renderer pack EMBER 02 supplied by the project lead, 7 Oct 2026: src/live-dag.js
and src/proof-core.js adopted byte for byte (sha256 582f2e73... and
c2a094a6...), reviewed as third-party code (one same-origin fetch of
/api/live when poll is on, no eval, no CDN, no font download, tokens
read from :root in both themes, checkpoints placed only on an exact
blue score, proof never implies inclusion, a lock only when reported),
its tests/verify.py run on this Mac (73 of 73) and the module mounted
against the real observer feed (state live, only /api/live requested,
zero records promoted). Home: the pack's full mode in the one-screen
fold with the legend row and the newest block's caption, fed by the
page's own reader. /live: the pack in the graph slot, the four miner
stats (blocks in window, your blocks, proven, latest checkpoint), the
All blocks / Selected chain / Your blocks tabs, Pause and Follow, the
window stepper, the inspector column with IgneumProof's shard scene,
the proof shards list, inclusion, miner key, blue score, DAA, parents,
header time, checkpoint, finality, and the three-beat Motion, with
meaning block; the observatory's six tiles, identities, event stream,
block activity, light client and table stay. site.css gains --included
and --excluded. The standalone demo is the pack's standalone.html; the
10-second recording is from this branch's /live.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/testnet-go.md, "Launch gates": LG-1 income per tier (done, re-generate at the cut), LG-2 hash origin on Devnet 2 for seven days, LG-3 signed and notarised installers, LG-4 first-share time per release, LG-5 the text on the site, LG-6 to LG-10 the community gates (first 100 keys, first outside block, first outside-reproduced benchmark, first attested outside pool, first 1,000 independent keys), LG-11 a signed proving customer as a MAINNET gate (the owner, 7 October 2026: a customer paying at a published rate or a letter of intent with a volume), LG-12 the report daily for 90 days, LG-13 the USD 50,000 disclosure prize (approved, staged until the entity address and the publish word). Each with its check, its state and its owner.
docs/plans/launch-pack.md: the Apple organisation and EV Authenticode runbooks (provider, cost, the entity's documents, where the keys live, never on the box), the signing step for the shipper (windows.yml before ISCC and the Inno SignTool directive, build-dmg.sh Developer ID plus notarytool and stapler, the manifest's signed_by and notarized fields, the shipper's fetch and verify checks), the first-share measurement specification, the hash-origin timer on the box and today's reading with its consequences, the handoff block for the site lane (the three wants on the front page, finality on page two, the block sentence, the eight sentences of future.md 8.3 verified and numbered under the label, the journey gate changes, the ledger rows X13, X37, X38, E23, L10), and the nine items that need the owner.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/launch/income-tiers.mjs renders docs/analysis/income-tiers.md (public) from tools/launch/income-tiers.json: eleven measured cards (the 6 October rented-card rows, the 9070 XT telemetry run, the M5 Max Metal bench, each with its source), IGN a day at 1, 10 and 100 GH/s after the ramp on EmissionSchedule::TESTNET_1 (100 IGN a block, 90-day ramp from 10 percent, monthly 2^(-1/24), the 80 percent producer share), electricity a day and per mined IGN at USD 0.005, 0.02 and 0.10 a kWh, a rig and a pool-user line, the consequences per tier, the owed rows; --check fails CI when the page and its inputs disagree; the test pins the arithmetic (6,912 IGN a day for 100 MH/s on 100 GH/s at the launch rate, day 1 at 10 percent, one step at 2^(-1/24)).
tools/observer/hash-origin.mjs: once a day from the observer's tables, who found the blocks: keys with a block and above dust, attested pools against shared payout addresses (a multi-key machine is not a pool until its operator attests), the project fleet's share from the intake identity lines plus the fleet registry's key file, the ten largest keys, the 2x step since yesterday, the community gates (first 100 keys, first outside block, first attested outside pool at 10 percent for 7 days; the X5 count stays an upper bound until the two observer columns exist). --dry reads only; --write keeps hash_origin_days and hash_origin_reports and live_state.hash_origin; --post goes through the Discord poster's guard. Fixture, a known-finished and a known-failed day in the test. Ran read-only on the live devnet today: 113 keys, 0.76 GH/s, the fleet share wrong until the key file exists.
tools/ci/launch-gates-check.mjs (in pre-push.sh with the two test lines): every row of the Launch gates table in testnet-go.md has a check and every backticked path exists; the site-lane handoff and the income table carry no served-page or export pattern and no em dash; the eight regulatory sentences are present in order under the label. Self-test fires on each.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The reference page's composition in our tokens and words, every number
from the observer: the header row (eyebrow, the title with its ember
full stop, one sentence, two buttons, the state word), six tiles in one
hairline row each with a definition, the block graph panel (our
live-dag.js in the graph slot, the block-count chip, selected chain
only, pause and follow, the inspector column with hash, lane, time, blue
score, DAA, chain, colour word, shards, checkpoint and lock state, the
drag-to-explore line, the zoom control, the legend row and the blue
score range), the three panels (block activity with per-minute bars,
mining identities with share bars and the reader's own key marked when
set, the event stream), the blocks table, our footer. live-dag.js gains
an onSelect hook on click (additive; the app's copy unchanged).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
remote-run.sh checkout_tree ran `git clean -fd` on the box mirror before every build from any agent, so the attack rows
lost attack-f3/, attack-f1-venv/ and tools/attack/*/target to each other's builds (7 October 2026, 09:2x UK). The clean now
also spares the fixed prefixes attack-*, scratch-*, target-attack-*, .build-remote.log and every glob in the mirror-local
.igneum-scratch-spare (one per line, # comments, the file itself spared), keeps the target and stamp excludes and still runs
without -x. The clean-tree test asks `git clean -nd` with the same excludes instead of filtering the status list, so a spared
dir is not "not clean". --self-test: a fixed-prefix dir at the root and nested, a declared dir and the spare file survive, an
undeclared dir is removed. tools/ci/scratch-spare-check.sh in the pre-push gate fails when the clean line loses the spare
arguments, spare_args stops reading the file, a fixed prefix goes, or -x appears. docs/plans/build-server.md R4a says how a
lane declares its prefix.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Light theme shows light screenshots on the miner and app pages (the
0.3.16 renders from the RTX 5090 Windows rig's live state, the 390 px
pair included). The X9 never shipped: pre-orders 26 December 2025,
withdrawn mid-May 2026 before any unit shipped, no benchmark; every
public sentence that had it shipping now says so, with k about 0.33
labelled as the claimed, unmeasured core; ledger X36, notes on X34, X35,
M34 and C2. Every public Discord link is https://discord.gg/igneum.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead added the read-only deploy key on 7 October 2026 (SHA256:51ice3W8...). The sync still said 'mirror' because ssh -T to GitHub
exits 1 after its greeting and observer-sync.sh runs under pipefail, so su ... | grep -q reported failure although grep had
matched (the same line by hand, without pipefail, said authenticated; shown under the unit's environment with systemd-run -v).
The probe's output is captured first. First github pass 07:30:54 UTC: the clone moved from the mirror's d79f4a6 to origin/master
8b878ba4, the observer restarted on it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner's word this morning: the 56 px header, the eleven-word
statement, two buttons, the step scene full bleed, three facts, the
downloads and one line to the ledger. Kept from the nights since: the
X31 testnet sentence, the X35 chip range with k stated, the Discord
line. The RandomX correction (X34), G4, C2 and X8 stand on the
litepaper; the ledger notes and the text check say so. The app showcase
moves to the miner page in the next step.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's order of 7 October 2026 after RunPod's Ubuntu 22.04 canaries (glibc 2.35) refused the box's GLIBC_2.38 binaries and HiveOS
turned out Ubuntu 20.04 based (2.31). The table lives once, in tools/ci/glibc-ceiling-check.sh (--class, --ceiling-of; self-test
covers the table, an unknown class and a 2.34 need against hive); tools/build-remote.sh --ship hive|rig|seed|linux (default seed)
and tools/workers-remote.sh --class (default rig) build with zig at the class's glibc and check against it. provision.sh installs
docker.io (user build in the docker group) for the proof. Proof: fork 3bfe346f at class hive, igneumd and igneum-miner need
GLIBC_2.30; the workers at class rig need GLIBC_2.17; all four run in ubuntu:20.04 (ldd 2.31) and ubuntu:22.04 (ldd 2.35) and
print their version or usage lines (the OpenCL worker its own no-libOpenCL message, the binary running in a GPU-less container).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The previous commit's plan edit aborted on a changed anchor, so section 5c was missing; written now with the public half
(ssh-ed25519 ... igneum-build-1 observer read-only) and the CI-runner row closed. observer-sync.sh ran git rev-parse as root
against the build-owned clone (safe.directory refused it, 'up to date at' with no commit); every git call runs as build now.
Verified on the box: one sync pass prints 'source: mirror (the deploy key is not accepted by GitHub yet ...)' and the commit.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The previous commit's 'the workers at 2.36' was not yet true: the first zig build died on __isoc23_strtol because -I /usr/include
for CL/cl.h put Ubuntu's glibc 2.39 stdlib.h in front of zig's bundled 2.36 headers. Fixed; proof on the box (6 s):
igneum-worker-cuda 6,759,272 B sha256 690c8e91..., igneum-worker-opencl 307,264 B sha256 329fb6a9..., each needing GLIBC_2.34
and libc only, the ceiling check passing. The two static flags zig ignores are dropped on the zig path (zig links its libc++ in).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's order of 7 October 2026 after a seed took 14 restarts and three minutes down on a glibc 2.39 binary. provision.sh:
step_zig (zig 0.17.0 from ziglang.org, sha256 from the official download index) and cargo-zigbuild 0.23.4 in the cargo tools.
tools/build-remote.sh --ship [--glibc 2.36]: cargo zigbuild --target x86_64-unknown-linux-gnu.2.36 with zig as the C/C++
toolchain (the Mac's infra/cross/build-linux.sh recipe), artefacts from the target-triple dir, each checked by
tools/ci/glibc-ceiling-check.sh (need at most the ceiling; self-test fires on 2.38 against 2.36, passes 2.34 and 2.36;
--symbols reads a saved objdump -T text so CI needs no ELF tools). tools/workers-remote.sh builds the two GPU workers with
zig at 2.36 by default (GLIBC=native for clang). Proof on the box: fork 3bfe346f igneumd needs GLIBC_2.34 (47,023,120 B,
sha256 345dfb95...), igneum-miner GLIBC_2.34 (9,248,808 B, d09dc27b...), 3 min 17 s cold through zig; the workers at 2.36.
Rule: anything that ships to a seed or a HiveOS rig is built with --ship; a plain build (glibc 2.39) is for the box and
Ubuntu 24.04 hosts only.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/hands-on-build-1.md section 6: the move of 6 October 2026 23:06 to 23:22 UTC, observer node, observer, node 1, unload,
each hand's first executing line, digest eada4bda MATCH, IBD and acceptance, the open readback (the Mac's Miner app has not
started its own node since 26610/26611 were freed). lib.sh: the shipper's class from the 0.3.17 tree, the fork's igneum-exec
embeds proving/igneum-prove/elf/*.vk by include_bytes! five levels up, which is no path dependency; every .rs in the trees that
travel is scanned for include_bytes!/include_str! paths leaving the crate's repository and their directories join the overlay;
proving/igneum-prove/elf is the fixed fallback for a fork build. move-hand.sh: igneumd --version exits 1 (tolerated; it ended
the binary step before the override was written), and the launchd pid lookup used \s in macOS awk (printed 'pid none').
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The X9 made the k = 0.33 column of the chip model a product class, so
every public sentence that stated 2.1x alone now states 2.1x (k = 1) to
3.9x (k about 0.33), with the ladder's second rung taking the X9 bracket
to about 2.8x. The ladder lane's litepaper paragraph 'The work that waits
can grow' and ledger row M34 are taken from branch ladder (7003f9f, those
two hunks only) so the ladder is on the site before the code ships.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The reset itself has been master's behaviour since 9df9688 (remote-run.sh checkout_tree: git checkout -- . and git clean of the
overlay files, target dirs and stamps kept, before the branch checkout); the UI lane met the class again from worktrees whose
tools predate it (remote-run.sh is piped to the box from each worktree per build). The check reads checkout_tree() and fails
when the reset and the clean do not both come before the branch checkout; self-test: the real script passes, a copy without the
reset fails, the same lines moved after the checkout fail. cargo-audit: already owned by provision.sh step_cargo_tools
(b2262e5), confirmed ok (0.22.2) on the box; nothing added. Gate GREEN, 33 checks.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The light variants of the Overview and Cards cards are the 0.3.16 UI
rendered from the rig's own api/state and api/live at 23:33 UK, captioned
as renders so nothing is passed off as a screen capture; the job strip is
cropped out and the machine's hostname painted over before serving. The
shipped Mine page shows its one real mining capture in both themes; the
idle light shot is no longer used here.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The two files stay on their branches (tail-emission, vote-weigh) and are not merged here; the section names the branch and commit for each.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fleet's 22:09 UK incident (a Mac-side pkill -f <log file name> matched nothing, the roll-everything script lived on and wiped a held box) and the day's two pgrep self-matches are one class. The check flags pgrep -f / pkill -f with a plain literal (every one on a line), any pgrep/pkill on a file-name shape, and ps | grep with a literal; it allows the bracket form, -x, -F pidfile, kill $(cat pidfile), a variable and a full path; 11 banned and 16 allowed shapes in its self-test; 0.15 s over the tree. The 25 pkill -f sp1-gpu-server inside bash -c bodies (which matched the calling bash) are pkill -x; the other 11 literals take the bracket form; prover-socket-check accepts both. Row R in the record; the CLAUDE.md rule names the check and covers pkill and file names.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Bitmain's Antminer X9 (1 MH/s at 2,472 W, about USD 5,600) ships from
July 2026 and RandomX 2.0 shipped on 25 March 2026. Five sentences on
the home page and the litepaper that said or implied RandomX is
chip-free now state the X9 and its date; sentences that only name the
technique stand. Ledger row X34, C2 closed by the fact, the text check
carries the new sentences.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A section between the live scene and Your card: three real screenshots
(the shipped Mine page of 0.3.14, and the next release's Overview and
Cards pages from the app in development), light and dark variants,
three lines (one click, every card tuned, the chain on your screen),
the download list repeated, and the wallet in one card.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The box's 34 red rows of 6 October classified (docs/analysis/ci-failures-2026-10-06.md section 6): 22 iterations, 12 in three real classes (instant deaths with nothing kept, a shared worktree directory, an unread dry run). remote-run.sh now: pre-flight (subcommand, manifest, -p package, --features) refuses in a second with exit 3 and a class; the last 400 lines of every run kept in /srv/builds/_log/runs; a class on every row (compile-error, link-error, test-failure, instant, no-test-matched, slot-timeout, no-dir, preflight-*); a cargo test whose filter matched no test exits 3; a per-worktree lock in checkout and run mode; every red row appended to /srv/ci-red/red.jsonl as source box. red-watch.mjs never posts a box row alone and sends one digest a day (counts per class with each class's guard); the timer runs tick. Shared group cired on the box so the runner and build append to one file. Shown in a sandbox on the box: pass, failing test, empty filter, bad package, bad feature, missing subcommand, compile error, broken manifest, two concurrent runs of one worktree.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "Im not sure about the site can we revert it but polish it? minimal, simple but everything needed
for the dopamine and emotional triggers of the gpu miner", then "cant we have a dag animation like we had before? with the
shards making up the block, then the final line and the other bits that looked really cool but brought upto date?"
Restored (a new commit, no history rewrite): site/index.html as it stood at 14da2b8, the step-view page with its hero, facts,
scene, three things to check, downloads, build, wallet, journey, economics and the ledger band; nothing from tonight's other
work is undone (the litepaper, /live, the roadmap and benchmark wording, ledger X31 to X33, the scroll-zoom fix). Where the
page named a month it now carries tonight's sentences: the proofs card reads "Live rows arrive with the public testnet. The
public testnet is weeks away: three seed nodes and the public RPC are up, and it opens when the go checklist closes."; the
journey lead reads "Six phases, four public gates ... No calendar dates: each phase closes at its gate." and its inlined
phases are the gate-worded ones. No "August 2027", no month anywhere on the page.
The scene (site/live-steps.js): the original bits, every one driven by the live feed. A real block arrives from the right
with a glow and its chain number under it; its outline is grey while pending and ember once included; as its shards are
verified or paid, particles fly in from the edges and its quarter cells fill molten; when every shard is proven the block
turns ember and the caption says how many provers were paid; a locked checkpoint takes a ring and a ripple and the dashed
"final" line sweeps in from the right to it, drawn only while finality is active (the legend no longer says "final to its
left"; the wallet card's state word "final, checkpoint 5" is the wallet's own vocabulary and stays). A proof or a lock that
lands on a block already off screen re-enters from the right as its own event, so every step is seen when it happens. The
counters gain blocks per second. The caption follows the newest block that changed step.
The miner's triggers, each one element with live or measured numbers, none invented: a network strip under the facts
(hash rate, blocks in the last ten minutes, the latest block's age ticking every second with its chain number and word,
shards proven and paid with the last ten minutes), each value flashing molten when it changes; a card picker from the bench
table with the time a card alone takes to find a block at the live hash rate (RTX 5090 127.7 MH/s at 227 W and RTX 4070
28.8 MH/s at 76 W from the 6 October Ember Tune on the three-card Windows rig, RX 9070 XT 17.8 MH/s from the 5 October eGPU
entry, Apple M5 Max 26.7 MH/s from the first live swap; the RTX 4090 and RX 7900 XTX shown as not yet measured with the
bench table linked) with the pool note; the fairness line (graphics cards only, a new program every hour, your card proves
the blocks, 80% to the miner and 20% to the provers, nothing to anyone else); the download buttons with sizes; a Discord join
line (the standing invite, recorded in docs/community/discord-hooks.md so nobody asks again); the testnet sentence.
docs/fud-ledger.md: G4, C2 and X8 each gain a status line saying the restored home page carries their sentence again; the
ledger-text check guards them on the home page again (55 sentences, 0 missing).
Measured headless over 40 s against the live feed: 19 captioned transitions, the strip reading 2.3 GH/s, 562 blocks in ten
minutes, 8 s ago, 2,970 shards paid, the picker's times 18 s (5090), 79 s (4070), 2 min (9070 XT), 86 s (M5 Max) at that
hash rate, 0.92 blocks/s; no console errors at 1440 or 390 in either theme; no horizontal overflow. Captures in
docs/plans/site-ui-3-shots/after-v2/: home-{1440,390}-{dark,light}-fold.jpg, home-{1440,390}-{dark,light}.jpg and
home-steps-1440-dark.webm (ten seconds of the scene). Checks: identity grep 0 hits on served files, link check 934 links
across 16 pages 0 broken, ledger text 55 of 55, contrast 32 pairs 0 under 4.5:1, api tests 5 pass. Not deployed: the owner
sees it first.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/analysis/horizon-2026-10.md section 1 rewritten as a standalone page: the project lead's three lines verbatim (fees cannot fund security for a decade; miners need to be the security; wrong constants and claims in our own text) with the recorded meaning (miners are the security always, no time bound, no stake, no outside checkpoints or committee; emission plus fees pay the miners, nobody pays upkeep; emission never decays on a schedule that assumes fees take over); the nine items with what landed tonight (proof verification in consensus da2d17ec with the switch off by default; the leave item 766e70ca; seven-window signalling 0760b844; the peer-driven unwrap class 8e2f5cbe; the receive-side version gate f1ea7a38; Ember's pause wording and activation guard b43d329, e5e1e92, e54a87b; the export-disk cap f9ad70e; the nine ledger rows plus X31 to X33); lane 8's measured verdicts (B never as class content, C the class v5 candidate); lane 5's 1 block/s verdict with the three gates for 10; the four decisions still owed
- lanes table, section 4 (lanes 5, 6, 8) and section 5 (A2 dropped) brought current
- docs/plans/ledger-decisions.md: the fud-close file (c6b0bad) now on master, since docs/fud-ledger.md already points at it, with the standing decisions section appended
- docs/analysis/block-rate-devnet2.md: lane 5's experiment from gpu-fleet b965b64, unchanged
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
pgrep -x git over the whole machine kept the lock whenever any git ran (the pre-push hook's own git push, another agent's build) and the checkout died with "index.lock: File exists". The fact is the lock's age. Class Q in docs/analysis/ci-failures-2026-10-06.md with the GIT_DIR leak of the previous commit.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
168 non-green runs since the first workflow run were classified (docs/analysis/ci-failures-2026-10-06.md): 102 were tree checks that finish in under 25 s on the pushing machine, 40 were GitHub-side refusals nobody saw.
tools/ci/pre-push.sh is the one list of fast checks; ci.yml's site job calls it with --ci and the pre-push hook with --hook (full gate for master and release-*, structural checks for other refs; never writes into the worktree). tools/ci/export-exclude.txt lists research documents outside the public export list, pruned by identity-check.sh and by the mirror's sync.sh (self-test: an excluded path may quote the patterns, an exported one may not); polish.md and this record are its first entries, which makes master green. tools/ci/windows-paths-check.sh (colon, trailing dot or space, reserved names, over 240 characters) runs as the pre-commit hook on staged paths and in the gate. tools/ci/red-watch.mjs plus the red job on the box's runner record one line per failed master or release-* run to /srv/ci-red/red.jsonl; igneum-ci-red.timer posts each once to the updates channel. pow and sims read IGNEUM_CI_RUNNER for the box. no-foreign-tree-writes.sh no longer exits silently on its warning pipeline under pipefail.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/build-server/capacity: igneum-capacity.service (user build, Nice 19, SCHED_IDLE,
CPUQuota leaving 8 threads free) runs run.sh, a controller over a priority queue of jobs
that pauses (SIGSTOP) the instant a build slot or the measure hold is taken (5 s poll of
/srv/builds/_locks) and resumes after. Jobs, each with a dry-run and a 10-min smoke:
pow fuzz (continuous, seed base advances), sync-request fuzz against a throwaway pruned
node on loopback (the Horizon 28-unwrap gate, igneum-p2p-probe sync-fuzz), GHOSTDAG and
finality sweeps seeds 1 to 1,000, model.py sweeps cached, clippy+audit per recent branch.
Summaries to /srv/workers/capacity.json; the worker dashboard gains a Background lane
(collect.mjs doc.background, page renderBackground). Night battery stops and restarts the
layer. docs/plans/build-server.md section 8. igneum-pow fuzz tests and ghostdag_sim.py /
attacks.py gain a seed-base knob for the continuous sweeps.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner's ruling, 6 October 2026, the same as the roadmap's: the litepaper said the public benchmark with a leaderboard "is
January 2027" (For miners) and "ships in January 2027" (Questions miners ask). Both now read "The public benchmark with a
leaderboard ships with the public testnet." (the second keeps its tail: its source is public with the repository then, so you
run it on your own card and post the number). One gate the reader already knows from the roadmap's phase 5. docs/fud-ledger.md
gains X33; the 5 October answers that named the month stay as the history of the plan. The ledger page regenerated (179
entries, 0 leaks).
Checks: identity grep 0 hits on every served site file, link check 912 links across 16 pages 0 broken, ledger text 51 of 51,
contrast 32 pairs 0 under 4.5:1, orphan check 0 site headings, api tests 5 pass, no calendar month on the litepaper or the
home page.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner's ruling, 6 October 2026: a phase 4 dated "Apr to Jul 2027" before a phase 5 that is weeks away is a contradiction a
reader spots at once. The roadmap (site/litepaper.html Roadmap, site/journey.json, the home page's inlined journey) now names
no month. Each phase in the shape phase 5 has, the order unchanged:
1 Under way; closes when the specification is out for external review
2 Under way; closes at its gate
3 Live since 3 October 2026; closes at its gate
4 Closes when the finality design passes external review and one rollup signs for the testnet
5 Weeks away: when the go checklist closes
6 After the testnet has passed its gate: 1,000 independent miners for 30 days and rollup proofs on time
The lead reads "Six phases from specification to a fair launch, with four public gates and no calendar dates: each phase
closes at its gate." The devnet's 3 October 2026 start is a fact and stays. Not in the roadmap and left as it is: the public
benchmark's "January 2027" in For miners and Questions miners ask (its own commitment, for the owner's word).
docs/fud-ledger.md: row X32 records the change; rows G4, C2 and X8 gain a status line (the old kept as history) saying the
home page no longer carries their sentence and the litepaper does, after the home-page redesign; X3 got its line in the
previous commit. The ledger page regenerated (178 entries, 0 leaks).
Checks: identity grep 0 hits on every served site file, link check 912 links across 16 pages 0 broken, ledger text 51 of 51,
contrast 32 pairs 0 under 4.5:1, orphan check 0 site headings, api tests 5 pass, no calendar month on the roadmap surfaces.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "August 2027" is false. igneum-testnet-1's genesis is final, three seed nodes and the public RPC
are up, and the testnet opens when the go checklist (docs/plans/testnet-go.md) closes, which is weeks away. No calendar
month is given; the owner gives one if he wants one.
The sentence everywhere: "The public testnet is weeks away: three seed nodes and the public RPC are up, and it opens when
the go checklist closes." In site/litepaper.html the proving section's proofs feed ("Live rows arrive with the public
testnet." then the sentence), the For miners paragraph ("Pools come with the public testnet." then the sentence) and the
roadmap's phase 5 ("Weeks away: when the go checklist closes"); site/journey.json phase 5 and the home page's inlined
journey carry the same row. docs/fud-ledger.md gains X31 recording the correction (the old sentences, the new one and where
each lived), row X3 a new status line pointing at it (the old line kept as history), and O-X.2's blocker note and
overclaim item 75's replacement text read the new state. tools/ci/ledger-text-check.mjs checks X3's new sentence and X31
(51 sentences, 0 missing). The ledger page regenerated (177 entries, 0 leaks).
Checks on the tree: link check 912 links across 16 pages 0 broken, contrast 32 pairs 0 under 4.5:1, orphan check 0 site
headings, api tests 5 pass, identity grep clean on every served site file (the one hit is master's polish.md, the polish
lane's), no "final" on / or /live while finality is paused, no console errors, "August 2027" on no page.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026, on the live home page: "too left and text heavy ... we want the home page to suck people in and let
the litepaper carry the weight; also minimise the header." The home page only; nothing else above the fold.
Header (this page only, a page-block override of the shared nav): the wordmark, Litepaper, Live devnet and Download the miner,
56 px, transparent over the hero; the phone sheet shows the same three.
Hero: one statement, eleven words ("A proof-of-work chain for graphics cards, whose miners prove the blocks."), two buttons,
then the step scene (site/live-steps.js on the shared feed) full bleed with its one caption line. Hero copy 17 words with the
buttons. At 1440 by 900 the hero ends at 849 px; at 390 by 844 at 699 px.
Below the fold: three facts, each one number and one sentence: the live hash rate with the vote keys of the last ten
minutes, the shards proven and paid on the chain (with the last ten minutes), and the chip model's one line with its link;
a note under them says the chain's state in the ledger's words (tonight: finality paused) and that the chip figures are a
cost model, not a measurement. Then the downloads row (three platforms) with the devnet and testnet notices and the dev-fee
sentence, then one line to the ledger and to what Igneum does not claim. The footer is unchanged.
Moved, nothing cut: the light-client card to /live (its verifier module with it); the testnet terms to the litepaper's For
miners section (with an id for the metamask page's link); "Live rows arrive with the public testnet, August 2027" to the
litepaper's proving section; "since 2019 (approximate)" onto the litepaper's RandomX date; the journey, economics, wallet,
build and RandomX sections were already in the litepaper (roadmap, economics, wallet, building, vs RandomX). The footer's
Journey link points at the litepaper's roadmap. tools/ci/ledger-text-check.mjs: the home page is checked for E5, X2 and
X7; G4, C2, X3 and X8 are checked on the litepaper (G4 and X8 were already there). The ledger's own "stated on" notes for
those four rows are owed an update by the ledger owner.
Polish lane Q5: the word "final" is drawn and captioned only while finality is active (site/live-steps.js), so nothing on
the page says final while finality is paused; the hero is under 40 words; the Open Graph card is the 1200 by 630 image.
Measured headless at 1440 and 390, dark and light: header 56 px with three items, no "final" anywhere, no horizontal
overflow, no console errors; the caption advanced on every capture. Captures: docs/plans/site-ui-3-shots/after/
home-{1440,390}-{dark,light}.jpg (full page) and home-{1440,390}-{dark,light}-fold.jpg (above the fold).
Checks: link check 912 links across 16 pages 0 broken, ledger text 50 of 50, contrast 32 pairs 0 under 4.5:1, orphan check
0 site headings, api tests 5 pass. The identity grep's one hit is docs/analysis/horizon/polish.md line 433 on master,
untouched here (the polish lane's own table of regex literals); it is main's to route.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every shipped surface audited against a named comparator with the file or screen: the pause of
6 October had no cause on any surface for two hours (the node reports no frozen-table reason,
the observer copies the flag alone, /live computes the silent share from the sliding table,
Ember has no pause state); a fresh machine meets two warnings before the first screen (ad hoc
codesign, no notarisation, unsigned Windows installer); every update has been urgent since the
0.3.14 manifest (fork_is_close treats any passed activation as close). Rows Q1 to Q105 with
severity, hours, owner and gate; cross-cutting: one formatter table for every number, the five
6 October rule rows without a tools/ci check, the forbidden-string scope gaps.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/horizon/new-pow.md sections 0 to 9: scheme A (mining is proving) never, on bytes,
the verifier and sampleability; scheme B (the tensor-shaped integer shadow) prototyped as
proto-newpow/mma-shadow and measured, never as class content on the energy reading, with the R8
two-output correction; scheme C (proof of stored state, sd1: the daily dataset derived from the
execution state) prototyped as proto-newpow/state-dataset, measured on the GPU and the box's
CPU, and put forward as the class v5 candidate with its spec items and the Devnet 2 gate. The
lane's standing rule: a shadow lever only works through joules the honest card is forced to
spend, so shadow work goes where the GPU is least efficient per op. Chip rows in
sim/horizon/new-pow/chip_rows.py by the chip-model-v3 method. Rented box addresses replaced by
placeholders in the READMEs and the run script.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "I liked it when we could see each step of the algo working." The home page's scene is again the
lane chart where a square moves through mined, shards being proven, proven and locked checkpoint, now as site/live-steps.js on
the shared feed (site/scenes/feed.js, which gains onData):
- every square is a real block from /api/live (a 300 s window so late proofs still reach the caption), released one every
2.5 s so a square crosses the scene in about 34 s; the chain merges a pending block in about 10 s, so its step changes
while it is still on screen (at the original 10 s crossing most transitions landed after the square had left). The feed is
sampled for the stream; item 0's counters read the chain. The first reply seeds the scene across its width, so nothing
starts empty;
- each step is drawn as before: an outline (grey while pending, ember once included), molten quarter cells filling as shards
are verified or paid, an ember fill when proven, a ring on a locked checkpoint with the dashed "final" line to its left,
excluded blocks dimmed; every transition glows for a second and a lock ripples;
- one caption line under the scene for the newest block that changed step, e.g. "block 144,564: mined 21:16:03, on the
selected chain; 1 shard planned", or with its shards "8 shards on 3 cards; proven in 48 s" and "locked at checkpoint 7,084".
/api/live now carries each block's chain number for it. When no block changes step for a minute the caption says why in
the ledger's words: finality paused (under two thirds of the weight signing), no proof landed in the last 10 minutes
(with the median lag), or no block changed step;
- the wheel is never touched: the module has no wheel handler, so the page scrolls through the scene;
- light and dark from the tokens, 390 px, a still frame under reduced motion. The DAG module stays as /live's scene and the
three scenes stay unlinked on /scenes.
Proved headless over 40 s against the live feed: thirteen captioned transitions, no console errors at 1440 or 390, no
overflow. Captures: docs/plans/site-ui-3-shots/after/index-steps-1440-dark-clip.jpg, index-steps-390-dark-clip.jpg and
index-steps-1440-dark.webm (ten seconds of blocks moving through the steps). Checks: identity grep 0 hits, link check 931
links 0 broken, ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1, api tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
From docs/analysis/horizon/economy-and-utility.md (sections 3.1, 4.1 to 4.4, proposals 2, 3, 4, 7) and
docs/analysis/horizon/consensus-security.md (finding 3, proposal 1), both on master.
(a) The litepaper's "proofs at the cost of power" and the customer brief's "priced in dollars per proof" are
conditioned: electricity is close to power, the price a prover must charge is the subsidy it forgoes, published as a
formula with network hash as the input (per shard, card hash over network hash x 0.8 x 31.688 IGN x shard seconds,
plus electricity), never a number; 100 to 300x the published market rate at the devnet's 1.16 GH/s, competitive near
100 GH/s beside the miner, approximate beyond the one card measured. Six litepaper passages and two brief rows. The
text check's P6 sentence moves to the conditioned form. Ledger E20.
(b) One threshold sentence in Governance and Mining: 60 percent of blue blocks over two weeks for a parameter genesis
leaves open, 90 percent for an upgrade (new code), 95 percent with a floor height for a class change (the Mining
section had said a 90 percent signal turns a spare defence on, which is a class change). Ledger G15.
(c) The 20% proving-pool row carries the caveat that consensus does not yet verify the carried proof, so a block
producer could claim shard pay with a false proof today (P21; the 0.3.16 fix). Ledger P24.
(d) The dev fee reads "default-on, switchable, 1 percent of the producer share" in the payment-routes row and the
Ember section; docs/plans/funding.md section 4's ceiling is 1 percent of the producer share, USD 38,520 / 154,080 /
770,400 at the three prices, corrected from 48,000 / 193,000 / 963,000. Ledger E21.
(e) The pool row's note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls it
into the next proven segment (0.3.16). Ledger P25.
site/ledger.html regenerated (176 entries); tools/ci/ledger-text-check.mjs carries the five new sentences (53, 0 missing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's rule of 6 October 2026 from the 0.3.14 repro (docs/evidence/reproduced/0.3.14.md): prost's protowire.rs embeds OUT_DIR,
libmimalloc-sys embeds __DATE__/__TIME__, sccache hid both. lib.sh bs_repro_env exports SOURCE_DATE_EPOCH=<author time> TZ=UTC in
front of every remote command (build-remote.sh, cross-remote.sh, workers-remote.sh); remote-run.sh exports BR_SDE too and logs it
as source_date_epoch; proto-cuda/windows-node/cross-build.sh exports the same; the PC job carries node.commit_time in the manifest
(push-build-inputs.sh) and exports it before every cargo build of a stage (jobbuild.rs, unit test asserts it; 4 of 4 pass on the
box). Target dirs stay one fixed path per target. tools/build-remote.sh --self-test-repro [--full] from a fork worktree, run on
the box: igneum-miner twice a minute apart without sccache (RUSTC_WRAPPER=/usr/bin/env, an empty value is unset to cargo) MATCH
91e130f5..., a per-run target path differs (OUT_DIR shown); --full: kaspad with libmimalloc-sys recompiled a minute later MATCH
70219bc2..., without the epoch differs (__DATE__ shown).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Utility curves for IGN beyond gas with dollar inputs labelled; the proving price as the
forgone subsidy (1 / network hash) against Boundless's published rate; the adopted job floor
overprices the market above about USD 0.014 per IGN; a ten-year security budget with the
measured 5090 row (sustained hash USD 24.8 per GH/s-day against USD 281 rented, so the 20-day
34 percent weight attack costs 11.8x the honest fleet at every price); sim/economy re-run with
the eleven measured cards under eight stresses (T1 to T5 hold; a ten-day prover refusal strands
547,570 IGN a day of pool credit in the escrow with no rule to return it); the dev fee, the
signalling game, and the twelve-row table of what Kaspa, Monero, Ethereum and the zk rollups
did (rusty-kaspa cited by file and line).
Models: sim/horizon/economy-and-utility/ (utility.py, stress.py, security_budget_10y.py,
signal_game.py, devfee.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/51-percent.md: what a 51 percent attacker can and cannot do on Igneum, with
numbers (the selected-chain race over a 90-s hold, the lock as the reorder bound, the veto
at 1/3 of weight and its rental cost, the departure case and the LEAVE item, the p2p surface).
docs/analysis/horizon/consensus-security.md: the attack catalogue across GHOSTDAG ordering,
the difficulty rule, the finality weight, miner signalling, proof records, the exec layer and
p2p, each with the bound and the rental cost at the measured USD 11.7 per GH/s-hour; the
pruned-node unwrap class with its sibling list in the sync and IBD flows; fourteen ranked
defences, three of them not recommended with the reason.
Models and results: sim/horizon/consensus-security/ (ghostdag_sim.py, finality_horizon.py,
cost_model.py, signalling.py, result files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- rebuild-on-box.sh: the DIFFER reason comes from the binaries (glibc need of both, the build path each embeds, the
mimalloc clock string, the PE timestamp, the commit string), never from an assumed story; the three string helpers run
their producer under `|| true` so a consumer that stops early (grep -m1, awk exit) no longer trips pipefail into the
fallback and a second line in a table cell.
- docs/evidence/reproduced/0.3.15.md, and the 0.3.14 file re-reported with the same column.
- docs/plans/build-server.md 7.3: the 0.3.15 row and what the two files mean for shipping from the box.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026, item 3: three alternative scenes for the same live data, side by side at 1440, each a self-contained
module on one shared feed, the ledger's words in the legend (pending, included, excluded, proven, locked).
site/scenes/feed.js polls /api/live every 2 s and pushes the reply to every scene; it carries the site's state words
(connecting, live devnet, observer offline with the age, live feed unavailable) and the shared helpers (theme tokens from
CSS, the word for a block, DPR-sharp sizing, a frame loop that stops when hidden or off screen and draws a still frame under
reduced motion). Every mark in every scene is a block the observer stored; nothing is invented.
A, Forge (site/scenes/forge.js): blocks rise from the hearth as embers, one column per miner, at the height of their header
age over a 120 s window; a block cools as its word changes (pending molten, included ember, proven bone, excluded ash);
a new arrival glows for a second; a lock is a dark band that sweeps up the scene at the newest locked checkpoint, and
everything under it is final and settles to ash.
B, Lattice (site/scenes/lattice.js): a slow isometric DAG, time left to right, the selected chain as the lit spine in the
front lane, the other miners one shallow step deeper each (ranked by blocks, the shear capped to a third of the width so a
narrow card keeps its time axis), parent threads reaching forward, chain edges heavy with a soft halo, checkpoints as rings
that close around the spine when they lock with the lock weight beside them, new blocks glowing in; the camera drifts at
chain speed.
C, Pulse (site/scenes/pulse.js): the tip at the centre breathing, time outward with a ring every 30 s, each miner a ray,
each block a bead on its ray drifting outward, filling when proven, hollow while pending; the selected chain as short arcs
winding between consecutive beads (never a chord through the centre); a checkpoint is a ring that hardens from dashed to
solid when it locks.
site/scenes.html: the three cards side by side at 1440 and stacked under 1000 px, the shared legend, a note on the window
and reduced motion; ?only=a|b|c shows one scene full width (the card filter copies the children before removing, so the
right card survives). noindex, not linked from any page; registered in the build's PAGES so it takes the shared chrome.
Captures (docs/plans/site-ui-3-shots/scenes/, one niced headless Chromium): scenes-1440-dark.jpg (the three side by side),
scene-{a,b,c}-1440-dark.jpg and scene-{a,b,c}-390-dark.jpg, and scene-{a,b,c}-1440-dark.webm, ten seconds each at 1440 by
900 (VP8, recorded by Playwright and cut with its ffmpeg, which has no mp4 muxer). No console errors on any scene at either
width; no horizontal overflow at 390. Tonight's chain shows in all three: finality paused, so no band, closed ring or hardened
ring appears, and the checkpoint marks read pending.
Checks: identity grep 0 hits over 232 export files and 33 served site files, link check 931 links across 16 pages 0 broken,
ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 6 October 2026 pause from the observer rows: 20 keys holding 42.7 percent of the frozen
voter table left in three minutes; locks formed without the hub; the 2/3 rule paused at
checkpoint 6843 (53.1 percent of total) and the frozen table (Q5) held the pause for a window
where rule v2 would have locked after 35 minutes. Candidate rules run in a copy of the finality
simulator (seeds 7, 11, 13): only the departure announcement keeps 0 conflicting locks and ends
the pause under an hour. Weight capture priced at the measured USD 11.7 per GH/s-hour: the veto
0.52 x N for 30 days (USD 4,300 per GH/s of network), a lock alone 2.03 x N. Lock delay by voter
count measured on node 1; the ZK light client and prover attestations costed.
Models: sim/horizon/finality-and-weight/ (finality_horizon.py, weight_capture.py,
lightclient_cost.py, merge_results.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- infra/build-server/repro/rebuild-on-box.sh: one target path per target with each pass's artefacts copied aside (prost's
protowire.rs embeds its OUT_DIR path, so a pass in a dir of another name differs), SOURCE_DATE_EPOCH from the node commit
and TZ=UTC (libmimalloc-sys compiles mimalloc's C with __DATE__ and __TIME__), --reuse for a re-report, reason text
for a shipped file that is not on hand (innoextract 1.9 cannot open the Inno Setup 6 installer; the 0.3.14 HiveOS
tarball left dl/public when 0.3.15 published).
- tools/repro/rebuild-release.sh: the plan's hashes always travel (the miners' 8-hex prefixes too), bash 3.2 empty-array
fix, the box half's exit code is the script's.
- docs/evidence/reproduced/0.3.14.md: igneumd 03f35e05..., igneum-miner 900c1f0b..., igneumd.exe 166e604e...,
igneum-miner.exe fefd266c... identical across two clean passes; DIFFER against the shipped 934f393c... (zig, glibc 2.36)
and 44fa74c0... (Homebrew mingw before the timestamp fix, from a worktree).
- docs/plans/build-server.md 7.2 (night battery: timer, dry run 3 min 54 s, 10 pass, the fork's 22 cargo-audit
advisories as the one FAIL and what follows) and 7.3 (repro: results, the two classes, SOURCE_DATE_EPOCH proposed for
every build script).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's 6 October 2026 ask: deep backward and forward research across the hash, finality,
economy, network and every shipped surface. This commit carries the first three lanes.
- docs/analysis/horizon/algorithm.md: the chip model on the 6 October numbers (f = 1 GDDR7
chip 5.7x per joule against the 5090 at class v3, 2.1x at class v4 with k = 1), the FPGA
lane tightened to 0.30x to 0.47x per watt, the reserve R0 to R8, the reconciled shadow-N
ladder (section 5.3a) with HBM4 and three verifier brackets, the first measured verifier
proxy on igneum-build-1 (class v4 5.06 ms cold, dr736 10.51: out), the dataset schedule
to 2030; model sim/horizon/algorithm/model.py.
- docs/analysis/horizon/frontier.md: sixteen ideas ranked by payoff over difficulty with the
Monero and Kaspa attacks, prior art cited, the honest never column; model
sim/horizon/frontier/frontier_model.py.
- docs/analysis/horizon/new-pow.md sections 0 to 4: three new proof-of-work schemes defined,
reviewed in two personas, scheme A (mining is proving) ruled out on bytes and
sampleability, B and C in prototype on two rented 4090s; measured rows follow.
- docs/analysis/horizon-2026-10.md: the summary skeleton and the lane table.
Every rental cost cites docs/bench-log.md "Rental cost of hash, 6 October 2026".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
From the Horizon lane analyses of 6 October 2026 (docs/analysis/horizon/algorithm.md sections 5.1, 5.4 and 8;
docs/analysis/horizon/frontier.md sections 3.11, 4.1 and item I13; both land with the lane's own commit).
(1) Wherever the litepaper or the home page implied that the hourly program, the era draw or the instruction reserve
defeat a chip by surprise (the hero SVG line, the home hourly-program note, the Mining section's three ideas, the
"Every six months" row, the "A chip is impossible" item), the text now says what holds: they are automatic schedule
changes against fixed datapaths and against human forks; a chip wired for one program is useless; against the chip
that stores the dataset every drawn parameter is firmware and everything it needs is public at genesis, so the defence
is the latency-shadow work (class v4) and the price per joule. Ledger M32.
(2) docs/analysis/chip-model-v3.md section 5.3: the HBM activate-bound ceiling (8 per 12 ns, 10.7 G reads/s a stack)
is marked UNMEASURED beside the JEDEC HBM2 figure (tFAW 28 ns, 4 activates: 2.3 G), and the public FPGA line carries
only the measured row (Shuhai, FCCM 2020: 2.4 G reads/s, 0.30x to 0.39x of the RTX 5090 per watt) until an AWS F2
hour measures the ceiling. Ledger M33.
(3) The finality section's "What is not here" paragraph and the glance table's Finality row carry, verbatim: "No coin
is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window,
and equivocation strips it for 30 days." Ledger F26.
(4) "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September
2026 tracker cost (a secondary source) against about USD 13,700 a day of year-1 emission at USD 0.005 per IGN (the
price an input, not a forecast), so external proving is a small second income at launch and the lottery pays the
bills. Ledger E19.
docs/fud-ledger.md gains the four rows (Conceded, stated, 6 October 2026); site/ledger.html regenerated (171 entries);
tools/ci/ledger-text-check.mjs carries the five new stated sentences (48 sentences, 0 missing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026: the miners table and the events feed were too long for the story. The miners card is now a strip:
the count ("66 vote keys in 10 min"), the top five lanes by blocks with a bar each and the last-seen time, and "and N more"
with the bench table linked. The events card shows the last five, one line each, with the count of the rest in the note.
Two columns from 900 px. Measured headless: at 1440 both cards end at 1.9 screens (the scene fills the first); at 390 the
miners card ends at 2.5 screens and events at 2.95; no horizontal overflow, no console errors. Captures replaced in
docs/plans/site-ui-3-shots/after/live-1440-dark.jpg and live-390-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- provision.sh step_runner: actions/runner 2.338.0 (sha256 checked) at /opt/actions-runner under a dedicated user `runner`
(no sudo, not in build's group), rustup 1.99.0 pinned with both targets, sccache against /srv/sccache in READ_ONLY mode
on its own server port, Node 22 and mingw from the system, GitHub's svc.sh unit with a Nice 10 drop-in; registered on
igneum-network/igneum as igneum-build-1 (labels self-hosted, linux, x64, igneum-build-1) through
infra/build-server/runner/register.sh (gh as igneum-labs, the token on ssh stdin, never logged). Idempotent after
the env files moved behind svc.sh install (its env.sh rewrites them). libicu74 and python3-numpy added to APT.
- main's slots ruling: SLOTS default 2; remote-run.sh sets CARGO_BUILD_JOBS 90 when it holds the only taken slot and 45
when both are held, BR_MEASURE=1 takes the `measure` file exclusively and excludes builds (builds hold it shared),
lock files open in append mode (the old `exec {fd}>` truncated a busy slot's holder line on every probe), env
IGNEUM_BUILD_SLOTS_DIR and IGNEUM_BUILD_LOG_DIR win over the profile, `--self-test-slots` with five cases (the old
script fails it with JOBS=none); build-remote.sh and cross-remote.sh pass -j only when --jobs is given.
- infra/build-server/prover/cpu-trial.sh: the SP1 CPU prover on one fixture shard under the measure hold with a VmHWM
poller; 6 Oct 2026 run: core 34.2 s, compressed 85.9 s, peak RSS 28.2 GB on 96 threads, so no standing CPU prover.
- docs/plans/ci-self-hosted.md: the proposed runs-on change for ci.yml behind the repository variable IGNEUM_CI_RUNNER
(GitHub-hosted is the fallback), and why windows.yml cannot move to a Linux box. Workflows untouched.
- docs/plans/build-server.md section 7.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Rebased onto origin/master. Resolved: site/miner.html and site/miners.html taken whole from master (the site-miner copy,
the PC 1 images, the 42-character h1, lever 4 dated, the ember-tune "Measured by the team" row) and re-dressed in the shared
chrome by the build; site/build.mjs is master's (the shipper's downloads rule: the snapshot is written only on
SITE_DOWNLOADS_REFRESH=1, --refresh-downloads or CI; the priors team rows) plus the generated-page template on site.css and
the per-page eyebrow; site/index.html is the one-screen page with master's content ported in: the hero's proving sentence
(today's app on 24 GB, the 6 October rented-card measurement with its log link, "ships when the packaging row lands"), the
mine lead, the "Four pages" and "Ember Tune, measured" rows, the PC 1 figure and caption. The ledger generator's section
heading balances its lines and sits at 20 to 28 px so "Launch and operations" no longer leaves a word alone at 390 px.
Checks on this tree: identity grep 0 hits over 232 files, link check 884 links 0 broken, ledger text 43 of 43, contrast
32 pairs 0 under 4.5:1, orphan check 0 site headings (14 log titles reported), ledger page 0 leaks. Proof captures at 1440
dark: docs/plans/site-ui-3-shots/after/index-1440-dark.jpg and miner-1440-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/site.css: the tokens of the miner app's third redesign in light and dark (a darker light-mode ember and molten for text
so every pair passes 4.5:1, checked by tools/ci/site-contrast-check.mjs), the type scale on Unbounded, Plex Sans and Plex
Mono, the nav with one primary, the footer with a System/Light/Dark control, cards, tiles, tables that scroll on a phone,
buttons, pills, notes, callouts, the state words, focus rings, reduced motion, print. Partials rebuilt; the head loads the
stylesheet and applies the stored theme before paint. Every page's own style block is reduced to its page rules.
site/live-dag.js: the shared DAG view for / and /live (docs/plans/site-ui-3.md section 6): blocks by header time and
miner lane, parent edges with the selected chain as one heavier path, blue lit, red dim, pending grey, proven filled,
checkpoint bands with their lock weight (locked solid, pending dashed), new blocks arriving with a glow, hover and tap
details in the ledger's words, wheel and pinch zoom of the window (30 to 300 s), a pause button, device-pixel sharpness,
a still frame under reduced motion; opts.mine marks the user's own blocks (the miner app embeds the same file),
opts.poll:false with dag.push(reply) lets a host feed it. Every pixel is a block the observer stored.
site/index.html: the one-screen story (what it is, the live scene with chain block, shards proven, last lock, vote keys and
hash rate as state words, three things a sceptic checks, the download, how it works, the wallet, the journey, economics),
every tick-list row kept, the chip model's numbers moved to the sceptic card, the testnet terms behind a chevron, the
scroll-reveal gone, the Open Graph set on the 1200 by 630 image, no horizontal overflow at 390.
site/litepaper.html: dark like the site with light on request, whole paper by default (the section mode kept, deep links
intact, print prints the paper), repository paths off the surface, the cover dated 6 October, the wallet at 0.1.4, the
roadmap's verifier figure aligned with the Mining section, the proof lag stated as measured (about 380 s against the 60 s
gate), the 0.3.6 plan dated with 0.3.14 stated, the two "tonight" placeholders said as not yet measured. Every ledger
sentence verbatim (tools/ci/ledger-text-check.mjs, 43 sentences).
site/live.html: the lane chart replaced by the module; "proven A/B in 10 min", "finality paused, last #N", "pending" for
"n/a"; the fee sentence true on both sides of DAA 210,000. site/metamask.html: its own canonical, the explorer linked, the
wallet's state said true. site/404.html: the page count and section count said true. site/build.mjs: the generated pages
on the system, each with its own eyebrow, the miners page's source notes as sentences. downloads.json refreshed from the
host (0.3.14). tools/ci/site-orphan-check.mjs: no site heading leaves one word alone at 390 px (log titles reported).
Checks: identity grep 0 hits, link check 854 links 0 broken, ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1,
no horizontal overflow at 390 on 14 pages (the wallet page's timed table overflows by 5 px, for the wallet-ui-3 owner),
orphan check 0 site headings (the miner h1 at 96 characters is the site-miner agent's copy). After captures beside the
audit's: docs/plans/site-ui-3-shots/after/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/site-ui-3-audit.md: the project lead's ask of 6 October 2026 ("run the website and all pages and litepaper through the same
apple lens as the miner app", "leave no stone unturned") against the miner-ui-3 standard. Method, screen by screen with the
10-point scale (home 6, litepaper 5, live 6, miner 5, wallet 6, miners 5, explorer 7, block and address 6, faucet 7,
metamask 6, 404 6, bench 5, evidence 6, ledger 5), links and downloads (914 attributes followed, four installers hashed
against the host), the live elements' loading, failed and stale states, contrast of every token pair in both themes,
keyboard focus, phone width, the litepaper's print, the top ten findings, and appendix B listing the stones turned.
docs/plans/site-ui-3-ticklist.md (appendix A): 502 rows across 17 inventories, every claim, number, date, link and
feature with its source and today's verdict (MATCH, STALE, UNSOURCED, APPROX), the ledger's stated sentences and their
presence, the thirteen "does not claim" sentences verbatim, the scrub rules.
docs/plans/site-ui-3.md: the design: one stylesheet (tokens light and dark, type on Unbounded, Plex Sans and Plex Mono,
the card and table rules, state words, nav, footer), the home page as one screen, the litepaper as a readable paper
with a sticky section nav and the whole paper by default, per-page notes, and the live DAG module brief (the project lead's "can this
look more advanced and cool?").
docs/plans/site-ui-3-shots/before/ and before-states/: every page at 1440 and 390, dark and light, the failed-fetch and
stale-observer captures, the litepaper print PDFs, the focus captures; headless Chromium (Playwright's build, never
Chrome.app), one browser at a time, niced.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
provision.sh step_cuda: NVIDIA's ubuntu2404 apt repository, cuda-nvrtc-dev-12-8, cuda-cudart-dev-12-8, cuda-driver-dev-12-8
(the libcuda stub) and opencl-c-headers; no nvcc (no build file calls it), no driver. tools/workers-remote.sh builds
igneum-worker-cuda and igneum-worker-opencl on the box from proto-cuda and proto-opencl with clang++ (static libstdc++),
prints sha256 and the glibc ceiling (2.38: fine for Ubuntu 24.04 hosts, not for 22.04 containers or HiveOS, where the Mac's
zig build stays). Proof: igneum-worker-cuda 1,613,992 B sha256 6db8a9ad..., igneum-worker-opencl 124,904 B sha256 0dea75bb...
remote-run.sh evaluates the command string in a subshell (a leaked set -e killed the runner after a successful build).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/community/discord-hooks.mjs (Node 22, standard library): one ember embed per post to #numbers, #announcements and
#incidents. Network pulse every 6 h (03/09/15/21 UK) from /api/stats, /api/live, /api/supply with the 6 h window from its
own snapshot and a Devnet 2 line that uses the fleet file's numbers and gate word only; a 24 h digest and the reddit kit's
weekly template at 09:00 UK; a release subcommand for the shipper (three downloads with sha256, node commit, digest, up to
five plain "what changed" lines read from the release plan); incident open and resolve by hand; a watcher that opens one
incident per condition (finality paused 5 min, median proof lag 15 min, observer silent 3 min) and resolves after 2 clear
minutes, and never opens on a condition already firing when it first looks (the pulse says "finality paused since" instead).
Guards before every post: the founder's name and logins, hosts, machine ids, paths, IP addresses, standalone 32-hex
tokens, dl.igneum.network outside /public/, webhook URLs, mentions, the tools/ci/forbidden-strings.txt patterns; Discord's
limits refused rather than cut; idempotency keys per slot in a state file; exponential backoff on 429; dry run by default
with a Discord-like preview in tools/community/out/preview.html. 30 tests on fixtures cut from the live API.
infra/build-server/discord-hooks: a tick every minute on igneum-build-1 (the Mac sleeps). install.sh copies the webhook file
to /srv/discord-hooks/env (mode 600, over ssh stdin) and refuses without IGNEUM_SECRET_ON_BOX_OK=1; the recorded exception
to rule R6 is in docs/plans/build-server.md (main's ruling, 6 October 2026).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's decision of 6 October 2026: the Mac runs nothing the network depends on. docs/plans/hands-on-build-1.md plans node 1
and the observer (its node and tools/observer) as systemd units on the box, one hand at a time, with ports, DNS names,
exec recovery, rollback and the decisions for main; infra/build-server/hands/install-hands.sh writes users, dirs, run
scripts and units (inert, run on the box); move-hand.sh (dry run by default) builds 0.3.15 on the box, copies the override
and snapshot, rsyncs each data dir hot then stopped, starts the unit and prints the hand's first executing line, copies the
observer env by scp (mode 600), stops the Mac's observer first, unloads the launchd agents last. CLAUDE.md's running-agents
rule carries the decision. lib.sh: a per-worktree lock on the box across sync, build and fetch (the shipper's collision at
18:48:56Z). remote-run.sh: the clean-tree test excuses stamps and target dirs at any depth with --untracked-files=all (a
nested stamp failed every checkout of /srv/builds/igneum for twenty minutes) and removes a stale .git/index.lock; the
self-test covers both. Plan rows for the three and the cuda prover pair built for the shipper.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fleet's 10-member load run (6 October 2026, 18:14Z to 18:24Z) accepted 0 shares: the pool fork's miner re-checked GPU
shares with a fixed class v2 program while the 0.3.14 workers hashed class v3 (docs/plans/pool.md section 9).
pool: node.rs builds the share verifier's seeds from the template's pow_epoch with the class and the era, installs the
node's genesis day, dataset size and class v3 activation beside the schedule, and sends program_class, next_program_class,
era_seed, era_index, genesis_day_index, genesis_dataset_log2 and program_class_v3_activation_daa in `seeds` and
program_class and era_seed in `job` (protocol.rs, additive fields); verify.rs tests through EpochSeeds::v2. Protocol,
vardiff, PPLNS, stats API and page otherwise unchanged. Suite 22 of 22 on igneum-build-1.
igneum-pow tests/recheck.rs: for class v3 (packs-ca2-mixer/mx8-devnet-epoch0) and class v4 (packs-ca3-v4/v4-devnet-epoch0)
the pack's program reproduces the pack's 96 vectors (the worker's reference), the chain seam the node engine calls
(Epoch::chain_program, chain_dataset_day) builds the same program, one known nonce hashes equal through both paths, and
the fixed-v2 program of the same seed disagrees; the pinned v3 and v4 program ids differ. 2 of 2 on igneum-build-1.
packaging/hive: the pool:// mode merged with master's per-card IDENTITIES=auto and OVERRIDE handling (selftest passes).
pool/README.md and pool.md: building on igneum-build-1 (the vendor/igneum-node symlink on the box).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proving/igneum-prove depends on vendor/igneum-node-exec/igneum/evm-types, a member of the fork's workspace that inherits
from the fork's root manifest; syncing that one directory left cargo without a workspace root on the box. lib.sh now groups
path dependencies by git top level: a repository under vendor/ is pushed to its mirror (a fork worktree to
/srv/igneum-node.git, a repository of its own to /srv/<name>.git, created on first use), checked out whole at
/srv/builds/<worktree>/vendor/<name> and overlaid whole; run-from-mac.sh wires every vendor repository the Cargo.toml files
reach. libprotobuf-dev added (sp1-prover-types imports google/protobuf/empty.proto). build-remote.sh no longer fails on a
default artefact the caller's own -p selection did not build. Proof on the box: igneum-prove-host 71,943,192 B, sha256
e9213e3a6c979512d7859f6d8e848105bab53f4355e99fb0d30fb4a72c2d5714, 1 min 05 s warm. Plan: gotcha rows for the case, the
protoc miss and one lost ssh session (collector cleared by test).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Mine, Earnings and Settings on igneum.network/miner are now the installed 0.3.14 app on PC 1 (RTX 5090 at 122 MH/s,
222 W, 0.55 MH/W, 56 C; RTX 4070 at 28.7 MH/s, 76 W; RX 9070 XT at 18.9 MH/s, 198 W; 169 MH/s at 532 W; Ember Tune
and Power control on), shot read only by the signed run job site-capture-pc1-1 with Edge headless and brought back
over the relay. Masked in pixels: the job's own strip cut out of the content column, the rail foot and the Settings
name field (hostname, address) painted over, the Earnings address box painted over. Captions say PC 1, the time, that
no electricity price is set and that the tune lines are stopped tunes from before that afternoon's Power Helper fix.
Prove, light and the phone width stay the Mac's (PC 1's Prove shows an exporter error line that belongs in a bug
report; headless Edge followed the Windows theme so its light set is dark; its 390 px window clipped the right edge).
The contact sheet is refreshed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The node pin moves to 4c6b129d (release-0.3.14-node), which is what the live payload inputs carry, so windows-ci's payload-inputs step is green again (red since e9eca23 on master's 0.3.13 pin against the 0.3.14 inputs).
Conflicts: infra/fast-time/override-60x.json keeps master's side (the fresh-rule field was already there at u64::MAX; the release line would be a duplicate key); tools/ci/playbook-quit-check.sh keeps master's rule 2 and pre-rule list with the release side's Ember allow entry and the 0.3.15 expiry check.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
remote-run.sh gains a checkout mode used by lib.sh: git checkout -- . and git clean -fd (target dirs, the sha stamps and
ignored files kept), fetch, branch at the commit, then a clean-tree check; the overlay follows. Before this, the rsync of
uncommitted files stayed in the box's tree and the next commit's git checkout -B refused with 'local changes would be
overwritten'. remote-run.sh --self-test reproduces the dirty tree (edited tracked file, untracked file, target dir, sha
stamp), shows the plain checkout refusing and the mode landing clean on the new commit; it runs in ci.yml and passed on the
Mac and the box; a live dirty-then-clean pair on the fork worktree passed too. Plan: section 5, gotchas of the first day.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The "LIVE DEVNET" scene on the home page showed blocks 21, proven 0, locked 3 and grey nodes while the devnet stood past
chain block 140,000 with 2,090 shards paid and a checkpoint locking every 30 s. Four causes, all in site/index.html:
- "blocks" was the scene's own spawn counter, never the chain;
- "proven" counted blocks of the 90 s window whose shards were all paid, and proofs land a median 380 s behind the tip
(median_proof_lag_s), so the window can never hold one;
- "locked" counted locked checkpoint blocks inside the same 90 s window (always about 3);
- the live path skipped the colour state machine, so every real block stayed grey, and a failed first fetch left the
simulation running under a label that looked live, with no further polls.
Now: /api/live carries state.height (the chain block number, the same field /api/stats reports, one indexed subquery);
the scene's counters read chain block (state.height), shards proven (proving.paid_shards_total, the node's count of paid
shard records, with the 10-minute count and the median lag in the note) and last lock (finality.latest_locked_index);
live blocks take the observer's own words (pending, included, excluded, proven, locked checkpoint, final to its left),
refreshed on every poll, with a legend in those words; the hero tile shows the chain block instead of the node's
held-block count; polling never stops (2 s while fresh, 10 s while off) and the off state is labelled "simulated preview ·
live feed unavailable" or "observer offline, last update N ago" with a note that the counters count simulated blocks.
Also found while verifying: the scene advanced a fixed 16 ms per frame, so it ran at double speed on 120 Hz displays;
it now uses the real frame time, capped at 50 ms.
/live had the same window bug in its "proven 0/16" counter; it now reads the observer's 10-minute truth (chain blocks
with every shard paid, of the chain blocks planned in 10 min) with the lag and the chain total in its title.
Verified against the live API through tools/site-serve.mjs in the built-in browser and headless Chromium:
chain block 140,489, shards proven 2,130, last lock #6,784; the failed-fetch state shown by blocking /api/live.
Screenshots: docs/plans/site-ui-3-shots/item0/ (1440 and 390, live and failed). Checks: identity grep 0 hits,
link check 708 links 0 broken, site/api tests 14 pass, site build clean.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Real screenshots of the live 0.3.14 app on the Apple M5 Max (paused, Ember Tune off, as the project lead left it), shot headless
at 1440x900 and 390 px, dark and light, the rail foot, the address and the machine id masked: miner-dashboard.webp
(the hero, same name), miner-earnings, miner-prove, miner-settings, miner-dashboard-light, miner-phone.
miner.html: a page-by-page section (the card row cell by cell, three page shots, light and the phone), the lead and
the meta copy name the four pages and pounds a day at the user's price, the Ember Tune feat carries the app's one
sentence and the measured PC 1 rows from the 6 Oct log (5090: 311.0 to 226.8 W for 0.15% of rate; 4070: 106.0 to
75.6 W for none; the floor, not the optimum), the Power control feat (one approval, then the helper task, no prompts),
the dev fee moved to Earnings as in the app. index.html: the same hero shot, two pills. build.mjs: the caption no
longer says 'until 0.3.6' (0.3.14 still says Igneum Miner). The 9070 XT row, the market price for pounds earned and
the bench anchor (the run 6 entry is on the ship0314 branch) are marked as owed or coming.
relay/playbooks/site-capture-pc1.ps1: a read-only run job that shoots the installed app's UI on PC 1 with Edge
headless and drops the PNGs on the relay (no quit, pause, resume or settings change; passes the playbook checks).
docs/plans/site-miner-2026-10-06.png: before and after.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's decision of 6 October 2026. CLAUDE.md 'Running agents on this Mac': every Linux and Windows cargo build and every
Linux test suite goes to igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh; the PCs keep GPU and
Windows-runtime jobs; the Mac keeps macOS binaries, the DMG and Metal tests under the lock. -Wl,--no-insert-timestamp in
cross-remote.sh, proto-cuda/windows-node/cross-build.sh and jobbuild.rs (two box builds byte-identical, verified).
The empty-commit class: tools/ci/commit-string-check.sh (self-test in ci.yml, shown firing on a Mac worktree build and
passing on a box build) runs on every igneumd from the three build scripts; push-build-inputs.sh adds node.commit_full,
the PC job writes a minimal node/.git from it at extract and cleans kaspa-build-info on a new commit (4 jobbuild tests
pass, run on the box); cross-build.sh refuses a worktree and cleans on a new commit. Plan: second worktree's clean build
1 min 18 s with sccache 604 hits of 993.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
remote-run.sh runs on the box behind BR_* exports: slot, sccache stats, the RESULT line and one JSON line per run in
/srv/builds/_log/builds.jsonl (v 1, id, host, tool, worktree, crate, kind, command, target, branch, sha, label, agent, slot,
wait_s, queued_at, start, end, secs, exit, compiles, sccache, load_end, artefacts; written on success, failure and the 2 h
slot give-up), the label ending in '; agent=<name>' (IGNEUM_AGENT, default the worktree). The remote checkout is a branch and
build-remote.sh cleans kaspa-build-info (release profile) on a new commit, so the box's igneumd carries its commit hash
(no Mac worktree build does: .git is a file there). cross-remote.sh fetches the GCC 13 runtime DLLs beside an exe that
imports libstdc++-6.dll. The plan holds the three benchmarks: clean node build 1 min 27 s (Mac 12 to 18 min), incremental
7 s (Mac 2 to 15 min), Windows cross 1 min 44 s (Mac 4 min 49 s to 12 min 28 s), their consequences and the proposed rules.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>