Commit graph

24 commits

Author SHA1 Message Date
igneum-labs
735887a309 Ember Tune: every card tuned for MH per watt out of the box, the fleet prior per card model in the signed manifest, the console and /miners priors table
the project lead, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (35e3d26, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (652e848). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.

- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
  (power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
  neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
  the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
  no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
  no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
  probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
  tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
  Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
  {json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
  control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
  query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
  switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
  median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
  make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
  tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).

Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt the project lead cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:25:09 +00:00
igneum-labs
4295346a2c Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI
Fed by /api/explorer from the observer's tables. Latest blocks (hash, number, DAA, blue score, miner, txs, proof
records, time); a block's header, parents, children, mergeset, coinbase outputs, EVM transactions, shards, checkpoint
and certificate; an address's blocks, what they earned, vote keys and balance (eth_getBalance when EXPLORER_EVM_RPC is
set). Same tokens as live.html. vercel.json rewrites /block/:id and /address/:addr; the footer links the explorer; the
link checker skips template literals and resolves /api/<name> to its function. node tools/site-serve.mjs previews the
site with the functions in-process.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
35b103dd64 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
ebab129e04 Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
28a8c6dc44 ci: no conflict markers in tracked files (check + pre-push hook that also builds the site)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:45:09 +00:00
igneum-labs
81bf81e99c Public testnet launch, the public side: dl/public downloads path, site download buttons, HiveOS package, faucet
Downloads: packaging/ota/publish-public.sh publishes the current installers, the HiveOS package and the two signed
manifests into dl/public/ with no token in any URL, writes the four /public/ aliases as vercel.json rewrites and an
unsigned index for the site; publish-manifest.sh --public and ship-app.mjs --public run it on every release (dry run
and self-test cover it). Nothing removed from the token folders.

Site: the miner and wallet buttons link the public aliases and show the version and size from the index, read at
build time (site/downloads.json is the offline snapshot); TESTNET_OPEN in build.mjs drops the "Public testnet: not yet
open" line on the go; the HiveOS Flight Sheet install line on the miner page; /faucet page.

HiveOS: igneum-hive-0.3.8.tar.gz from the 0.3.8 node (2b6d23ef, PC build job) and the zig-built Linux workers.

Faucet: site/api/faucet.mjs (10 IGN per address and per IP per day, Neon table faucet_grants, EIP-1559 transfer signed
by site/lib/eth.mjs with no dependencies: keccak, RLP, secp256k1 with RFC 6979), FAUCET_KEY and FAUCET_RPC from the
Vercel env only; 15 unit tests with a fake database and node, run in CI.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:31 +00:00
igneum-labs
33743d0751 Merge branch 'update-popup' into release-0.3.8
# Conflicts:
#	.github/workflows/ci.yml
2026-10-05 13:14:52 +00:00
igneum-labs
08bb0dc047 Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
9fc1486e6d Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
36fe6a90ae Miner app 0.3.7: the update card, one centred card over the window for an update
The strip under the header stays; the card is the first sight of an update. The mark with a progress ring, "Igneum
Ember 0.3.7", one line (is available, is downloading with the percent, is ready to install, Installing. The app
restarts itself., did not install with the one-line cause and Try again), up to three lines of release notes from the
manifest with the rest behind "What changed", the size, Install now and Later. Escape and the backdrop are Later.
Reduced motion is honoured.

Rules (UpdateCard, pure, app/igneum-app/ui/update-card.test.mjs): the card never opens while a job runs, in the
engine's first 60 s, while the key sheet is up or while the app quits; it waits and comes once the block lifts.
Later hides this version at this stage and leaves the strip; the card comes back for a newer version, or when the
download is ready and automatic updates are off (with them on it installs by itself). An open card follows its
update through downloading, ready, installing and failed; installing and failed never open a card by themselves.

?update=<kind>[&auto=0][&card=1] and ?uptime= on the page show every state without an engine. CI runs the new test
file next to notices.test.mjs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:33:17 +00:00
igneum-labs
8b3140ce74 Merge app-ui (the notice strip) into update-popup 2026-10-05 09:15:50 +00:00
igneum-labs
9014a111a1 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
20bf44cdbb Merge rotation-2 (d5986d2) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
849d0dff85 Merge app-ui (e936d0f) into release-0.3.6: one notice strip under the header; CI runs both the wake and the notice tests 2026-10-05 08:32:52 +00:00
igneum-labs
df1064f63d Merge origin/testnet-adopt (2267d95) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
baa109d647 relay: /wake long-poll for the apps' remote jobs (public GET held 45 s, authenticated POST of the stamp)
GET /wake?since=<stamp> is public (the apps hold no token) and rate limited (30 a minute per IP). It holds up to
45 s, re-reading the stamp every 2 s, and answers {stamp, at, added, changed, held_ms} the moment the stored stamp
differs from since, else the unchanged stamp at the deadline. POST /r/<token>/wake {stamp, added} (the relay's
auth, also x-relay-token or x-igneum-key on /wake) records a stamp; one row per stamp in relay_wake, created by the
first POST. maxDuration 60 s for api/wake.mjs in vercel.json. api/relay.mjs is untouched.

The handler lives in lib/wake.mjs with its dependencies injected; relay/test/wake.test.mjs drives it with a fake
database, a fake clock and a fake sleep (the hold, the change, the deadline, the rate limit, the hold cap, auth, a
database error). CI's site job runs it with the other relay tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
e936d0fb28 Miner app UI: one notice strip under the header replaces the three stacked banners (updates, jobs, clock)
One notice at a time, the most important first (app/igneum-app/ui/app.js, Notices; pure, unit tested):
  0 update installing, urgent or failed   1 job failed   2 clock   3 job running
  4 update available, downloading, ready, waiting for permission, manual   5 job done   6 updated
Lower notices wait their turn. Every notice has a close control; closing hides that notice's key until the
state moves on (a new status, version or job id).

States and their rules:
  update available      "Igneum Miner X is available." Install now, Later. Key update:X:pending.
  update downloading    "Downloading Igneum Miner X: 43%." (no percent when unknown), progress bar; same key as
                        available and checking, so Later hides the whole download until it is ready.
  update checking       "Checking Igneum Miner X." (the engine's staging step).
  update ready          "Igneum Miner X is ready. It installs by itself at a quiet moment." (auto on) or just
                        "... is ready." Install now, Later. Key update:X:ready.
  update waiting        Windows, nobody answered the administrator prompt: "... is waiting for permission. It
                        installs the next time someone is at this PC. Mining continues."
  update manual         "... is downloaded. Open it and drag the app over the old one." Open the download.
  update installing     "Installing Igneum Miner X. The app restarts itself. Mining continues until then."
                        (on a Mac, where the engine quits at once: "The app restarts itself in a moment.")
                        Also while the engine says "installing now" after Install now.
  update urgent         the engine's consensus-deadline text, ember, downloading percent when it downloads.
  update failed         "The update to X failed." plus one line of cause and Try again; rolled back:
                        "Igneum Miner X did not stay up and was rolled back." A dev build with no manifest
                        configured shows nothing (Settings still says it).
  updated               "Updated to Igneum Miner X from Y." Gone 60 s after the new version started.
  job running           "Job: <title> running, N min. <Stage>." with the last RESULT line underneath.
  job done              "Job: <title> done after N min. Report uploaded." Gone after 5 minutes.
  job failed            "Job: <title> failed after N min, exit C. Report not uploaded." plus the first error
                        line (BUILD FAILED / error / failed / panic among the result lines, else the summary).
                        Stays until closed. Timeout and aborted are "hit its time cap" and "was stopped".
  clock                 as before: the engine's words, Sync clock, the manual hint; on the setup screens only
                        (the node card carries it on the dashboard). Jobs show on the dashboard only.

Layout: the strip reserves no height while empty; when a notice appears or goes, main's top moves once with a
150 ms transition (none under prefers-reduced-motion). Existing tokens only, nothing newer than 2022 CSS.
Screenshots: ?update=<state> as before, ?job=running|done|failed added (packaging/ota/README.md).

Test: node --test app/igneum-app/ui/notices.test.mjs (ordering, dismissed keys, wording, the 5-minute and
60-second timers); added to the CI site job. Built once with cargo (include_str) and checked against the
ui-mock scenarios and a scratch engine instance (IGNEUM_APP_DATA in a temp dir, fake worker).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:16:29 +00:00
igneum-labs
d5986d253c Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
911e78586f Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
38e8db2ec3 Relay: secrets compared in constant time (relay/lib/auth.mjs, unit test in CI), HSTS header, tools/relay.mjs prints /r/<token> in list and watch (round 4, X28 and X24 part)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:31:22 +00:00
igneum-labs
235823b23d Bug hunt: console cards for other/intel workers and a stale mark on old STATUS lines (relay/lib/parse.mjs + test in CI); publish-jobs verifies the live file with retries and named reasons, a verify command, a failed deploy stops, a collect command without $_ is refused; the dl token masked in printed URLs; docs/bugs.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:15:05 +00:00
igneum-labs
48ce378881 Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:52:45 +00:00
igneum-labs
bd4a64d559 Windows CI: the one-click app built on GitHub runners, no PC needed
windows.yml: parse job (every .ps1 through the Windows PowerShell 5.1 parser with a negative fixture, PSScriptAnalyzer
as warnings, parenthesis check of every .bat/.cmd with a negative fixture), build job (engine on the MSVC target,
window host through BUILD-APP.bat as it is, payload through make-payload.sh in Git Bash, installer through
build-installer.ps1, smoke run of both exes, launcher DRY_RUN, three artifacts for 90 days).
push-inputs.sh publishes payload-inputs.zip (node, miner, workers, NVRTC DLLs) to the downloads host from the Mac;
fetch-ci-artifacts.sh pulls the green run's installer and payload back into the downloads folder.
Host: --version and --help, version.h shared with host.rc. Launcher: DRY_RUN=1 prints the plan and starts nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:32:20 +00:00
igneum-labs
89bdb899c6 CI on every push: igneum-pow tests, census build, simulator quick modes, site build + link check, identity grep
GitHub Actions workflow (.github/workflows/ci.yml) on push and pull_request with three jobs on the free runners:
igneum-pow `cargo test --release` and the igneum-census build; the two Python simulators' --quick modes under a
120-second timeout; the site build, an internal link check of site/*.html (tools/ci/link-check.mjs) and a gh-free
identity grep of the public export list (tools/ci/identity-check.sh over tools/ci/forbidden-strings.txt: machine
names, LAN and overlay addresses, home paths, local time zones, the log-intake key pattern; never a key or a name).
The node fork is too big for CI today and the workflow says so.

sim/finality_v2.py --quick is now a genuine smoke run (one day or hour per scenario, one partition and one eclipse
setting): 149 s at nice 19 on a loaded Mac, was 745 s. sim/difficulty/sim.py gains --quick (up50 and warmup-hard,
kaspa and igneum controllers, 36 s). One bench-log time-zone label reworded so the identity grep passes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 09:57:34 +00:00