Commit graph

140 commits

Author SHA1 Message Date
igneum-labs
a5450e6116 packaging/mac/packaged-config.sh: the thirteen-field object (exec_restart_number 27276, exec_restart_hash bb45cf0d..., exec_restart_trust_daa 200000) in the packaged line (C34)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:51:27 +00:00
igneum-labs
016b5afcb3 Igneum Miner 0.3.13: the six version files (node-only cut: the exec follower fix and the finality route fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 13:14:55 +00:00
igneum-labs
54ec7eb66e packaging/mac/packaged-config.sh: proving_v1_fresh_rule_daa re-pinned to 198000 (the floor read 10,418 at 11:20Z, tip 181,582)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:21:33 +00:00
igneum-labs
b3bb4c9311 Windows payload inputs: node 83089544 (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.12
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:49:08 +00:00
igneum-labs
9245d1592b packaging/mac/packaged-config.sh: the ten-field object (proving_v1_fresh_rule_daa 192000) in the packaged line (C34)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:38:59 +00:00
igneum-labs
fad0505fd5 make-payload.sh: the AMD telemetry helper is taken from the unpacked inputs on CI (the worker glob missed igneum-gpu-telemetry.exe, so the 0.3.12 payload of run 37435975425 lacked it)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:33:25 +00:00
igneum-labs
4965220bad release 0.3.12: merge ember-tune 27c2db6 (Ember Tune, the quit source, no OTA and no pipe in a second engine, the elevated follow_file, the BOM fix, Power control, job-console's hidden-console builder and spawn check)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:22:22 +00:00
igneum-labs
563463b35f Merge release-0.3.12 (fda4684) into ember-tune: 0.3.11's six-section View and card order kept, Ember Tune's line and switches re-added on it; the tune fields move into hotplug::apply_pref; the power-cap plan keeps present(); both CI test lists; 132 app tests, 26 UI tests, every gate green
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:20:46 +00:00
igneum-labs
24b42e0509 Igneum Miner 0.3.12: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:19:00 +00:00
igneum-labs
fda4684e28 release 0.3.12: merge hive-words: the bundled node takes the override from the Flight Sheet
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:17:02 +00:00
igneum-labs
08547b0cac HiveOS: the bundled node takes the override from the Flight Sheet (C41)
The finding (release-0.3.11.md section 5): h-run.sh started the rig's node with --devnet --appdir
--rpclisten --listen and the peers and no --override-params-file, so a HiveOS rig in local mode ran
on genesis parameters, printed the no-override digest and was refused by every devnet peer; no
package ever carried the override.

h-config.sh: OVERRIDE=<json object> in the Flight Sheet's extra config, read as a whole line (JSON
may carry spaces; single or double quotes around it are stripped), refused unless it is {...},
written to igneum.conf single-quoted (sq helper; EXTRA gets the same quoting, the same class: a
value with shell characters sourced unquoted). Still sourceable (return, never exit).

h-run.sh, local branch: writes data/override-params.json from OVERRIDE when set and passes
--override-params-file=<that path> to igneumd; when empty, a WARNING in the main log that the node
runs on genesis parameters and devnet peers will refuse it. After the node answers, the switch
lines and the "Consensus params digest" line from node.log are copied into the main log as
"node: ..." so the operator can compare the digest with the downloads page.

README: the Flight Sheet table gains the OVERRIDE row with the four-field devnet object as the
example (nine fields after the 0.3.11 switch; the downloads page carries the live one), the rule
"set OVERRIDE from the downloads page when it changes", the sentence that a rig without it is
refused, the digest check in the requirements, and the gap entry. No "every override publish
needs a package republish" sentence exists in packaging/hive/README.md on this branch or master,
so nothing was replaced; the new rule stands alone.

selftest.sh: a fake igneumd that records its argv and prints the real digest line; OVERRIDE
single-quoted on its own line beside other keys round-trips through the conf; OVERRIDE=notjson
refused; empty OVERRIDE named in the summary; the main h-run run checks the file, the flag on the
node and the digest and switch lines in the main log; a second short run without OVERRIDE checks
the warning and the absence of the flag. bash packaging/hive/selftest.sh on this Mac:

== h-config.sh OVERRIDE
   OVERRIDE (single-quoted, own line) sourced back intact beside the other keys ok
   OVERRIDE that is not {...} refused ok
   no OVERRIDE: empty in the conf and named in the summary ok
== h-run.sh (fake GPUs: 2 NVIDIA, fake node, fake miner)
   data/override-params.json written from OVERRIDE ok
   the node got --override-params-file ok
   the node's digest and switch lines reached the main log ok
   NVIDIA cards got the cuda worker ok
   exit 42 restarted the miner and re-exported the pack ok
== h-stats.sh (sourced)
   stats JSON ok: hs [118500.0, 118500.0] temp [61, 58] ar [24, 0] bus [1, 2]
== h-run.sh without OVERRIDE (the warning)
   no OVERRIDE: warning in the main log, no flag on the node ok
== self-test passed (scripts and stats shape; Hive itself is untested)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:35:03 +00:00
igneum-labs
6f95751e06 Windows payload inputs: node 89dfcb95 (push-inputs.sh, the PC 2 build, the class-aware workers, signed); release-0.3.11 plan: the PC 2 job
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:18:28 +00:00
igneum-labs
b9acc5733f packaged-config: the nine-field devnet override object (program class v3 and proving v1 at DAA 154,800, the first multiple of 3,600 at or above the forecast publish tip + 14,400; proving v1 segment 8, unproven 600, aggregator share 1000 bps) in the packaged line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:45:59 +00:00
igneum-labs
123838199f Igneum Miner 0.3.11: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:40:42 +00:00
igneum-labs
8ad50d119b Merge branch 'bash-body-check' into release-0.3.11
# Conflicts:
#	.github/workflows/ci.yml
#	tools/ci/prover-socket-check.sh
2026-10-05 22:40:22 +00:00
igneum-labs
b2e6d6159e CI: run jobs test their fetched kit before use (the wiped-jobs-folder class)
The app's install clears the jobs folder on a PC, so a run job whose kit was fetched by an earlier fetch job finds
nothing after an update and fails in seconds (5 October 2026, 21:49Z, the AMD kit; bench-log 4df339f). Rule: a run
playbook that reaches a path under the jobs folder other than its own tests the kit is there before its first use,
and the fetch is republished under a new id after any app update.

tools/ci/kit-path-check.sh reads every *.ps1 under relay/playbooks/ and tools/. A kit root is a path derived from
the jobs folder (`$jobs = Split-Path $env:IGNEUM_JOB_DIR` then `Join-Path $jobs '<fetch id>'`, the race-5090.ps1
shape) or one carrying a literal `jobs\` (the amd-card-test.ps1 shape); every path built from it belongs to that kit.
A presence check (Test-Path, [IO.File]::Exists, [IO.Directory]::Exists, Get-Item or Get-ChildItem with -ErrorAction)
on the root or anything under it covers the whole kit. A use before that line fails with "kit path used before a
presence check: republish the fetch after any app update", as does a literal jobs\ path in a command with no check.
The job's own folder ($env:IGNEUM_JOB_DIR) is not a kit path.

Fixtures: kit-path-ok.ps1 (both shapes, checked; a sibling pack file covered by the worker's check) and
kit-path-unchecked.ps1 (the worker run before its check, a literal never checked); --self-test asserts the lines.
Wired into ci.yml after the bash-body step, and into publish-jobs.sh add --kind run beside the other two checks;
test-publish-jobs.sh gains the refusal (34 passed, 0 failed). The current tree: race-5090.ps1 is the one playbook
with a kit, checked before use. README-ship.md: the rule.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:37:29 +00:00
igneum-labs
2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
igneum-labs
a5533177d3 CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class)
Twice on 5 October 2026 a PowerShell job script carried a bash body inside a string, a quote was lost on the way
through PowerShell, and bash refused the body: pc1-cpu-prove.ps1 (first version) reported exit 0 having done
nothing, the 0.3.10 installer job failed in 4 s. tools/amd-prove/check-job-bash.sh covered only its own here-string.

tools/ci/bash-body-check.sh reads every *.ps1 under relay/playbooks/ and tools/, finds each bash body however it is
handed over (bash -c "...", bash -lc '...', bash -c $var, a + concatenation in parentheses, the Start-Process argument
list, a here-string written to a file that is later run with bash), unescapes it the way PowerShell would (backtick
escapes and "" in double-quoted strings, '' in single-quoted strings, here-strings verbatim; $var left as-is, a $(...)
subexpression replaced by ${PS_SUBEXPR}), and runs bash -n on it. One line per body with the file line of the error.
A body it sees but cannot read is "unextractable body" and fails too: a skip would be a hole in the class check.
bash 3.2 compatible; python3 for the extractor.

--self-test runs three fixtures under tools/ci/fixtures/: the correct shapes (8 bodies, must pass), the lost quotes
(the awk apostrophe, a dropped closing quote in a literal and in a variable; must fail with the line), and three
unreadable bodies (must fail). Wired into ci.yml next to the copied-sources check, self-test first. The current tree:
7 inline bodies in 3 playbooks, all parse. packaging/README-ship.md: the job-script rule (body to a file, bash <file>).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:38:41 +00:00
igneum-labs
3d504447ce HiveOS README: the per-card table from the S_p curve
The "Once a Linux prover ships" column and the sentence above it now follow the proving agent's
S_p curve (bench-log "proving v1" on proving-v1) and the app's default at 894022b (proving on at
24 GB or more, off below): 32 GB mines and proves the prototype shard (28.3 GB alone, 30.0 GB
beside the miner, 2.5 GB spare); 24 GB proves the adopted v1 shard of 30,000 pgas (20.4 GB alone,
about 22 GB beside the miner, approximate) from the fee switch at DAA 210,000 and nothing before
it; 16 GB proves only empty shards alone (13.9 GB) and nothing beside the miner (15.7 GB), so in
practice mines only; 12 GB proves nothing on SP1 6.8.1's GPU server; 8 GB mines only. The sources
line stays; "before the v1-shard row" and the v1-budget caveat are gone, the curve measured it.
README only; selftest.sh unchanged and still passing from df6598f.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:46:03 +00:00
igneum-labs
fe852a4335 AMD telemetry: igneum-gpu-telemetry (ADLX on Windows, amdgpu sysfs on Linux, PDH utilisation fallback) feeds the card row's draw, temperature, fan, memory clock and MH/W; measured on PC 1: 9070 XT 198.9 W, 64 C, 657 rpm, 17.73 MH/s = 0.089 MH/W beside the 5090 at 307.6 W, 122.30 MH/s = 0.398 MH/W
the project lead watched the 9070 XT at 90% usage with its fans barely turning and the app could not say what it drew: the
draw, temperature and MH per watt line came from nvidia-smi only, and the earlier per-watt figure used the board
rating. proto-opencl/gpu-telemetry.c prints one line per AMD card per sample (bus from SetupAPI by the display
device's name, kind, name, watts, temp_c, fan_rpm, fan_pct, mclk_mhz, gclk_mhz, util_pct, source), built by
build-windows.sh against vendor/adlx (the SDK clone), shipped by make-payload.sh and push-inputs.sh. The engine
runs it with -l 5 beside nvidia-smi (Source::AmdTelemetry, tick_amd_telemetry), parse_amd_telemetry fills
power_w, temp_gpu, fan_pct, fan_rpm, mclk_mhz, util_pct and telemetry_at on the AMD card matched by kind and
ordinal, so eff_mhw and the dashboard's existing line show it; app.js shows fan and memory clock when present.
Tests: three on the parser with lines captured on PC 1 and the Mac fixture; the sysfs path ran on a fixture tree.

Measured over 20:27:45 to 20:29:41 UTC with both cards mining (docs/bench-log.md, under the 9070 XT ceiling table):
9070 XT 198.9 W (193 to 212), 64 C, 657 rpm, 2,505 MHz memory, 3,290 MHz shader, 100% busy, 17.73 MH/s =
0.089 MH/W; RTX 5090 307.6 W, 69 C, 44% fan, 122.30 MH/s = 0.398 MH/W.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:21 +00:00
igneum-labs
df6598f41a HiveOS: rigs mine only until a Linux prover ships; IDENTITIES=auto by VRAM
README: a second paragraph under the title says the package carries igneumd, igneum-miner and
the two workers and no prover (make-hive-package.sh), so a HiveOS rig earns nothing from the 20%
proving share until a Linux prover build is published; the rig installer on rig-install (cf716a6,
packaging/linux/README.md) idles its prover unit in state setup for the same reason. A per-card
table (8, 12, 16, 24, 32 GB) from the app's rule in provedefault.rs and the proving agent's
measurements of 5 October 2026 (bench-log "proving v1": 13.9 GB prover alone on an empty shard,
28.3 GB on the full prototype shard, 15.6 GB and 16.75 GB mine-and-prove on one 5090, 30.0 GB
full shard beside the miner), marked before the v1-shard row.

IDENTITIES: the app's rule (detect.rs) is 8 vote keys for a card with 8 GiB or more, else 2.
h-config.sh now defaults to IDENTITIES=auto and resolves it per card from nvidia-smi
memory.total or /sys/class/drm/card<N>/device/mem_info_vram_total (amdgpu), 8 when neither
answers, writing IDENTITIES_GPU<N> keys into igneum.conf beside the IDENTITIES=8 fallback; a
number still overrides every card. h-run.sh reads IDENTITIES_GPU<N> first, else IDENTITIES.
The README and the h-config comment say the number.

selftest.sh: IDENTITIES=auto with no GPU tools (8, no per-card keys), the default being auto,
a stubbed nvidia-smi printing 6144 and 24576 (gpu0=2, gpu1=8), the numeric override, and h-run
taking IDENTITIES_GPU1=3 over the fallback. bash packaging/hive/selftest.sh on this Mac:

   auto with no GPU tools: IDENTITIES=8, no per-card keys ok
   default (no IDENTITIES line) is auto ok
   auto with nvidia-smi 6144/24576: gpu0=2, gpu1=8 ok
   numeric override keeps IDENTITIES=4 ok
== h-run.sh (fake GPUs: 2 NVIDIA, fake node, fake miner)
   dev fee lines in the main log: 4
   DEV_FEE=0 reached the miner as --dev-fee 0 ok
   gpu0 took the IDENTITIES=8 fallback ok
   gpu1 took IDENTITIES_GPU1=3 over the fallback ok
   NVIDIA cards got the cuda worker ok
   exit 42 restarted the miner and re-exported the pack ok
== h-stats.sh (sourced)
   stats JSON ok: hs [118500.0, 118500.0] temp [61, 58] ar [24, 0] bus [1, 2]
== self-test passed (scripts and stats shape; Hive itself is untested)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:41:40 +00:00
igneum-labs
18f244bcfb Merge miner-ui-2 (6acfaed) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
cbe031b39c Merge gpu-hotplug (bd21f2a) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
1065b81d05 relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14)
Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:46:13 +00:00
igneum-labs
7c7c1b6b0a Windows payload inputs: node 21d4c73c (push-inputs.sh, the PC 1 build, signed, live 18:36Z)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:36:17 +00:00
igneum-labs
d905730d45 Merge c4-fix (3e129ee) into release-0.3.10: the certificate-driven reorg in spec 3.5, 3.2, 3.10, 3.11.7, ledger C4, bench-log; c4.mjs v2 mode; the signer never piped into head (signer-pipe-check); one build-inputs zip per job
# Conflicts:
#	docs/bench-log.md
2026-10-05 18:20:50 +00:00
igneum-labs
3e129eeb5c C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning)
Fork: vendor/igneum-node-c4 branch c4-fix on release-0.3.6 a24ab01a.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:17:36 +00:00
igneum-labs
cb67729091 packaged-config: the devnet override object with all four switches (finality v3 at DAA 135,200, published 17:59Z) in the packaged line; the self-test's no-override check passes an empty value itself instead of reading the shipped default
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:03:17 +00:00
igneum-labs
c091eec39d Igneum Miner 0.3.10: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:01:00 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
381cbd29df Windows payload inputs: node a24ab01a (push-inputs.sh, signed, live 16:32Z) 2026-10-05 16:32:29 +00:00
igneum-labs
ef3cbaf4f5 Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 16:30:47 +00:00
igneum-labs
38486f9551 Igneum Miner 0.3.9: the prover mirrors the fee switch (new pinned guest, shard id 0x2b1a81cb...), node a24ab01a (igneum_exportSegments names the mergeset and every entry's block and body position), the devnet fee-switch runbook; the six version files 2026-10-05 16:28:36 +00:00
igneum-labs
3551069c51 Public testnet launch, the public side: dl/public downloads path, site download buttons, HiveOS package, faucet
Downloads: packaging/ota/publish-public.sh publishes the current installers, the HiveOS package and the two signed
manifests into dl/public/ with no token in any URL, writes the four /public/ aliases as vercel.json rewrites and an
unsigned index for the site; publish-manifest.sh --public and ship-app.mjs --public run it on every release (dry run
and self-test cover it). Nothing removed from the token folders.

Site: the miner and wallet buttons link the public aliases and show the version and size from the index, read at
build time (site/downloads.json is the offline snapshot); TESTNET_OPEN in build.mjs drops the "Public testnet: not yet
open" line on the go; the HiveOS Flight Sheet install line on the miner page; /faucet page.

HiveOS: igneum-hive-0.3.8.tar.gz from the 0.3.8 node (2b6d23ef, PC build job) and the zig-built Linux workers.

Faucet: site/api/faucet.mjs (10 IGN per address and per IP per day, Neon table faucet_grants, EIP-1559 transfer signed
by site/lib/eth.mjs with no dependencies: keccak, RLP, secp256k1 with RFC 6979), FAUCET_KEY and FAUCET_RPC from the
Vercel env only; 15 unit tests with a fake database and node, run in CI.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:31 +00:00
igneum-labs
6cecbd4c67 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
c5f3cd17e4 Igneum Miner 0.3.8: pinned proving programs (one program id on every machine, the verifier answers in about 2 s), the update card, the Windows exporter path fix, re-stamped WSL scripts; node 2b6d23ef unchanged 2026-10-05 13:17:12 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
a0e092d109 Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
b3f25c7632 publish-jobs: the signed jobs file goes to both downloads folders while the rotation runs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:44:32 +00:00
igneum-labs
980b7b7f62 inputs: pin node 2b6d23ef for 0.3.6 (payload-inputs.json signed and deployed) 2026-10-05 09:27:28 +00:00
igneum-labs
a8f2d1a9e2 build inputs: every staged file is stamped now before zipping (the PC's cargo cache judged 0.3.6 sources older than its 0.3.5 build)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit e0627a32d8)
2026-10-05 09:12:07 +00:00
igneum-labs
e0627a32d8 build inputs: every staged file is stamped now before zipping (the PC's cargo cache judged 0.3.6 sources older than its 0.3.5 build)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:10:29 +00:00
igneum-labs
6de84cf4b9 push-build-inputs: the live sha256 check retries for a minute (the edge served the previous file right after the deploy; the 0.3.6 build job failed here on 5 October 2026) 2026-10-05 08:50:53 +00:00
igneum-labs
fb8c48651b Igneum Miner 0.3.6: instant jobs, a proof verifier on every node, one notice strip, lower miner latency, packaged configuration, hidden helper windows, WSL scripts from files; node 2b6d23ef: testnet identity and fee table behind a height switch, signed build inputs 2026-10-05 08:48:57 +00:00
igneum-labs
0f6fc2ead5 Merge rotation-2 (7c9a939) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
c797fe49b3 Merge proving-app (05051c1) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 9835f49), tile shows the verifier 2026-10-05 08:33:13 +00:00
igneum-labs
b00de4f4f3 Merge app-ui (7388a20) into release-0.3.6: one notice strip under the header; CI runs both the wake and the notice tests 2026-10-05 08:32:52 +00:00
igneum-labs
fc137257ed Merge origin/testnet-adopt (3be4501) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
7e0fc7da65 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
25350f254a app: the node gets a proof verifier, the WSL2 probe checks both layouts, the tile shows the verifier state (0.3.6 items 1 to 3)
Spec 7.7 item 4: a node without a verifier relays proof records and never includes them. On 5 October no app node ran one.

1. src/verifier.rs decides once per node start and engine.rs passes it to the igneumd spawn. macOS and Linux: igneum-prove-host
   next to the engine's binaries. Windows: the new igneum-prove-verify.exe (src/bin/prove-verify.rs, a bin target of this crate,
   shipped by make-payload.sh) is set only when its --probe finds a host inside WSL2; it rewrites --proof with wslpath -a,
   runs the host in the order of src/wslhost.rs and returns its exit code, 2 when there is no host. Trust mode is never the
   default: the setting proof_verify_trust (Settings, "devnet only") sets IGNEUM_PROOF_VERIFY=trust only when no verifier was
   found; changing it restarts the node. After the WSL2 setup runs, the prover thread asks for one node restart.
2. The prover's WSL2 probe looks at the payload's wsl2/bin, ~/igneum-prove/proving/igneum-prove/target/release (what
   setup-wsl.sh builds), ~/igneum-prove/target/release and /opt/igneum, in that order (one list in src/wslhost.rs, shared
   with the wrapper); the tile's message names every path it looked at.
3. The prover thread reads igneum_getProvingStatus().verifier every 30 s, proving on or off; /api/state carries
   proving.verifier, verifier_mode, verifier_set, verifier_reason, verifier_note and the pool counts; the tile has a
   verifier row and says when this node relays proofs but does not verify them.

Tests: cargo test -p igneum-app, 89 passed. The wrapper cross-compiles with --target x86_64-pc-windows-gnu on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
7388a20f95 Miner app UI: one notice strip under the header replaces the three stacked banners (updates, jobs, clock)
One notice at a time, the most important first (app/igneum-app/ui/app.js, Notices; pure, unit tested):
  0 update installing, urgent or failed   1 job failed   2 clock   3 job running
  4 update available, downloading, ready, waiting for permission, manual   5 job done   6 updated
Lower notices wait their turn. Every notice has a close control; closing hides that notice's key until the
state moves on (a new status, version or job id).

States and their rules:
  update available      "Igneum Miner X is available." Install now, Later. Key update:X:pending.
  update downloading    "Downloading Igneum Miner X: 43%." (no percent when unknown), progress bar; same key as
                        available and checking, so Later hides the whole download until it is ready.
  update checking       "Checking Igneum Miner X." (the engine's staging step).
  update ready          "Igneum Miner X is ready. It installs by itself at a quiet moment." (auto on) or just
                        "... is ready." Install now, Later. Key update:X:ready.
  update waiting        Windows, nobody answered the administrator prompt: "... is waiting for permission. It
                        installs the next time someone is at this PC. Mining continues."
  update manual         "... is downloaded. Open it and drag the app over the old one." Open the download.
  update installing     "Installing Igneum Miner X. The app restarts itself. Mining continues until then."
                        (on a Mac, where the engine quits at once: "The app restarts itself in a moment.")
                        Also while the engine says "installing now" after Install now.
  update urgent         the engine's consensus-deadline text, ember, downloading percent when it downloads.
  update failed         "The update to X failed." plus one line of cause and Try again; rolled back:
                        "Igneum Miner X did not stay up and was rolled back." A dev build with no manifest
                        configured shows nothing (Settings still says it).
  updated               "Updated to Igneum Miner X from Y." Gone 60 s after the new version started.
  job running           "Job: <title> running, N min. <Stage>." with the last RESULT line underneath.
  job done              "Job: <title> done after N min. Report uploaded." Gone after 5 minutes.
  job failed            "Job: <title> failed after N min, exit C. Report not uploaded." plus the first error
                        line (BUILD FAILED / error / failed / panic among the result lines, else the summary).
                        Stays until closed. Timeout and aborted are "hit its time cap" and "was stopped".
  clock                 as before: the engine's words, Sync clock, the manual hint; on the setup screens only
                        (the node card carries it on the dashboard). Jobs show on the dashboard only.

Layout: the strip reserves no height while empty; when a notice appears or goes, main's top moves once with a
150 ms transition (none under prefers-reduced-motion). Existing tokens only, nothing newer than 2022 CSS.
Screenshots: ?update=<state> as before, ?job=running|done|failed added (packaging/ota/README.md).

Test: node --test app/igneum-app/ui/notices.test.mjs (ordering, dismissed keys, wording, the 5-minute and
60-second timers); added to the CI site job. Built once with cargo (include_str) and checked against the
ui-mock scenarios and a scratch engine instance (IGNEUM_APP_DATA in a temp dir, fake worker).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:16:29 +00:00
igneum-labs
b3ba9ac1ee build inputs: ship igneum-pow beside the zip root and the coin image the engine embeds
The first PC build (job build-20261005-075300) failed in 52 s: the node's crates depend on ../../../../igneum-pow,
which the zip did not carry, and the engine embeds brand/igneum-coin-1024.png, which the staged brand/ lacked.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:01:17 +00:00
igneum-labs
fd07ef569f Merge origin/testnet-prep (28f6ccc) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
77fa43d1b1 Igneum Miner 0.3.5: Pruning proofs on the lottery hash (M20), memory fix (M30), coinbase limit on every network (M31), chain-decided equivocation bans (F23), re-determination after reorgs (F24), params digest in the handshake (G12, X18), miner fee 1% switchable, efficiency sweep, variant racing, reliability watchdog, log panel and screens, PC build job, Windows updater launch fix 2026-10-05 06:33:18 +00:00
igneum-labs
7210fd4683 Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
ec843737c2 Merge origin/dev-fee into release-0.3.5
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
2026-10-04 21:48:04 +00:00
igneum-labs
1028c2579f Miner dev fee: app switch and UI line, HiveOS package, Linux worker cross-build, docs and public text
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.

- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
  "dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
  miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
  with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
  stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
  proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
  docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
  miner section note

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:46:41 +00:00
igneum-labs
1867a4819b Merge origin/build-job into release-0.3.5
Conflict resolved: publish-jobs.sh keeps master's verify command and --tries (the retrying live check) alongside the
build kind's arguments; the usage range covers the merged header.
2026-10-04 21:32:48 +00:00
igneum-labs
ca2ac6dfa8 Merge origin/miner-perf into release-0.3.5
Conflicts resolved: state.rs keeps both the sweep fields (miner-eff) and the race fields (miner-perf); bench-log.md
keeps both appended entries; publish-manifest.sh keeps master's --override implementation (8082576, the "every
height switch" rule, --verify-only, --tries, the retrying live check) and adds miner-perf's --tuning / --no-tuning
with the carry-over of consensus.override and tuning from the current manifest. One --override case, one parser.
2026-10-04 21:31:26 +00:00
igneum-labs
9f0c9036ea Build job: a PC builds the node and the app engine for Linux and Windows inside WSL2, mining untouched
New job kind `build` (jobs.rs, jobbuild.rs, jobrun.rs run_build): free-space check on both sides (20 GB), the
build-inputs zip by sha256, setup inside the distro as root (mingw-w64 posix, clang for bindgen, protoc, zstd, the
Windows rust target; idempotent), sources extracted with the target dir persisting under /root/igneum-build,
cargo build --release native and for x86_64-pc-windows-gnu, cargo test for the manifest's packages, binaries
zstd-compressed and sent to the relay (fn=upload, Blob PUT, fn=drop; 50 MB each) with sha256 in RESULT lines,
STAGE lines with UTC times, a 40-minute default budget and per-stage caps, the Linux side killed on a cap. The
app's runner stays serial (one Active at a time), so a build never overlaps a shard job; nothing stops the miners.
From this version an unknown job kind is skipped by the app (parse_lenient) instead of rejecting the whole file;
the signer stays strict.

Mac side: packaging/windows/push-build-inputs.sh packs a fork worktree, app/igneum-app, brand/icons and
proto-cuda with a manifest (branch, commit, dirty, builds, tests) and the sha256; publish-jobs.sh add --kind build;
tools/build-job.mjs packs, publishes, watches, fetches, checks both sha256 per file and the PE header of every exe
(plus verify-exe.py on igneum-app.exe), and places the binaries where push-inputs.sh, make-payload.sh and the
cloud-devnet scripts look. relay.mjs drop <file> --body carries the body.

Tested on the Mac: 33 app tests (6 new) and the signer's 21; cargo check for x86_64-pc-windows-gnu; the packer
(7.9 MB zip, no target dirs); the publisher against a scratch folder with the rebuilt signer, the old signer
refusing the kind, a bad job refused at signing; the fetch path against the live relay with a real exe (sha256
and PE pass, a wrong sha256 refused; test items deleted). Not run on a PC: the job itself. docs/plans/build-job.md
has the first job for PC 1 and the rollout order (0.3.4 must be on the PCs before a build job is published).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:17:55 +00:00
igneum-labs
568d6ed9cb publish-manifest.sh: the live manifest must be byte-identical to the folder's and verify, with retries and named reasons; --verify-only; a failed deploy stops before the check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:17:01 +00:00
igneum-labs
8082576477 publish-manifest.sh: --override carries every height switch in consensus.override (proving v0 activation needs it)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:09:35 +00:00
igneum-labs
13ae84ecdb Igneum Miner 0.3.4: Finality rule v3 (dormant behind finality_v3_activation_daa), proving v0, job-channel fixes 2026-10-04 20:08:30 +00:00
igneum-labs
0abe66b424 Bug hunt: the site's Vercel project is in the igneum team (link, env and deploy commands in README-ship.md); bugs.md rows for the collect branch and the Vercel link, Sam's Mac closed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:20:32 +00:00
igneum-labs
9915c883b1 Bug hunt: console cards for other/intel workers and a stale mark on old STATUS lines (relay/lib/parse.mjs + test in CI); publish-jobs verifies the live file with retries and named reasons, a verify command, a failed deploy stops, a collect command without $_ is refused; the dl token masked in printed URLs; docs/bugs.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:15:05 +00:00
igneum-labs
fe3a3ab701 Fleet learning for the kernel race: the TUNING record, the aggregator, the manifest's tuning object, the PC 1 race job
The engine turns a worker's race line into one TUNING {json} line in the app log (card model as the worker names it,
driver, arch, program class loads and wide loads, every variant's MH/s, winner, gain, the card's power cap and
draw, MH per watt), which the existing intake receives; the card state carries the variant for the dashboard and
one event per race. tools/tuning.mjs aggregates the records from miner_logs per card model (median MH/s or MH per
watt, at least 3 samples, de-duplicated per race) and writes tuning.json; publish-manifest.sh --tuning puts it in
the signed manifest (and now takes --override for consensus.override; both are carried over from the current
manifest when not given, --no-tuning drops it); manifest.rs parses it; ota.rs writes <app data>/tuning.json and
removes it when the manifest drops it; procs::spawn takes an environment and every miner starts with
IGNEUM_TUNING_FILE, which its worker reads at every prepare. Dry run of the publisher against a scratch folder:
tuning and override written, carried over, dropped, signature verified.

docs/plans/miner-perf.md: the signed jobs for PC 1 (fetch the race build of the NVRTC worker, then
relay/playbooks/race-5090.ps1 with the miners stopped: 17 variants, 3 rounds, twice) with the exact publish
commands for the main session; not published by the agent.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:08:45 +00:00
igneum-labs
9f940a5ee8 Ship tool: one command cuts an Igneum Miner version (tools/ship-app.mjs)
the project lead, 4 Oct 2026: 0.3.1, 0.3.2 and 0.3.3 each took eight hand steps and an hour. The tool runs them in order, each
step idempotent and resumable (--from): preflight, bump (six version files, one function, read back), push-inputs,
commit and push, the windows.yml run polled with gh (auth switch before every call), fetch, DMG under the build lock,
copy, signed manifest, one deploy, HEAD/GET verification with sizes and sha256, one console item. --dry-run prints
the plan, --check compares the version files, --self-test bumps a scratch copy. Secrets never printed.

Found by --check: Igneum-Miner.iss and Info.plist were left at 0.3.2 when 0.3.3 was cut (CI passed -Version from
Cargo.toml, so the installer was right; the Mac bundle said 0.3.2 because build-dmg.sh's sed only matched 0.3.0).
Both aligned to 0.3.3; build-dmg.sh now stamps the version with plutil. fetch-ci-artifacts.sh: CONSOLE_SKIP=1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 18:29:21 +00:00
igneum-labs
afbc54b317 Igneum Miner jobs: the wsl-prover probe logs why it fails, tries the configured then the default WSL user with cargo and sp1 on PATH, and accepts the shipped wsl2\bin prover; publish-jobs --requires none|"" = no requirement
PC 2 on 0.3.3 logged 'needs wsl-prover' although the toolchain is there as user [user]. Every negative probe now
lands in the engine log with its exit code and the first 200 characters of output (it reaches the intake). The
probe sources ~/.cargo/env and sets ~/.cargo/bin and ~/.sp1/bin itself (a login shell from a console-less process
need not), runs as the job's wsl_user or IGNEUM_APP_WSL_USER first and the distro default user second, and a
payload with wsl2\bin\igneum-prove-host next to the app meets the requirement when the distro answers.
publish-jobs.sh: --requires none or "" publishes an empty list (none was a literal requirement, "" fell back
to the kind's default).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 16:54:02 +00:00
igneum-labs
20d91af7a4 Difficulty v2: Hetzner rehearsal passed (12 nodes, one chain through N + 600), binaries for every platform, the devnet rollout plan
rollout-v2.sh stages the Linux igneumd (gateways from the Mac, private nodes from their gateway), rolls one node at a time with
difficulty_v2_activation_daa in every override file, checks the common chain and watches the height; results/2026-10-04/
rollout-v2*.log and v2/ (the hash-rate step under v2 and the v1 comparison). docs/plans/difficulty-v2-rollout-devnet.md: the
binaries and their sha256, the activation rule (N = DAA at publish + 10,800; baked at the cut as DAA + 14,400), the exact
restart lines for the observer node, the seed and Mac node 1, the OTA path for the two PCs through NODE_OVERRIDE_PARAMS in
packaged-config.sh (the engine side landed in 0dd587d), the rehearsal record. Bench-log entry.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 15:19:31 +00:00
igneum-labs
dc33031c3a Igneum Miner 0.3.3: an unattended Windows miner is never stranded by an update (4 Oct 15:40 incident: both PCs stopped at the installer's UAC prompt). Per-user installer (PrivilegesRequired=lowest, %LOCALAPPDATA%\Programs, migration from Program Files offered only when someone is at the keyboard, firewall rule asked once on first run and mining without it); the Windows helper runs the installer FIRST with the engine still mining and only the installer's own stop step ends it, a declined or unanswered prompt leaves the machine mining with "OTA: waiting for administrator approval" / "administrator approval not given; waits for the next time someone is at this PC" in the log and the intake, retry on Install now, next start or 6 h; machines take turns (apply only in the minute = machine id8 mod 60) and hold while /api/live shows over 30% of identities gone in 10 minutes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:59:51 +00:00
igneum-labs
3f23df38b7 Packaging for proving v0: the Mac DMG carries igneum-prove-host and igneum-prove-export, the Windows payload carries the Linux host and exporter under wsl2/bin with the WSL2 scripts and the fixtures; the prover probes the shipped WSL2 binaries first and runs helpers by absolute path; push-inputs takes IGNEUM_NODE_SRC; the test script's --network-only mode
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:36:59 +00:00
igneum-labs
b598c85c74 Igneum Miner 0.3.2: signed job channel, seed-mismatch and stall guards, power-cap readback, round-4 security fixes, node with the difficulty v2 switch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 14:11:59 +00:00
igneum-labs
456eff08d5 Igneum Miner round-4 fixes: the dashboard token is never logged and token lines never upload (R4.3.8); every helper by absolute path and Program Files read-only, fallback worker build under the app data folder (R4.3.3); the download and the staged bundle re-verified right before the swap or the elevated run, quarantine stripped only after that (R4.3.5); mutating POSTs refused unless same-origin (R4.3.7); no rollback below min_supported_version and no automatic re-apply of a failed version (R4.3.6); the signed manifest's consensus.override written to override.json for --override-params-file with a safe-moment node restart and 'consensus switch at DAA N' on the node tile, an old node that rejects the file runs without it; devnet vote-key note in the key sheet and READMEs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:58:23 +00:00
igneum-labs
552d5a30c2 Igneum console at the relay URL: Machines, Jobs, Builds, Chain, Work log, Results and the relay as tabs
relay/api/console.mjs reads the log intake (miner_logs) and console_items in Neon, the OTA manifest, the
CI json and the jobs file from the downloads host (DL_TOKEN in the project env, never in the client), and
igneum.network/api/live; 10 s cache per answer. tools/console.mjs: post --kind log|build|note, log, machines,
chain, jobs, builds, results, sync-bench, sync-dl, sync-hetzner, sync, url. The two Mac-side build scripts
post build events. Screenshots at 375 px and desktop in docs/design/console/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:53:33 +00:00
igneum-labs
cdb9b3a734 Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:52:45 +00:00
igneum-labs
b4ca73419f Igneum Miner 0.3.1: the first build with over-the-air updates
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:26:24 +00:00
igneum-labs
9de0429633 Igneum Miner: over-the-air updates (the project lead's rule: every app updates itself and downloads the update by itself). Signed manifest (Ed25519, key on the Mac, public key compiled in), hourly check with jitter, download with resume and sha256, staged bundle on macOS, silent Inno upgrade on Windows, apply at a safe moment (node synced, no hour boundary within 3 min, no worker starting), red bar and no waiting near a consensus activation height, rollback to .previous / the previous installer, Settings: Check now, Install now, automatic switch; publish-manifest.sh, fetch-ci-artifacts.sh adds the Windows entry; dry run on a private devnet 0.3.0 -> 0.3.1 and back (rollback), screenshots; TEST.md for PC 2
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 13:25:14 +00:00
igneum-labs
c6a425ed8c Brand: one master mark (black square, no circle) for every icon, favicon and profile picture
the project lead's rule, 4 October 2026: the mark sits in a black square, never in a circle, never on another colour, 20% clear
space; the Mac app is the model. brand/master/igneum-mark-square.svg (1024, #0C0C0E, the exact header polygons at 62%)
and igneum-mark-square-rounded.svg (Apple's 824-on-1024 grid, DMG volume icon only). make-icons.py now rasterises the
masters (rsvg-convert if installed, else Pillow draws the polygons) into igneum.icns (plain square, 16 to 1024),
igneum-volume.icns, igneum.ico (each size from the vector), the Inno art, the DMG background, site favicons
(favicon.ico 16/32/48, favicon-32, apple-touch 180, 192, 512, maskable 512 + manifest entry), relay favicons, and
brand/profile (400/512/1024, github-org-512, X banner). Every page head's inline SVG favicon and the relay header lose
the ring. The .rc and Info.plist paths are unchanged (same file names). docs/brand/before holds the old set.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 11:39:55 +00:00
igneum-labs
d69d70c3fc Windows exes carry the coin icon and a version block (the project lead's rule, 4 Oct 2026)
Every Windows executable now ships with the coin icon Explorer shows and the version block Properties shows
(CompanyName Igneum, ProductName Igneum Miner, FileDescription per exe, 0.3.0, LegalCopyright Igneum contributors),
like the Mac app and DMG already do.

- igneumd.exe, igneum-miner.exe: packaging/windows/embed-resources.sh now takes the worktree and target dir
  (defaults vendor/igneum-node-v4 and vendor/igneum-node/target-integration) and relinks with a linker shim first in
  PATH instead of `cargo rustc -- -C link-arg`: cargo rustc takes one package and unifies features differently from
  the two-package cross-build (300 crates differ), and a configured linker is fingerprinted and rebuilds everything;
  the PATH shim changes neither. .rc files moved to 0.3.0.
- igneum-worker-cuda.exe, igneum-worker-opencl.exe: proto-cuda/nvrtc/build-windows.sh compiles the two new .rc
  files with windres and links the objects; the icon is made with make-icons.py if missing.
- igneum-app.exe: app/igneum-app/build.rs runs windres on resources/igneum-app.rc for Windows targets and links it
  (cargo:rustc-link-arg-bins, no crate dependency); it fails the build if the .rc version drifts from Cargo.toml.
- packaging/windows/resources/verify-exe.py: small PE parser that checks the .rsrc section, icon group and version
  strings on the Mac; both build scripts call it, and it checks every exe inside the packages.
- proto-opencl/cl_dynamic.h: clGetEventInfo added to the run-time loader table (4714b51 added the call in host.c
  without it, so the one-click OpenCL worker no longer linked under IGNEUM_CL_DYNAMIC).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:44:20 +00:00
igneum-labs
a1ad8fffb9 Windows installer: Inno Setup version from the uninstall key or ISCmplr.dll when ISCC.exe has no version block (the GitHub runner image)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:36:39 +00:00
igneum-labs
7717c4fdac Windows CI: the one-click app built on GitHub runners, no PC needed
windows.yml: parse job (every .ps1 through the Windows PowerShell 5.1 parser with a negative fixture, PSScriptAnalyzer
as warnings, parenthesis check of every .bat/.cmd with a negative fixture), build job (engine on the MSVC target,
window host through BUILD-APP.bat as it is, payload through make-payload.sh in Git Bash, installer through
build-installer.ps1, smoke run of both exes, launcher DRY_RUN, three artifacts for 90 days).
push-inputs.sh publishes payload-inputs.zip (node, miner, workers, NVRTC DLLs) to the downloads host from the Mac;
fetch-ci-artifacts.sh pulls the green run's installer and payload back into the downloads folder.
Host: --version and --help, version.h shared with host.rc. Launcher: DRY_RUN=1 prints the plan and starts nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:32:20 +00:00
igneum-labs
a7d7f5da2a Igneum Miner 0.3.0: GPU selection per card (switch, kind, VRAM, identities), Windows WebView2 host + BUILD-APP.bat, Mac DMG and Windows payload around the app, installer scripts for the engine
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:11:47 +00:00
igneum-labs
aa90c6f65b Bench log: first hourly swap on the live devnet, no pause on three vendors
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:07:35 +00:00
igneum-labs
38380d9035 Release: devnet v4 cut-over staged (Windows 0.2.0 packages, Mac app 0.2.0, seed igneumd-v4 unit, runbook)
Windows combined package 0.2.0 (proto-cuda/windows-app): v4 exes from target-integration, peers = seed then Mac,
fresh appdir devnet-v4, one miner and one worker per card with --identities 8, --evm-address (PAYOUT_EVM or derived
per vendor from the PC name), voting on (VOTE=0 opts out), --prepare-packs for the hot swap with --exit-on-seed-change
as the fallback, --yes on the node, STATUS regex tolerant of the v4 now= segment, version in the dashboard header.
Mac app 0.2.0 (packaging/mac): v4 binaries, Metal worker rebuilt for macOS 11, data folder devnet-v4, EVM payout,
identities in one process, synced= flag honoured. Seed (infra/seed-nodes): stage-v4.sh builds v4 on the VM as a
niced, memory-capped transient service and installs a disabled igneumd-v4 unit with a fresh data dir; switch-v4.sh
swaps the units (--back reverses); health.sh reports active-v4. Runbook: docs/plans/cutover-2026-10-04.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 01:48:56 +00:00
igneum-labs
381061a077 Mac app: dial the public seed node first, the home node second
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:28:58 +00:00
igneum-labs
3baf399615 Packaging: Igneum Miner for Mac and Windows, one-tap installs with the coin on every file and window
Mac: bundle renamed Igneum Miner.app (network.igneum.miner, 0.1.0, LSMinimumSystemVersion 11.0, igneum.icns),
Terminal title Igneum Miner, seed line in the first-run text, branded DMG (volume icon, background, icon slots via
dmgbuild), dist/Igneum-Miner-0.1.0.dmg at 16.2 MB, tested synced against the live node on 27400/27401.
Windows: packaging/windows with windres .rc files and embed-resources.sh (relink commands for the next cross-build),
Igneum-Miner.iss (Program Files, Start Menu group, firewall rule, uninstall stops the processes, licence, seed line),
BUILD-INSTALLER.bat and build-installer.ps1 for the project lead's PC (winget Inno Setup 6, rcedit fallback for the exe icon).
Icons: brand/icons/make-icons.py makes igneum.icns, igneum.ico, the Inno wizard art and the DMG background.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:26:57 +00:00
igneum-labs
87df9eac9d Harness: consensus attack catalogue runner and first results
tools/harness runs the standard consensus-attack catalogue against a private
test network of our own igneumd nodes (127.0.0.1 ports 27200+, /tmp/igneum-harness,
never the live devnet or the PC node), with a pass criterion per scenario from the
spec and a measured result each. Built on the node fork's own crates
(igneum-harness-sim on kaspa_utils::sim as simpa does; igneum-p2p-probe for the
wire). Scenarios: 1 withholding, 2 timestamp edges and drift, 3 partition and heal,
4 eclipse, 5 malformed and boundary inputs on every p2p and RPC surface, 6 resource
exhaustion, 7 fast-miner flood. Finality and difficulty-controller scenarios are
stubs with their criteria written.

bench-log: one dated entry, a row per scenario (criterion, measured, pass or fail).
First run: 19 of 20 measured rows pass. Findings recorded in the entry: scenario 5
reproduces ledger M15 on HEAD (bogus past-day or DAA headers build a 256 MiB cache
before rejection; the r3-fixes branch removes it); scenario 1 at 45% hash with
burst withholding shows a selfish-mining blue-share gain (50.7% of blues), the one
failing row.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:17:37 +00:00
igneum-labs
543833c50d Mac packaging: Igneum Devnet.app and DMG for Apple silicon miners
packaging/mac: build-dmg.sh assembles Igneum Devnet.app (shell launcher that opens
igneum-devnet.sh in Terminal, stripped ad-hoc-signed copies of igneumd, igneum-miner
and the Metal worker), README.txt, Stop Igneum.command and an Applications link into
dist/igneum-devnet-mac.dmg (17 MB, lzfse). The script starts the node peered to
SEED_PEERS, waits for sync, runs one miner identity mac-<hostname> on the Metal worker,
prints a status line every 30 s, uploads logs every 60 s, keeps the Mac awake and stops
everything in order on Ctrl+C, window close, --stop or the Stop command.

Tested on this Mac from the mounted DMG against a test node on 27310/27311 peered to the
live node: sync in 22 s, 24 accepted blocks, listed on igneum.network/live, clean stop
with no stray process on SIGINT, SIGTERM and Stop Igneum.command.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 21:54:22 +00:00