Observer (tools/observer/observer.mjs): reads the execution layer's JSON-RPC of a node on the proving build
(IGNEUM_EVM_RPC, default the Mac app's node 26800): every chain block's shard plan as it joins the chain
(igneum_getShardPlan by blockHash, one live_proofs row per shard, planned), the proof records of the chain
blocks of the last 10 minutes polled in rotation (igneum_getProofRecords, four in flight, 40 blocks per tick
while active, 10 before activation): proving (in the pool), verified (SP1 proof verified, or carried and checked
by consensus), paid (a carrying segment paid it), with the prover's id8, the carrier, lag in DAA and the payout.
live_state.proving = {supported, active, activation_daa, tip_daa, verifier, pool, blocks_10m,
blocks_fully_proven_10m, shards_proven_10m, shards_paid_10m, median_proof_lag_s, provers_10m}. A node without
the RPCs gives supported false (rechecked every 5 min); an unreachable endpoint is retried every 20 s. Events:
proving (activation, first paid shard), prover_seen. Additive schema (live_proofs, live_state.proving).
API (site/api/live.mjs): proving, and per block shards: [{i, n, state, prover, lag, payout (IGN), pgas}] and
proven; ?window=N (30 to 300 s) for the page's diagnostic long view; LIVE_TABLE_PREFIX reads a test observer's
tables.
Live page (site/live.html), the design change of 4 Oct 2026: three thin strips sharing one time axis, newest at
the right. BLOCKS keeps the per-miner lanes, chain path, blue/red/pending colouring, arrival glow and tooltips;
the lock ring, dashed lock line and final band leave it. FINALITY is an 18 px bar: ember wash = final (up to the
newest locked checkpoint on screen), molten tick = locked checkpoint, faint = proposed, one label at the newest
lock ("locked #522, 12 s ago"); while finality is not active it reads "finality paused: N% of weight silent" and
nothing else (R4.6.3). PROVING shows one cell per shard under each chain block, outline (planned), molten
(proving), prover colour (verified), tick (paid), a dashed "proofs land N s behind the tip" line, or the one
honest line before activation ("Proving layer: not yet activated on this devnet; activation at DAA N" / "node
without proving"). Header stats: on screen, chain, identities, last lock, proven. Legend: one line per strip.
Hover and tap tooltips on blocks and cells (block, shard, prover, lag, payout). Lanes snap on resize (they used
to ease from a zero-height layout). Phone width, no horizontal scroll; draw 0.6 ms avg, 1 ms max with 110 blocks
on screen (playwright, 1280 px).
Hero (site/index.html): a faint second glint behind a real block once every shard of it is verified, only while
the proving layer is active; pace and sampling untouched.
Verified on the private 3-node proving network (tools/proving-v0/run.mjs --network-only, activation 60) with a
CPU prover loop signing as v0/v1/v2: records relayed, verified on node 0, carried and paid (block 155 by 405,
lag 259 DAA, 0.634 IGN); screenshots in docs/design/live-proving (devnet before activation at 1280 and 375 px,
test network active, the ?window=300 view with paid cells). The live devnet shows the "not yet activated;
activation not set" line once the observer runs this build.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
make-icons.py make_social(): og-small.png (256 square, the compact card index/live/litepaper declare), og-square.png
(1024), og-coin.png and og.png (1200x630: mark left, IGNEUM wordmark, tagline, subline; same layout as before, no ring,
no glow). bench.html, evidence.html and build.mjs referenced /og.png, which did not exist; they now get the 1200x630 card
with width/height 1200x630 and twitter:card summary_large_image. Every og:image and twitter:image carries ?v=2 so
Slack, X and iMessage refetch. brand/profile: github-social-1280x640.png (repository social preview) and
vercel-avatar-512.png. bench.html edited by hand for the meta only (a build.mjs run would publish uncommitted log entries).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
After the 4 Oct 2026 stall (no block stored from 11:57 to 13:15 UTC, then 7,022
blocks in two minutes). Notifications only enqueue; a drain loop handles them
in bounded batches. Block flush, colour marking and certificate work each run
on their own timer and never wait on one another. Mergesets come from the
notification's verbose data (bounded cache); getBlock only on a miss, four at
a time. live_state gains observer_lag_s and queue_depth; the API serves them;
the page shows "observer N s behind" past 30 s instead of waiting for the
first block. blocks_per_minute and blocks_60s are bucketed by the block's own
timestamp and reseeded from the table on start, so a catch-up fills past
minutes instead of painting a spike. If no blockAdded arrives for 60 s while
the node's block_count advances, the observer resubscribes; after two failed
attempts it exits 2 and tools/observer/run.sh restarts it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's rule, 4 October 2026: the mark sits in a black square, never in a circle, never on another colour, 20% clear
space; the Mac app is the model. brand/master/igneum-mark-square.svg (1024, #0C0C0E, the exact header polygons at 62%)
and igneum-mark-square-rounded.svg (Apple's 824-on-1024 grid, DMG volume icon only). make-icons.py now rasterises the
masters (rsvg-convert if installed, else Pillow draws the polygons) into igneum.icns (plain square, 16 to 1024),
igneum-volume.icns, igneum.ico (each size from the vector), the Inno art, the DMG background, site favicons
(favicon.ico 16/32/48, favicon-32, apple-touch 180, 192, 512, maskable 512 + manifest entry), relay favicons, and
brand/profile (400/512/1024, github-org-512, X banner). Every page head's inline SVG favicon and the relay header lose
the ring. The .rc and Info.plist paths are unchanged (same file names). docs/brand/before holds the old set.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/fast-time/override-60x.json is the devnet with every clock-like consensus parameter divided by 60 and every
block count unchanged (finality window, ban and min_daa 120 DAA; merge depth 60; Kaspa finality depth 720; pruning
depth at the anticone bound 13,838; coinbase maturity 2; the hourly program epoch 60 blocks with a 10-block lead;
the dataset day 24 minutes). The epoch length, lead and day are consensus parameters of the node since devnet-v4
a5ef8b07, carried by the override file. README lists each field, why it scales or not, the flags and the numbers.
Measured (simnet.mjs, three devnet-v4 nodes, three vmine voters at 1 block/s, one real-hash CPU miner): next
epoch seed in the template at 56.1 s, program swap at 65.1 s wall (DAA 60), first finality lock at 185.5 s wall
(checkpoint 5, DAA 149). Both harnesses take --fast-time: finality-attacks s3 PASS in 113 s wall with 16 locks
per node (the devnet rule needs 20 min of warm-up at 6 blocks/s before any lock); harness s3 partition and heal
43 s wall for three cuts against 983 s for four on the devnet profile with the same binary. Bench-log entry.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The selected chain runs along one horizontal rail; crowded chain blocks
stagger to three rows around it. Side blocks hang above and below in time
order, packed into rows so none overlap. The miner is the ring colour; the
gutter lists active miners with their on-screen block counts. A ruler under
the blocks ticks every 5 s with clock labels and now at the right edge. New
blocks slide in from the right. Red blocks are a dim ember tint. Header stats
gain a pending count. Density steps, tooltips, final band and the one-rAF
loop are unchanged.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Observer: additive live_blocks.color (pending by default). Every chain block's
mergeset marks its blues blue and its reds red, from the notification's verbose
data or getBlock for chain blocks learned via virtualChainChanged; a reorg puts
the removed chain blocks' mergesets back to pending. API serves color. Page:
blue side blocks filled in the miner's hue at 70% with the ring, pending the
faint outline, red a dark outline with a strike; tooltip and legend name the
state.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One lane per miner ranked by share, overflow in an others lane with a count.
Lane labels in a left gutter in the miner's colour (3-character tag on phones).
No per-block labels: short id on the chain tip, the lock, and on hover or tap
with a canvas tooltip (id, blue, DAA, parents, chain or side). Same-lane
overlaps nudged in a fixed sequence. Chain as one path, side blocks linked to
their first parent only, clamped cubics so no edge becomes a tall loop. Block
size and time scale step down together at density. One rAF loop, DPR aware,
paused when hidden or scrolled out. Final band and lock marker. Before and
after screenshots in docs/design/live-dag.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A lock needs two thirds of all 30-day weight signing; finality pauses
whenever less than two thirds is connected and signing, the chain runs
on proof of work meanwhile and the node reports it. Spec 3.3, 3.3.1,
3.7, 3.9, 3.10 Q3 row, 3.11 rewritten with the new arithmetic (safety
one third in every view, liveness two thirds connected, the per-view
window bound stated as 3.7 item 9); O-3.15 decided, O-3.16 closed,
O-3.18 and O-3.19 narrowed. Simulator: --floor, the +local partition
mode, scenario L; A to L re-run at the 2/3 floor over five seeds with
the 0.85 deltas in results_v2.md. Litepaper finality sentences and the
'does not claim' item. Ledger F2, F9, F16, F18 restated, F21 added
(the window bound and the post-heal finality fork from the devnet).
Bench-log: node build and tests, simulator deltas, three-node six-voter
runs of 6A, 6B and 6A with a long heal on ports 29200 and up.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/evidence.md and site/evidence.html: 28 public claims with one of five status labels (7 designed, 3 implemented, 18 tested by the team, 0 reproduced externally, 0 reviewed independently), version or commit, the reproducible test, the result with date and machine, and independent verification (none yet for every row). Evidence link in the homepage nav and the generated pages' nav.
docs/benchmarks/proving-e2e.md: replaces the 20-second shard gate with three fixed workloads, job-received-to-accepted-proof latency, cost per proof, the eligible card list with mining and proving reported separately, the verbatim acceptance standard and the three-unrelated-operator protocol.
docs/plans/funding.md: cost, what is funded (founder's means, the client's 1% fee once there is mining), what waits on revenue, what pauses.
docs/analysis/security-budget.md: emission through six halvings at three price inputs, miners and provers separate from burns, the USD 1M floor and the year it is crossed.
docs/design/payment-routes.md: Mermaid flowchart and table of every flow, with operator, app, team and protocol revenue labelled.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Measured at 375, 768, 1280 and 1680 with headless Chrome. One token set in
all four stylesheets: container 1200 px with a clamp(16px,4vw,32px) gutter,
section rhythm clamp(56px,8vw,96px), cards clamp(18px,3vw,28px) padding and
18 px radius, tiles 18 by 20 px padding and 14 px radius, 24 px card gap and
12 px tile gap, headings h1 clamp(32,5.5vw,56) h2 clamp(28,4.2vw,44) h3
clamp(18,2vw,22), tile values clamp(20,2.2vw,26).
Home: the live strip spans the full hero width with economics-spec tiles;
stat strip and economics tiles share one spec; journey phases and log take
the tile and card boxes; inline padding-top overrides removed, consecutive
dark sections share one gap; every nav anchor lands the heading 11 px under
the sticky bar at every width (padded sections subtract their own padding).
Live: head, strip, cards and gaps on the tokens; four tiles a row, two on
phones; network name no longer clips. Litepaper: real gutter instead of a
fixed 16 px, cover, layout, tables, figures, pull quotes and stat tiles on
the tokens, pager stacks on phones. Engineering log: same tokens, long code
tokens wrap so phones no longer scroll sideways, duplicate h1 hidden.
Copy shortened so no label orphans at any width: stat strip labels, the
economics tiles, the strip tile labels, the litepaper stat tiles, the
mining-program eyebrow. The light-client card block is untouched.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/verify/core.js recomputes every header hash (keyed BLAKE2b, the
node's field order), checks the parent links from the previous locked
checkpoint, hashes each voter's G1 key to its vote_key_hash, verifies the
BLS aggregate over "igneum-vote-v1/" || chain_id || 0 || index_le64 ||
checkpoint under the vote tag with the bitmap's keys, and applies Q3
(2/3 of active, 17/30 of total). verify.js drives it from /api/checkpoint
with @noble/hashes 2.4.0 and @noble/curves 2.4.0 pinned from jsdelivr and
fills the homepage card; the badge says LIVE only after a pass in the tab.
site/api/checkpoint.mjs ships the data: certificate bytes, voter table
with public keys, header chain. tools/observer stores every certificate a
block carries (new table live_certificates, voter table read at the lock,
selected-chain headers back to the previous lock, one-off backfill of the
newest lock on start) and keeps header nonces exact; the FinalityLock
write no longer fails on a missing votes_seen.
Tested on the igneum-devnet-7 test network: checkpoint 95 verifies in
Chrome in 103 ms; a flipped signature bit, a dropped voter, an altered key,
an altered header and a removed header all fail with the reason named.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/fork-divergence.md: "Finality v2" table (every file, risk, merge note), decisions
- docs/spec/03-finality.md: section 3.10 implementation notes, clause by clause
- docs/bench-log.md: test-network results (72 of 72 steady locks, median 0.80 s; equivocation
strip; partition: 0 locks at 39.6% of total with the floor binding, heal in 30 s), follower
- tools/observer: live_checkpoints table, FinalityLock subscription, "checkpoint N locked" events
- site: /api/live adds checkpoints and locked/final flags; /live draws the lock ring and final line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The hero canvas now has a live path fed by the same 2 s fetch as the chain scene (one poller, three subscribers: hero, stats strip, chain scene). When the observer is fresh each dot is one miner seen in the last ten minutes (at most 24, no id drawn), it flashes ember when that miner finds a sampled block, and faint lines reach the miners of the block's parents for a moment. Dots join on a new miner and fade out when one leaves the ten-minute set. The drift, colours and pace are the simulation's; the simulation runs unchanged when the observer is off or stale.
A live stats strip under the hero buttons (miners active, blocks / s, network hash rate, blocks on the devnet) shows only while the observer is fresh and hides again when it goes stale. Two tiles per row at phone width.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>