Commit graph

89 commits

Author SHA1 Message Date
igneum-josh
2f5e04cd8d bench log + plan: PC 1 run 1 aborted by the 0.3.11 update 47 s in, the before snapshots of both cards, the AMD offset-range finding and its consequence per tier
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:44:46 +01:00
igneum-josh
5d7ced9d4f ember-tune.md: a signed prior is a starting point inside the card's own reported limits, never a memory clock; the tests that prove the clamp (consequences row C25)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:31:06 +01:00
igneum-josh
54ff1bc933 Ember Tune: every card tuned for MH per watt out of the box, the fleet prior per card model in the signed manifest, the console and /miners priors table
Josh, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (7adcd4c, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (3562f26). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.

- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
  (power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
  neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
  the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
  no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
  no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
  probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
  tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
  Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
  {json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
  control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
  query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
  switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
  median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
  make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
  tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).

Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt Josh cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:25:09 +01:00
igneum-josh
be4b29507b docs: Counter ASIC 2.0, the second set of chip-resistance layers and the plan to measure and decide them
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:40:33 +00:00
igneum-josh
9746391242 docs/plans/explorer.md: Etherscan, Blockscout and Otterscan compared, Blockscout's requirements against the fork's RPC, the recommendation, the load and supply measurements, the pool item; screenshots
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:35:40 +01:00
igneum-josh
bf8d1ba5b8 finality-v3-devnet-publish.md: the app nodes, the sweep (every live node on 1f4b4425), the Mac app's external-node finding, the checkpoint read 2026-10-05 19:19:03 +01:00
igneum-josh
46a6a4e60f docs/plans/finality-v3-devnet-publish.md: N3 = 135,200, digest 1f4b4425, the hand nodes, the seed and the three manifests 2026-10-05 19:09:05 +01:00
igneum-josh
6f31657be5 release-0.3.9 plan: the ship, the proving rollout, the fee switch (H 210,000, digest ab8847da) and the sweep; restart-hand-nodes.sh: grep -c instead of grep -q under pipefail, lines() never ends the script 2026-10-05 18:55:35 +01:00
igneum-josh
f2d618c5e4 release-0.3.9 plan: the cut so far (branch, tests, node builds, hand nodes and seed on a24ab01a, DMG, package) 2026-10-05 17:51:20 +01:00
igneum-josh
97b1a74f49 Merge origin/master (fb076de) into release-0.3.9: fud-a round 6, the entity imprint, the conflict-marker check; docs/bench-log.md both entries, the site taken from master and rebuilt (519 links, 0 broken) 2026-10-05 17:48:00 +01:00
igneum-josh
1269db8357 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 17:32:53 +01:00
igneum-josh
318a2de158 Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 17:30:47 +01:00
igneum-josh
f7a41a2c71 Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 17:28:21 +01:00
igneum-josh
1c461bcdcb release-0.3.6 plan: why the PC-built Windows node died at start, answered and fixed in the fork (static libstdc++); the stale comments on the Windows DLLs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:26:05 +01:00
igneum-josh
15bb6cdd43 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:24:35 +01:00
igneum-josh
83a0bcf748 Merge testnet-infra: testnet seed profile, DNS and RPC installers, build-job watcher fix, docs/testnet, the go checklist
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:05:16 +01:00
igneum-josh
e1beff0b1e docs/plans/testnet-go.md: the go checklist with the state of every line at 16:05 UTC, the final genesis, the cost
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:04:09 +01:00
igneum-josh
62389887d7 release-0.3.6 plan: the two finality tests under the parallel suite answered (fork 7003055b); build-job.mjs forwards --node-tests, --app-tests, --no-app
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:59:59 +01:00
igneum-josh
ec37792937 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:52:34 +01:00
igneum-josh
8ae2b00e6f rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:37:02 +01:00
igneum-josh
e557634a21 release-0.3.8 plan: the cut, the proving rollout, the first cross-verified shard 2026-10-05 15:08:31 +01:00
igneum-josh
b8b40a5a92 Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:54:31 +01:00
igneum-josh
0a9778417e release-0.3.6 plan: every reachable machine on 0.3.7 with node state, the open items 2026-10-05 11:31:26 +01:00
igneum-josh
74830647f6 release-0.3.6 plan: the three Windows machines on 0.3.7 with their nodes up 2026-10-05 11:29:19 +01:00
igneum-josh
19814a9818 release-0.3.6 plan: the Mac on 0.3.7 2026-10-05 11:27:46 +01:00
igneum-josh
ddb842a764 release-0.3.6 plan: the update-now job's run times per machine 2026-10-05 11:27:34 +01:00
igneum-josh
f6d41211d1 release-0.3.6 plan: the jobs file mirrored into the NEXT folder by hand (publish-jobs.sh does not) 2026-10-05 11:22:37 +01:00
igneum-josh
77bde6fb85 release-0.3.6 plan: the 0.3.7 ship, both manifests compared, the update-now job, the baseline 2026-10-05 11:18:18 +01:00
igneum-josh
c528ce8b62 release-0.3.6 plan: the 0.3.7 cross-built exes, the -static-libstdc++ result 2026-10-05 11:10:01 +01:00
igneum-josh
bbbbdd4509 release-0.3.6 plan: the watch's end 2026-10-05 10:59:51 +01:00
igneum-josh
07f5974383 release-0.3.6 plan: the PC-built Windows node dies at start even with matching DLLs; 0.3.7 ships the Mac cross-build; 0.3.8 open item 2026-10-05 10:56:22 +01:00
igneum-josh
61ef09d106 release-0.3.6 plan: the OTA helper logs of the three machines 2026-10-05 10:50:32 +01:00
igneum-josh
0d372d2522 release-0.3.6 plan: PC 2 and the Mac after the publish, the node restart loop on the PCs 2026-10-05 10:50:05 +01:00
igneum-josh
26b10a9b36 release-0.3.6 plan: the 0.3.7 DMG 2026-10-05 10:49:51 +01:00
igneum-josh
b74f700778 release-0.3.6 plan: section 9, the 0.3.6 Windows runtime incident and the 0.3.7 hotfix 2026-10-05 10:47:12 +01:00
igneum-josh
4c2a403691 release-0.3.6 plan: the machines after the publish, PC 1 first 2026-10-05 10:39:36 +01:00
igneum-josh
662d1112c2 release-0.3.6 plan: verify and console steps, the ship's close 2026-10-05 10:35:53 +01:00
igneum-josh
04054c0b2c release-0.3.6 plan: the ship, the live manifest compared field by field 2026-10-05 10:35:31 +01:00
igneum-josh
5483322db1 release-0.3.6 plan: PC 1 take 2 binaries and hashes, the PC 2 pair read precisely, the finality test-isolation finding 2026-10-05 10:27:28 +01:00
igneum-josh
d89acf095a release-0.3.6 plan: the DMG hash 2026-10-05 10:19:49 +01:00
igneum-josh
5b2856ef40 release-0.3.6 plan: PC 2 suite result (M30 pow-cache queue under full-suite parallelism), the two follow-up jobs, the DMG with the 0.3.5 prover 2026-10-05 10:19:14 +01:00
igneum-josh
a7e1181a8b release-0.3.6 plan: the PC 1 build failure (cargo mtime freshness over the persistent target dir), the fix, take 3, the PC 2 suites job 2026-10-05 10:13:59 +01:00
igneum-josh
822b53fc82 release-0.3.6 plan: section 8, the cut (merges, changes, tests, secrets, binaries, digest, live manifest) 2026-10-05 09:53:28 +01:00
igneum-josh
50920da7b6 Merge rotation-2 (5317305) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 09:33:37 +01:00
igneum-josh
ada90aa768 Merge proving-app (010a372) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 31c1b34), tile shows the verifier 2026-10-05 09:33:13 +01:00
igneum-josh
c9bc6d4b85 Merge origin/testnet-adopt (09baf8e) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 09:32:40 +01:00
igneum-josh
3da3c88184 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:22:02 +01:00
igneum-josh
010a372f44 docs: release 0.3.6 done notes for the app-side proving items
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:13 +01:00
igneum-josh
09baf8e15d release-0.3.6 plan: the fork results, miner-latency in after its three gates, the release dev-fee address
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:00 +01:00
igneum-josh
3763da77c4 docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:45:45 +01:00