Commit graph

136 commits

Author SHA1 Message Date
igneum-labs
9786f3c4c9 Miner app: plug, tune, play (the project lead, 7 October 2026): node readiness gate, the retry ladder, no permanent fault, fault lines to the intake, the signed cards job, the fault-class register
docs/plans/miner-faults.md: MF-1 to MF-7, each with its rule, test and gate line.
- MF-1/MF-2: a worker starts and is judged only when the node is READY (synced and igneum_getExecStatus reports an
  executed tip; execrpc::probe every 5 s off the engine thread); the node watchdog never counts the catch-up (settled
  once read synced; 30 min cap before that; any RPC answer is a sign of life); the watchdog restarts on a ladder 10 s,
  30 s, 2 min, 5 min, then every 5 min for ever (watchdog::RETRY_LADDER_S); the faulted state and the one-restart
  budget are gone (tools/ci/permanent-fault-check.sh in the gate); a node-caused restart resets the ladder at sync.
- MF-3: the hot-plug pass starts a recovered or revived card's worker (unchanged rule, now in the register).
- MF-4: the status clock starts at ready (program loaded), loading bounded by 300 s; a self-test failure holds the
  card 30 min with the reason on its row, released on a driver change; a crash loop climbs the ladder; the pack is
  exported once a minute for every card (a refused pack forces one).
- MF-5: the app reads template_wait=, template_ms=, identities_active= from the 0.3.20 miner's STATUS; waiting on
  the node is never the card's fault; the row says node slow; every node-wait label clears on the first rate.
- MF-6: a miners hold belongs to the job that took it and releases when that job is gone or at its own cap.
- MF-7: the engine owns every igneum-miner it started: an untracked one on this engine's node RPC is killed at start,
  after every stop and every minute, one line and one fault report per kill; a restart kills the old process first.
- Every fault line posts one FAULT line to the log intake (label fault-<id8>, app and node version, 60/h cap).
- The signed cards job kind (per card enabled, identities, power_pct; refused for a card the machine lacks; applied
  through the app's own card path, persisted, read back): packaging/ota/publish-jobs.sh add --kind cards.
- LG-4 as a job: relay/playbooks/first-share.ps1 and tools/fleet/first-share-gate.mjs (no Windows box yet).
- tools/reliability: the fault injector with one step per class (catch-up, card-appears, own-restart, zero-ladder,
  no-status, node-silent, one-card-fails, orphan-miner); fake-worker.mjs lists devices and fails self-tests on command.
- master's build tooling (18a086b9) and release-0.3.20's igneum-pow taken into the worktree for the box routes.
Box: app 198 + 27 + 8 tests green on igneum-build-2; the tree gate green (33 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 13:11:48 +00:00
igneum-labs
c28a6cedc0 Driver table: a referer per row, sent as curl -e (drivers.amd.com answers 403 without an amd.com one; the AMD row carries it); a plain user agent on the download
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 2dc7457068)
2026-10-07 13:09:47 +00:00
igneum-labs
f549564c61 Driver table: the NVIDIA 617.42 and AMD 26.9.2 rows measured on igneum-build-2 (sha256, size, Authenticode subject from the vendors' own files); the stray #[test] above the Intel test's doc comment removed
NVIDIA GeForce Game Ready 617.42 WHQL (6 October 2026): us.download.nvidia.com/Windows/617.42/..., 990,853,168
bytes, sha256 f115c927..., subject CN=NVIDIA Corporation (DigiCert G4). AMD Software Adrenalin 26.9.2 WHQL
(29 September 2026, the win11-b build): drivers.amd.com/drivers/whql-amd-software-adrenalin-edition-26.9.2-win11-b.exe
(an amd.com Referer required), 1,000,800,840 bytes, sha256 593c1d73..., subject CN=Advanced Micro Devices (Sectigo).
Read on the box: curl, sha256sum, the PKCS7 out of the PE security directory through openssl pkcs7 -print_certs.
The table's placeholders are gone: every row installs. The drivertable test sample, the mock and the view test name
the real NVIDIA release. detect.rs:990 carried a #[test] above the doc comment of the Intel test from the cherry-pick,
the test build's one warning ("duplicated attribute"): removed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit afafbcd52e)
2026-10-07 13:09:47 +00:00
igneum-labs
fac6db03de Driver check: the app detects a missing or old driver per card and installs it on one click from the vendor's own server (branch driver-check, 7 October 2026)
the project lead: can the drivers be packaged with the miner, for all cards, with the system knowing which to install if not
present. Not bundled: detected and installed on one click. A per-vendor table rides the signed manifest (drivers.json:
min_version, the version on offer, the vendor's URL, size, sha256 and its source page, the silent arguments, the
restart exit codes, the Authenticode signer, the Linux and HiveOS package), validated by the signer and the app alike
(src/drivertable.rs, shared), written to <app data>/drivers.json by ota.rs. Each card's driver version is read at
every detection (nvidia-smi's driver_version; Windows' DriverVersion for AMD and Intel) and compared; a missing or
old driver puts the offer on the card's row, on the dashboard and on the first-run list. The click downloads with
curl (resume), checks size, sha256 and the Authenticode subject, runs the installer through one elevated prompt
(platform::elevated_command, the PC 1 driver job's shape), reports restart required with a Restart now button, and
never restarts by itself; the miners keep mining. macOS: no step; Linux and HiveOS: the package line. Dry run through
IGNEUM_DRIVER_DRY_RUN or the table. Tests: the table, the versions, the offers per tier, the exit codes, the
Authenticode verdicts, the download against a mocked vendor server on 127.0.0.1, the UI's strip per state; the mock's
drivers scenarios; captures light and dark in docs/plans/driver-check-shots. publish-manifest.sh --drivers carries the
table. Also the doubled #[test] in detect.rs from the cherry-pick.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit e49f988c5c)
2026-10-07 13:09:46 +00:00
igneum-labs
de314e37a9 Remote jobs: cards_leave_off, a run job's --cards-off cards restored as OFF on any exit (persisted by the app's own card path)
The way to hold a card out of mining past a job without a script on api/cards (the 6 October rule): the runner's hold
is built with enabled=false (identities and cap kept), the report line says LEFT OFF, publish-jobs.sh carries
--cards-leave-off. For the Arc B580 on PC 1 while its worker fix rides to the shipped app. Test:
cards_leave_off_restores_the_card_as_off_with_its_settings_kept (igneum-app 157 of 157 on the box).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 9e794503d2e9689ae3a0996e703cb97ea6d95cef)
2026-10-07 11:31:55 +00:00
igneum-labs
b8eda95c9f ui-ota: the publisher (tools/ui-ota/publish.mjs), publish-manifest.sh --ui and --no-ui, the plan with the security notes
publish.mjs packs the fifteen served files with one fixed mtime (reproducible; the self-test checks it), hashes, signs
the entry through igneum-ota-sign sign-ui with the key in ~/.config/igneum (never read or printed here), copies the
bundle into the folder's ui/ and hands ui.json to publish-manifest.sh --ui, the one writer of the signed manifest,
which verifies the entry and the bundle's hash before signing; --dry-run writes nothing, --verify reads the live
manifest back against dl/<token>/ui and dl/public/ui; --no-ui withdraws the channel. Both self-tests sit on the one
gate. docs/plans/ui-ota.md: the shape, the engine, the security notes, the operator recipe, the tests, per tier.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 3b6ccfc3ce)
2026-10-07 10:44:51 +00:00
igneum-labs
2654c31800 0.3.20: this feature tree renumbered (0.3.19 is the app-only miner-ui-5 cut); plan moved to release-0.3.20.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 09:35:42 +00:00
igneum-labs
23f883ef00 0.3.19: this tree renumbered again (0.3.18 is the app-only N7 cut); plan moved to release-0.3.19.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 08:28:05 +00:00
igneum-labs
82c89653aa 0.3.18: the node pin at e69e8a39 (the exec RPC bounds-check and template timers on ae17ad00)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 07:04:04 +00:00
igneum-labs
f16c8e2d6b 0.3.18: the node pin at ae17ad00 (12153428 plus ca3-v4-0318, two merges)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 06:19:56 +00:00
igneum-labs
cfa4ea7c28 0.3.18: this tree renumbered (tonight's 0.3.17 is the node-only hotfix); plan moved to release-0.3.18.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 03:36:46 +00:00
igneum-labs
bd02b28333 hive package: no AppleDouble entries in the tar (COPYFILE_DISABLE, no mac metadata)
GNU tar on HiveOS materialised the Mac's extended headers as ._ files next to every binary.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 02:43:07 +00:00
igneum-labs
c8fc49fdfe 0.3.17: the node pin at 12153428 (the IBD-guard fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 02:38:02 +00:00
igneum-labs
c32390f8e7 packaged-config: the packaged object is the live sixteen-field one (a fresh 0.3.17 install peers at once; the thirteen-field object would be refused until the first manifest read)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 00:33:41 +00:00
igneum-labs
fced05dc83 0.3.17: the node pin at b49c58c1
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 00:32:39 +00:00
igneum-labs
794e841b60 build-dmg: a DMG never ships without the prover pair (the warning branch built a 0.3.17 DMG 18 MB short)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 00:25:32 +00:00
igneum-labs
bd54e566a3 Igneum Miner 0.3.17: the class v4 vote's seven-window rule and the node's new switches (every one off on the devnet), igneum_getNodeInfo, the miner's stall guard, Ember's helper fix, the Overview's node source, an external node that goes away hands the ports back
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 23:46:27 +00:00
igneum-labs
87b4120b66 Merge commit 'ec64c57f' into release-0.3.17
# Conflicts:
#	docs/bench-log.md
2026-10-06 23:20:19 +00:00
igneum-labs
2ec6d46c6a publish-manifest.sh: the activation height check as a function with --self-test-height (the known-bad case 33000 against 201776, at the DAA, pending, unknown), the shape the shipper's 0.3.15 guard had; the public /api/live stays the source
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 9ded2663a8)
2026-10-06 23:19:08 +00:00
igneum-labs
49cbc112af Horizon polish for 0.3.16: (Q4) fork_is_close treats a passed activation as not close (every update since the 0.3.14 manifest read it as 0 blocks away and skipped every guard), publish-manifest.sh refuses an activation height at or below the live DAA unless --allow-passed-activation; (Q83, Q84, Q2) the finality pause shown: state.finality.paused, paused_since, reason, held_by, line ("Finality paused since 18:39 UTC: under two thirds of the weight is signing", the node's cause when it carries finality_reason/held_by), on the node line, the Overview's state and the Finality card, no lock called final while paused; tests
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit c040eabfb9)
2026-10-06 23:18:34 +00:00
igneum-labs
2e05cf3b24 Merge commit '58cc162' into release-0.3.17
# Conflicts:
#	.github/workflows/ci.yml
2026-10-06 23:10:56 +00:00
igneum-labs
cb4ee1cd29 publish-jobs guard ignores the index's updated stamp; plan: the hive rename, the card, the finality notes' number
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 22:17:40 +00:00
igneum-labs
343b547e00 Staging rule: publish-jobs.sh --deploy ships a jobs-only change (refuses when anything else differs from the live folder); restart-seed.sh refuses a binary whose GLIBC need exceeds the seed's; the CLAUDE.md rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 21:58:58 +00:00
igneum-labs
dd96702870 Igneum Miner 0.3.16: the same release as 0.3.15 under a new number, so every machine takes the final node build (f1ea7a38)
The Mac and PC 1 took earlier 0.3.15 builds (nodes 713ef876 and 7961c5f1) through deploys of the shared downloads folder before the publish; the updater compares version strings only, so the number moves them to the final build. Node pin unchanged at f1ea7a38.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 21:55:32 +00:00
igneum-labs
89b0829668 0.3.15: the node pin at f1ea7a38 (the receive-side header-version rule)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:48:43 +00:00
igneum-labs
e68534a45d publish-manifest: an activation height at or below the live DAA is refused (every app would read it as urgent); --self-test-height
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:27:23 +00:00
igneum-labs
6dfb303a35 0.3.15: the node pin at 7961c5f1 (the version gate and the pruned-node sync fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:14:55 +00:00
igneum-labs
4989caef13 Merge remote-tracking branch 'origin/master' into release-0.3.15 2026-10-06 20:14:55 +00:00
igneum-labs
a528b6adac Reproducible builds: SOURCE_DATE_EPOCH from the commit's author time, TZ=UTC and one fixed target path in every build path; self-test
Main's rule of 6 October 2026 from the 0.3.14 repro (docs/evidence/reproduced/0.3.14.md): prost's protowire.rs embeds OUT_DIR,
libmimalloc-sys embeds __DATE__/__TIME__, sccache hid both. lib.sh bs_repro_env exports SOURCE_DATE_EPOCH=<author time> TZ=UTC in
front of every remote command (build-remote.sh, cross-remote.sh, workers-remote.sh); remote-run.sh exports BR_SDE too and logs it
as source_date_epoch; proto-cuda/windows-node/cross-build.sh exports the same; the PC job carries node.commit_time in the manifest
(push-build-inputs.sh) and exports it before every cargo build of a stage (jobbuild.rs, unit test asserts it; 4 of 4 pass on the
box). Target dirs stay one fixed path per target. tools/build-remote.sh --self-test-repro [--full] from a fork worktree, run on
the box: igneum-miner twice a minute apart without sccache (RUSTC_WRAPPER=/usr/bin/env, an empty value is unset to cargo) MATCH
91e130f5..., a per-run target path differs (OUT_DIR shown); --full: kaspad with libmimalloc-sys recompiled a minute later MATCH
70219bc2..., without the epoch differs (__DATE__ shown).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:09:23 +00:00
igneum-labs
79f7f43e56 Plan 0.3.15: the DMG row (423b2d8 build)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:46:55 +00:00
igneum-labs
31f7bcddf8 publish-public: a platform the manifest lacks keeps the newest versioned file already in dl/public, stamped with its own version (a staggered publish never darkens a link or names an absent version)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:46:21 +00:00
igneum-labs
f3791ee387 Igneum Miner 0.3.15: class v4 signalling node (publish 2 opens the signal window), generator-4 GPU workers on every platform, miner-ui-4 (Overview and Cards), Ember tunes through the Power Helper, the Linux prover pair in the Windows payload, an update never installs under a running job
The six version files at 0.3.15 and the node pin at 713ef876 (release-0.3.15-node).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:26:14 +00:00
igneum-labs
5cb1b98205 Merge remote-tracking branch 'origin/master' into release-0.3.15 2026-10-06 18:59:50 +00:00
igneum-labs
1f638d877d Windows payload: the Linux prover pair is required and travels in the inputs (flat names), placed at wsl2\bin with SHA256SUMS
The CI payload had never carried igneum-prove-host or igneum-prove-export for WSL2 (make-payload.sh's warning branch), so every PC ran a stale pair built by setup-wsl.sh from an old package; after 0.3.14 no PC verified peer proofs or exported segments. push-inputs.sh refuses to publish without the pair (IGNEUM_PROVE_LINUX names the folder) and make-payload.sh refuses a payload without it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:54:44 +00:00
igneum-labs
7e4b8c135b Pool v0: igneum-pool (spec 09 newline JSON, per-member templates with the member's vote key, vardiff, CPU warp-verified shares, PPLNS on the EVM side with a 1% default fee and dry run, stats API and page), the Hive hooks' pool:// mode, the private-network measurement harness
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:40:21 +00:00
igneum-labs
9654a0cc95 Merge release-0.3.14: Igneum Miner 0.3.14 (exec-sync deep-reorg reload, miner-ui-3, ember-tune), publish 1 on the thirteen-field object
The node pin moves to 4c6b129d (release-0.3.14-node), which is what the live payload inputs carry, so windows-ci's payload-inputs step is green again (red since e9eca23 on master's 0.3.13 pin against the 0.3.14 inputs).
Conflicts: infra/fast-time/override-60x.json keeps master's side (the fresh-rule field was already there at u64::MAX; the release line would be a duplicate key); tools/ci/playbook-quit-check.sh keeps master's rule 2 and pre-rule list with the release side's Ember allow entry and the 0.3.15 expiry check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:18:17 +00:00
igneum-labs
e6f2e689ae Merge commit 'd354d5f' into ca3-pc1-amd
# Conflicts:
#	app/igneum-app/src/engine.rs
#	tools/ci/playbook-quit-check.sh
2026-10-06 18:10:29 +00:00
igneum-labs
49bebec7f8 Counter ASIC 3.0 PC 1 AMD: the runner owns a job's card switch: --cards-off <key,key> (matched with or without the device index, switched through the app's card path before the script, restored exactly on any exit including the app quitting; report lines; two tests, igneum-app 114 of 114 on igneum-build-1); playbook-quit-check rule 2 fails any script that requests api/cards (pre-rule playbooks on a dated allow list)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:07:52 +00:00
igneum-labs
82a1a5dc97 Build server adopted: box-first build rule in CLAUDE.md, reproducible Windows exes, the commit-string gate, PC and Mac recipes
Main's decision of 6 October 2026. CLAUDE.md 'Running agents on this Mac': every Linux and Windows cargo build and every
Linux test suite goes to igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh; the PCs keep GPU and
Windows-runtime jobs; the Mac keeps macOS binaries, the DMG and Metal tests under the lock. -Wl,--no-insert-timestamp in
cross-remote.sh, proto-cuda/windows-node/cross-build.sh and jobbuild.rs (two box builds byte-identical, verified).
The empty-commit class: tools/ci/commit-string-check.sh (self-test in ci.yml, shown firing on a Mac worktree build and
passing on a box build) runs on every igneumd from the three build scripts; push-build-inputs.sh adds node.commit_full,
the PC job writes a minimal node/.git from it at extract and cleans kaspa-build-info on a new commit (4 jobbuild tests
pass, run on the box); cross-build.sh refuses a worktree and cleans on a new commit. Plan: second worktree's clean build
1 min 18 s with sccache 604 hits of 993.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:50:39 +00:00
igneum-labs
f5f078f61f packaging/mac/packaged-config.sh: back to the thirteen-field object for publish 1 (a fresh install joins the live digest; the fourteen-field line goes with publish 2)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:08:58 +00:00
igneum-labs
14ab9a58d4 Windows payload inputs: node 4c6b129d (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.14
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:06:17 +00:00
igneum-labs
1a64180923 packaging/mac/packaged-config.sh: the fourteen-field object (exec_restart_state_root 0xed27bb2d...) in the packaged line (C34)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 16:51:39 +00:00
igneum-labs
b8ef4c5747 Igneum Miner 0.3.14: the six version files (node-only: the exec layer survives a deep reorg and a moved pruning point)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:54:14 +00:00
igneum-labs
b2e82604cb Windows payload inputs: node bb43e9a8 (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:12:13 +00:00
igneum-labs
c114667f6c Windows payload inputs: node 544fc30f (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:05:53 +00:00
igneum-labs
cb1011e047 Windows payload inputs: node a9dfe78e (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:57:33 +00:00
igneum-labs
0740e189fc packaging/mac/packaged-config.sh: the thirteen-field object (exec_restart_number 27276, exec_restart_hash bb45cf0d..., exec_restart_trust_daa 200000) in the packaged line (C34)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:51:27 +00:00
igneum-labs
2a8a0b3485 Igneum Miner 0.3.13: the six version files (node-only cut: the exec follower fix and the finality route fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 13:14:55 +00:00
igneum-labs
83242a6135 packaging/mac/packaged-config.sh: proving_v1_fresh_rule_daa re-pinned to 198000 (the floor read 10,418 at 11:20Z, tip 181,582)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:21:33 +00:00
igneum-labs
2b9ead2cda Windows payload inputs: node 83089544 (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.12
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:49:08 +00:00