Commit graph

377 commits

Author SHA1 Message Date
igneum-labs
545bdb2f0e app: every process the engine starts on Windows is hidden (platform::quiet on the window host, icacls, reg, the setup's cmd; igneum-prove-verify is a windows-subsystem exe, the node starts it with no console of its own)
The four helpers (detect::run_timeout, jobrun::run_capture, jobrun::run_streamed, procs::spawn) already set
CREATE_NO_WINDOW; the direct .output()/.spawn() sites did not. 5 October 2026: a console window on both PCs.
2026-10-05 08:39:49 +00:00
igneum-labs
0f6fc2ead5 Merge rotation-2 (7c9a939) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
c797fe49b3 Merge proving-app (05051c1) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 9835f49), tile shows the verifier 2026-10-05 08:33:13 +00:00
igneum-labs
b00de4f4f3 Merge app-ui (7388a20) into release-0.3.6: one notice strip under the header; CI runs both the wake and the notice tests 2026-10-05 08:32:52 +00:00
igneum-labs
fc137257ed Merge origin/testnet-adopt (3be4501) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
9835f493c7 app: the prover's WSL probe runs hidden (it opened a console window on PC 2 once a minute)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:30:00 +00:00
igneum-labs
65cb2e68b9 app: the job relaunch helper starts with CREATE_NO_WINDOW only (DETACHED_PROCESS exits powershell without a console, the OTA stall class)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:28:19 +00:00
igneum-labs
2edc5f693c Merge job-wake: instant job wake-up (relay /wake long-poll, 2-minute fallback poll, publisher wake)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:26:07 +00:00
igneum-labs
c40aa303a6 app jobs: wake long-poll on the relay, fetch within seconds of a publish; safety-net poll 2 minutes (was 10)
the project lead, 5 October 2026: "why is it taking so long for pc2 and pc1s tasks to spin up?". The PCs have no inbound ports
and one miner is off the LAN, so one thread per app now long-polls the relay's public /wake with the last stamp
(GET <url>?since=<stamp>, held up to 45 s there). A changed stamp sends Event::Wake and the engine fetches the jobs
file at once (signature check unchanged); a wake during a fetch in flight fetches again right after it. The first
reply only seeds the stamp. Backoff 5, 15, then 60 s while the relay is unreachable, a 10 s floor between requests,
a full hold when the relay has no stamp yet: never a busy loop. One log line per wake, one when it falls back, one
on recovery. IGNEUM_APP_JOBS_WAKE_URL overrides the URL (set and empty: no waker).

CHECK_EVERY_S 600 -> 120: the poll is the fallback now; the first poll stays 40 to 60 s after start. An unchanged
file is no longer logged on every poll. Remote jobs off stops the waker too.

Unit tests: the stamp logic (seed, same, changed, empty), the backoff sequence and the recovery flag, the floor,
the URL and query. cargo test -p igneum-app: 60 + 22 pass; cargo build --release -p igneum-app: finished.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:25:29 +00:00
igneum-labs
2866737139 relay: the packaged intake key reports too (build job uploads got 'no token' after the key split)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:24:31 +00:00
igneum-labs
7e0fc7da65 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
0550f58857 relay: /wake long-poll for the apps' remote jobs (public GET held 45 s, authenticated POST of the stamp)
GET /wake?since=<stamp> is public (the apps hold no token) and rate limited (30 a minute per IP). It holds up to
45 s, re-reading the stamp every 2 s, and answers {stamp, at, added, changed, held_ms} the moment the stored stamp
differs from since, else the unchanged stamp at the deadline. POST /r/<token>/wake {stamp, added} (the relay's
auth, also x-relay-token or x-igneum-key on /wake) records a stamp; one row per stamp in relay_wake, created by the
first POST. maxDuration 60 s for api/wake.mjs in vercel.json. api/relay.mjs is untouched.

The handler lives in lib/wake.mjs with its dependencies injected; relay/test/wake.test.mjs drives it with a fake
database, a fake clock and a fake sleep (the hold, the change, the deadline, the rate limit, the hold cap, auth, a
database error). CI's site job runs it with the other relay tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
05051c111d docs: release 0.3.6 done notes for the app-side proving items
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
25350f254a app: the node gets a proof verifier, the WSL2 probe checks both layouts, the tile shows the verifier state (0.3.6 items 1 to 3)
Spec 7.7 item 4: a node without a verifier relays proof records and never includes them. On 5 October no app node ran one.

1. src/verifier.rs decides once per node start and engine.rs passes it to the igneumd spawn. macOS and Linux: igneum-prove-host
   next to the engine's binaries. Windows: the new igneum-prove-verify.exe (src/bin/prove-verify.rs, a bin target of this crate,
   shipped by make-payload.sh) is set only when its --probe finds a host inside WSL2; it rewrites --proof with wslpath -a,
   runs the host in the order of src/wslhost.rs and returns its exit code, 2 when there is no host. Trust mode is never the
   default: the setting proof_verify_trust (Settings, "devnet only") sets IGNEUM_PROOF_VERIFY=trust only when no verifier was
   found; changing it restarts the node. After the WSL2 setup runs, the prover thread asks for one node restart.
2. The prover's WSL2 probe looks at the payload's wsl2/bin, ~/igneum-prove/proving/igneum-prove/target/release (what
   setup-wsl.sh builds), ~/igneum-prove/target/release and /opt/igneum, in that order (one list in src/wslhost.rs, shared
   with the wrapper); the tile's message names every path it looked at.
3. The prover thread reads igneum_getProvingStatus().verifier every 30 s, proving on or off; /api/state carries
   proving.verifier, verifier_mode, verifier_set, verifier_reason, verifier_note and the pool counts; the tile has a
   verifier row and says when this node relays proofs but does not verify them.

Tests: cargo test -p igneum-app, 89 passed. The wrapper cross-compiles with --target x86_64-pc-windows-gnu on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
3be4501c8d release-0.3.6 plan: the fork results, miner-latency in after its three gates, the release dev-fee address
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:00 +00:00
igneum-labs
37c947beb9 lock: build slots open to new builds come from ~/.config/igneum/build-slots (1 to 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:19:52 +00:00
igneum-labs
7388a20f95 Miner app UI: one notice strip under the header replaces the three stacked banners (updates, jobs, clock)
One notice at a time, the most important first (app/igneum-app/ui/app.js, Notices; pure, unit tested):
  0 update installing, urgent or failed   1 job failed   2 clock   3 job running
  4 update available, downloading, ready, waiting for permission, manual   5 job done   6 updated
Lower notices wait their turn. Every notice has a close control; closing hides that notice's key until the
state moves on (a new status, version or job id).

States and their rules:
  update available      "Igneum Miner X is available." Install now, Later. Key update:X:pending.
  update downloading    "Downloading Igneum Miner X: 43%." (no percent when unknown), progress bar; same key as
                        available and checking, so Later hides the whole download until it is ready.
  update checking       "Checking Igneum Miner X." (the engine's staging step).
  update ready          "Igneum Miner X is ready. It installs by itself at a quiet moment." (auto on) or just
                        "... is ready." Install now, Later. Key update:X:ready.
  update waiting        Windows, nobody answered the administrator prompt: "... is waiting for permission. It
                        installs the next time someone is at this PC. Mining continues."
  update manual         "... is downloaded. Open it and drag the app over the old one." Open the download.
  update installing     "Installing Igneum Miner X. The app restarts itself. Mining continues until then."
                        (on a Mac, where the engine quits at once: "The app restarts itself in a moment.")
                        Also while the engine says "installing now" after Install now.
  update urgent         the engine's consensus-deadline text, ember, downloading percent when it downloads.
  update failed         "The update to X failed." plus one line of cause and Try again; rolled back:
                        "Igneum Miner X did not stay up and was rolled back." A dev build with no manifest
                        configured shows nothing (Settings still says it).
  updated               "Updated to Igneum Miner X from Y." Gone 60 s after the new version started.
  job running           "Job: <title> running, N min. <Stage>." with the last RESULT line underneath.
  job done              "Job: <title> done after N min. Report uploaded." Gone after 5 minutes.
  job failed            "Job: <title> failed after N min, exit C. Report not uploaded." plus the first error
                        line (BUILD FAILED / error / failed / panic among the result lines, else the summary).
                        Stays until closed. Timeout and aborted are "hit its time cap" and "was stopped".
  clock                 as before: the engine's words, Sync clock, the manual hint; on the setup screens only
                        (the node card carries it on the dashboard). Jobs show on the dashboard only.

Layout: the strip reserves no height while empty; when a notice appears or goes, main's top moves once with a
150 ms transition (none under prefers-reduced-motion). Existing tokens only, nothing newer than 2022 CSS.
Screenshots: ?update=<state> as before, ?job=running|done|failed added (packaging/ota/README.md).

Test: node --test app/igneum-app/ui/notices.test.mjs (ordering, dismissed keys, wording, the 5-minute and
60-second timers); added to the CI site job. Built once with cargo (include_str) and checked against the
ui-mock scenarios and a scratch engine instance (IGNEUM_APP_DATA in a temp dir, fake worker).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:16:29 +00:00
igneum-labs
b3ba9ac1ee build inputs: ship igneum-pow beside the zip root and the coin image the engine embeds
The first PC build (job build-20261005-075300) failed in 52 s: the node's crates depend on ../../../../igneum-pow,
which the zip did not carry, and the engine embeds brand/igneum-coin-1024.png, which the staged brand/ lacked.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:01:17 +00:00
igneum-labs
eadb6c9352 site: Igneum Wallet on the home page (section, buttons, nav link on every page)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:54:01 +00:00
igneum-labs
9aa5d5da24 app ui: a finished job's banner stays 5 minutes when it succeeded, 30 when it failed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:50:57 +00:00
igneum-labs
b243ed7e95 docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:45:45 +00:00
igneum-labs
fd07ef569f Merge origin/testnet-prep (28f6ccc) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
c6d3e1ab22 Ledger: merge conflict markers removed, both sides kept 2026-10-05 07:25:45 +00:00
igneum-labs
175052b0a9 Site: rebuilt after the E15 and ledger-sweep merge 2026-10-05 07:25:30 +00:00
igneum-labs
bccb4c7261 E15 decided: the 4 billion cap stays, no tail emission; spec 5.10 with the measured security-budget table and the review trigger, O-5.11 closed, litepaper and homepage state the cap and the years
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:24:38 +00:00
igneum-labs
77fa43d1b1 Igneum Miner 0.3.5: Pruning proofs on the lottery hash (M20), memory fix (M30), coinbase limit on every network (M31), chain-decided equivocation bans (F23), re-determination after reorgs (F24), params digest in the handshake (G12, X18), miner fee 1% switchable, efficiency sweep, variant racing, reliability watchdog, log panel and screens, PC build job, Windows updater launch fix 2026-10-05 06:33:18 +00:00
igneum-labs
22615d54cf release-0.3.5 plan: the final fork suites and totals filled in
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:16:42 +00:00
igneum-labs
b3310e616a release-0.3.5 plan: final round from fork 20139145, every suite green, header and digest confirmed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:16:14 +00:00
igneum-labs
24e68edaf1 release-0.3.5 plan: fud-consensus fork results, the scratch run, m20-pruning merged (final-round hashes to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:43:56 +00:00
igneum-labs
c6116c805a release-0.3.5 plan: fud-consensus on both repos (fork results to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:21:12 +00:00
igneum-labs
d791efd4be Merge origin/fud-consensus into release-0.3.5
bench-log.md: both appended entries kept (the round-4 consensus items and the red team next to the branch's own).
2026-10-05 02:19:41 +00:00
igneum-labs
25e8da065a Round-4 consensus items: final runs on 977db931 (reorg-final2, the red team's f23 / f24b / f24c), the M31 and un-determination entries, result files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:17:49 +00:00
igneum-labs
98a2234375 Ledger F23, F24, G12, X18, M30, M31, F25 to 'Fix built, pending rollout' with the measured runs; bench-log entry for the round-4 consensus items; red team branch merged
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:57:24 +00:00
igneum-labs
e12f768e3c Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:56:28 +00:00
igneum-labs
90478b5cf4 Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:49:46 +00:00
igneum-labs
a32b10aad8 Merge branch 'redteam' into fud-consensus
# Conflicts:
#	docs/fud-ledger.md
2026-10-05 01:34:21 +00:00
igneum-labs
2cb3d88bca fud.mjs: node logs kept per scenario, pre-F24 refusal wording counted, reorg criterion as the rule promises; first-pass and control results kept
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:34:04 +00:00
igneum-labs
0c6b75bdfb FUD ledger sweep, round 5: s5 and s4 on the finality-fixes build (F1 burster locks nothing alone, F3 vote-dropping adds 0 ms), F2 floor note, final counts
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:17:45 +00:00
igneum-labs
7548f88517 release-0.3.5 plan: master merged once more
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:14:24 +00:00
igneum-labs
d80b384360 Merge remote-tracking branch 'origin/master' into release-0.3.5 2026-10-05 01:14:23 +00:00
igneum-labs
d5cb313954 release-0.3.5 plan: round-3 binaries from fork 2e75a238 (build-info fix), header igneumd/2.1.0-2e75a238 confirmed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:14:05 +00:00
igneum-labs
d9182273ce Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:12:27 +00:00
igneum-labs
be99cb3821 Lock: three run slots for functional runs; a measurement waits for all of them
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:10:17 +00:00
igneum-labs
20e664cd35 FUD ledger sweep, round 4: M25 confirmed on a real-PoW test node (mismatched day length rejected with no reason named), fix row 127
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:09:07 +00:00
igneum-labs
32fe292a85 bench-log: M30 floods re-run on the committed fork build 796f758d (second after pass)
s6 +6/+3/+1 MB per load, s7 302 to 318 MB, 0 cache builds, epochs 0 to 3
rolled, 202 blocks accepted; the pass-1 column stays beside it. Result JSON
after-{s6-exhaustion,s7-flood}.json added. The s6 one-instant sink check is
noted as a harness flake.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:06:07 +00:00
igneum-labs
59a77b5b4b release-0.3.5: master 00baf75 and bugfix-collect-exit merged, site rebuilt, plan rows (round-3 hashes to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:04:17 +00:00
igneum-labs
4b26d04bc0 Red team 4 Oct 2026: every attack suite against the 0.3.4 finality-fixes build (rule v3 on, fast time); 30 scenarios, ledger F25 M30 M31 new, F21 F23 F24 measured
Report docs/review/redteam-2026-10-04.md: finality attacks s1-s8 plus 34% withholding, 50/50 long partition, F23 and
F24 custom runs, ordering harness, execution suite and EVM smoke, proving hostile tests and a proof flood, difficulty v2
timestamp forging in the simulator. New fails: the fast-time harnesses corrupt the u64::MAX sentinels of the override
(F25), a block or transaction flood grows the node by hundreds of MB in a minute (M30), the coinbase does not fit the
204-byte limit on mainnet, testnet and simnet parameters (M31). F23 and F24 reproduced on this build; F21's bound
measured at one window of the side's own DAA. Scenario scripts under tools/finality-attacks/redteam/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:03:08 +00:00
igneum-labs
7a81dc73f7 Merge remote-tracking branch 'origin/bugfix-collect-exit' into release-0.3.5 2026-10-05 01:02:23 +00:00
igneum-labs
799d920102 Merge remote-tracking branch 'origin/master' into release-0.3.5 2026-10-05 01:02:23 +00:00