Commit graph

129 commits

Author SHA1 Message Date
igneum-labs
6e9bd00dbb miner-ui-3: the banner only (the project lead: 'lets not actually change the miner page just sort the banner')
Variant C and the Earnings reshaping reverted: Mine and Earnings are exactly as shipped in 0.3.14. Kept from the
polish round: every strip, ask and clock card on the brand tokens (the row surface, a 1 px ember hairline on top,
ash text, ember only on the dot and the chevron; no filled brown or mustard field anywhere; the update strip and the
job strip share .notice), the plain-language strip and event sentences with the technical line behind the chevron,
the header baseline and the pill wording. 36 UI tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:18:58 +00:00
igneum-labs
5143cd2ed6 miner-ui-3: variant C is the default (the fleet rate big, the button a bar under it; Earnings the same shape); every strip on the brand tokens
the project lead picked C. The Mine hero is the fleet rate at 84 px on a graphite-to-obsidian fade with W, £ a day and blocks
beside it, Start/Stop as a full-width bar under it; Earnings carries the same shape with the £ figure big. The
?variant switch is gone. Every strip, ask and clock card is one component: the row surface, a 1 px ember hairline on
top, ash text, ember only on the dot and the chevron; no filled brown or mustard field anywhere in the app (the rail's
active item, the pill, the ghost-on button, the option, the ring, the log hit and mark lost their tints). The update
strip and the job strip share .notice. 36 UI tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:09:55 +00:00
igneum-labs
9a45ea3785 miner-ui-3 polish: the strip, the feed and the pill in the app's voice; three Mine layouts to pick from
No raw job, manifest or relay text on a user surface: the job strip reads 'A job from the team ran: update check,
0 min.' with the technical line behind a chevron; 'Updated to 0.3.14 at 18:52.'; the Activity feed maps every engine
event string to a sentence (View.plainEvent, 80 patterns, the engine line as the tooltip) with a kind dot. The header
puts the title, subtitle and pill on one baseline; the pill is a sentence with a coloured dot (Mining · 511 MH/s,
Paused, Syncing the node, Node restarting, Engine not answering). Three Mine layouts behind ?variant=a|b|c (quieter,
denser, hero number) for the project lead to pick. 390 px strip on one line. 36 UI tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:01:47 +00:00
igneum-labs
bd3fb7a809 miner-ui-3: the card row is the product (audit, design, build)
The audit (docs/plans/miner-ui-3-audit.md, 27 screenshots): no money anywhere, three red n/a per Apple row,
tuning split across two pages, 370 px of controls per card, Prove's 95 words and four zeros, Node's eleven
numbers, the jobs table on every Updates page, fixes two taps away, no light mode, no layout under 900 px,
developer lines on user surfaces.

The design (docs/plans/miner-ui-3.md): four sections (Mine, Earnings, Prove, Settings); the card row carries the
state word with its reason, MH/s, W with MH/W, £ a day at the user's electricity price, °C, Tune, the switch,
and its details under a chevron (cap slider, identities, pin, telemetry, the tune table); the tune line per row
(not tuned yet / tuning: step k of n with a bar / tuned N ago · point · next check <weekday> / measured only and
why / pinned / stopped / fleet pause); Tune all; the goal (Efficiency, Balanced, Maximum) with its £ a day; Power
control as one switch where it is the fix; the node as one line with Details; updates as one card; earnings money
first, IGN second; proving as a tier sentence per card; every costly action confirmed in place (quit, change
address, show key, trust mode), no dialogs; light and dark; a bottom tab bar under 720 px.

The build: index.html, app.css, app.js rewritten on the same engine routes; the pure blocks keep their API and
carry ember-tune's tuneNotice, tuneWord, toggle states and tune-line test (0bf27b1) so the merge is clean; the
update card is named Igneum Miner; the Rust side is untouched. node --test on the four UI files: 35 pass.
Screenshots of the result: docs/plans/miner-ui-3/n00 to n26.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:55:45 +00:00
igneum-labs
aed5ca9bd7 Build server adopted: box-first build rule in CLAUDE.md, reproducible Windows exes, the commit-string gate, PC and Mac recipes
Main's decision of 6 October 2026. CLAUDE.md 'Running agents on this Mac': every Linux and Windows cargo build and every
Linux test suite goes to igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh; the PCs keep GPU and
Windows-runtime jobs; the Mac keeps macOS binaries, the DMG and Metal tests under the lock. -Wl,--no-insert-timestamp in
cross-remote.sh, proto-cuda/windows-node/cross-build.sh and jobbuild.rs (two box builds byte-identical, verified).
The empty-commit class: tools/ci/commit-string-check.sh (self-test in ci.yml, shown firing on a Mac worktree build and
passing on a box build) runs on every igneumd from the three build scripts; push-build-inputs.sh adds node.commit_full,
the PC job writes a minimal node/.git from it at extract and cleans kaspa-build-info on a new commit (4 jobbuild tests
pass, run on the box); cross-build.sh refuses a worktree and cleans on a new commit. Plan: second worktree's clean build
1 min 18 s with sccache 604 hits of 993.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:50:39 +00:00
igneum-labs
7883ff17dd release 0.3.13: merge ember-tune 0cba030 (the Power Helper: one approval registers a per-user elevated scheduled task, no prompt after; the folder-lock ACL; the verbatim settings copy; the watchdog; no firewall prompt for a sweep engine; the jobrun follow_file)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:03:27 +00:00
igneum-labs
0cba03027e lock_permissions: the folder grant is user:(OI)(CI)F WITHOUT /T (measured on PC 1, collect ember-acl-2: /T re-applies /inheritance:r to each file after the propagation and an (OI)(CI) entry on a file is inherit-only, so the copied settings still read as nothing); the playbook prefers ember-kit-5
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:50:49 +00:00
igneum-labs
add025fb25 Why every measurement engine on PC 1 ran on defaults: lock_permissions cut the app folder's inheritance with a non-inheritable user:F, which left files COPIED in before the start (settings.json, machine-id, wallet.json) with no ACE at all, unreadable by their owner; the folder grant is now user:(OI)(CI)F with /T (unit test on the argument shape); a --sweep engine never asks for the firewall rule; the playbook copies the firewall flag; the settings fixture test
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:39:18 +00:00
igneum-labs
f225ccf842 run 4's cause: the playbook's PowerShell JSON round trip rewrote the copied settings (big integers as doubles), the engine read the file as defaults (no payout address, every card off, 96 old remote jobs run in the scratch root). Fix: the copies are verbatim and a --sweep engine applies Settings::for_measurement in memory (remote jobs, updates, proving and Power control off, not paused, tune on, every card due and unpinned); the CI check fails any playbook that rewrites settings.json through ConvertTo-Json; unit test
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:21:06 +00:00
igneum-labs
016b5afcb3 Igneum Miner 0.3.13: the six version files (node-only cut: the exec follower fix and the finality route fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 13:14:55 +00:00
igneum-labs
5888eea534 One administrator approval, ever (the project lead, 6 October 2026 11:50 UTC): the first Power control approval also registers the per-user scheduled task 'Igneum Power Helper' (RunLevel Highest, no trigger, action = the app's own exe --power-helper); every later cap and every tune's helper starts the task and writes the command file, no prompt, across restarts, updates and reboots; Power control off sends remove and the task unregisters itself; the helper runs only fixed verbs with digit-only nvidia-smi arguments (threat note in ember-tune.md 7a); 4 tests
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:50:49 +00:00
igneum-labs
e651e281d4 release 0.3.12: merge proving-v1 app f0a40cd (the segment-aligned prover, the held fresh record, the fresh-record rule harness)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:37:18 +00:00
igneum-labs
4965220bad release 0.3.12: merge ember-tune 27c2db6 (Ember Tune, the quit source, no OTA and no pipe in a second engine, the elevated follow_file, the BOM fix, Power control, job-console's hidden-console builder and spawn check)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:22:22 +00:00
igneum-labs
27c2db64c3 app: every elevated launch through one hidden-console builder; CI check for Windows spawns; PC 1 console watchers
The console-window class (the project lead, 5 October 2026: "Windows Command Processor" windows on PC 1 whenever a remote job runs).
Measured on PC 1 (ae432dc7, Windows 11 Pro 26200, default terminal "Let Windows decide" = Windows Terminal 1.24) with
tools/windows/console-watch.ps1 (job run-20261005-182528): no child a job script starts from the app's headless
console opens a window (powershell, cmd, query, curl, nvidia-smi, wsl --status, a distro, interop cmd and powershell,
powershell -WindowStyle Hidden: 0 windows each); Start-Process in a new console opens a Terminal window (the known-failed
case: 2 windows), the same with -WindowStyle Hidden opens none (the known-finished case). The elevated path
(Start-Process -Verb RunAs -WindowStyle Hidden through the AppInfo service) is the one road left; its watcher
(console-watch-elevated.ps1, job run-20261005-184610) was cancelled at the UAC prompt.

- platform.rs: elevated_ps_line + elevated_command build the one PowerShell line every elevated launch uses (the NVIDIA
  power cap, the sweep helper, the clock sync, an elevated remote job), -WindowStyle Hidden by construction; unit
  tests on the line, the quoting and the Command.
- jobrun.rs: the elevated job path uses it; the relaunch helper's Start-Process carries the reason it has no
  -WindowStyle Hidden (igneum-app.exe is a windows-subsystem program).
- tools/ci/windows-spawn-check.mjs (+ ci.yml): fails when a Command::new in app/igneum-app/src is not quieted,
  a creation_flags is not CREATE_NO_WINDOW alone, a Start-Process the Rust code writes lacks -WindowStyle Hidden or
  -NoNewWindow, or host.cpp spawns without CREATE_NO_WINDOW / SW_HIDE; self-test on known-good and known-bad samples.
- tools/windows/console-watch.ps1, console-watch-bg.ps1, console-watch-elevated.ps1: the watchers (run jobs).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:21:46 +00:00
igneum-labs
563463b35f Merge release-0.3.12 (fda4684) into ember-tune: 0.3.11's six-section View and card order kept, Ember Tune's line and switches re-added on it; the tune fields move into hotplug::apply_pref; the power-cap plan keeps present(); both CI test lists; 132 app tests, 26 UI tests, every gate green
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:20:46 +00:00
igneum-labs
24b42e0509 Igneum Miner 0.3.12: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:19:00 +00:00
igneum-labs
622e3c90bb release 0.3.12: merge card-order: the GPU list by performance
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:16:26 +00:00
igneum-labs
328b6088ec release 0.3.12: merge update-catchup: an old update skips the hourly slot
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:16:26 +00:00
igneum-labs
92b109cddb release 0.3.12: merge proving-v1 app: paid_wei as a decimal string
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/bench-log.md
2026-10-06 08:16:26 +00:00
igneum-labs
50a08e8d50 app: an update published over an hour before the engine started skips the hourly rollout slot
PC 1, 6 October 2026 06:58:47Z: the app came up after the 0.3.11 publish, had the installer verified 44 s
later and sat on "installs at the next safe moment" with its slot at minute 35; the project lead pressed Install now at
07:00:48Z. The slot staggers a fleet through a NEW publish; a machine that was off through the publish has
nothing to stagger. Now: published_at + 3,600 s <= engine start => slot_ok, logged once. The other safe-moment
guards (node synced, miner idle, boundary, network drop) are unchanged. manifest::unix_from_rfc3339 with tests.
For 0.3.12.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:13:51 +00:00
igneum-labs
a113557da2 prover: a segment record the chain rule refuses is held and offered again every pass until the segment's deadline (the fresh-record window on the 0.3.11 rule is one segment length in DAA); the tile counts held records; the fast-time file sets the fresh-rule switch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:03:46 +00:00
igneum-labs
6de4827ccb a job that cannot mine never burns its budget silently: the elevated job path follows its output file while the script runs (the 5-minute progress reports carry the lines; 0.3.12), and the tune playbook's watchdog fails a run that mines nothing within 120 s of its first status line (the engine's last log line in the RESULT, the tree ended, mining restored by the runner)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:03:13 +00:00
igneum-labs
85e7e8e527 app: order the GPU list by performance (usable, discrete before integrated, rate in 5 MH/s buckets, memory)
the project lead, 6 October 2026: on PC 1 the integrated card sat between the 5090 and the 9070 XT. The list now shows
usable cards first, ordered by the measured rate since the start in 5 MH/s buckets (no flicker), discrete,
external and Apple before integrated, then memory; removed and unusable cards last; ties keep the detection
order. The row signature follows the order, so a reorder re-renders. Three UI tests. For 0.3.12.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:23:25 +00:00
igneum-labs
3671918fb4 prover: segment-aligned work (proving v1): a free prover claims a whole segment, proves every shard from one export in one chain run, submits the shard records and the segment record; the host's chain mode takes --prev and writes per-shard records with --save-shards
One prover at 2.2% coverage never had 8 consecutive proven blocks (C47, 6 October 2026); claiming whole segments makes it complete about 1 segment in 75 instead of none. The choice is deterministic per key (FNV of first block and key hash) over the untouched whole segments inside their deadline by a margin (240 DAA or 1.5x the last segment's time); the per-block path stays as the fallback. Unit tests for the grid, the grouping, the margin, the attempted set and the per-key order; 120 app tests, 8 core and 9 host tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:12:23 +00:00
igneum-labs
3d505766d2 C35 named: PC 1's 22:31 UTC quit was the per-user installer launched by the second engine's own updater (0.3.9 under min_supported_version = urgent, beating auto_update = false); a second engine never runs the updater (IGNEUM_APP_NO_OTA=1, implied by --sweep; the playbooks set it; the CI check demands it); bench log and plan carry the named source
Source: the scratch engine's own log in collect ember-c35-collect-1 (06:59Z): 22:31:02Z '0.3.10 is available: downloading',
22:31:05Z 'update: starting the installer first ... ota-apply.ps1', and the installed app's 'quit:' at 22:31:06Z.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:01:57 +00:00
igneum-labs
42f36b3fd3 app: /api/state never answers {} again (paid_wei over u64::MAX broke to_value; the field is a decimal string, the error is logged once)
serde_json's to_value refuses a u128 over u64::MAX (18.45 IGN) and state_json turned the error into json!({}). A paid shard is 1.23 IGN on average, so a proving machine's dashboard went blank about 15 paid shards after every app start. Unit test over the boundary; 114 app tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 00:27:35 +00:00
igneum-labs
d69e1c9fae C35: every quit names its source (Cmd::Quit carries it: the window host's stdin, the host gone, POST /api/quit, the --sweep run's end); the --sweep job never counts as Power control and sets no cap at start (it raised a UAC prompt on PC 1 at 22:30 UTC); the tune playbook's budget quit goes only to its own scratch URL file and says so
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:53:32 +00:00
igneum-labs
794e23c5ac ember: the AMD helper's gmax range is an offset from stock (PC 1's 9070 XT: -500 to 1000), not MHz: the clock knob stays closed on an offset range and the power ladder is bounded by plimit_range (-30 to 10) on a percent scale
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:43:43 +00:00
igneum-labs
123838199f Igneum Miner 0.3.11: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:40:42 +00:00
igneum-labs
a2f08e3f70 prover loop: a PermissionDenied from the host names the root-owned GPU-server socket and the fix (the root-socket class); the plan's two times
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:38:22 +00:00
igneum-labs
9f6a4ebc65 App: every worker gets --prepare-packs in the platform's path form and runs with the app data folder as cwd (program class v3: the Metal worker compiles v3 only from a prepared pack; the Macs would have answered need lines at the first v3 epoch)
cargo test --release -p igneum-app under the build lock: 113 + 27 + 8 passed, 0 failed (the prepare_packs_tests,
resume_tests and provedefault tests among them).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:22:44 +00:00
igneum-labs
c4da08d302 App: the resume path re-arms every stopped card, re-exports its pack and checks 90 s later that every enabled card mines (PC 2 at 21:25:11Z and the Mac that afternoon stayed at 0 MH/s after resume); the PC 2 socket-fix job
The known-failed case, from PC 2's 0.3.9 log (run win-1ccfe586-20261005-200114): 1791234223 pause -> 'stopping the
miners (paused)' (every slot's restart_at cleared, the 5090 'off'); 1791235511 '[ok] mining resumed'; then
'0.00 MH/s, waiting' at every 30-s status line until the 0.3.10 restart at 21:49:41Z. Cause: Cmd::Resume re-armed
only slots whose watchdog said faulted; the 5090's slot was healthy and stopped, so nothing restarted it. The test
the_pc2_resume_of_21_25_11z_restarts_under_the_new_rule_and_not_the_old encodes that slot (faulted false, live
false): the old rule returns [] (the defect), the new rule [0]. cargo test -p igneum-app resume: 3 passed;
provedefault: 6 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:56:20 +00:00
igneum-labs
5c808b89e0 Ember Tune: every card tuned for MH per watt out of the box, the fleet prior per card model in the signed manifest, the console and /miners priors table
the project lead, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (423936b, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (057f0ec). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.

- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
  (power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
  neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
  the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
  no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
  no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
  probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
  tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
  Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
  {json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
  control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
  query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
  switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
  median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
  make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
  tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).

Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt the project lead cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:25:09 +00:00
igneum-labs
d7c28ec695 prover loop: the CPU path is refused under 32 GB of RAM on every OS with the measured reason, and its tile line names the cost (consequences C22)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:12:37 +00:00
igneum-labs
5424c30bba Proving v1: the app's default restores Decision and gb (lost in the tier rewrite), the AMD-only and Apple 'mines and does not prove' line with the CPU prover's measured cost, the plan's AMD/Apple row
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:03:42 +00:00
igneum-labs
1aff0b79d1 Proving v1: the miner-on curve (the adopted shard 22.2 GB and 13.2 s beside the miner; the prototype 30.1 GB): the 24 GB tier measured, the public lines updated
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:55:54 +00:00
igneum-labs
894022b926 Proving v1: the tiers from the S_p curve (24 GB proves the adopted shard, 32 GB mines and proves the prototype one, 12 and 16 GB off on this build) in the app's default, the litepaper, evidence rows 15 and 16 and the plan
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:45:01 +00:00
igneum-labs
192aa3b83c app: Power control setting (default off): the app never asks for administrator rights on its own
the project lead, 5 October 2026: "if we don't have to ask then don't ask". The NVIDIA power cap and the efficiency sweep need
administrator rights (one UAC prompt); PC 1 raised that prompt for cmd.exe at every app start and every sweep attempt
(17:00, 17:30, 18:12, 19:04 UTC today, each cancelled unanswered after 2 minutes; the "Windows Command Processor"
the project lead saw).

- config.rs: `power_control` (default OFF on every machine); `sweep` default becomes off and is implied by it (an
  install carrying sweep = true without power_control is migrated to off on load).
- engine.rs: `elevation_allowed(power_control, sweep_only)` gates the power cap (`power_cap_plan` builds nothing when
  off, the card note says so), the sweep scheduler, Sweep now, the sweep helper; no prompt on quit (the limits reset at
  the next reboot); no second prompt through PowerShell when the window host's prompt goes unanswered.
  Cmd::PowerControl(on): on = ONE prompt at that moment (every NVIDIA cap in one step), off = nothing asks;
  `power_control_after_prompt` turns a refused, cancelled or unanswered prompt into "power control off:
  administrator rights were not given" (switch back off, sweep off, no retries). Unit tests: off builds no elevated
  command; on + refusal gives the notice; rights given keeps it on.
- platform.rs: `elevated_failure` maps the launcher's exit 251 and the "canceled" wording to the prompt, any other
  code to the step itself.
- server.rs: POST /api/power/control {on}. ui: the Power control switch with the line "Windows asks for administrator
  rights once; the cap and the sweep need them", the note beside it, the sweep switch disabled while it is off.
- The clock-sync prompt stays behind the Sync clock button only (unchanged).
- tools/windows/power-prompts-off.ps1: the 0.3.9 job that switched PC 1's sweep off through the API it has
  (run-20261005-192313: sweep True -> False; the 0.3.9 cap has no off switch, it asks at an app start only).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:33 +00:00
igneum-labs
fe852a4335 AMD telemetry: igneum-gpu-telemetry (ADLX on Windows, amdgpu sysfs on Linux, PDH utilisation fallback) feeds the card row's draw, temperature, fan, memory clock and MH/W; measured on PC 1: 9070 XT 198.9 W, 64 C, 657 rpm, 17.73 MH/s = 0.089 MH/W beside the 5090 at 307.6 W, 122.30 MH/s = 0.398 MH/W
the project lead watched the 9070 XT at 90% usage with its fans barely turning and the app could not say what it drew: the
draw, temperature and MH per watt line came from nvidia-smi only, and the earlier per-watt figure used the board
rating. proto-opencl/gpu-telemetry.c prints one line per AMD card per sample (bus from SetupAPI by the display
device's name, kind, name, watts, temp_c, fan_rpm, fan_pct, mclk_mhz, gclk_mhz, util_pct, source), built by
build-windows.sh against vendor/adlx (the SDK clone), shipped by make-payload.sh and push-inputs.sh. The engine
runs it with -l 5 beside nvidia-smi (Source::AmdTelemetry, tick_amd_telemetry), parse_amd_telemetry fills
power_w, temp_gpu, fan_pct, fan_rpm, mclk_mhz, util_pct and telemetry_at on the AMD card matched by kind and
ordinal, so eff_mhw and the dashboard's existing line show it; app.js shows fan and memory clock when present.
Tests: three on the parser with lines captured on PC 1 and the Mac fixture; the sysfs path ran on a fixture tree.

Measured over 20:27:45 to 20:29:41 UTC with both cards mining (docs/bench-log.md, under the 9070 XT ceiling table):
9070 XT 198.9 W (193 to 212), 64 C, 657 rpm, 2,505 MHz memory, 3,290 MHz shader, 100% busy, 17.73 MH/s =
0.089 MH/W; RTX 5090 307.6 W, 69 C, 44% fan, 122.30 MH/s = 0.398 MH/W.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:21 +00:00
igneum-labs
344cba8e8c Proving v1: the memory sweep and the miner-on peaks, the root-socket class fix (cleanup lines, tools/ci/prover-socket-check.sh in CI), the host's --budget re-plan and the S_p curve job, the RAM and aggregation-card gates, N = 8 in the fast-time file and spec 7.4
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:35:13 +00:00
igneum-labs
340d7f4cd7 Proving v1: the decisions (N 8, T 600, a tenth to the aggregator, H = tip + 14,400, no sortition, Apple off) with the other networks' rules read tonight; the profile rows wait for the sweep
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:22:32 +00:00
igneum-labs
55ea10cc26 Proving v1: prover on by default, the aggregated segment record, host modes chain, aggregate and verify-segment, the app's aggregator step, spec 7.8, the fast-time harness and the coverage tool
Step 1: app/igneum-app/src/provedefault.rs decides once per install (NVIDIA 12 GB or more, WSL2 answering on
Windows, Linux native, Apple silicon off until measured), never switching an explicit on back off; the Settings
switch line and the tile line say why (5 unit tests). tools/proving-v1/pc2-prover-cost.ps1 is the PC 2 job
(5 min mining alone, 5 min with the prover, GPU memory and host RAM peaks, the sp1-gpu-server's SM targets).

Step 2: the host gains --mode chain (consecutive fixtures, each block aggregated with the previous block's
proof by recursion), --mode aggregate (the live aggregator over shard proof files, a run of blocks in one
process) and --mode verify-segment (the node's verifier against the pinned aggregator key); the app's prover
loop gains aggregate_once (spec 7.8). Eight consecutive live fixtures (blocks 81046 to 81053, node 1's export
at tip 81076) under proving/fixtures/chain/. tools/proving-v1/pc2-chain.ps1 is the PC 2 job (held).

Steps 3 and 4: tools/proving-v1/coverage.mjs (the proven-block share and the on-chain latency from one node's
RPC), tools/proving-v1/net.mjs (the fast-time 3-node harness on 29950+ with the known-finished and
known-failed cases of the chain rule and the unproven rule), the four proving_v1 fields in
infra/fast-time/override-60x.json. Spec 7.8, the 7.4 rows, the 5.3 sentence, docs/plans/proving-v1.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:04 +00:00
igneum-labs
a0864f0842 engine: one pack export at a time (EXPORT_LOCK around both export-pack call sites; the hunk of opencl-rdna4 23810df, whose other changes conflict with gpu-hotplug and wait for the next cut)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:23:59 +00:00
igneum-labs
d5da02a851 Merge pack-loop (4163143) into release-0.3.10: a pack's seed words are its program attempt's words, not the bare seed's (the epoch 34 outage)
# Conflicts:
#	relay/test/parse.test.mjs
2026-10-05 19:23:59 +00:00
igneum-labs
18f244bcfb Merge miner-ui-2 (6acfaed) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
cbe031b39c Merge gpu-hotplug (bd21f2a) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
41631431c0 Workers: a pack's seed words are its program attempt's words, not the bare seed's (epoch 34 incident, 5 October 2026)
From 18:23Z both Windows workers (CUDA on PC 1 and PC 2, OpenCL on PC 1 after the 18:34Z node restart)
refused every pack for epoch 34 with "the epoch seed bytes do not give the pack's IGNEUM_SEEDW_INIT", and
the miner and the app restarted them every 5 to 60 s until 18:44Z and beyond. The packs were correct.
The generator retries a rejected candidate with seed || k_le32 (attempt_words); epoch 34's attempt 0 was
rejected (246 of 16384 final register values saturated, limit 163) and attempt 1 accepted, so the pack
carried attempt 1's words while pf_load (proto-cuda/nvrtc/packfile.h) derived the expected words from
the bare seed. Both workers also matched jobs to pairs by those bare-seed words, so even a loaded pack
of a retried program would have answered "epoch seed mismatch" on every job.

The rule, in one place per language:
- packfile.h: pf_program_words(bytes, attempt); pf_load reads IGNEUM_PROGRAM_ATTEMPT and checks the
  attempt's words; the refusal says "program pack and its seeds disagree: IGNEUM_SEEDW_INIT is not
  attempt N of the epoch seed ..." in plain words.
- worker.cpp and proto-opencl/host.c: a job belongs to a pair when the seed hex the node sent is the
  pair's (pairIs); the compiled-in placeholder pack keeps the word comparison.
- igneum-pow/src/packcheck.rs: verify_pack_texts / verify_pack_dir, the same rule in Rust; the miner
  checks every pack it writes with it before a worker sees it (vendor/igneum-node pack-loop branch).
  Tests pin the attempt vectors of epoch 34 on both sides (one vector, two implementations), that
  epoch 34 is attempt 1 and epoch 33 attempt 0, a known-good pack of a later attempt, a known-mismatched
  (out of date) pack, and self-contradicting packs.
- proto-cuda/nvrtc/emu/packfile-test.c (+ .sh, in CI): pf_load on a known-good attempt-1 pack, the
  checked-in attempt-0 pack, and the known-mismatched bare-words pack.

The app (app/igneum-app):
- watchdog.rs: PACK_OUT_OF_DATE_CODE 44, PackRebuilds (at most 3 pack exports per epoch, then the card
  shows the reason), pack_refusal (the worker's "error 0 pack" line and the miner's "PACK OUT OF DATE"
  line), pack_epoch_of; tests on the incident lines, known-good and known-mismatched.
- engine.rs: exit 44 exports the pack again before the restart instead of a blind restart, the strip
  says "program pack out of date, rebuilding", the card and the log name the condition; at the cap the
  card is marked failed with the reason and tries again in 10 minutes.

The relay (relay/lib/parse.mjs): PACK_MISMATCH; the card reads "pack mismatch, rebuilding (N refusals
in the tail, M restarts)" in `node tools/console.mjs machines` instead of a bare restart count; tests
on the PC 2 tail of 18:27Z and a healthy tail.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:10:07 +00:00
igneum-labs
6bf6af9533 Igneum Miner UI 2: six sections behind a rail (Mine, Prove, Rewards, Node, Updates, Settings)
The one long page becomes a rail with six sections, a thin top bar and the status strip under it; the setup
screens and the key sheet stay. Mine: one big start/stop, the numbers, one row per GPU with its switch, hash
rate, temperature and power. Prove: the switch with plain words, the counts, the verifier, the pinned ids.
Rewards: the address with one Copy, the key backup card, another address. Node: the plain lines, the consensus
digest, the next switch. Updates: the version, the jobs. Settings: one switch or slider per setting with one line
of help. Every function that existed is placed, none removed.

Engine (three small additions, each with a unit test): node.consensus_digest from the node's own line,
node.consensus_switches from the override file, proving.program_id and aggregator_id from the host's --mode id.
Hosts: the window minimum is 900 x 600 on both. UI tests: view.test.mjs (10) joins notices and update-card in CI.
Proof: docs/plans/miner-ui-2.md and the 19 screenshots under docs/plans/miner-ui-2/, taken from a build of this
tree running on its own port against the devnet.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:06:27 +00:00
igneum-labs
8831b53326 Merge elevated-exit (574eacc) into release-0.3.10: a refused, cancelled or timed-out administrator prompt fails the job with exit 251 2026-10-05 18:21:07 +00:00
igneum-labs
b36beeee5d Merge gpu-hotplug (bd21f2a) into release-0.3.10: cards re-enumerated every minute and on WM_DEVICECHANGE, one row per physical GPU, Code 43 cards marked, integrated GPUs off by default, the cards line in the console 2026-10-05 18:21:07 +00:00