Commit graph

69 commits

Author SHA1 Message Date
igneum-labs
bb7e851c92 Igneum Wallet: the Windows build chain (8 October 2026, main's order after 0.1.6: a Windows arm by the wallet's next OTA, PC 2 by job when it is back). The pieces, the miner's chain step for step with the wallet's names: packaging/windows/push-build-inputs.sh --wallet packs app/igneum-wallet and app/igneum-common into the build-inputs zip with vendor/igneum-node as a symlink to node/ (the wallet links the node's rpc crates by that path; unzip restores it inside the distro) and adds the build unit {app/igneum-wallet, igneum-wallet, windows} with its tests, so the PC's build job makes igneum-wallet.exe on the gnu target as it makes igneum-app.exe; packaging/windows/push-wallet-kit.sh publishes the kit zip (the host sources and BUILD-WALLET-APP.bat, build-installer.ps1, Igneum-Wallet.iss, stop-igneum-wallet.ps1, the icons, the wallet's packaged igneum-wallet.json from the token file) to the downloads host; relay/playbooks/wallet-kit-pc2.ps1 is the run job on PC 2: the host through BUILD-WALLET-APP.bat (MSVC, WebView2 SDK), the payload from the build job's engine and the node pin, the installer through build-installer.ps1 -Product wallet (Inno, rcedit), the smoke run with the host's version block, and, over a running older wallet, the installer end to end with the installed version read back (rule 14), every output dropped on the relay with its sha256; packaging/windows/build-installer.ps1 takes -Product miner|wallet (folder, engine, stop script, exes, .iss, setup name, the version-block stamping by product); packaging/windows/Igneum-Wallet.iss is rebuilt on release-0.3.25's detach-safe miner shape (install-close-23 and install-detach-25: the payload's own stop script with -Install, the install marker under igneum\wallet, the one-shot detached task under the app's job runner, the version-named file refusal, the stale-marker clear) with the wallet's names; packaging/windows/stop-igneum-wallet.ps1 is the miner's 0.3.23 stop script for the wallet (the host first by path, the engine through its API, the unlock wait with the STILL LOCKED line); make-wallet-payload.sh is the Mac-side payload maker for a hand build. release-0.3.25's installer-stop-check passes on the wallet pair (every rule holds); the check itself stays on the release line, whose miner installer carries the shape master's does not yet. Signing: as the miner's, deferred until the certificates exist (release-0.3.20 section 2.4). Untested on a PC until PC 2 returns: the first run is the known-failed run by design.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-08 11:59:16 +00:00
igneum-labs
ba9319f84b Merge master into wallet-bridge (the wallet's line meets master for the landing of the page bridge)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	packaging/ota/publish-manifest.sh
#	site/index.html
#	site/wallet.html
2026-10-08 11:33:30 +00:00
igneum-labs
f3c2f7800a Igneum Wallet 0.1.6: the page bridge (main's order of 8 October 2026: igneum.network/swap connected any injected wallet, the Igneum Wallet signed only inside its own window). The engine listens on a fixed loopback port, 127.0.0.1:26811 (src/bridge.rs, igneum_common::http::serve_on), beside its token-guarded window server; a page's provider (site/wallet-provider.js: window.ethereum when nothing is injected, window.igneum beside MetaMask, announced through EIP-6963) POSTs JSON-RPC there with the X-Igneum-Bridge header (a preflight first; the private-network allow header answered) and polls a request the window has to answer. Rules: a site is approved once (eth_requestAccounts raises a connect request; Approve in the window stores the origin in the settings, Decline or five minutes ends it with 4001); every other method from an unapproved origin answers 4100 and creates nothing; eth_sendTransaction (priced by the node: gas with the call's data, the fees, the balance check), personal_sign (EIP-191) and eth_signTypedData_v4 (EIP-712, src/eip712.rs, the specification's Mail vector) each wait as their own request, shown with the origin and the facts and confirmed in the window (Touch ID or Windows Hello when enrolled, the same gate as a send); after a transaction the card keeps the node's word and the checkpoint this wallet verified; reads go to the wallet's node for a connected site; wallet_switchEthereumChain accepts the wallet's chain and refuses another with 4902. Settings: a Websites card with the switch and the connected sites (Disconnect); the lock screen says which site waits. Known-failed first: a page without approval gets nothing (bridge::tests::a_page_without_approval_gets_nothing, the view and provider tests on build-2 before the files existed). Tests: bridge.rs (4), eip712.rs (3), tx.rs (the digest signer recovers), ui/view.test.mjs (the words), site/wallet-provider.test.mjs (5). Versions 0.1.6 in the three places; rust-toolchain.toml taken from master so cargo on the Mac reads the pinned 1.99.0.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-08 11:13:27 +00:00
igneum-labs
69e5de2d6e Merge build-server a3f15d28 into master on the box mirror: lease pool classes and pre-emption, the runner prelude, the manifest digest guard, the inline-rm gate, the site deploy checks, cloud-sweep, forgejo (tools/ci conflicts resolved as the union of both sides)
# Conflicts:
#	tools/ci/README.md
#	tools/ci/pre-push.sh
2026-10-07 21:34:58 +00:00
igneum-labs
78551d3bac Site deploy: master only (no branch or commit argument) and the post-deploy checks before the edge time (main, 7 Oct 2026 22:1x BST): /api/live network == igneum-devnet-3, the launch-first chip line and the git.igneum.network link on the index, \"Not legal advice\" on the litepaper, at least 30 /miners rows; any mismatch prints DEPLOY RED <field> and exits 1; --self-test-checks known-failed first (a wrong network, a missing string). push-inputs.sh honours IGNEUM_WORKERS_DIR and IGNEUM_NODE_SRC
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 21:16:45 +00:00
igneum-labs
ed7c3de8e8 Pre-public scrub, second pass (7 October 2026, 20:0x UK, main's rulings 2 and 4): the public tree names igneum-labs only; the public ledger generated from the full ledger
Ruling 2: every tracked text mention of the login's pre-rename spelling becomes igneum-labs (29 files); the commit identity in the scripts becomes igneum-labs <337424239+igneum-labs@users.noreply.github.com> (the same noreply id); the three scripts that hand the stored gh keyring name to gh (register.sh, fetch-ci-artifacts.sh, ship-app.mjs) read it from ~/.config/igneum/gh-user (never in the repository), default igneum-labs; fresh-repo.sh reads the login to rewrite from the encoded list's row 10; the old spelling joins the founder-strings list, so no tracked file may spell it; CLAUDE.md's GitHub paragraph rewritten. The red watcher's self-test fixtures use a neutral author.

Ruling 4: docs/ledger-public.md, one row per ledger item (id, the claim in one line, status, what was done in one line, the evidence link or the evidence in words), generated by tools/ledger/export-public.mjs from docs/fud-ledger.md: no round or status-update sections, no commit ids, no time of day, no lane, agent or branch names. 190 items. The gate runs its self-test (a fixture with a commit id, a time, a lane and a branch name comes out clean; --check fails on drift) and its --check on every merge; the founder check reads the output like every tracked file.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:56:08 +00:00
igneum-labs
7355d53fde Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).

The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.

Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:39:50 +00:00
igneum-labs
6cb1500410 master re-pinned to the published 0.3.20 node (c4459193): packaging/windows/node-source.pin against the live payload-inputs.json, so windows-ci's payload inputs step reads green; release rule 14, master re-pinned at every publish
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 15:13:10 +00:00
igneum-labs
6ba44e51c9 Reproducible builds: SOURCE_DATE_EPOCH from the commit's author time, TZ=UTC and one fixed target path in every build path; self-test
Main's rule of 6 October 2026 from the 0.3.14 repro (docs/evidence/reproduced/0.3.14.md): prost's protowire.rs embeds OUT_DIR,
libmimalloc-sys embeds __DATE__/__TIME__, sccache hid both. lib.sh bs_repro_env exports SOURCE_DATE_EPOCH=<author time> TZ=UTC in
front of every remote command (build-remote.sh, cross-remote.sh, workers-remote.sh); remote-run.sh exports BR_SDE too and logs it
as source_date_epoch; proto-cuda/windows-node/cross-build.sh exports the same; the PC job carries node.commit_time in the manifest
(push-build-inputs.sh) and exports it before every cargo build of a stage (jobbuild.rs, unit test asserts it; 4 of 4 pass on the
box). Target dirs stay one fixed path per target. tools/build-remote.sh --self-test-repro [--full] from a fork worktree, run on
the box: igneum-miner twice a minute apart without sccache (RUSTC_WRAPPER=/usr/bin/env, an empty value is unset to cargo) MATCH
91e130f5..., a per-run target path differs (OUT_DIR shown); --full: kaspad with libmimalloc-sys recompiled a minute later MATCH
70219bc2..., without the epoch differs (__DATE__ shown).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:09:23 +00:00
igneum-labs
3155d375f4 Merge release-0.3.14: Igneum Miner 0.3.14 (exec-sync deep-reorg reload, miner-ui-3, ember-tune), publish 1 on the thirteen-field object
The node pin moves to 4c6b129d (release-0.3.14-node), which is what the live payload inputs carry, so windows-ci's payload-inputs step is green again (red since e9eca23 on master's 0.3.13 pin against the 0.3.14 inputs).
Conflicts: infra/fast-time/override-60x.json keeps master's side (the fresh-rule field was already there at u64::MAX; the release line would be a duplicate key); tools/ci/playbook-quit-check.sh keeps master's rule 2 and pre-rule list with the release side's Ember allow entry and the 0.3.15 expiry check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 18:18:17 +00:00
igneum-labs
d6c4956403 Build server adopted: box-first build rule in CLAUDE.md, reproducible Windows exes, the commit-string gate, PC and Mac recipes
Main's decision of 6 October 2026. CLAUDE.md 'Running agents on this Mac': every Linux and Windows cargo build and every
Linux test suite goes to igneum-build-1 through tools/build-remote.sh and tools/cross-remote.sh; the PCs keep GPU and
Windows-runtime jobs; the Mac keeps macOS binaries, the DMG and Metal tests under the lock. -Wl,--no-insert-timestamp in
cross-remote.sh, proto-cuda/windows-node/cross-build.sh and jobbuild.rs (two box builds byte-identical, verified).
The empty-commit class: tools/ci/commit-string-check.sh (self-test in ci.yml, shown firing on a Mac worktree build and
passing on a box build) runs on every igneumd from the three build scripts; push-build-inputs.sh adds node.commit_full,
the PC job writes a minimal node/.git from it at extract and cleans kaspa-build-info on a new commit (4 jobbuild tests
pass, run on the box); cross-build.sh refuses a worktree and cleans on a new commit. Plan: second worktree's clean build
1 min 18 s with sccache 604 hits of 993.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:50:39 +00:00
igneum-labs
d5a402a4e6 Windows payload inputs: node 4c6b129d (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.14
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 17:06:17 +00:00
igneum-labs
c1fd40ea70 Igneum Wallet 0.1.5: the three version files (the 0.3.14 node and the thirteen-field consensus object bundled; the wallet's node peers again)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:56:07 +00:00
igneum-labs
c36705f846 wallet 0.1.5: merge release-0.3.13 (the 0.3.13 tree under the wallet app: igneum-common, packaged-config, the ten-to-thirteen-field objects)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	.github/workflows/ci.yml
#	.gitignore
#	docs/bench-log.md
#	packaging/README-ship.md
#	packaging/mac/packaged-config.sh
#	packaging/ota/publish-manifest.sh
2026-10-06 15:54:57 +00:00
igneum-labs
1736d4a3ac Igneum Miner 0.3.14: the six version files (node-only: the exec layer survives a deep reorg and a moved pruning point)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:54:14 +00:00
igneum-labs
182d19c7c5 Windows payload inputs: node bb43e9a8 (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:12:13 +00:00
igneum-labs
427b9c37d9 Windows payload inputs: node 544fc30f (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:05:53 +00:00
igneum-labs
34dcd99379 Windows payload inputs: node a9dfe78e (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.13
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:57:33 +00:00
igneum-labs
924c52c155 Igneum Miner 0.3.13: the six version files (node-only cut: the exec follower fix and the finality route fix)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 13:14:55 +00:00
igneum-labs
ce486b3977 Windows payload inputs: node 83089544 (push-inputs.sh, the Mac cross-build, the 0.3.11 workers, the AMD telemetry helper, signed); release 0.3.12
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:49:08 +00:00
igneum-labs
e746f50a0e make-payload.sh: the AMD telemetry helper is taken from the unpacked inputs on CI (the worker glob missed igneum-gpu-telemetry.exe, so the 0.3.12 payload of run 37435975425 lacked it)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:33:25 +00:00
igneum-labs
36c894b047 release 0.3.12: merge ember-tune 3afb051 (Ember Tune, the quit source, no OTA and no pipe in a second engine, the elevated follow_file, the BOM fix, Power control, job-console's hidden-console builder and spawn check)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:22:22 +00:00
igneum-labs
59461cc020 Merge release-0.3.12 (aac607c) into ember-tune: 0.3.11's six-section View and card order kept, Ember Tune's line and switches re-added on it; the tune fields move into hotplug::apply_pref; the power-cap plan keeps present(); both CI test lists; 132 app tests, 26 UI tests, every gate green
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:20:46 +00:00
igneum-labs
30627ea5c4 Igneum Miner 0.3.12: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:19:00 +00:00
igneum-labs
b2a79ee2f3 Windows payload inputs: node 89dfcb95 (push-inputs.sh, the PC 2 build, the class-aware workers, signed); release-0.3.11 plan: the PC 2 job
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:18:28 +00:00
igneum-labs
2ee81a96fa Igneum Miner 0.3.11: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:40:42 +00:00
igneum-labs
e0be65f138 AMD telemetry: igneum-gpu-telemetry (ADLX on Windows, amdgpu sysfs on Linux, PDH utilisation fallback) feeds the card row's draw, temperature, fan, memory clock and MH/W; measured on PC 1: 9070 XT 198.9 W, 64 C, 657 rpm, 17.73 MH/s = 0.089 MH/W beside the 5090 at 307.6 W, 122.30 MH/s = 0.398 MH/W
the project lead watched the 9070 XT at 90% usage with its fans barely turning and the app could not say what it drew: the
draw, temperature and MH per watt line came from nvidia-smi only, and the earlier per-watt figure used the board
rating. proto-opencl/gpu-telemetry.c prints one line per AMD card per sample (bus from SetupAPI by the display
device's name, kind, name, watts, temp_c, fan_rpm, fan_pct, mclk_mhz, gclk_mhz, util_pct, source), built by
build-windows.sh against vendor/adlx (the SDK clone), shipped by make-payload.sh and push-inputs.sh. The engine
runs it with -l 5 beside nvidia-smi (Source::AmdTelemetry, tick_amd_telemetry), parse_amd_telemetry fills
power_w, temp_gpu, fan_pct, fan_rpm, mclk_mhz, util_pct and telemetry_at on the AMD card matched by kind and
ordinal, so eff_mhw and the dashboard's existing line show it; app.js shows fan and memory clock when present.
Tests: three on the parser with lines captured on PC 1 and the Mac fixture; the sysfs path ran on a fixture tree.

Measured over 20:27:45 to 20:29:41 UTC with both cards mining (docs/bench-log.md, under the 9070 XT ceiling table):
9070 XT 198.9 W (193 to 212), 64 C, 657 rpm, 2,505 MHz memory, 3,290 MHz shader, 100% busy, 17.73 MH/s =
0.089 MH/W; RTX 5090 307.6 W, 69 C, 44% fan, 122.30 MH/s = 0.398 MH/W.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:21 +00:00
igneum-labs
c7b6c79676 Merge miner-ui-2 (2287529) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
0d64c1f59d Merge gpu-hotplug (12d5011) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
fcdd2b913d Windows payload inputs: node 21d4c73c (push-inputs.sh, the PC 1 build, signed, live 18:36Z)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:36:17 +00:00
igneum-labs
6144d2d4c6 Merge c4-fix (698dce3) into release-0.3.10: the certificate-driven reorg in spec 3.5, 3.2, 3.10, 3.11.7, ledger C4, bench-log; c4.mjs v2 mode; the signer never piped into head (signer-pipe-check); one build-inputs zip per job
# Conflicts:
#	docs/bench-log.md
2026-10-05 18:20:50 +00:00
igneum-labs
698dce3e78 C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning)
Fork: vendor/igneum-node-c4 branch c4-fix on release-0.3.6 a24ab01a.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:17:36 +00:00
igneum-labs
2c255ec263 Igneum Miner 0.3.10: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:01:00 +00:00
igneum-labs
cc95932842 Windows payload inputs: node a24ab01a (push-inputs.sh, signed, live 16:32Z) 2026-10-05 16:32:29 +00:00
igneum-labs
aa09cf078b Igneum Miner 0.3.9: the prover mirrors the fee switch (new pinned guest, shard id 0x2b1a81cb...), node a24ab01a (igneum_exportSegments names the mergeset and every entry's block and body position), the devnet fee-switch runbook; the six version files 2026-10-05 16:28:36 +00:00
igneum-labs
abff030f7f Igneum Wallet 0.1.4: the lock screen; the Touch ID sheet on a tap, once by itself when the wallet opens; the idle lock's minutes
The lock screen (ui/lock-screen.js, pure, with lock-screen.test.mjs): the coin large on the ember glow, the name in
Unbounded, the short address in mono, one control. Touch ID enrolled in the app window: the fingerprint button, its
line, a quiet "Use password" that reveals the field in place (the control area keeps one height). Otherwise the
password field is the control. Locking is a 250 ms transition from the home screen, not a cut. The glow breathes;
reduced motion stops it.

No automatic sheet: it appears on a tap, Return or Space on the button (focused on arrival and when the window
comes back). One exception: the first arrival after the person opened the app, 600 ms after the lock screen is
drawn, when "Ask for Touch ID when the wallet opens" is on (new setting, default on). Never on an idle lock, a hand
lock, the window coming back, after a cancelled sheet ("Touch ID cancelled, tap to try again", no modal), or on the
updater's relaunch (updated_from set). Escape in the password field returns to the button.

The idle lock: Settings > Lock when idle, 1, 5 (default), 15, 60 minutes or never (settings.json idle_lock_min;
idle_lock mirrors on/off for 0.1.2 and 0.1.3; /api/settings takes idle_lock_min and ask_on_open and refuses other
minutes). The engine's lock event names the minutes.

Also: the three wallet switches in Settings were invisible (the miner's .switch hid the input behind a .track the
wallet never renders); the box shows now. ?bio=touch shows the Touch ID layout without a host, for screenshots.

Tests: node --test ui/lock-screen.test.mjs (5) + update-card.test.mjs (4); cargo test in app/igneum-wallet, 18
passed (the settings migration test is new). Verified in the browser pane at 900x700 and 1280x800 against a scratch
engine. Shipped: Igneum-Wallet-0.1.4.dmg published to the new download folder and bridged into the old one (the
installed 0.1.3 polls the old folder; rotation phase 2 had removed the wallet manifest there); the project lead's wallet went
0.1.3 -> 0.1.4 in 28 s (check 15:48:50Z, 0.1.4 up 15:49:19Z), no sheet on the relaunch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:51:07 +00:00
igneum-labs
7f1e3e846a Igneum Miner 0.3.8: pinned proving programs (one program id on every machine, the verifier answers in about 2 s), the update card, the Windows exporter path fix, re-stamped WSL scripts; node 2b6d23ef unchanged 2026-10-05 13:17:12 +00:00
igneum-labs
a55f7af7ac Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
f6bd95053b inputs: pin node 2b6d23ef for 0.3.6 (payload-inputs.json signed and deployed) 2026-10-05 09:27:28 +00:00
igneum-labs
96a9729de4 Igneum Wallet 0.1.2: Touch ID (unlock, every send, the backup, idle lock), Windows Hello written untested; the coin and the chain line on the balance card; the version in the header and Settings
The window host owns the prompt and the secret (app/mac/Biometric.swift): LAPolicy.deviceOwnerAuthenticationWithBiometrics
with "Use password" as the fallback button (never the device password), the wallet's password sealed to a Secure
Enclave key made with .biometryCurrentSet (the Keychain refuses biometric access controls under the ad hoc signature,
-34018, measured) in <data>/wallet/biometric.json; a fingerprint change invalidates it. The engine owns the gate
(igneum-common/src/biometric.rs): a nonce per action, read by the host with its token (the HOST line on stdout,
X-Igneum-Host on host-only calls), confirmed after the prompt, taken once within 30 s and bound to the exact quote;
/api/send refuses without it while enrolled; /api/reveal with a nonce reads the unlocked key in memory; the password
never goes through the page (enrolment parks it under a one-time token the host takes). Idle lock after 5 minutes
without window activity (setting, default on). A password change or a wallet removal deletes the sealed file.
Reason lines in our voice ("Unlock your wallet", "Send 1.5 IGN to 0x7E5F…5Bdf", "Show your recovery words"); the page
shows its own ember line after every prompt. Windows: app/windows/biometric.h (UserConsentVerifier through
IUserConsentVerifierInterop, DPAPI), wired into wallet-host.cpp and BUILD-WALLET-APP.bat, not yet compiled on a PC.
Hosts gain a @main entry so Biometric.swift compiles alongside; build-wallet-dmg.sh links LocalAuthentication.
Balance card: the coin at 56 px, "0" (or the balance) as soon as the node answers, "reading the chain, N of M blocks"
under it while the history scans. Version: v0.1.2 in the brand band, "Igneum Wallet 0.1.2 · up to date" in Settings.
Unit tests: the gate (7, igneum-common), the wallet's 17 still green. README: the flows, the threat model, what was
verified on this Mac (enrol and unlock through the real prompt) and what was not.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:09 +00:00
igneum-labs
c86967c9f2 build inputs: every staged file is stamped now before zipping (the PC's cargo cache judged 0.3.6 sources older than its 0.3.5 build)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 140fb8a898)
2026-10-05 09:12:07 +00:00
igneum-labs
8c49c6e39f push-build-inputs: the live sha256 check retries for a minute (the edge served the previous file right after the deploy; the 0.3.6 build job failed here on 5 October 2026) 2026-10-05 08:50:53 +00:00
igneum-labs
a6541e837e Igneum Miner 0.3.6: instant jobs, a proof verifier on every node, one notice strip, lower miner latency, packaged configuration, hidden helper windows, WSL scripts from files; node 2b6d23ef: testnet identity and fee table behind a height switch, signed build inputs 2026-10-05 08:48:57 +00:00
igneum-labs
7a66a79454 Merge rotation-2 (e8dc998) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
e09a13da31 Merge proving-app (c510f29) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master cce1a12), tile shows the verifier 2026-10-05 08:33:13 +00:00
igneum-labs
9be5d48e07 Merge origin/testnet-adopt (c00c0c4) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
d2860e7f8e app: the node gets a proof verifier, the WSL2 probe checks both layouts, the tile shows the verifier state (0.3.6 items 1 to 3)
Spec 7.7 item 4: a node without a verifier relays proof records and never includes them. On 5 October no app node ran one.

1. src/verifier.rs decides once per node start and engine.rs passes it to the igneumd spawn. macOS and Linux: igneum-prove-host
   next to the engine's binaries. Windows: the new igneum-prove-verify.exe (src/bin/prove-verify.rs, a bin target of this crate,
   shipped by make-payload.sh) is set only when its --probe finds a host inside WSL2; it rewrites --proof with wslpath -a,
   runs the host in the order of src/wslhost.rs and returns its exit code, 2 when there is no host. Trust mode is never the
   default: the setting proof_verify_trust (Settings, "devnet only") sets IGNEUM_PROOF_VERIFY=trust only when no verifier was
   found; changing it restarts the node. After the WSL2 setup runs, the prover thread asks for one node restart.
2. The prover's WSL2 probe looks at the payload's wsl2/bin, ~/igneum-prove/proving/igneum-prove/target/release (what
   setup-wsl.sh builds), ~/igneum-prove/target/release and /opt/igneum, in that order (one list in src/wslhost.rs, shared
   with the wrapper); the tile's message names every path it looked at.
3. The prover thread reads igneum_getProvingStatus().verifier every 30 s, proving on or off; /api/state carries
   proving.verifier, verifier_mode, verifier_set, verifier_reason, verifier_note and the pool counts; the tile has a
   verifier row and says when this node relays proofs but does not verify them.

Tests: cargo test -p igneum-app, 89 passed. The wrapper cross-compiles with --target x86_64-pc-windows-gnu on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
d4263e3be5 build inputs: ship igneum-pow beside the zip root and the coin image the engine embeds
The first PC build (job build-20261005-075300) failed in 52 s: the node's crates depend on ../../../../igneum-pow,
which the zip did not carry, and the engine embeds brand/igneum-coin-1024.png, which the staged brand/ lacked.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:01:17 +00:00
igneum-labs
7f18167674 Merge origin/testnet-prep (e8f8044) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
e8dc998406 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00