the index moved).

Console: the engine logs "cards: <name> [<kind>, <state>] | ..." at start, on every change and every 10 minutes;
relay/lib/parse.mjs reads it and the hot-plug events, the machines API and tools/console.mjs machines show them.

Tests: hotplug.rs (added, removed, moved, errored, recovered, revived, unchanged, twins, user override kept,
the console line), detect.rs (PC 1's adapter lines, the Mac, kind classification, the unusable row),
notices.test.mjs (card notices), relay parse.test.mjs (cards line). cargo test -p igneum-app: 91 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:45:05 +00:00
igneum-labs
7d09857f91 observer: a watchdog forces a reconnect after ten failed ticks (the live page went stale for an hour after a node restart)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:22:22 +00:00
igneum-labs
a96bcea470 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
addeb660fd Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
8b4b1e500a Merge origin/master (974805b) into release-0.3.9: fud-a round 6, the entity imprint, the conflict-marker check; docs/bench-log.md both entries, the site taken from master and rebuilt (519 links, 0 broken) 2026-10-05 16:48:00 +00:00
igneum-labs
974805b9df ci: no conflict markers in tracked files (check + pre-push hook that also builds the site)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:45:09 +00:00
igneum-labs
ee7cfa9c27 Merge entity: Igneum Labs LTD and the DIFC address as the entity and contact everywhere, repository public at the public testnet, ledger published with it, no team page
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/fud-ledger.md
#	site/bench.html
#	site/index.html
#	site/journey.json
2026-10-05 16:42:40 +00:00
igneum-labs
02b19ed761 Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
8703d9e731 Merge fud-a: ledger sweep round 6 (11 fixes closed with rollout evidence, M1/M11/M16/M21/P3/P9/P14/X5 measured, C4 finding, F16 options)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/bench-log.md
2026-10-05 16:33:15 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00