A section between the live scene and Your card: three real screenshots
(the shipped Mine page of 0.3.14, and the next release's Overview and
Cards pages from the app in development), light and dark variants,
three lines (one click, every card tuned, the chain on your screen),
the download list repeated, and the wallet in one card.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "Im not sure about the site can we revert it but polish it? minimal, simple but everything needed
for the dopamine and emotional triggers of the gpu miner", then "cant we have a dag animation like we had before? with the
shards making up the block, then the final line and the other bits that looked really cool but brought upto date?"
Restored (a new commit, no history rewrite): site/index.html as it stood at 14da2b8, the step-view page with its hero, facts,
scene, three things to check, downloads, build, wallet, journey, economics and the ledger band; nothing from tonight's other
work is undone (the litepaper, /live, the roadmap and benchmark wording, ledger X31 to X33, the scroll-zoom fix). Where the
page named a month it now carries tonight's sentences: the proofs card reads "Live rows arrive with the public testnet. The
public testnet is weeks away: three seed nodes and the public RPC are up, and it opens when the go checklist closes."; the
journey lead reads "Six phases, four public gates ... No calendar dates: each phase closes at its gate." and its inlined
phases are the gate-worded ones. No "August 2027", no month anywhere on the page.
The scene (site/live-steps.js): the original bits, every one driven by the live feed. A real block arrives from the right
with a glow and its chain number under it; its outline is grey while pending and ember once included; as its shards are
verified or paid, particles fly in from the edges and its quarter cells fill molten; when every shard is proven the block
turns ember and the caption says how many provers were paid; a locked checkpoint takes a ring and a ripple and the dashed
"final" line sweeps in from the right to it, drawn only while finality is active (the legend no longer says "final to its
left"; the wallet card's state word "final, checkpoint 5" is the wallet's own vocabulary and stays). A proof or a lock that
lands on a block already off screen re-enters from the right as its own event, so every step is seen when it happens. The
counters gain blocks per second. The caption follows the newest block that changed step.
The miner's triggers, each one element with live or measured numbers, none invented: a network strip under the facts
(hash rate, blocks in the last ten minutes, the latest block's age ticking every second with its chain number and word,
shards proven and paid with the last ten minutes), each value flashing molten when it changes; a card picker from the bench
table with the time a card alone takes to find a block at the live hash rate (RTX 5090 127.7 MH/s at 227 W and RTX 4070
28.8 MH/s at 76 W from the 6 October Ember Tune on the three-card Windows rig, RX 9070 XT 17.8 MH/s from the 5 October eGPU
entry, Apple M5 Max 26.7 MH/s from the first live swap; the RTX 4090 and RX 7900 XTX shown as not yet measured with the
bench table linked) with the pool note; the fairness line (graphics cards only, a new program every hour, your card proves
the blocks, 80% to the miner and 20% to the provers, nothing to anyone else); the download buttons with sizes; a Discord join
line (the standing invite, recorded in docs/community/discord-hooks.md so nobody asks again); the testnet sentence.
docs/fud-ledger.md: G4, C2 and X8 each gain a status line saying the restored home page carries their sentence again; the
ledger-text check guards them on the home page again (55 sentences, 0 missing).
Measured headless over 40 s against the live feed: 19 captioned transitions, the strip reading 2.3 GH/s, 562 blocks in ten
minutes, 8 s ago, 2,970 shards paid, the picker's times 18 s (5090), 79 s (4070), 2 min (9070 XT), 86 s (M5 Max) at that
hash rate, 0.92 blocks/s; no console errors at 1440 or 390 in either theme; no horizontal overflow. Captures in
docs/plans/site-ui-3-shots/after-v2/: home-{1440,390}-{dark,light}-fold.jpg, home-{1440,390}-{dark,light}.jpg and
home-steps-1440-dark.webm (ten seconds of the scene). Checks: identity grep 0 hits on served files, link check 934 links
across 16 pages 0 broken, ledger text 55 of 55, contrast 32 pairs 0 under 4.5:1, api tests 5 pass. Not deployed: the owner
sees it first.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner's ruling, 6 October 2026, the same as the roadmap's: the litepaper said the public benchmark with a leaderboard "is
January 2027" (For miners) and "ships in January 2027" (Questions miners ask). Both now read "The public benchmark with a
leaderboard ships with the public testnet." (the second keeps its tail: its source is public with the repository then, so you
run it on your own card and post the number). One gate the reader already knows from the roadmap's phase 5. docs/fud-ledger.md
gains X33; the 5 October answers that named the month stay as the history of the plan. The ledger page regenerated (179
entries, 0 leaks).
Checks: identity grep 0 hits on every served site file, link check 912 links across 16 pages 0 broken, ledger text 51 of 51,
contrast 32 pairs 0 under 4.5:1, orphan check 0 site headings, api tests 5 pass, no calendar month on the litepaper or the
home page.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner's ruling, 6 October 2026: a phase 4 dated "Apr to Jul 2027" before a phase 5 that is weeks away is a contradiction a
reader spots at once. The roadmap (site/litepaper.html Roadmap, site/journey.json, the home page's inlined journey) now names
no month. Each phase in the shape phase 5 has, the order unchanged:
1 Under way; closes when the specification is out for external review
2 Under way; closes at its gate
3 Live since 3 October 2026; closes at its gate
4 Closes when the finality design passes external review and one rollup signs for the testnet
5 Weeks away: when the go checklist closes
6 After the testnet has passed its gate: 1,000 independent miners for 30 days and rollup proofs on time
The lead reads "Six phases from specification to a fair launch, with four public gates and no calendar dates: each phase
closes at its gate." The devnet's 3 October 2026 start is a fact and stays. Not in the roadmap and left as it is: the public
benchmark's "January 2027" in For miners and Questions miners ask (its own commitment, for the owner's word).
docs/fud-ledger.md: row X32 records the change; rows G4, C2 and X8 gain a status line (the old kept as history) saying the
home page no longer carries their sentence and the litepaper does, after the home-page redesign; X3 got its line in the
previous commit. The ledger page regenerated (178 entries, 0 leaks).
Checks: identity grep 0 hits on every served site file, link check 912 links across 16 pages 0 broken, ledger text 51 of 51,
contrast 32 pairs 0 under 4.5:1, orphan check 0 site headings, api tests 5 pass, no calendar month on the roadmap surfaces.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "August 2027" is false. igneum-testnet-1's genesis is final, three seed nodes and the public RPC
are up, and the testnet opens when the go checklist (docs/plans/testnet-go.md) closes, which is weeks away. No calendar
month is given; the owner gives one if he wants one.
The sentence everywhere: "The public testnet is weeks away: three seed nodes and the public RPC are up, and it opens when
the go checklist closes." In site/litepaper.html the proving section's proofs feed ("Live rows arrive with the public
testnet." then the sentence), the For miners paragraph ("Pools come with the public testnet." then the sentence) and the
roadmap's phase 5 ("Weeks away: when the go checklist closes"); site/journey.json phase 5 and the home page's inlined
journey carry the same row. docs/fud-ledger.md gains X31 recording the correction (the old sentences, the new one and where
each lived), row X3 a new status line pointing at it (the old line kept as history), and O-X.2's blocker note and
overclaim item 75's replacement text read the new state. tools/ci/ledger-text-check.mjs checks X3's new sentence and X31
(51 sentences, 0 missing). The ledger page regenerated (177 entries, 0 leaks).
Checks on the tree: link check 912 links across 16 pages 0 broken, contrast 32 pairs 0 under 4.5:1, orphan check 0 site
headings, api tests 5 pass, identity grep clean on every served site file (the one hit is master's polish.md, the polish
lane's), no "final" on / or /live while finality is paused, no console errors, "August 2027" on no page.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026, on the live home page: "too left and text heavy ... we want the home page to suck people in and let
the litepaper carry the weight; also minimise the header." The home page only; nothing else above the fold.
Header (this page only, a page-block override of the shared nav): the wordmark, Litepaper, Live devnet and Download the miner,
56 px, transparent over the hero; the phone sheet shows the same three.
Hero: one statement, eleven words ("A proof-of-work chain for graphics cards, whose miners prove the blocks."), two buttons,
then the step scene (site/live-steps.js on the shared feed) full bleed with its one caption line. Hero copy 17 words with the
buttons. At 1440 by 900 the hero ends at 849 px; at 390 by 844 at 699 px.
Below the fold: three facts, each one number and one sentence: the live hash rate with the vote keys of the last ten
minutes, the shards proven and paid on the chain (with the last ten minutes), and the chip model's one line with its link;
a note under them says the chain's state in the ledger's words (tonight: finality paused) and that the chip figures are a
cost model, not a measurement. Then the downloads row (three platforms) with the devnet and testnet notices and the dev-fee
sentence, then one line to the ledger and to what Igneum does not claim. The footer is unchanged.
Moved, nothing cut: the light-client card to /live (its verifier module with it); the testnet terms to the litepaper's For
miners section (with an id for the metamask page's link); "Live rows arrive with the public testnet, August 2027" to the
litepaper's proving section; "since 2019 (approximate)" onto the litepaper's RandomX date; the journey, economics, wallet,
build and RandomX sections were already in the litepaper (roadmap, economics, wallet, building, vs RandomX). The footer's
Journey link points at the litepaper's roadmap. tools/ci/ledger-text-check.mjs: the home page is checked for E5, X2 and
X7; G4, C2, X3 and X8 are checked on the litepaper (G4 and X8 were already there). The ledger's own "stated on" notes for
those four rows are owed an update by the ledger owner.
Polish lane Q5: the word "final" is drawn and captioned only while finality is active (site/live-steps.js), so nothing on
the page says final while finality is paused; the hero is under 40 words; the Open Graph card is the 1200 by 630 image.
Measured headless at 1440 and 390, dark and light: header 56 px with three items, no "final" anywhere, no horizontal
overflow, no console errors; the caption advanced on every capture. Captures: docs/plans/site-ui-3-shots/after/
home-{1440,390}-{dark,light}.jpg (full page) and home-{1440,390}-{dark,light}-fold.jpg (above the fold).
Checks: link check 912 links across 16 pages 0 broken, ledger text 50 of 50, contrast 32 pairs 0 under 4.5:1, orphan check
0 site headings, api tests 5 pass. The identity grep's one hit is docs/analysis/horizon/polish.md line 433 on master,
untouched here (the polish lane's own table of regex literals); it is main's to route.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every shipped surface audited against a named comparator with the file or screen: the pause of
6 October had no cause on any surface for two hours (the node reports no frozen-table reason,
the observer copies the flag alone, /live computes the silent share from the sliding table,
Ember has no pause state); a fresh machine meets two warnings before the first screen (ad hoc
codesign, no notarisation, unsigned Windows installer); every update has been urgent since the
0.3.14 manifest (fork_is_close treats any passed activation as close). Rows Q1 to Q105 with
severity, hours, owner and gate; cross-cutting: one formatter table for every number, the five
6 October rule rows without a tools/ci check, the forbidden-string scope gaps.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/horizon/new-pow.md sections 0 to 9: scheme A (mining is proving) never, on bytes,
the verifier and sampleability; scheme B (the tensor-shaped integer shadow) prototyped as
proto-newpow/mma-shadow and measured, never as class content on the energy reading, with the R8
two-output correction; scheme C (proof of stored state, sd1: the daily dataset derived from the
execution state) prototyped as proto-newpow/state-dataset, measured on the GPU and the box's
CPU, and put forward as the class v5 candidate with its spec items and the Devnet 2 gate. The
lane's standing rule: a shadow lever only works through joules the honest card is forced to
spend, so shadow work goes where the GPU is least efficient per op. Chip rows in
sim/horizon/new-pow/chip_rows.py by the chip-model-v3 method. Rented box addresses replaced by
placeholders in the READMEs and the run script.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The owner, 6 October 2026: "I liked it when we could see each step of the algo working." The home page's scene is again the
lane chart where a square moves through mined, shards being proven, proven and locked checkpoint, now as site/live-steps.js on
the shared feed (site/scenes/feed.js, which gains onData):
- every square is a real block from /api/live (a 300 s window so late proofs still reach the caption), released one every
2.5 s so a square crosses the scene in about 34 s; the chain merges a pending block in about 10 s, so its step changes
while it is still on screen (at the original 10 s crossing most transitions landed after the square had left). The feed is
sampled for the stream; item 0's counters read the chain. The first reply seeds the scene across its width, so nothing
starts empty;
- each step is drawn as before: an outline (grey while pending, ember once included), molten quarter cells filling as shards
are verified or paid, an ember fill when proven, a ring on a locked checkpoint with the dashed "final" line to its left,
excluded blocks dimmed; every transition glows for a second and a lock ripples;
- one caption line under the scene for the newest block that changed step, e.g. "block 144,564: mined 21:16:03, on the
selected chain; 1 shard planned", or with its shards "8 shards on 3 cards; proven in 48 s" and "locked at checkpoint 7,084".
/api/live now carries each block's chain number for it. When no block changes step for a minute the caption says why in
the ledger's words: finality paused (under two thirds of the weight signing), no proof landed in the last 10 minutes
(with the median lag), or no block changed step;
- the wheel is never touched: the module has no wheel handler, so the page scrolls through the scene;
- light and dark from the tokens, 390 px, a still frame under reduced motion. The DAG module stays as /live's scene and the
three scenes stay unlinked on /scenes.
Proved headless over 40 s against the live feed: thirteen captioned transitions, no console errors at 1440 or 390, no
overflow. Captures: docs/plans/site-ui-3-shots/after/index-steps-1440-dark-clip.jpg, index-steps-390-dark-clip.jpg and
index-steps-1440-dark.webm (ten seconds of blocks moving through the steps). Checks: identity grep 0 hits, link check 931
links 0 broken, ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1, api tests pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
From docs/analysis/horizon/economy-and-utility.md (sections 3.1, 4.1 to 4.4, proposals 2, 3, 4, 7) and
docs/analysis/horizon/consensus-security.md (finding 3, proposal 1), both on master.
(a) The litepaper's "proofs at the cost of power" and the customer brief's "priced in dollars per proof" are
conditioned: electricity is close to power, the price a prover must charge is the subsidy it forgoes, published as a
formula with network hash as the input (per shard, card hash over network hash x 0.8 x 31.688 IGN x shard seconds,
plus electricity), never a number; 100 to 300x the published market rate at the devnet's 1.16 GH/s, competitive near
100 GH/s beside the miner, approximate beyond the one card measured. Six litepaper passages and two brief rows. The
text check's P6 sentence moves to the conditioned form. Ledger E20.
(b) One threshold sentence in Governance and Mining: 60 percent of blue blocks over two weeks for a parameter genesis
leaves open, 90 percent for an upgrade (new code), 95 percent with a floor height for a class change (the Mining
section had said a 90 percent signal turns a spare defence on, which is a class change). Ledger G15.
(c) The 20% proving-pool row carries the caveat that consensus does not yet verify the carried proof, so a block
producer could claim shard pay with a false proof today (P21; the 0.3.16 fix). Ledger P24.
(d) The dev fee reads "default-on, switchable, 1 percent of the producer share" in the payment-routes row and the
Ember section; docs/plans/funding.md section 4's ceiling is 1 percent of the producer share, USD 38,520 / 154,080 /
770,400 at the three prices, corrected from 48,000 / 193,000 / 963,000. Ledger E21.
(e) The pool row's note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls it
into the next proven segment (0.3.16). Ledger P25.
site/ledger.html regenerated (176 entries); tools/ci/ledger-text-check.mjs carries the five new sentences (53, 0 missing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The build-server agent's two findings on rebuild-on-box.sh (6 Oct 2026, 20:1xZ): tools/ci/copied-sources-check.sh named it
(a tar on a code line plus cargo build with no touch), and `RUSTC_WRAPPER=` did not switch sccache off, so some passes of the
first runs took hits. Both 0.3.14 and 0.3.15 are re-run with this version before their evidence files are trusted.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's rule of 6 October 2026 from the 0.3.14 repro (docs/evidence/reproduced/0.3.14.md): prost's protowire.rs embeds OUT_DIR,
libmimalloc-sys embeds __DATE__/__TIME__, sccache hid both. lib.sh bs_repro_env exports SOURCE_DATE_EPOCH=<author time> TZ=UTC in
front of every remote command (build-remote.sh, cross-remote.sh, workers-remote.sh); remote-run.sh exports BR_SDE too and logs it
as source_date_epoch; proto-cuda/windows-node/cross-build.sh exports the same; the PC job carries node.commit_time in the manifest
(push-build-inputs.sh) and exports it before every cargo build of a stage (jobbuild.rs, unit test asserts it; 4 of 4 pass on the
box). Target dirs stay one fixed path per target. tools/build-remote.sh --self-test-repro [--full] from a fork worktree, run on
the box: igneum-miner twice a minute apart without sccache (RUSTC_WRAPPER=/usr/bin/env, an empty value is unset to cargo) MATCH
91e130f5..., a per-run target path differs (OUT_DIR shown); --full: kaspad with libmimalloc-sys recompiled a minute later MATCH
70219bc2..., without the epoch differs (__DATE__ shown).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Utility curves for IGN beyond gas with dollar inputs labelled; the proving price as the
forgone subsidy (1 / network hash) against Boundless's published rate; the adopted job floor
overprices the market above about USD 0.014 per IGN; a ten-year security budget with the
measured 5090 row (sustained hash USD 24.8 per GH/s-day against USD 281 rented, so the 20-day
34 percent weight attack costs 11.8x the honest fleet at every price); sim/economy re-run with
the eleven measured cards under eight stresses (T1 to T5 hold; a ten-day prover refusal strands
547,570 IGN a day of pool credit in the escrow with no rule to return it); the dev fee, the
signalling game, and the twelve-row table of what Kaspa, Monero, Ethereum and the zk rollups
did (rusty-kaspa cited by file and line).
Models: sim/horizon/economy-and-utility/ (utility.py, stress.py, security_budget_10y.py,
signal_game.py, devfee.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/51-percent.md: what a 51 percent attacker can and cannot do on Igneum, with
numbers (the selected-chain race over a 90-s hold, the lock as the reorder bound, the veto
at 1/3 of weight and its rental cost, the departure case and the LEAVE item, the p2p surface).
docs/analysis/horizon/consensus-security.md: the attack catalogue across GHOSTDAG ordering,
the difficulty rule, the finality weight, miner signalling, proof records, the exec layer and
p2p, each with the bound and the rental cost at the measured USD 11.7 per GH/s-hour; the
pruned-node unwrap class with its sibling list in the sync and IBD flows; fourteen ranked
defences, three of them not recommended with the reason.
Models and results: sim/horizon/consensus-security/ (ghostdag_sim.py, finality_horizon.py,
cost_model.py, signalling.py, result files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- rebuild-on-box.sh: the DIFFER reason comes from the binaries (glibc need of both, the build path each embeds, the
mimalloc clock string, the PE timestamp, the commit string), never from an assumed story; the three string helpers run
their producer under `|| true` so a consumer that stops early (grep -m1, awk exit) no longer trips pipefail into the
fallback and a second line in a table cell.
- docs/evidence/reproduced/0.3.15.md, and the 0.3.14 file re-reported with the same column.
- docs/plans/build-server.md 7.3: the 0.3.15 row and what the two files mean for shipping from the box.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026, item 3: three alternative scenes for the same live data, side by side at 1440, each a self-contained
module on one shared feed, the ledger's words in the legend (pending, included, excluded, proven, locked).
site/scenes/feed.js polls /api/live every 2 s and pushes the reply to every scene; it carries the site's state words
(connecting, live devnet, observer offline with the age, live feed unavailable) and the shared helpers (theme tokens from
CSS, the word for a block, DPR-sharp sizing, a frame loop that stops when hidden or off screen and draws a still frame under
reduced motion). Every mark in every scene is a block the observer stored; nothing is invented.
A, Forge (site/scenes/forge.js): blocks rise from the hearth as embers, one column per miner, at the height of their header
age over a 120 s window; a block cools as its word changes (pending molten, included ember, proven bone, excluded ash);
a new arrival glows for a second; a lock is a dark band that sweeps up the scene at the newest locked checkpoint, and
everything under it is final and settles to ash.
B, Lattice (site/scenes/lattice.js): a slow isometric DAG, time left to right, the selected chain as the lit spine in the
front lane, the other miners one shallow step deeper each (ranked by blocks, the shear capped to a third of the width so a
narrow card keeps its time axis), parent threads reaching forward, chain edges heavy with a soft halo, checkpoints as rings
that close around the spine when they lock with the lock weight beside them, new blocks glowing in; the camera drifts at
chain speed.
C, Pulse (site/scenes/pulse.js): the tip at the centre breathing, time outward with a ring every 30 s, each miner a ray,
each block a bead on its ray drifting outward, filling when proven, hollow while pending; the selected chain as short arcs
winding between consecutive beads (never a chord through the centre); a checkpoint is a ring that hardens from dashed to
solid when it locks.
site/scenes.html: the three cards side by side at 1440 and stacked under 1000 px, the shared legend, a note on the window
and reduced motion; ?only=a|b|c shows one scene full width (the card filter copies the children before removing, so the
right card survives). noindex, not linked from any page; registered in the build's PAGES so it takes the shared chrome.
Captures (docs/plans/site-ui-3-shots/scenes/, one niced headless Chromium): scenes-1440-dark.jpg (the three side by side),
scene-{a,b,c}-1440-dark.jpg and scene-{a,b,c}-390-dark.jpg, and scene-{a,b,c}-1440-dark.webm, ten seconds each at 1440 by
900 (VP8, recorded by Playwright and cut with its ffmpeg, which has no mp4 muxer). No console errors on any scene at either
width; no horizontal overflow at 390. Tonight's chain shows in all three: finality paused, so no band, closed ring or hardened
ring appears, and the checkpoint marks read pending.
Checks: identity grep 0 hits over 232 export files and 33 served site files, link check 931 links across 16 pages 0 broken,
ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 6 October 2026 pause from the observer rows: 20 keys holding 42.7 percent of the frozen
voter table left in three minutes; locks formed without the hub; the 2/3 rule paused at
checkpoint 6843 (53.1 percent of total) and the frozen table (Q5) held the pause for a window
where rule v2 would have locked after 35 minutes. Candidate rules run in a copy of the finality
simulator (seeds 7, 11, 13): only the departure announcement keeps 0 conflicting locks and ends
the pause under an hour. Weight capture priced at the measured USD 11.7 per GH/s-hour: the veto
0.52 x N for 30 days (USD 4,300 per GH/s of network), a lock alone 2.03 x N. Lock delay by voter
count measured on node 1; the ZK light client and prover attestations costed.
Models: sim/horizon/finality-and-weight/ (finality_horizon.py, weight_capture.py,
lightclient_cost.py, merge_results.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- infra/build-server/repro/rebuild-on-box.sh: one target path per target with each pass's artefacts copied aside (prost's
protowire.rs embeds its OUT_DIR path, so a pass in a dir of another name differs), SOURCE_DATE_EPOCH from the node commit
and TZ=UTC (libmimalloc-sys compiles mimalloc's C with __DATE__ and __TIME__), --reuse for a re-report, reason text
for a shipped file that is not on hand (innoextract 1.9 cannot open the Inno Setup 6 installer; the 0.3.14 HiveOS
tarball left dl/public when 0.3.15 published).
- tools/repro/rebuild-release.sh: the plan's hashes always travel (the miners' 8-hex prefixes too), bash 3.2 empty-array
fix, the box half's exit code is the script's.
- docs/evidence/reproduced/0.3.14.md: igneumd 03f35e05..., igneum-miner 900c1f0b..., igneumd.exe 166e604e...,
igneum-miner.exe fefd266c... identical across two clean passes; DIFFER against the shipped 934f393c... (zig, glibc 2.36)
and 44fa74c0... (Homebrew mingw before the timestamp fix, from a worktree).
- docs/plans/build-server.md 7.2 (night battery: timer, dry run 3 min 54 s, 10 pass, the fork's 22 cargo-audit
advisories as the one FAIL and what follows) and 7.3 (repro: results, the two classes, SOURCE_DATE_EPOCH proposed for
every build script).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's 6 October 2026 ask: deep backward and forward research across the hash, finality,
economy, network and every shipped surface. This commit carries the first three lanes.
- docs/analysis/horizon/algorithm.md: the chip model on the 6 October numbers (f = 1 GDDR7
chip 5.7x per joule against the 5090 at class v3, 2.1x at class v4 with k = 1), the FPGA
lane tightened to 0.30x to 0.47x per watt, the reserve R0 to R8, the reconciled shadow-N
ladder (section 5.3a) with HBM4 and three verifier brackets, the first measured verifier
proxy on igneum-build-1 (class v4 5.06 ms cold, dr736 10.51: out), the dataset schedule
to 2030; model sim/horizon/algorithm/model.py.
- docs/analysis/horizon/frontier.md: sixteen ideas ranked by payoff over difficulty with the
Monero and Kaspa attacks, prior art cited, the honest never column; model
sim/horizon/frontier/frontier_model.py.
- docs/analysis/horizon/new-pow.md sections 0 to 4: three new proof-of-work schemes defined,
reviewed in two personas, scheme A (mining is proving) ruled out on bytes and
sampleability, B and C in prototype on two rented 4090s; measured rows follow.
- docs/analysis/horizon-2026-10.md: the summary skeleton and the lane table.
Every rental cost cites docs/bench-log.md "Rental cost of hash, 6 October 2026".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
From the Horizon lane analyses of 6 October 2026 (docs/analysis/horizon/algorithm.md sections 5.1, 5.4 and 8;
docs/analysis/horizon/frontier.md sections 3.11, 4.1 and item I13; both land with the lane's own commit).
(1) Wherever the litepaper or the home page implied that the hourly program, the era draw or the instruction reserve
defeat a chip by surprise (the hero SVG line, the home hourly-program note, the Mining section's three ideas, the
"Every six months" row, the "A chip is impossible" item), the text now says what holds: they are automatic schedule
changes against fixed datapaths and against human forks; a chip wired for one program is useless; against the chip
that stores the dataset every drawn parameter is firmware and everything it needs is public at genesis, so the defence
is the latency-shadow work (class v4) and the price per joule. Ledger M32.
(2) docs/analysis/chip-model-v3.md section 5.3: the HBM activate-bound ceiling (8 per 12 ns, 10.7 G reads/s a stack)
is marked UNMEASURED beside the JEDEC HBM2 figure (tFAW 28 ns, 4 activates: 2.3 G), and the public FPGA line carries
only the measured row (Shuhai, FCCM 2020: 2.4 G reads/s, 0.30x to 0.39x of the RTX 5090 per watt) until an AWS F2
hour measures the ceiling. Ledger M33.
(3) The finality section's "What is not here" paragraph and the glance table's Finality row carry, verbatim: "No coin
is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window,
and equivocation strips it for 30 days." Ledger F26.
(4) "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September
2026 tracker cost (a secondary source) against about USD 13,700 a day of year-1 emission at USD 0.005 per IGN (the
price an input, not a forecast), so external proving is a small second income at launch and the lottery pays the
bills. Ledger E19.
docs/fud-ledger.md gains the four rows (Conceded, stated, 6 October 2026); site/ledger.html regenerated (171 entries);
tools/ci/ledger-text-check.mjs carries the five new stated sentences (48 sentences, 0 missing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The rebase onto e69117a kept master's captions and build scrub and this branch's wheel handler, chip and note. The build
re-inlined the journey feed from master's journey.json. A code comment in site/live-dag.js named the owner; master's
identity grep now covers every served file and caught it, so the comment says the owner.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026: the miners table and the events feed were too long for the story. The miners card is now a strip:
the count ("66 vote keys in 10 min"), the top five lanes by blocks with a bar each and the last-seen time, and "and N more"
with the bench table linked. The events card shows the last five, one line each, with the count of the rest in the note.
Two columns from 900 px. Measured headless: at 1440 both cards end at 1.9 screens (the scene fills the first); at 390 the
miners card ends at 2.5 screens and events at 2.95; no horizontal overflow, no console errors. Captures replaced in
docs/plans/site-ui-3-shots/after/live-1440-dark.jpg and live-390-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026: scrolling past the DAG zoomed it. The module's wheel listener took every vertical wheel. Now a plain wheel
or a trackpad's two-finger scroll is never captured: the handler returns before preventDefault unless ctrl or cmd is held or
the scene is engaged. A click into the scene engages it (the canvas takes an ember outline and a chip reads "scroll to zoom,
Esc to release"); Escape, a click outside the scene or the chip releases it. Pinch zoom is unchanged. Same module on / and
/live; both pages carry the chip and the note says how to zoom. opts.chip and opts.onEngage are new, optional; dag.engage(bool)
is exposed.
Proved headless on both pages: a plain wheel over the scene scrolled the page 300 px and left the window at 120 s; engaged, a
wheel zoomed the window from 120 to 138 s with the default prevented; the chip showed on click and hid on Escape; no console
errors. Link check 884 links 0 broken.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- infra/build-server/night/night-battery.sh: checkout of master and the newest release-*-node fork branch under
/srv/builds/_night, cargo test --release --no-fail-fast per crate (repo and fork), igneum-pow fuzz at 10x, the three
simulators in full, the fast-time harnesses (finality-attacks, harness s3 s4, exec-sync reorg) on binaries built into
target-integration, clippy per crate dir, cargo audit per Cargo.lock; docs/benchmarks/night/<date>.md with a pass/fail
table and "new since last night"; committed as igneum-labs on night-battery and pushed to the mirror, never master.
NIGHT_SUBSET=1 is the dry-run subset. The unit runs it through remote-run.sh so the slot spans the invocation.
- igneum-night-battery.{service,timer}: 02:00 Europe/London, User build, Nice 19, idle IO, 8 h limit, not Persistent.
- provision.sh: step_cargo_tools (cargo-audit), step_night (files from the mirror at NIGHT_REF, timer enabled), innoextract.
- tools/repro/rebuild-release.sh + infra/build-server/repro/rebuild-on-box.sh: pins from docs/plans/release-<v>.md
("(node <sha>, app <sha>)"), shipped hashes from the public downloads (the HiveOS tarball, the installer via
innoextract) or --shipped, a clean clone of repo and fork on the box, two passes per target without sccache under build
slots, MATCH or DIFFER per artefact against the shipped bytes and against the other pass, with the reason read off the
binaries (glibc version needed, PE timestamp, commit string); evidence into docs/evidence/reproduced/<version>.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copy, from origin/master 0a63474 (site audit). The home and miner pages named "PC 1" in the figure captions, the
page-by-page lead, two alt texts, the Ember Tune table title, the Ember row's source line and the home pill; they now
say "a Windows rig with an RTX 5090, RTX 4070 and RX 9070 XT" at the first mention on each page and "the Windows rig"
after. The generated pages carried the same names from the bench-log (80 on /bench, 7 on /evidence, the inlined
journey on the home page): site/scrub.mjs now maps PC 1 to "the three-card Windows rig (RTX 5090, RTX 4070, RX 9070
XT)" and PC 2 to "the RTX 5090 Windows rig", build.mjs re-scrubs the stored journey entries, two /bench anchors on the
miner page follow the renamed headings, and \bPC [12]\b joins site/forbidden-strings.txt so the build fails if a number
returns. The scrub also covers the audit's other page-leak shapes (a pid, 0.0.0.0:port, ~/.config paths, --rpclisten=),
which the bench page carried and which now fail the build if they return.
CI: tools/ci/forbidden-strings.txt's appended audit block sat on one physical line with literal \n text, so none of its
patterns was active; \bPC [12]\b is now a real line there and the identity check's export scrub maps the two machines
the same way (igneum-public/tools/sync.sh must carry the same two rules). The other four audit patterns moved to
site/forbidden-strings.txt, since the public export carries simulator schedule logs where a pid is a pid. The identity
check gains a second pass over every served file under site/ (html, json, txt, xml, webmanifest, css, js; not api/ or
the build scripts), unscrubbed, with both pattern lists; dl\.igneum is narrowed to the tokened path so the public
download buttons pass. Shown to fire on a page naming PC 1 (exit 1) and to pass on the tree (0 hits over 232 export
files and 32 served site files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- provision.sh step_runner: actions/runner 2.338.0 (sha256 checked) at /opt/actions-runner under a dedicated user `runner`
(no sudo, not in build's group), rustup 1.99.0 pinned with both targets, sccache against /srv/sccache in READ_ONLY mode
on its own server port, Node 22 and mingw from the system, GitHub's svc.sh unit with a Nice 10 drop-in; registered on
igneum-network/igneum as igneum-build-1 (labels self-hosted, linux, x64, igneum-build-1) through
infra/build-server/runner/register.sh (gh as igneum-labs, the token on ssh stdin, never logged). Idempotent after
the env files moved behind svc.sh install (its env.sh rewrites them). libicu74 and python3-numpy added to APT.
- main's slots ruling: SLOTS default 2; remote-run.sh sets CARGO_BUILD_JOBS 90 when it holds the only taken slot and 45
when both are held, BR_MEASURE=1 takes the `measure` file exclusively and excludes builds (builds hold it shared),
lock files open in append mode (the old `exec {fd}>` truncated a busy slot's holder line on every probe), env
IGNEUM_BUILD_SLOTS_DIR and IGNEUM_BUILD_LOG_DIR win over the profile, `--self-test-slots` with five cases (the old
script fails it with JOBS=none); build-remote.sh and cross-remote.sh pass -j only when --jobs is given.
- infra/build-server/prover/cpu-trial.sh: the SP1 CPU prover on one fixture shard under the measure hold with a VmHWM
poller; 6 Oct 2026 run: core 34.2 s, compressed 85.9 s, peak RSS 28.2 GB on 96 threads, so no standing CPU prover.
- docs/plans/ci-self-hosted.md: the proposed runs-on change for ci.yml behind the repository variable IGNEUM_CI_RUNNER
(GitHub-hosted is the fallback), and why windows.yml cannot move to a Linux box. Workflows untouched.
- docs/plans/build-server.md section 7.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Rebased onto origin/master. Resolved: site/miner.html and site/miners.html taken whole from master (the site-miner copy,
the PC 1 images, the 42-character h1, lever 4 dated, the ember-tune "Measured by the team" row) and re-dressed in the shared
chrome by the build; site/build.mjs is master's (the shipper's downloads rule: the snapshot is written only on
SITE_DOWNLOADS_REFRESH=1, --refresh-downloads or CI; the priors team rows) plus the generated-page template on site.css and
the per-page eyebrow; site/index.html is the one-screen page with master's content ported in: the hero's proving sentence
(today's app on 24 GB, the 6 October rented-card measurement with its log link, "ships when the packaging row lands"), the
mine lead, the "Four pages" and "Ember Tune, measured" rows, the PC 1 figure and caption. The ledger generator's section
heading balances its lines and sits at 20 to 28 px so "Launch and operations" no longer leaves a word alone at 390 px.
Checks on this tree: identity grep 0 hits over 232 files, link check 884 links 0 broken, ledger text 43 of 43, contrast
32 pairs 0 under 4.5:1, orphan check 0 site headings (14 log titles reported), ledger page 0 leaks. Proof captures at 1440
dark: docs/plans/site-ui-3-shots/after/index-1440-dark.jpg and miner-1440-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>