Commit graph

32 commits

Author SHA1 Message Date
igneum-labs
7a1fb95cb5 Merge master into wallet-bridge (the wallet's line meets master for the landing of the page bridge)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	packaging/ota/publish-manifest.sh
#	site/index.html
#	site/wallet.html
2026-10-08 11:33:30 +00:00
igneum-labs
2de98ee98b Igneum Wallet 0.1.6: the page bridge (main's order of 8 October 2026: igneum.network/swap connected any injected wallet, the Igneum Wallet signed only inside its own window). The engine listens on a fixed loopback port, 127.0.0.1:26811 (src/bridge.rs, igneum_common::http::serve_on), beside its token-guarded window server; a page's provider (site/wallet-provider.js: window.ethereum when nothing is injected, window.igneum beside MetaMask, announced through EIP-6963) POSTs JSON-RPC there with the X-Igneum-Bridge header (a preflight first; the private-network allow header answered) and polls a request the window has to answer. Rules: a site is approved once (eth_requestAccounts raises a connect request; Approve in the window stores the origin in the settings, Decline or five minutes ends it with 4001); every other method from an unapproved origin answers 4100 and creates nothing; eth_sendTransaction (priced by the node: gas with the call's data, the fees, the balance check), personal_sign (EIP-191) and eth_signTypedData_v4 (EIP-712, src/eip712.rs, the specification's Mail vector) each wait as their own request, shown with the origin and the facts and confirmed in the window (Touch ID or Windows Hello when enrolled, the same gate as a send); after a transaction the card keeps the node's word and the checkpoint this wallet verified; reads go to the wallet's node for a connected site; wallet_switchEthereumChain accepts the wallet's chain and refuses another with 4902. Settings: a Websites card with the switch and the connected sites (Disconnect); the lock screen says which site waits. Known-failed first: a page without approval gets nothing (bridge::tests::a_page_without_approval_gets_nothing, the view and provider tests on build-2 before the files existed). Tests: bridge.rs (4), eip712.rs (3), tx.rs (the digest signer recovers), ui/view.test.mjs (the words), site/wallet-provider.test.mjs (5). Versions 0.1.6 in the three places; rust-toolchain.toml taken from master so cargo on the Mac reads the pinned 1.99.0.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-08 11:13:27 +00:00
igneum-labs
2552163340 release 0.3.14: merge ember-tune 8be7339 (the engine commits bb2bbe6, 692ce53, acc8de6 and the helper repoint: task_exe prefers the installed exe; a power step on a card with no limit readback is skipped)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	app/igneum-app/ui/app.js
#	app/igneum-app/ui/index.html
#	docs/bench-log.md
2026-10-06 16:54:36 +00:00
igneum-labs
c8fb4ec0b5 Igneum Wallet 0.1.5: the three version files (the 0.3.14 node and the thirteen-field consensus object bundled; the wallet's node peers again)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:56:07 +00:00
igneum-labs
7d6911031d wallet 0.1.5: merge release-0.3.13 (the 0.3.13 tree under the wallet app: igneum-common, packaged-config, the ten-to-thirteen-field objects)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	.github/workflows/ci.yml
#	.gitignore
#	docs/bench-log.md
#	packaging/README-ship.md
#	packaging/mac/packaged-config.sh
#	packaging/ota/publish-manifest.sh
2026-10-06 15:54:57 +00:00
igneum-labs
b8ef4c5747 Igneum Miner 0.3.14: the six version files (node-only: the exec layer survives a deep reorg and a moved pruning point)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:54:14 +00:00
igneum-labs
fc2ed67df5 The one approved Power control step on PC 1 failed with exit 1 (15:45:21Z, no cap applied, no helper registered): cmd.exe strips the first and last quote of a /c line that starts with one and holds more than two (two NVIDIA cards, or a cap plus the registration script); both launchers now wrap the line in one outer pair (platform::cmd_c_args, host.cpp runElevated), unit-tested; Ember 2: the memory clock set through nvidia-smi -lmc/-rmc (direct and through the helper's lmc/rmc verbs), the goal, the electricity price and the hill-climb switch in Settings and /api/tune/goal, the chosen point's memory clock and the measured curve on the card
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:48:14 +00:00
igneum-labs
2a8a0b3485 Igneum Miner 0.3.13: the six version files (node-only cut: the exec follower fix and the finality route fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 13:14:55 +00:00
igneum-labs
d60a8ad47f Igneum Miner 0.3.12: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:19:00 +00:00
igneum-labs
4fb9988677 Igneum Miner 0.3.11: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:40:42 +00:00
igneum-labs
a6c5662048 Merge miner-ui-2 (adab2bb) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
45c41702e1 Merge gpu-hotplug (bf76278) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
efb39eefbe Igneum Miner UI 2: six sections behind a rail (Mine, Prove, Rewards, Node, Updates, Settings)
The one long page becomes a rail with six sections, a thin top bar and the status strip under it; the setup
screens and the key sheet stay. Mine: one big start/stop, the numbers, one row per GPU with its switch, hash
rate, temperature and power. Prove: the switch with plain words, the counts, the verifier, the pinned ids.
Rewards: the address with one Copy, the key backup card, another address. Node: the plain lines, the consensus
digest, the next switch. Updates: the version, the jobs. Settings: one switch or slider per setting with one line
of help. Every function that existed is placed, none removed.

Engine (three small additions, each with a unit test): node.consensus_digest from the node's own line,
node.consensus_switches from the override file, proving.program_id and aggregator_id from the host's --mode id.
Hosts: the window minimum is 900 x 600 on both. UI tests: view.test.mjs (10) joins notices and update-card in CI.
Proof: docs/plans/miner-ui-2.md and the 19 screenshots under docs/plans/miner-ui-2/, taken from a build of this
tree running on its own port against the devnet.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:06:27 +00:00
igneum-labs
846835dc87 Merge gpu-hotplug (bf76278) into release-0.3.10: cards re-enumerated every minute and on WM_DEVICECHANGE, one row per physical GPU, Code 43 cards marked, integrated GPUs off by default, the cards line in the console 2026-10-05 18:21:07 +00:00
igneum-labs
7953be7820 Igneum Miner 0.3.10: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:01:00 +00:00
igneum-labs
df9e0a6dcf app: GPU hot-plug (re-detection every minute, WM_DEVICECHANGE on Windows), faulty cards listed with the problem code, integrated GPUs off by default, the card list in the console
5 October 2026: an RX 9070 XT went into PC 1 through a Sonnet USB4 box while the app ran and nothing noticed; the
app detected cards once at start. Now src/hotplug.rs compares every enumeration with the list (key, else vendor +
name when unique; a card whose tool did not answer is never called removed): a new usable card starts a worker,
enabled by default like a card at start, with "New card: <name>, mining" on the strip and in the log; a card
Windows lists with a problem code (Win32_VideoController Status / ConfigManagerErrorCode) is shown as "<name>: not
usable (Code 43)" with the reboot-or-reinstall hint and no worker; a card that disappears has its worker stopped
(quit, 8 s) and its row says removed for five minutes, then hides; an unchanged list touches nothing. The Windows
host sends "detect" on WM_DEVICECHANGE; the engine polls every 60 s (300 s on macOS, no GPU hot-plug there).

detect.rs: the Ryzen iGPU is "gfx1036" to the OpenCL worker, so the APU gfx codes count as integrated, plus the
adapter row's Intel processor string and a dedicated memory under 1 GB; integrated defaults to off with "integrated
GPU, off by default (2 to 3 MH/s for 30 W)" on the row, and the user's choice is kept across re-detections and
restarts (settings, found by key or by vendor + name when the index moved).

Console: the engine logs "cards: <name> [<kind>, <state>] | ..." at start, on every change and every 10 minutes;
relay/lib/parse.mjs reads it and the hot-plug events, the machines API and tools/console.mjs machines show them.

Tests: hotplug.rs (added, removed, moved, errored, recovered, revived, unchanged, twins, user override kept,
the console line), detect.rs (PC 1's adapter lines, the Mac, kind classification, the unusable row),
notices.test.mjs (card notices), relay parse.test.mjs (cards line). cargo test -p igneum-app: 91 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:45:05 +00:00
igneum-labs
3c5848069a Igneum Miner 0.3.9: the prover mirrors the fee switch (new pinned guest, shard id 0x2b1a81cb...), node a24ab01a (igneum_exportSegments names the mergeset and every entry's block and body position), the devnet fee-switch runbook; the six version files 2026-10-05 16:28:36 +00:00
igneum-labs
6c2eea7dfb Igneum Wallet 0.1.4: the lock screen; the Touch ID sheet on a tap, once by itself when the wallet opens; the idle lock's minutes
The lock screen (ui/lock-screen.js, pure, with lock-screen.test.mjs): the coin large on the ember glow, the name in
Unbounded, the short address in mono, one control. Touch ID enrolled in the app window: the fingerprint button, its
line, a quiet "Use password" that reveals the field in place (the control area keeps one height). Otherwise the
password field is the control. Locking is a 250 ms transition from the home screen, not a cut. The glow breathes;
reduced motion stops it.

No automatic sheet: it appears on a tap, Return or Space on the button (focused on arrival and when the window
comes back). One exception: the first arrival after the person opened the app, 600 ms after the lock screen is
drawn, when "Ask for Touch ID when the wallet opens" is on (new setting, default on). Never on an idle lock, a hand
lock, the window coming back, after a cancelled sheet ("Touch ID cancelled, tap to try again", no modal), or on the
updater's relaunch (updated_from set). Escape in the password field returns to the button.

The idle lock: Settings > Lock when idle, 1, 5 (default), 15, 60 minutes or never (settings.json idle_lock_min;
idle_lock mirrors on/off for 0.1.2 and 0.1.3; /api/settings takes idle_lock_min and ask_on_open and refuses other
minutes). The engine's lock event names the minutes.

Also: the three wallet switches in Settings were invisible (the miner's .switch hid the input behind a .track the
wallet never renders); the box shows now. ?bio=touch shows the Touch ID layout without a host, for screenshots.

Tests: node --test ui/lock-screen.test.mjs (5) + update-card.test.mjs (4); cargo test in app/igneum-wallet, 18
passed (the settings migration test is new). Verified in the browser pane at 900x700 and 1280x800 against a scratch
engine. Shipped: Igneum-Wallet-0.1.4.dmg published to the new download folder and bridged into the old one (the
installed 0.1.3 polls the old folder; rotation phase 2 had removed the wallet manifest there); the project lead's wallet went
0.1.3 -> 0.1.4 in 28 s (check 15:48:50Z, 0.1.4 up 15:49:19Z), no sheet on the relaunch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:51:07 +00:00
igneum-labs
1a4de0b899 Igneum Miner 0.3.8: pinned proving programs (one program id on every machine, the verifier answers in about 2 s), the update card, the Windows exporter path fix, re-stamped WSL scripts; node 2b6d23ef unchanged 2026-10-05 13:17:12 +00:00
igneum-labs
7258483515 Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
78b9fab46b Igneum Wallet 0.1.2: Touch ID (unlock, every send, the backup, idle lock), Windows Hello written untested; the coin and the chain line on the balance card; the version in the header and Settings
The window host owns the prompt and the secret (app/mac/Biometric.swift): LAPolicy.deviceOwnerAuthenticationWithBiometrics
with "Use password" as the fallback button (never the device password), the wallet's password sealed to a Secure
Enclave key made with .biometryCurrentSet (the Keychain refuses biometric access controls under the ad hoc signature,
-34018, measured) in <data>/wallet/biometric.json; a fingerprint change invalidates it. The engine owns the gate
(igneum-common/src/biometric.rs): a nonce per action, read by the host with its token (the HOST line on stdout,
X-Igneum-Host on host-only calls), confirmed after the prompt, taken once within 30 s and bound to the exact quote;
/api/send refuses without it while enrolled; /api/reveal with a nonce reads the unlocked key in memory; the password
never goes through the page (enrolment parks it under a one-time token the host takes). Idle lock after 5 minutes
without window activity (setting, default on). A password change or a wallet removal deletes the sealed file.
Reason lines in our voice ("Unlock your wallet", "Send 1.5 IGN to 0x7E5F…5Bdf", "Show your recovery words"); the page
shows its own ember line after every prompt. Windows: app/windows/biometric.h (UserConsentVerifier through
IUserConsentVerifierInterop, DPAPI), wired into wallet-host.cpp and BUILD-WALLET-APP.bat, not yet compiled on a PC.
Hosts gain a @main entry so Biometric.swift compiles alongside; build-wallet-dmg.sh links LocalAuthentication.
Balance card: the coin at 56 px, "0" (or the balance) as soon as the node answers, "reading the chain, N of M blocks"
under it while the history scans. Version: v0.1.2 in the brand band, "Igneum Wallet 0.1.2 · up to date" in Settings.
Unit tests: the gate (7, igneum-common), the wallet's 17 still green. README: the flows, the threat model, what was
verified on this Mac (enrol and unlock through the real prompt) and what was not.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:09 +00:00
igneum-labs
43b5ccd51f Igneum Miner 0.3.6: instant jobs, a proof verifier on every node, one notice strip, lower miner latency, packaged configuration, hidden helper windows, WSL scripts from files; node 2b6d23ef: testnet identity and fee table behind a height switch, signed build inputs 2026-10-05 08:48:57 +00:00
igneum-labs
503104a8c2 Igneum Miner 0.3.5: Pruning proofs on the lottery hash (M20), memory fix (M30), coinbase limit on every network (M31), chain-decided equivocation bans (F23), re-determination after reorgs (F24), params digest in the handshake (G12, X18), miner fee 1% switchable, efficiency sweep, variant racing, reliability watchdog, log panel and screens, PC build job, Windows updater launch fix 2026-10-05 06:33:18 +00:00
igneum-labs
b03bf694e4 Igneum Wallet v1: desktop wallet on the miner's bones, igneum-common crate, Mac app and DMG, test-network proof
app/igneum-common (new library crate): the platform helpers with the app identity as a parameter, the payout key
code, the signed OTA manifest (byte-identical to the miner's), the manifest fetch and download check, the 127.0.0.1
server primitives and a JSON client, run_timeout, the packaged config and machine id. Nothing in app/igneum-app
changed; `cargo check -p igneum-app` still passes.

app/igneum-wallet (new): create (24 words, three typed back) or import (words, raw key, the miner's wallet.json),
sealed with Argon2id + XChaCha20-Poly1305 under the user's password; balance, send (EIP-1559, signed in Rust, zero
address refused, fee shown as base fee + tip), receive with a QR drawn locally, history (transfers, block rewards from
the execution records, shard payouts when they exist); finality per transaction verified by the wallet itself with the
node's own finality code (certificate from the blocks after the checkpoint, canonical voter list, aggregate BLS
signature, 2/3 of active and of total weight), shown as pending / in a block / final with the checkpoint index; export
to MetaMask (key with a warning, network parameters, add-network link); node source order: the miner app's node,
the environment's node, the bundled igneumd, the packaged public RPC. 13 unit tests.

Hosts and packaging: app/mac/IgneumWallet.swift, app/windows/wallet-host.* (untested), packaging/mac/build-wallet-dmg.sh,
packaging/windows/Igneum-Wallet.iss, publish-manifest.sh --product wallet (miner path unchanged).

tools/wallet-testnet/run.mjs and the bench-log entry: on igneum-devnet-958 a transfer went pending, in a block and
final under checkpoint 5, 170.6 s after sending, the certificate verified by the wallet.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:48:00 +00:00
igneum-labs
dae5b1b35e Igneum Miner 0.3.4: Finality rule v3 (dormant behind finality_v3_activation_daa), proving v0, job-channel fixes 2026-10-04 20:08:30 +00:00
igneum-labs
1d27c7150c Igneum Miner 0.3.3: an unattended Windows miner is never stranded by an update (4 Oct 15:40 incident: both PCs stopped at the installer's UAC prompt). Per-user installer (PrivilegesRequired=lowest, %LOCALAPPDATA%\Programs, migration from Program Files offered only when someone is at the keyboard, firewall rule asked once on first run and mining without it); the Windows helper runs the installer FIRST with the engine still mining and only the installer's own stop step ends it, a declined or unanswered prompt leaves the machine mining with "OTA: waiting for administrator approval" / "administrator approval not given; waits for the next time someone is at this PC" in the log and the intake, retry on Install now, next start or 6 h; machines take turns (apply only in the minute = machine id8 mod 60) and hold while /api/live shows over 30% of identities gone in 10 minutes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:59:51 +00:00
igneum-labs
c372254051 Igneum Miner 0.3.2: signed job channel, seed-mismatch and stall guards, power-cap readback, round-4 security fixes, node with the difficulty v2 switch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:11:59 +00:00
igneum-labs
c4a2316222 Igneum Miner round-4 fixes: the dashboard token is never logged and token lines never upload (R4.3.8); every helper by absolute path and Program Files read-only, fallback worker build under the app data folder (R4.3.3); the download and the staged bundle re-verified right before the swap or the elevated run, quarantine stripped only after that (R4.3.5); mutating POSTs refused unless same-origin (R4.3.7); no rollback below min_supported_version and no automatic re-apply of a failed version (R4.3.6); the signed manifest's consensus.override written to override.json for --override-params-file with a safe-moment node restart and 'consensus switch at DAA N' on the node tile, an old node that rejects the file runs without it; devnet vote-key note in the key sheet and READMEs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:58:23 +00:00
igneum-labs
377693d9fa Igneum Miner: the NVIDIA power cap is judged by reading nvidia-smi back (anything but the requested watts = NOT applied), the card tile and Settings say 'power cap: N W applied' or 'power cap NOT applied (needs the administrator prompt)' with a Retry, the elevated step runs through the window host (ShellExecuteEx runas, a UI context) with the PowerShell path as the 150 s fallback, events either way, cap state in the stability line (PC 2 mined uncapped at 118 MH/s on 0.3.1)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:43:04 +00:00
igneum-labs
56bbf528d9 Igneum Miner 0.3.1: the first build with over-the-air updates
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:26:24 +00:00
igneum-labs
bd4a64d559 Windows CI: the one-click app built on GitHub runners, no PC needed
windows.yml: parse job (every .ps1 through the Windows PowerShell 5.1 parser with a negative fixture, PSScriptAnalyzer
as warnings, parenthesis check of every .bat/.cmd with a negative fixture), build job (engine on the MSVC target,
window host through BUILD-APP.bat as it is, payload through make-payload.sh in Git Bash, installer through
build-installer.ps1, smoke run of both exes, launcher DRY_RUN, three artifacts for 90 days).
push-inputs.sh publishes payload-inputs.zip (node, miner, workers, NVRTC DLLs) to the downloads host from the Mac;
fetch-ci-artifacts.sh pulls the green run's installer and payload back into the downloads folder.
Host: --version and --help, version.h shared with host.rc. Launcher: DRY_RUN=1 prints the plan and starts nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:32:20 +00:00
igneum-labs
78c276855e Igneum Miner 0.3.0: GPU selection per card (switch, kind, VRAM, identities), Windows WebView2 host + BUILD-APP.bat, Mac DMG and Windows payload around the app, installer scripts for the engine
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:11:47 +00:00