Commit graph

229 commits

Author SHA1 Message Date
igneum-josh
43c976e768 Testnet seeds: debian-13 images (the PC build's glibc 2.39), a glibc check before the upload, the final genesis in docs/testnet/README.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:58:18 +01:00
igneum-josh
e557634a21 release-0.3.8 plan: the cut, the proving rollout, the first cross-verified shard 2026-10-05 15:08:31 +01:00
igneum-josh
b58836713a Merge program-id: pinned shard and aggregator guests (elf/ + manifest), fast verify with the pinned key, CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	proving/igneum-prove/host/build.rs
2026-10-05 14:00:54 +01:00
igneum-josh
b8b40a5a92 Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:54:31 +01:00
igneum-josh
bb522db3ac Prover: the 5 October post-root assertion explained (stale build, empty-segment plan), fixture 58927, fixture test, source stamp
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.

The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit 1251f0a (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.

So the prover core needs no rule change: the fix is commit 1251f0a, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:

- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
  statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
  segment's shard ends at the root after the rewards, never the pre-root. With the pre-1251f0a rule put back
  the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
  untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
  printed on the first line of every run, so a stale build names itself in the log instead of in a line
  number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.

The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:50:40 +01:00
igneum-josh
de79359bf9 Bench log: the first shards proven, verified and paid on the live devnet (5 October 2026)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:54:47 +01:00
igneum-josh
2f60b202b0 Merge release-0.3.6 plan commits (0.3.7 results)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:36:39 +01:00
igneum-josh
33d03400cb benchmarks: the vmmap captures carry no local timezone stamp (identity check)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:31:44 +01:00
igneum-josh
0a9778417e release-0.3.6 plan: every reachable machine on 0.3.7 with node state, the open items 2026-10-05 11:31:26 +01:00
igneum-josh
74830647f6 release-0.3.6 plan: the three Windows machines on 0.3.7 with their nodes up 2026-10-05 11:29:19 +01:00
igneum-josh
19814a9818 release-0.3.6 plan: the Mac on 0.3.7 2026-10-05 11:27:46 +01:00
igneum-josh
ddb842a764 release-0.3.6 plan: the update-now job's run times per machine 2026-10-05 11:27:34 +01:00
igneum-josh
f6d41211d1 release-0.3.6 plan: the jobs file mirrored into the NEXT folder by hand (publish-jobs.sh does not) 2026-10-05 11:22:37 +01:00
igneum-josh
77bde6fb85 release-0.3.6 plan: the 0.3.7 ship, both manifests compared, the update-now job, the baseline 2026-10-05 11:18:18 +01:00
igneum-josh
c528ce8b62 release-0.3.6 plan: the 0.3.7 cross-built exes, the -static-libstdc++ result 2026-10-05 11:10:01 +01:00
igneum-josh
bbbbdd4509 release-0.3.6 plan: the watch's end 2026-10-05 10:59:51 +01:00
igneum-josh
07f5974383 release-0.3.6 plan: the PC-built Windows node dies at start even with matching DLLs; 0.3.7 ships the Mac cross-build; 0.3.8 open item 2026-10-05 10:56:22 +01:00
igneum-josh
61ef09d106 release-0.3.6 plan: the OTA helper logs of the three machines 2026-10-05 10:50:32 +01:00
igneum-josh
0d372d2522 release-0.3.6 plan: PC 2 and the Mac after the publish, the node restart loop on the PCs 2026-10-05 10:50:05 +01:00
igneum-josh
26b10a9b36 release-0.3.6 plan: the 0.3.7 DMG 2026-10-05 10:49:51 +01:00
igneum-josh
b74f700778 release-0.3.6 plan: section 9, the 0.3.6 Windows runtime incident and the 0.3.7 hotfix 2026-10-05 10:47:12 +01:00
igneum-josh
4c2a403691 release-0.3.6 plan: the machines after the publish, PC 1 first 2026-10-05 10:39:36 +01:00
igneum-josh
662d1112c2 release-0.3.6 plan: verify and console steps, the ship's close 2026-10-05 10:35:53 +01:00
igneum-josh
04054c0b2c release-0.3.6 plan: the ship, the live manifest compared field by field 2026-10-05 10:35:31 +01:00
igneum-josh
5483322db1 release-0.3.6 plan: PC 1 take 2 binaries and hashes, the PC 2 pair read precisely, the finality test-isolation finding 2026-10-05 10:27:28 +01:00
igneum-josh
d89acf095a release-0.3.6 plan: the DMG hash 2026-10-05 10:19:49 +01:00
igneum-josh
5b2856ef40 release-0.3.6 plan: PC 2 suite result (M30 pow-cache queue under full-suite parallelism), the two follow-up jobs, the DMG with the 0.3.5 prover 2026-10-05 10:19:14 +01:00
igneum-josh
a7e1181a8b release-0.3.6 plan: the PC 1 build failure (cargo mtime freshness over the persistent target dir), the fix, take 3, the PC 2 suites job 2026-10-05 10:13:59 +01:00
igneum-josh
822b53fc82 release-0.3.6 plan: section 8, the cut (merges, changes, tests, secrets, binaries, digest, live manifest) 2026-10-05 09:53:28 +01:00
igneum-josh
50920da7b6 Merge rotation-2 (5317305) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 09:33:37 +01:00
igneum-josh
ada90aa768 Merge proving-app (010a372) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 31c1b34), tile shows the verifier 2026-10-05 09:33:13 +01:00
igneum-josh
c9bc6d4b85 Merge origin/testnet-adopt (09baf8e) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 09:32:40 +01:00
igneum-josh
3da3c88184 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:22:02 +01:00
igneum-josh
010a372f44 docs: release 0.3.6 done notes for the app-side proving items
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:13 +01:00
igneum-josh
09baf8e15d release-0.3.6 plan: the fork results, miner-latency in after its three gates, the release dev-fee address
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:00 +01:00
igneum-josh
3763da77c4 docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:45:45 +01:00
igneum-josh
4aaff887bb Merge origin/testnet-prep (beed743) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:44:22 +01:00
igneum-josh
53173057f7 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-josh
c8b7852efd Ledger: merge conflict markers removed, both sides kept 2026-10-05 08:25:45 +01:00
igneum-josh
eabeed7bd7 Site: rebuilt after the E15 and ledger-sweep merge 2026-10-05 08:25:30 +01:00
igneum-josh
236fd47800 E15 decided: the 4 billion cap stays, no tail emission; spec 5.10 with the measured security-budget table and the review trigger, O-5.11 closed, litepaper and homepage state the cap and the years
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:24:38 +01:00
igneum-josh
a130c6361f release-0.3.5 plan: the final fork suites and totals filled in
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 04:16:42 +01:00
igneum-josh
e68ac6bbdb release-0.3.5 plan: final round from fork 20139145, every suite green, header and digest confirmed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 04:16:14 +01:00
igneum-josh
8e8b739bc0 release-0.3.5 plan: fud-consensus fork results, the scratch run, m20-pruning merged (final-round hashes to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:43:56 +01:00
igneum-josh
5695424e6b release-0.3.5 plan: fud-consensus on both repos (fork results to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:21:12 +01:00
igneum-josh
7abce72165 Merge origin/fud-consensus into release-0.3.5
bench-log.md: both appended entries kept (the round-4 consensus items and the red team next to the branch's own).
2026-10-05 03:19:41 +01:00
igneum-josh
0420c887e2 Round-4 consensus items: final runs on 977db931 (reorg-final2, the red team's f23 / f24b / f24c), the M31 and un-determination entries, result files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:17:49 +01:00
igneum-josh
6332f7aa92 Ledger F23, F24, G12, X18, M30, M31, F25 to 'Fix built, pending rollout' with the measured runs; bench-log entry for the round-4 consensus items; red team branch merged
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:57:24 +01:00
igneum-josh
eee7030321 Merge branch 'fud-memory' into fud-consensus 2026-10-05 02:56:28 +01:00
igneum-josh
afb2ce38d5 Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:49:46 +01:00