Commit graph

51 commits

Author SHA1 Message Date
igneum-labs
5db7932177 Public text: the era draw and the reserve are schedule changes, not chip defences; the FPGA ceiling is unmeasured; the stake sentence; the proving arithmetic (Horizon lanes 2 and 7)
From the Horizon lane analyses of 6 October 2026 (docs/analysis/horizon/algorithm.md sections 5.1, 5.4 and 8;
docs/analysis/horizon/frontier.md sections 3.11, 4.1 and item I13; both land with the lane's own commit).
(1) Wherever the litepaper or the home page implied that the hourly program, the era draw or the instruction reserve
defeat a chip by surprise (the hero SVG line, the home hourly-program note, the Mining section's three ideas, the
"Every six months" row, the "A chip is impossible" item), the text now says what holds: they are automatic schedule
changes against fixed datapaths and against human forks; a chip wired for one program is useless; against the chip
that stores the dataset every drawn parameter is firmware and everything it needs is public at genesis, so the defence
is the latency-shadow work (class v4) and the price per joule. Ledger M32.
(2) docs/analysis/chip-model-v3.md section 5.3: the HBM activate-bound ceiling (8 per 12 ns, 10.7 G reads/s a stack)
is marked UNMEASURED beside the JEDEC HBM2 figure (tFAW 28 ns, 4 activates: 2.3 G), and the public FPGA line carries
only the measured row (Shuhai, FCCM 2020: 2.4 G reads/s, 0.30x to 0.39x of the RTX 5090 per watt) until an AWS F2
hour measures the ceiling. Ledger M33.
(3) The finality section's "What is not here" paragraph and the glance table's Finality row carry, verbatim: "No coin
is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window,
and equivocation strips it for 30 days." Ledger F26.
(4) "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September
2026 tracker cost (a secondary source) against about USD 13,700 a day of year-1 emission at USD 0.005 per IGN (the
price an input, not a forecast), so external proving is a small second income at launch and the lottery pays the
bills. Ledger E19.
docs/fud-ledger.md gains the four rows (Conceded, stated, 6 October 2026); site/ledger.html regenerated (171 entries);
tools/ci/ledger-text-check.mjs carries the five new stated sentences (48 sentences, 0 missing).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:49:15 +00:00
igneum-labs
a0a7d60902 Site: the two Windows machines are described, never numbered, on every public page; the identity grep covers the served site
Copy, from origin/master 0a63474 (site audit). The home and miner pages named "PC 1" in the figure captions, the
page-by-page lead, two alt texts, the Ember Tune table title, the Ember row's source line and the home pill; they now
say "a Windows rig with an RTX 5090, RTX 4070 and RX 9070 XT" at the first mention on each page and "the Windows rig"
after. The generated pages carried the same names from the bench-log (80 on /bench, 7 on /evidence, the inlined
journey on the home page): site/scrub.mjs now maps PC 1 to "the three-card Windows rig (RTX 5090, RTX 4070, RX 9070
XT)" and PC 2 to "the RTX 5090 Windows rig", build.mjs re-scrubs the stored journey entries, two /bench anchors on the
miner page follow the renamed headings, and \bPC [12]\b joins site/forbidden-strings.txt so the build fails if a number
returns. The scrub also covers the audit's other page-leak shapes (a pid, 0.0.0.0:port, ~/.config paths, --rpclisten=),
which the bench page carried and which now fail the build if they return.
CI: tools/ci/forbidden-strings.txt's appended audit block sat on one physical line with literal \n text, so none of its
patterns was active; \bPC [12]\b is now a real line there and the identity check's export scrub maps the two machines
the same way (igneum-public/tools/sync.sh must carry the same two rules). The other four audit patterns moved to
site/forbidden-strings.txt, since the public export carries simulator schedule logs where a pid is a pid. The identity
check gains a second pass over every served file under site/ (html, json, txt, xml, webmanifest, css, js; not api/ or
the build scripts), unscrubbed, with both pattern lists; dl\.igneum is narrowed to the tokened path so the public
download buttons pass. Shown to fire on a page naming PC 1 (exit 1) and to pass on the tree (0 hits over 232 export
files and 32 served site files).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:38:13 +00:00
igneum-labs
b63be56016 Site UI 3: one design system, the live DAG module, the home page as one screen, the litepaper as a paper, every page on the shared tokens
site/site.css: the tokens of the miner app's third redesign in light and dark (a darker light-mode ember and molten for text
so every pair passes 4.5:1, checked by tools/ci/site-contrast-check.mjs), the type scale on Unbounded, Plex Sans and Plex
Mono, the nav with one primary, the footer with a System/Light/Dark control, cards, tiles, tables that scroll on a phone,
buttons, pills, notes, callouts, the state words, focus rings, reduced motion, print. Partials rebuilt; the head loads the
stylesheet and applies the stored theme before paint. Every page's own style block is reduced to its page rules.

site/live-dag.js: the shared DAG view for / and /live (docs/plans/site-ui-3.md section 6): blocks by header time and
miner lane, parent edges with the selected chain as one heavier path, blue lit, red dim, pending grey, proven filled,
checkpoint bands with their lock weight (locked solid, pending dashed), new blocks arriving with a glow, hover and tap
details in the ledger's words, wheel and pinch zoom of the window (30 to 300 s), a pause button, device-pixel sharpness,
a still frame under reduced motion; opts.mine marks the user's own blocks (the miner app embeds the same file),
opts.poll:false with dag.push(reply) lets a host feed it. Every pixel is a block the observer stored.

site/index.html: the one-screen story (what it is, the live scene with chain block, shards proven, last lock, vote keys and
hash rate as state words, three things a sceptic checks, the download, how it works, the wallet, the journey, economics),
every tick-list row kept, the chip model's numbers moved to the sceptic card, the testnet terms behind a chevron, the
scroll-reveal gone, the Open Graph set on the 1200 by 630 image, no horizontal overflow at 390.

site/litepaper.html: dark like the site with light on request, whole paper by default (the section mode kept, deep links
intact, print prints the paper), repository paths off the surface, the cover dated 6 October, the wallet at 0.1.4, the
roadmap's verifier figure aligned with the Mining section, the proof lag stated as measured (about 380 s against the 60 s
gate), the 0.3.6 plan dated with 0.3.14 stated, the two "tonight" placeholders said as not yet measured. Every ledger
sentence verbatim (tools/ci/ledger-text-check.mjs, 43 sentences).

site/live.html: the lane chart replaced by the module; "proven A/B in 10 min", "finality paused, last #N", "pending" for
"n/a"; the fee sentence true on both sides of DAA 210,000. site/metamask.html: its own canonical, the explorer linked, the
wallet's state said true. site/404.html: the page count and section count said true. site/build.mjs: the generated pages
on the system, each with its own eyebrow, the miners page's source notes as sentences. downloads.json refreshed from the
host (0.3.14). tools/ci/site-orphan-check.mjs: no site heading leaves one word alone at 390 px (log titles reported).

Checks: identity grep 0 hits, link check 854 links 0 broken, ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1,
no horizontal overflow at 390 on 14 pages (the wallet page's timed table overflows by 5 px, for the wallet-ui-3 owner),
orphan check 0 site headings (the miner h1 at 96 characters is the site-miner agent's copy). After captures beside the
audit's: docs/plans/site-ui-3-shots/after/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:27:47 +00:00
igneum-labs
39b5c94553 Ledger page: strip config and home paths, process ids, listen addresses, machine names and repository paths; the render fails on a leak
The public /ledger page (site/ledger.html) carried ~/.config/igneum paths five times, "pid 33114", --rpclisten=0.0.0.0:26610,
"PC 2" fifteen times, "the Mac" nineteen times and 202 repository file paths, because tools/ledger-page.mjs scrubbed with its
own short list and never ran the forbidden-strings hard stop (found by the site audit of 6 October 2026, docs/plans/site-ui-3-audit.md).

Now: the generator's scrub replaces every config or home-directory path with "a config file" or "a home-directory file", a pid with
"the process", a listen flag or 0.0.0.0 address with its plain words, "PC 1" and "PC 2" with "the Windows machine", "the Mac" with
"the Apple M5 Max" (the bench log's rule), and every repository file path with "a repository file"; the page's own source note
names no path. After rendering, the page is grepped with tools/ci/forbidden-strings.txt plus the leak classes and the render
exits 1 on a hit. The pattern list gains ~/.config, pid N, 0.0.0.0:port, PC 1 and PC 2 and --rpclisten=, and the identity grep
now covers site/ledger.html (html added to its file types). Regenerated: 167 entries, 0 leaks, identity grep 0 hits over 231
files, link check 0 broken.

Consequence per reader: the ledger keeps every criticism, status and answer; what a reader loses is the exact repository path
of a fix, which meant nothing outside the private repository. Nothing else on the site changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:07:20 +00:00
igneum-labs
f17826bd17 Site: the downloads snapshot is written only on SITE_DOWNLOADS_REFRESH=1 or in CI; a CI check against scripts writing into other worktrees
On 6 October 2026 the pre-push hook's site build fetched the live downloads index (0.3.14 since 17:47Z) and rewrote site/downloads.json and the stamped pages in five worktrees that had nothing to do with the release, as uncommitted edits to tracked files. A plain build and the hook now read live and warn when the snapshot lags; the ship step refreshes it with the flag and commits it. tools/ci/no-foreign-tree-writes.sh fails a script that builds a path from a worktree name, a glob over Projects or a worktree-list loop that writes; the eight absolute defaults into the shared checkout are listed as warnings until they move to env-only defaults. The journey, bench and index rebuilt from the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:19:58 +00:00
igneum-labs
a20d238fac Merge release-0.3.14: Igneum Miner 0.3.14 (exec-sync deep-reorg reload, miner-ui-3, ember-tune), publish 1 on the thirteen-field object
The node pin moves to 4c6b129d (release-0.3.14-node), which is what the live payload inputs carry, so windows-ci's payload-inputs step is green again (red since e9eca23 on master's 0.3.13 pin against the 0.3.14 inputs).
Conflicts: infra/fast-time/override-60x.json keeps master's side (the fresh-rule field was already there at u64::MAX; the release line would be a duplicate key); tools/ci/playbook-quit-check.sh keeps master's rule 2 and pre-rule list with the release side's Ember allow entry and the 0.3.15 expiry check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:18:17 +00:00
igneum-labs
1e8d6e5deb tools/ci/playbook-quit-check.sh: the executable bit back (lost in the rebuild on master's text) 2026-10-06 18:12:30 +00:00
igneum-labs
c6486f3132 Merge commit '141b559' into ca3-pc1-amd
# Conflicts:
#	app/igneum-app/src/engine.rs
#	tools/ci/playbook-quit-check.sh
2026-10-06 18:10:29 +00:00
igneum-labs
8b9edccff8 Counter ASIC 3.0 PC 1 AMD: the runner owns a job's card switch: --cards-off <key,key> (matched with or without the device index, switched through the app's card path before the script, restored exactly on any exit including the app quitting; report lines; two tests, igneum-app 114 of 114 on igneum-build-1); playbook-quit-check rule 2 fails any script that requests api/cards (pre-rule playbooks on a dated allow list)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:07:52 +00:00
igneum-labs
141b559b82 Merge origin/master into ca3-coord: Counter ASIC 3.0 complete (every gate green, P2 green, P1 written); the drive-ref check skips single-quoted here-strings and the copied-sources check reads code lines only (master's CI red on dbdfda0); main's decisions and the close in the status file 2026-10-06 18:05:54 +00:00
igneum-labs
aed5ca9bd7 Build server adopted: box-first build rule in CLAUDE.md, reproducible Windows exes, the commit-string gate, PC and Mac recipes
Main's decision of 6 October 2026. CLAUDE.md 'Running agents on this Mac': every Linux and Windows cargo build and every
Linux test suite goes to igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh; the PCs keep GPU and
Windows-runtime jobs; the Mac keeps macOS binaries, the DMG and Metal tests under the lock. -Wl,--no-insert-timestamp in
cross-remote.sh, proto-cuda/windows-node/cross-build.sh and jobbuild.rs (two box builds byte-identical, verified).
The empty-commit class: tools/ci/commit-string-check.sh (self-test in ci.yml, shown firing on a Mac worktree build and
passing on a box build) runs on every igneumd from the three build scripts; push-build-inputs.sh adds node.commit_full,
the PC job writes a minimal node/.git from it at extract and cleans kaspa-build-info on a new commit (4 jobbuild tests
pass, run on the box); cross-build.sh refuses a worktree and cleans on a new commit. Plan: second worktree's clean build
1 min 18 s with sccache 604 hits of 993.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:50:39 +00:00
igneum-labs
020ea6b3e3 Counter ASIC 3.0 PC 1 AMD: the family script's probe parameter renamed (the automatic unbound-arguments variable shadowed it, so nothing was splatted); the CI check gains the rule 2026-10-06 17:12:18 +00:00
igneum-labs
15b315e503 Counter ASIC 3.0: the identities job's ${appDir}: fix and the class guard tools/ci/ps-drive-ref-check.sh in CI (a $name: inside a double-quoted string is a PowerShell 5.1 parse error; backtick-escaped dollars ignored) 2026-10-06 17:03:32 +00:00
igneum-labs
97cb9830b1 playbook-quit-check: the three allow entries expire at 0.3.15 (the check fails the tree at 0.3.15 or later while they stand)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 16:55:49 +00:00
igneum-labs
8ec1ad3ed2 playbook-quit-check: ember-tune-pc1.ps1 and the two agg-cost playbooks allowed under a dated note (the coordinator's 15:30Z ruling; pending --stop-miners and the Ember playbook's rewrite)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 16:55:27 +00:00
igneum-labs
e925b20f7c Counter ASIC 3.0 gates (node): class v4 = mx8+sh256x27 through the stack (igneum-pow ProgramClass::V4, V4_CLASS, generator 4, program_id(4, seed, attempt), the era composed as v3's; program.h and program.json class v4; packcheck, packfile.h, the CUDA and OpenCL identity rule and the Metal worker accept generator 4 and the class=v4 token, the Metal worker takes v4 from the prepared pack only; v2 and v3 byte-identical, the pinned packs diffed); the G4 harness class-v4.mjs (two switches, the never case); override-60x.json: the v4 field at never, the duplicated proving v1 block removed, the four 0.3.12/0.3.13 fields added; CI check override-json-check.sh (no duplicate key in any override file)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:58:49 +00:00
igneum-labs
7ed0d75160 A card never shows 0 MH/s without a reason word (the project lead, 6 October 2026, watching PC 1 during the table run): the Mine row reads 'tuning: step k of n · measuring W W' with the live rate, 'held for a remote job: <title>' while a job holds the miners, and the Tuned line at the end; the big button reads 'Tuning, mining again in about N min'; the strip carries one tune line; a measurement engine prints a TUNE progress line every 10 s and the playbook forwards it (and TUNE chosen as done) to the installed app's POST /api/tune-progress, a post of state, never quit, pause or resume; the rule in ember-tune.md 6a; UI tests for the three states
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:36:07 +00:00
igneum-labs
452d74c3c2 playbook-quit-check: the ruling of 6 October 2026 15:30 UTC (a job script never pauses or resumes the installed app's miners, not even as a fallback; --stop-miners is the way): the two agg-cost allow entries dropped, so the gate names tools/proving-v1/pc2-agg-cost.ps1 and pc2-agg-cost-restore.ps1 until they move to --stop-miners
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:05:37 +00:00
igneum-labs
e9e1042fc9 playbook-quit-check: pc2-agg-cost.ps1 and pc2-agg-cost-restore.ps1 allowed pending the rule owner's word (they pause and resume the installed app as the fallback of a card switch)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:04:35 +00:00
igneum-labs
f225ccf842 run 4's cause: the playbook's PowerShell JSON round trip rewrote the copied settings (big integers as doubles), the engine read the file as defaults (no payout address, every card off, 96 old remote jobs run in the scratch root). Fix: the copies are verbatim and a --sweep engine applies Settings::for_measurement in memory (remote jobs, updates, proving and Power control off, not paused, tune on, every card due and unpinned); the CI check fails any playbook that rewrites settings.json through ConvertTo-Json; unit test
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:21:06 +00:00
igneum-labs
280631fbc6 tools/ci/playbook-quit-check.sh: the standing rule of 5 October 2026 23:05 UTC as a gate (a playbook that reads the installed app's URL file and sends quit, pause or resume fails; the installer's own stop step is the one allowed sender; self-test on a bad and a good case); shard-test.ps1 loses its api/quit to the installed app; ember-tune-pc1.ps1's refusal guard reworded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:52:08 +00:00
igneum-labs
27c2db64c3 app: every elevated launch through one hidden-console builder; CI check for Windows spawns; PC 1 console watchers
The console-window class (the project lead, 5 October 2026: "Windows Command Processor" windows on PC 1 whenever a remote job runs).
Measured on PC 1 (ae432dc7, Windows 11 Pro 26200, default terminal "Let Windows decide" = Windows Terminal 1.24) with
tools/windows/console-watch.ps1 (job run-20261005-182528): no child a job script starts from the app's headless
console opens a window (powershell, cmd, query, curl, nvidia-smi, wsl --status, a distro, interop cmd and powershell,
powershell -WindowStyle Hidden: 0 windows each); Start-Process in a new console opens a Terminal window (the known-failed
case: 2 windows), the same with -WindowStyle Hidden opens none (the known-finished case). The elevated path
(Start-Process -Verb RunAs -WindowStyle Hidden through the AppInfo service) is the one road left; its watcher
(console-watch-elevated.ps1, job run-20261005-184610) was cancelled at the UAC prompt.

- platform.rs: elevated_ps_line + elevated_command build the one PowerShell line every elevated launch uses (the NVIDIA
  power cap, the sweep helper, the clock sync, an elevated remote job), -WindowStyle Hidden by construction; unit
  tests on the line, the quoting and the Command.
- jobrun.rs: the elevated job path uses it; the relaunch helper's Start-Process carries the reason it has no
  -WindowStyle Hidden (igneum-app.exe is a windows-subsystem program).
- tools/ci/windows-spawn-check.mjs (+ ci.yml): fails when a Command::new in app/igneum-app/src is not quieted,
  a creation_flags is not CREATE_NO_WINDOW alone, a Start-Process the Rust code writes lacks -WindowStyle Hidden or
  -NoNewWindow, or host.cpp spawns without CREATE_NO_WINDOW / SW_HIDE; self-test on known-good and known-bad samples.
- tools/windows/console-watch.ps1, console-watch-bg.ps1, console-watch-elevated.ps1: the watchers (run jobs).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:21:46 +00:00
igneum-labs
563463b35f Merge release-0.3.12 (fda4684) into ember-tune: 0.3.11's six-section View and card order kept, Ember Tune's line and switches re-added on it; the tune fields move into hotplug::apply_pref; the power-cap plan keeps present(); both CI test lists; 132 app tests, 26 UI tests, every gate green
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:20:46 +00:00
igneum-labs
d1705e0e1b playbooks: the scratch settings.json is written without a BOM (PowerShell 5.1's -Encoding utf8 adds one, the engine's JSON parser refuses it, the copy read as defaults with no payout address and nothing mined in runs 1 and 2); the address is read back and the job fails at once if it is empty; the CI check fails any playbook writing JSON with Set-Content -Encoding utf8
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:58:39 +00:00
igneum-labs
3d505766d2 C35 named: PC 1's 22:31 UTC quit was the per-user installer launched by the second engine's own updater (0.3.9 under min_supported_version = urgent, beating auto_update = false); a second engine never runs the updater (IGNEUM_APP_NO_OTA=1, implied by --sweep; the playbooks set it; the CI check demands it); bench log and plan carry the named source
Source: the scratch engine's own log in collect ember-c35-collect-1 (06:59Z): 22:31:02Z '0.3.10 is available: downloading',
22:31:05Z 'update: starting the installer first ... ota-apply.ps1', and the installed app's 'quit:' at 22:31:06Z.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:01:57 +00:00
igneum-labs
d19441c14d C35 class: a second engine gets no pipe (its output goes to a file the playbook tails) and its whole tree is ended at the end and on the budget; ember-tune-pc1.ps1 and sweep-5090.ps1 fixed; tools/ci/second-engine-check.sh fails any playbook without both; the rule in ember-tune.md
PC 1, 22:31 UTC: the installed engine's quit hung 24 minutes in the jobs runner's abort, waiting for EOF on the script's
stdout pipe whose write end the second engine and its miners had inherited (Process.Start with redirection inherits
every inheritable handle), while the orphaned miners mined on against the relaunched app.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:00:06 +00:00
igneum-labs
b584e41e31 CI on the merged 0.3.11 tree: MacBook reworded in the analysis prose (the identity check's hostname pattern), a presence check before the kit's first use in the three proving-v1 PC 2 scripts (C32), pc1-cpu-prove.ps1 on the socket check's allow list (the CPU path starts no GPU server)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:44:09 +00:00
igneum-labs
8ad50d119b Merge branch 'bash-body-check' into release-0.3.11
# Conflicts:
#	.github/workflows/ci.yml
#	tools/ci/prover-socket-check.sh
2026-10-05 22:40:22 +00:00
igneum-labs
75a56182b2 Merge commit 'a2f08e3' into release-0.3.11
# Conflicts:
#	docs/bench-log.md
#	docs/evidence.md
#	site/litepaper.html
2026-10-05 22:39:34 +00:00
igneum-labs
b2e6d6159e CI: run jobs test their fetched kit before use (the wiped-jobs-folder class)
The app's install clears the jobs folder on a PC, so a run job whose kit was fetched by an earlier fetch job finds
nothing after an update and fails in seconds (5 October 2026, 21:49Z, the AMD kit; bench-log 4df339f). Rule: a run
playbook that reaches a path under the jobs folder other than its own tests the kit is there before its first use,
and the fetch is republished under a new id after any app update.

tools/ci/kit-path-check.sh reads every *.ps1 under relay/playbooks/ and tools/. A kit root is a path derived from
the jobs folder (`$jobs = Split-Path $env:IGNEUM_JOB_DIR` then `Join-Path $jobs '<fetch id>'`, the race-5090.ps1
shape) or one carrying a literal `jobs\` (the amd-card-test.ps1 shape); every path built from it belongs to that kit.
A presence check (Test-Path, [IO.File]::Exists, [IO.Directory]::Exists, Get-Item or Get-ChildItem with -ErrorAction)
on the root or anything under it covers the whole kit. A use before that line fails with "kit path used before a
presence check: republish the fetch after any app update", as does a literal jobs\ path in a command with no check.
The job's own folder ($env:IGNEUM_JOB_DIR) is not a kit path.

Fixtures: kit-path-ok.ps1 (both shapes, checked; a sibling pack file covered by the worker's check) and
kit-path-unchecked.ps1 (the worker run before its check, a literal never checked); --self-test asserts the lines.
Wired into ci.yml after the bash-body step, and into publish-jobs.sh add --kind run beside the other two checks;
test-publish-jobs.sh gains the refusal (34 passed, 0 failed). The current tree: race-5090.ps1 is the one playbook
with a kit, checked before use. README-ship.md: the rule.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:37:29 +00:00
igneum-labs
2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
igneum-labs
a5533177d3 CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class)
Twice on 5 October 2026 a PowerShell job script carried a bash body inside a string, a quote was lost on the way
through PowerShell, and bash refused the body: pc1-cpu-prove.ps1 (first version) reported exit 0 having done
nothing, the 0.3.10 installer job failed in 4 s. tools/amd-prove/check-job-bash.sh covered only its own here-string.

tools/ci/bash-body-check.sh reads every *.ps1 under relay/playbooks/ and tools/, finds each bash body however it is
handed over (bash -c "...", bash -lc '...', bash -c $var, a + concatenation in parentheses, the Start-Process argument
list, a here-string written to a file that is later run with bash), unescapes it the way PowerShell would (backtick
escapes and "" in double-quoted strings, '' in single-quoted strings, here-strings verbatim; $var left as-is, a $(...)
subexpression replaced by ${PS_SUBEXPR}), and runs bash -n on it. One line per body with the file line of the error.
A body it sees but cannot read is "unextractable body" and fails too: a skip would be a hole in the class check.
bash 3.2 compatible; python3 for the extractor.

--self-test runs three fixtures under tools/ci/fixtures/: the correct shapes (8 bodies, must pass), the lost quotes
(the awk apostrophe, a dropped closing quote in a literal and in a variable; must fail with the line), and three
unreadable bodies (must fail). Wired into ci.yml next to the copied-sources check, self-test first. The current tree:
7 inline bodies in 3 playbooks, all parse. packaging/README-ship.md: the job-script rule (body to a file, bash <file>).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:38:41 +00:00
igneum-labs
54132959be Merge origin/master (the explorer pages, the public API check, the CLAUDE.md note) into release-0.3.10; docs, site, observer and ci.yml only 2026-10-05 21:32:17 +00:00
igneum-labs
344cba8e8c Proving v1: the memory sweep and the miner-on peaks, the root-socket class fix (cleanup lines, tools/ci/prover-socket-check.sh in CI), the host's --budget re-plan and the S_p curve job, the RAM and aggregation-card gates, N = 8 in the fast-time file and spec 7.4
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:35:13 +00:00
igneum-labs
84d6d28253 Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI
Fed by /api/explorer from the observer's tables. Latest blocks (hash, number, DAA, blue score, miner, txs, proof
records, time); a block's header, parents, children, mergeset, coinbase outputs, EVM transactions, shards, checkpoint
and certificate; an address's blocks, what they earned, vote keys and balance (eth_getBalance when EXPLORER_EVM_RPC is
set). Same tokens as live.html. vercel.json rewrites /block/:id and /address/:addr; the footer links the explorer; the
link checker skips template literals and resolves /api/<name> to its function. node tools/site-serve.mjs previews the
site with the functions in-process.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
48d987cfb4 Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check
The numbers profitability sites and pool software read (WhatToMine's form: explorer or pool with an API, the halving
schedule, a source for total coins). Reward and supply from the emission rule at the node's DAA score; the halving table
(33 rows), the 30-day ramp and the observer's coinbase check. Cached 10 s, CORS open. FIELDS in each handler is the
contract; public-stats.test.mjs checks it from a fixture, tools/ci/public-api-check.mjs checks a deployment.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
d905730d45 Merge c4-fix (3e129ee) into release-0.3.10: the certificate-driven reorg in spec 3.5, 3.2, 3.10, 3.11.7, ledger C4, bench-log; c4.mjs v2 mode; the signer never piped into head (signer-pipe-check); one build-inputs zip per job
# Conflicts:
#	docs/bench-log.md
2026-10-05 18:20:50 +00:00
igneum-labs
3e129eeb5c C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning)
Fork: vendor/igneum-node-c4 branch c4-fix on release-0.3.6 a24ab01a.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:17:36 +00:00
igneum-labs
a96bcea470 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
addeb660fd Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
974805b9df ci: no conflict markers in tracked files (check + pre-push hook that also builds the site)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:45:09 +00:00
igneum-labs
02b19ed761 Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
7f1884290a ci: the pinned-guests check ignores comment lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:01:38 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
aa9b4da932 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
7210fd4683 Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
713fb56cf4 CI identity grep: .log files get the generic scrub too; the 4 October difficulty record carried a home path (every master run red since c01b954)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:09:09 +00:00
igneum-labs
cdb9b3a734 Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:52:45 +00:00
igneum-labs
7717c4fdac Windows CI: the one-click app built on GitHub runners, no PC needed
windows.yml: parse job (every .ps1 through the Windows PowerShell 5.1 parser with a negative fixture, PSScriptAnalyzer
as warnings, parenthesis check of every .bat/.cmd with a negative fixture), build job (engine on the MSVC target,
window host through BUILD-APP.bat as it is, payload through make-payload.sh in Git Bash, installer through
build-installer.ps1, smoke run of both exes, launcher DRY_RUN, three artifacts for 90 days).
push-inputs.sh publishes payload-inputs.zip (node, miner, workers, NVRTC DLLs) to the downloads host from the Mac;
fetch-ci-artifacts.sh pulls the green run's installer and payload back into the downloads folder.
Host: --version and --help, version.h shared with host.rc. Launcher: DRY_RUN=1 prints the plan and starts nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:32:20 +00:00