On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.
- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
host/src/pinned.rs embeds and checks them at every start; the prove modes
refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.
The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit 476063b (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.
So the prover core needs no rule change: the fix is commit 476063b, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:
- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
segment's shard ends at the root after the rewards, never the pre-root. With the pre-476063b rule put back
the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
printed on the first line of every run, so a stale build names itself in the log instead of in a line
number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.
The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
New sections "Ember, the miner" (features, the six levers with state and measurement, the
software dev fee, what Ember does not claim) and "The wallet" (Igneum Wallet 0.1.1) after
"For miners". "Igneum at a glance" gains the live devnet table (hourly swaps, difficulty v2
at DAA 33,000, finality v2 first lock at 77.4%, proving v0 from DAA 84,100) with the
one-verifier caveat. Roadmap phases 2 and 3 carry what is measured so far and a "What ships
next: Ember 0.3.6" table. Proving section carries the RTX 5090 shard figures; the stale
"Where is the miner?" answer now points at Ember. Every number cites its engineering-log
entry or plan in a source line. Version 0.2, status "devnet live, pre-testnet".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A tap or click on a block or a shard cell now pins its details. The panel stays until a tap or click lands
anywhere else, Escape, the close control, or the block scrolls out of the strip (then a 200 ms fade, no snap).
Another block switches the pin. The pinned block carries a molten ring. The pinned panel sits at a fixed
spot at the top left of the strip, so new blocks never move it, and shows a PINNED label and a 32 px close
control for a thumb.
Hover is unchanged on pointer devices: another block shows its floating panel for as long as the pointer is on
it, then the panel returns to the pinned block. Hover never clears a pin.
Pointer events only: one pointer, down to up, under 10 px of travel counts as a tap, so a scroll on a phone
never pins, and a touch tap fires once (the canvas ignores click). A touch gets a wider hit radius than a
pointer; the hover radius is as before.
Verified with real mouse, touch and key input through CDP on the cached headless Chromium against the local
page fed by igneum.network/api/live: 20 of 20 checks at 1200 px and 375 px, no console errors.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>