Commit graph

86 commits

Author SHA1 Message Date
igneum-labs
d5da02a851 Merge pack-loop (4163143) into release-0.3.10: a pack's seed words are its program attempt's words, not the bare seed's (the epoch 34 outage)
# Conflicts:
#	relay/test/parse.test.mjs
2026-10-05 19:23:59 +00:00
igneum-labs
18f244bcfb Merge miner-ui-2 (6acfaed) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
cbe031b39c Merge gpu-hotplug (bd21f2a) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
41631431c0 Workers: a pack's seed words are its program attempt's words, not the bare seed's (epoch 34 incident, 5 October 2026)
From 18:23Z both Windows workers (CUDA on PC 1 and PC 2, OpenCL on PC 1 after the 18:34Z node restart)
refused every pack for epoch 34 with "the epoch seed bytes do not give the pack's IGNEUM_SEEDW_INIT", and
the miner and the app restarted them every 5 to 60 s until 18:44Z and beyond. The packs were correct.
The generator retries a rejected candidate with seed || k_le32 (attempt_words); epoch 34's attempt 0 was
rejected (246 of 16384 final register values saturated, limit 163) and attempt 1 accepted, so the pack
carried attempt 1's words while pf_load (proto-cuda/nvrtc/packfile.h) derived the expected words from
the bare seed. Both workers also matched jobs to pairs by those bare-seed words, so even a loaded pack
of a retried program would have answered "epoch seed mismatch" on every job.

The rule, in one place per language:
- packfile.h: pf_program_words(bytes, attempt); pf_load reads IGNEUM_PROGRAM_ATTEMPT and checks the
  attempt's words; the refusal says "program pack and its seeds disagree: IGNEUM_SEEDW_INIT is not
  attempt N of the epoch seed ..." in plain words.
- worker.cpp and proto-opencl/host.c: a job belongs to a pair when the seed hex the node sent is the
  pair's (pairIs); the compiled-in placeholder pack keeps the word comparison.
- igneum-pow/src/packcheck.rs: verify_pack_texts / verify_pack_dir, the same rule in Rust; the miner
  checks every pack it writes with it before a worker sees it (vendor/igneum-node pack-loop branch).
  Tests pin the attempt vectors of epoch 34 on both sides (one vector, two implementations), that
  epoch 34 is attempt 1 and epoch 33 attempt 0, a known-good pack of a later attempt, a known-mismatched
  (out of date) pack, and self-contradicting packs.
- proto-cuda/nvrtc/emu/packfile-test.c (+ .sh, in CI): pf_load on a known-good attempt-1 pack, the
  checked-in attempt-0 pack, and the known-mismatched bare-words pack.

The app (app/igneum-app):
- watchdog.rs: PACK_OUT_OF_DATE_CODE 44, PackRebuilds (at most 3 pack exports per epoch, then the card
  shows the reason), pack_refusal (the worker's "error 0 pack" line and the miner's "PACK OUT OF DATE"
  line), pack_epoch_of; tests on the incident lines, known-good and known-mismatched.
- engine.rs: exit 44 exports the pack again before the restart instead of a blind restart, the strip
  says "program pack out of date, rebuilding", the card and the log name the condition; at the cap the
  card is marked failed with the reason and tries again in 10 minutes.

The relay (relay/lib/parse.mjs): PACK_MISMATCH; the card reads "pack mismatch, rebuilding (N refusals
in the tail, M restarts)" in `node tools/console.mjs machines` instead of a bare restart count; tests
on the PC 2 tail of 18:27Z and a healthy tail.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:10:07 +00:00
igneum-labs
6bf6af9533 Igneum Miner UI 2: six sections behind a rail (Mine, Prove, Rewards, Node, Updates, Settings)
The one long page becomes a rail with six sections, a thin top bar and the status strip under it; the setup
screens and the key sheet stay. Mine: one big start/stop, the numbers, one row per GPU with its switch, hash
rate, temperature and power. Prove: the switch with plain words, the counts, the verifier, the pinned ids.
Rewards: the address with one Copy, the key backup card, another address. Node: the plain lines, the consensus
digest, the next switch. Updates: the version, the jobs. Settings: one switch or slider per setting with one line
of help. Every function that existed is placed, none removed.

Engine (three small additions, each with a unit test): node.consensus_digest from the node's own line,
node.consensus_switches from the override file, proving.program_id and aggregator_id from the host's --mode id.
Hosts: the window minimum is 900 x 600 on both. UI tests: view.test.mjs (10) joins notices and update-card in CI.
Proof: docs/plans/miner-ui-2.md and the 19 screenshots under docs/plans/miner-ui-2/, taken from a build of this
tree running on its own port against the devnet.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:06:27 +00:00
igneum-labs
8831b53326 Merge elevated-exit (574eacc) into release-0.3.10: a refused, cancelled or timed-out administrator prompt fails the job with exit 251 2026-10-05 18:21:07 +00:00
igneum-labs
b36beeee5d Merge gpu-hotplug (bd21f2a) into release-0.3.10: cards re-enumerated every minute and on WM_DEVICECHANGE, one row per physical GPU, Code 43 cards marked, integrated GPUs off by default, the cards line in the console 2026-10-05 18:21:07 +00:00
igneum-labs
bd21f2a680 app: one card row per physical GPU across OpenCL platforms, Windows names on the rows, index-free card keys; the OpenCL worker prints the PCI address
PC 1 after Adrenalin 26.9.2 (5 October 2026): two AMD ICDs each listed the iGPU and the RX 9070 XT, so the 0.3.9
app showed five rows for three GPUs (gfx1036, gfx1201, gfx1036, gfx1201 plus the 5090), ran two workers on the one
9070 XT at 9 MH/s each, called the iGPU discrete, and re-enabled it when its key moved from amd:1:gfx1036 to
amd:0:gfx1036.

detect.rs: the Windows path is a pure assemble(Inputs) over nvidia-smi, the worker's --list and the adapter list.
dedupe_platforms keeps one entry per card per vendor: the fuller platform wins (most GPUs, then the newest driver,
then the first listed) and another platform's device survives only at a PCI address the winner lacks (without
addresses: the same code and ordinal); the dropped entries go to the log, never to a worker. resolve_name puts the
Windows adapter name on the row: by PCI bus (the adapter list now carries DEVPKEY_Device_BusNumber and Address),
else by the gfx code's PCI device ids, else by the card names in a gfx table (gfx1201, 1200, 1100, 1101, 1102,
1030, 1031, 1032, 1036, 1035, 1103, 1150, 90c, approximate), else the table's words, else the code. The code stays
in `code`, the key and the row's tooltip; the key is vendor:code with "#2" for a twin, no index. hotplug::pref_for
reads a 0.3.9 key (vendor:index:code) when exactly one matches; the diff matches by key and PCI address, then by
vendor and name or code. The iGPU is integrated and off by default; the choice survives a moved index.

proto-opencl/host.c: --list prints ", pci bb:dd.f" on the info line from CL_DEVICE_TOPOLOGY_AMD or the NVIDIA bus
and slot ids (needs a worker rebuild through proto-cuda/nvrtc/build-windows.sh and push-inputs; an old worker
still works, by code and ordinal).

Tests: detect::tests has the five-row PC 1 list as a fixture (two platforms, the three adapters with DEV_13C0,
DEV_2B85 and DEV_7550) and asserts three rows named NVIDIA GeForce RTX 5090, AMD Radeon(TM) Graphics (integrated,
off) and AMD Radeon RX 9070 XT (discrete, on, 8 identities), the keys, the console line, and the diff against the
one-platform list before the eGPU (iGPU moved, 9070 XT added, nothing removed); plus the list parser with and
without pci, dedupe with and without addresses, name resolution, twins' keys. cargo test -p igneum-app: 96 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:20:44 +00:00
igneum-labs
574eacc265 jobrun: a refused, cancelled or timed-out administrator prompt fails the job (exit 251)
The elevated launcher exited 0 after Windows cancelled an unanswered UAC prompt at 122 s (PC 1 driver job, 5 October 2026), so the job read as done. Start-Process now runs under -ErrorAction Stop in a try/catch, a missing process is exit 251, and the summary says what to do.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:05:08 +00:00
igneum-labs
c091eec39d Igneum Miner 0.3.10: the six version files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:01:00 +00:00
igneum-labs
d7049fdfda app: GPU hot-plug (re-detection every minute, WM_DEVICECHANGE on Windows), faulty cards listed with the problem code, integrated GPUs off by default, the card list in the console
5 October 2026: an RX 9070 XT went into PC 1 through a Sonnet USB4 box while the app ran and nothing noticed; the
app detected cards once at start. Now src/hotplug.rs compares every enumeration with the list (key, else vendor +
name when unique; a card whose tool did not answer is never called removed): a new usable card starts a worker,
enabled by default like a card at start, with "New card: <name>, mining" on the strip and in the log; a card
Windows lists with a problem code (Win32_VideoController Status / ConfigManagerErrorCode) is shown as "<name>: not
usable (Code 43)" with the reboot-or-reinstall hint and no worker; a card that disappears has its worker stopped
(quit, 8 s) and its row says removed for five minutes, then hides; an unchanged list touches nothing. The Windows
host sends "detect" on WM_DEVICECHANGE; the engine polls every 60 s (300 s on macOS, no GPU hot-plug there).

detect.rs: the Ryzen iGPU is "gfx1036" to the OpenCL worker, so the APU gfx codes count as integrated, plus the
adapter row's Intel processor string and a dedicated memory under 1 GB; integrated defaults to off with "integrated
GPU, off by default (2 to 3 MH/s for 30 W)" on the row, and the user's choice is kept across re-detections and
restarts (settings, found by key or by vendor + name when the index moved).

Console: the engine logs "cards: <name> [<kind>, <state>] | ..." at start, on every change and every 10 minutes;
relay/lib/parse.mjs reads it and the hot-plug events, the machines API and tools/console.mjs machines show them.

Tests: hotplug.rs (added, removed, moved, errored, recovered, revived, unchanged, twins, user override kept,
the console line), detect.rs (PC 1's adapter lines, the Mac, kind classification, the unusable row),
notices.test.mjs (card notices), relay parse.test.mjs (cards line). cargo test -p igneum-app: 91 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:45:05 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
38486f9551 Igneum Miner 0.3.9: the prover mirrors the fee switch (new pinned guest, shard id 0x2b1a81cb...), node a24ab01a (igneum_exportSegments names the mergeset and every entry's block and body position), the devnet fee-switch runbook; the six version files 2026-10-05 16:28:36 +00:00
igneum-labs
4bfb5d3928 release-0.3.6 plan: why the PC-built Windows node died at start, answered and fixed in the fork (static libstdc++); the stale comments on the Windows DLLs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:26:05 +00:00
igneum-labs
6cecbd4c67 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
c5f3cd17e4 Igneum Miner 0.3.8: pinned proving programs (one program id on every machine, the verifier answers in about 2 s), the update card, the Windows exporter path fix, re-stamped WSL scripts; node 2b6d23ef unchanged 2026-10-05 13:17:12 +00:00
igneum-labs
21a58ecd32 Merge branch 'update-popup' into release-0.3.8
# Conflicts:
#	.github/workflows/ci.yml
2026-10-05 13:14:52 +00:00
igneum-labs
d7596d1261 app: the WSL exporter path is built as a Linux path (PathBuf::join wrote a backslash on Windows and broke every export on PC 2)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:36:25 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
a0e092d109 Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
259d81afc8 Miner app 0.3.7: the update card, one centred card over the window for an update
The strip under the header stays; the card is the first sight of an update. The mark with a progress ring, "Igneum
Ember 0.3.7", one line (is available, is downloading with the percent, is ready to install, Installing. The app
restarts itself., did not install with the one-line cause and Try again), up to three lines of release notes from the
manifest with the rest behind "What changed", the size, Install now and Later. Escape and the backdrop are Later.
Reduced motion is honoured.

Rules (UpdateCard, pure, app/igneum-app/ui/update-card.test.mjs): the card never opens while a job runs, in the
engine's first 60 s, while the key sheet is up or while the app quits; it waits and comes once the block lifts.
Later hides this version at this stage and leaves the strip; the card comes back for a newer version, or when the
download is ready and automatic updates are off (with them on it installs by itself). An open card follows its
update through downloading, ready, installing and failed; installing and failed never open a card by themselves.

?update=<kind>[&auto=0][&card=1] and ?uptime= on the page show every state without an engine. CI runs the new test
file next to notices.test.mjs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:33:17 +00:00
igneum-labs
9bff1ce71e Merge app-ui (the notice strip) into update-popup 2026-10-05 09:15:50 +00:00
igneum-labs
aa9b4da932 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
1b4414dc8b build job: the extract stage stamps every unpacked file (the PC's persistent target dir judged 0.3.6 sources unchanged since the 0.3.5 build and linked new callers against stale crates); the packer stamps too, this guard holds if it regresses 2026-10-05 09:12:27 +00:00
igneum-labs
fb8c48651b Igneum Miner 0.3.6: instant jobs, a proof verifier on every node, one notice strip, lower miner latency, packaged configuration, hidden helper windows, WSL scripts from files; node 2b6d23ef: testnet identity and fee table behind a height switch, signed build inputs 2026-10-05 08:48:57 +00:00
igneum-labs
4bd816816c app: every WSL script runs from a file, never inline on the command line (src/wslhost.rs: write_script, bash_line, command)
5 October 2026, PC 2 on 0.3.5: the prover probe's inline script (double quotes, a path with a space) reached bash
mangled and the app said proving needed the WSL2 setup while /opt/igneum held the host. Now the probe, run_tool, the
setup launch, igneum-prove-verify (probe and run; the wslpath round trip dropped) and jobrun's six inline scripts
write a UTF-8, LF, no-BOM file under %LOCALAPPDATA%\igneum\wsl and run wsl -d <distro> -- bash [-l] '<file>' '<arg>'...
with every word single-quoted, placed raw on the command line; arguments reach the script as $1, $2. Unit tests pin
that the line never carries a double quote or a newline and that the file has LF endings and no BOM.
2026-10-05 08:47:40 +00:00
igneum-labs
545bdb2f0e app: every process the engine starts on Windows is hidden (platform::quiet on the window host, icacls, reg, the setup's cmd; igneum-prove-verify is a windows-subsystem exe, the node starts it with no console of its own)
The four helpers (detect::run_timeout, jobrun::run_capture, jobrun::run_streamed, procs::spawn) already set
CREATE_NO_WINDOW; the direct .output()/.spawn() sites did not. 5 October 2026: a console window on both PCs.
2026-10-05 08:39:49 +00:00
igneum-labs
0f6fc2ead5 Merge rotation-2 (7c9a939) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
c797fe49b3 Merge proving-app (05051c1) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 9835f49), tile shows the verifier 2026-10-05 08:33:13 +00:00
igneum-labs
b00de4f4f3 Merge app-ui (7388a20) into release-0.3.6: one notice strip under the header; CI runs both the wake and the notice tests 2026-10-05 08:32:52 +00:00
igneum-labs
fc137257ed Merge origin/testnet-adopt (3be4501) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
9835f493c7 app: the prover's WSL probe runs hidden (it opened a console window on PC 2 once a minute)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:30:00 +00:00
igneum-labs
65cb2e68b9 app: the job relaunch helper starts with CREATE_NO_WINDOW only (DETACHED_PROCESS exits powershell without a console, the OTA stall class)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:28:19 +00:00
igneum-labs
c40aa303a6 app jobs: wake long-poll on the relay, fetch within seconds of a publish; safety-net poll 2 minutes (was 10)
the project lead, 5 October 2026: "why is it taking so long for pc2 and pc1s tasks to spin up?". The PCs have no inbound ports
and one miner is off the LAN, so one thread per app now long-polls the relay's public /wake with the last stamp
(GET <url>?since=<stamp>, held up to 45 s there). A changed stamp sends Event::Wake and the engine fetches the jobs
file at once (signature check unchanged); a wake during a fetch in flight fetches again right after it. The first
reply only seeds the stamp. Backoff 5, 15, then 60 s while the relay is unreachable, a 10 s floor between requests,
a full hold when the relay has no stamp yet: never a busy loop. One log line per wake, one when it falls back, one
on recovery. IGNEUM_APP_JOBS_WAKE_URL overrides the URL (set and empty: no waker).

CHECK_EVERY_S 600 -> 120: the poll is the fallback now; the first poll stays 40 to 60 s after start. An unchanged
file is no longer logged on every poll. Remote jobs off stops the waker too.

Unit tests: the stamp logic (seed, same, changed, empty), the backoff sequence and the recovery flag, the floor,
the URL and query. cargo test -p igneum-app: 60 + 22 pass; cargo build --release -p igneum-app: finished.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:25:29 +00:00
igneum-labs
25350f254a app: the node gets a proof verifier, the WSL2 probe checks both layouts, the tile shows the verifier state (0.3.6 items 1 to 3)
Spec 7.7 item 4: a node without a verifier relays proof records and never includes them. On 5 October no app node ran one.

1. src/verifier.rs decides once per node start and engine.rs passes it to the igneumd spawn. macOS and Linux: igneum-prove-host
   next to the engine's binaries. Windows: the new igneum-prove-verify.exe (src/bin/prove-verify.rs, a bin target of this crate,
   shipped by make-payload.sh) is set only when its --probe finds a host inside WSL2; it rewrites --proof with wslpath -a,
   runs the host in the order of src/wslhost.rs and returns its exit code, 2 when there is no host. Trust mode is never the
   default: the setting proof_verify_trust (Settings, "devnet only") sets IGNEUM_PROOF_VERIFY=trust only when no verifier was
   found; changing it restarts the node. After the WSL2 setup runs, the prover thread asks for one node restart.
2. The prover's WSL2 probe looks at the payload's wsl2/bin, ~/igneum-prove/proving/igneum-prove/target/release (what
   setup-wsl.sh builds), ~/igneum-prove/target/release and /opt/igneum, in that order (one list in src/wslhost.rs, shared
   with the wrapper); the tile's message names every path it looked at.
3. The prover thread reads igneum_getProvingStatus().verifier every 30 s, proving on or off; /api/state carries
   proving.verifier, verifier_mode, verifier_set, verifier_reason, verifier_note and the pool counts; the tile has a
   verifier row and says when this node relays proofs but does not verify them.

Tests: cargo test -p igneum-app, 89 passed. The wrapper cross-compiles with --target x86_64-pc-windows-gnu on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:21:13 +00:00
igneum-labs
7388a20f95 Miner app UI: one notice strip under the header replaces the three stacked banners (updates, jobs, clock)
One notice at a time, the most important first (app/igneum-app/ui/app.js, Notices; pure, unit tested):
  0 update installing, urgent or failed   1 job failed   2 clock   3 job running
  4 update available, downloading, ready, waiting for permission, manual   5 job done   6 updated
Lower notices wait their turn. Every notice has a close control; closing hides that notice's key until the
state moves on (a new status, version or job id).

States and their rules:
  update available      "Igneum Miner X is available." Install now, Later. Key update:X:pending.
  update downloading    "Downloading Igneum Miner X: 43%." (no percent when unknown), progress bar; same key as
                        available and checking, so Later hides the whole download until it is ready.
  update checking       "Checking Igneum Miner X." (the engine's staging step).
  update ready          "Igneum Miner X is ready. It installs by itself at a quiet moment." (auto on) or just
                        "... is ready." Install now, Later. Key update:X:ready.
  update waiting        Windows, nobody answered the administrator prompt: "... is waiting for permission. It
                        installs the next time someone is at this PC. Mining continues."
  update manual         "... is downloaded. Open it and drag the app over the old one." Open the download.
  update installing     "Installing Igneum Miner X. The app restarts itself. Mining continues until then."
                        (on a Mac, where the engine quits at once: "The app restarts itself in a moment.")
                        Also while the engine says "installing now" after Install now.
  update urgent         the engine's consensus-deadline text, ember, downloading percent when it downloads.
  update failed         "The update to X failed." plus one line of cause and Try again; rolled back:
                        "Igneum Miner X did not stay up and was rolled back." A dev build with no manifest
                        configured shows nothing (Settings still says it).
  updated               "Updated to Igneum Miner X from Y." Gone 60 s after the new version started.
  job running           "Job: <title> running, N min. <Stage>." with the last RESULT line underneath.
  job done              "Job: <title> done after N min. Report uploaded." Gone after 5 minutes.
  job failed            "Job: <title> failed after N min, exit C. Report not uploaded." plus the first error
                        line (BUILD FAILED / error / failed / panic among the result lines, else the summary).
                        Stays until closed. Timeout and aborted are "hit its time cap" and "was stopped".
  clock                 as before: the engine's words, Sync clock, the manual hint; on the setup screens only
                        (the node card carries it on the dashboard). Jobs show on the dashboard only.

Layout: the strip reserves no height while empty; when a notice appears or goes, main's top moves once with a
150 ms transition (none under prefers-reduced-motion). Existing tokens only, nothing newer than 2022 CSS.
Screenshots: ?update=<state> as before, ?job=running|done|failed added (packaging/ota/README.md).

Test: node --test app/igneum-app/ui/notices.test.mjs (ordering, dismissed keys, wording, the 5-minute and
60-second timers); added to the CI site job. Built once with cargo (include_str) and checked against the
ui-mock scenarios and a scratch engine instance (IGNEUM_APP_DATA in a temp dir, fake worker).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:16:29 +00:00
igneum-labs
9aa5d5da24 app ui: a finished job's banner stays 5 minutes when it succeeded, 30 when it failed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:50:57 +00:00
igneum-labs
fd07ef569f Merge origin/testnet-prep (28f6ccc) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
77fa43d1b1 Igneum Miner 0.3.5: Pruning proofs on the lottery hash (M20), memory fix (M30), coinbase limit on every network (M31), chain-decided equivocation bans (F23), re-determination after reorgs (F24), params digest in the handshake (G12, X18), miner fee 1% switchable, efficiency sweep, variant racing, reliability watchdog, log panel and screens, PC build job, Windows updater launch fix 2026-10-05 06:33:18 +00:00
igneum-labs
7a81dc73f7 Merge remote-tracking branch 'origin/bugfix-collect-exit' into release-0.3.5 2026-10-05 01:02:23 +00:00
igneum-labs
7210fd4683 Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
cfb937b42d Merge origin/miner-reliability into release-0.3.5
Conflicts resolved keeping both: engine.rs carries the sweep state (miner-eff) and the node watchdog (reliability);
the STATUS line goes through watchdog::parse_status and still feeds the sweep's rate sample; main.rs declares both
modules; bench-log.md keeps both entries. site/build.mjs keeps master's partial-injected pages and adds the /miners
bench table through the same page() with active: 'miners'; the Miners link is in site/partials/nav.html; sitemap
gains /miners; every generated page rebuilt with node site/build.mjs.
2026-10-04 22:25:10 +00:00
igneum-labs
cad8aa0d96 Reliability measured: miner guards and the app watchdog on private test networks; M26, M27, X21 fixed in the ledger
docs/bench-log.md: the fake-worker measurements (slow start one trip and 2.0 s restart, fake-fast guard in under
0.1 s, exit 43 at 8.8 s, CPU re-check stop at 0.5 s, stall guard at 60.1 s with STATUS lines through the silence,
one prepare per epoch with refused retries held; app: zero-rate restart at 79.6 s and faulted at 75.4 s on the
repeat, no-status restart at 90.4 s, silent node restarted at 150.7 s and synced 7.2 s later; no double restart on
the miner's own worker restart). Two defects the harness found are named with their fork commits.
docs/fud-ledger.md and the round-4 review table: M26, M27, X21 Fixed with the commits.
engine.rs: the miner's restart note no longer hides the fault reason on the card.
tools/reliability: the harness matches the miner's stderr lines where they are printed there.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:22:16 +00:00
igneum-labs
ec843737c2 Merge origin/dev-fee into release-0.3.5
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
2026-10-04 21:48:04 +00:00
igneum-labs
5ccafcf4d2 Igneum Miner jobs: a collect job fails when its command exits non-zero (collect_done, unit test); collect-pc1-board3 had reported done (exit 0) over command exit Some(1)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:46:56 +00:00
igneum-labs
1028c2579f Miner dev fee: app switch and UI line, HiveOS package, Linux worker cross-build, docs and public text
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.

- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
  "dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
  miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
  with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
  stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
  proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
  docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
  miner section note

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:46:41 +00:00
igneum-labs
1867a4819b Merge origin/build-job into release-0.3.5
Conflict resolved: publish-jobs.sh keeps master's verify command and --tries (the retrying live check) alongside the
build kind's arguments; the usage range covers the merged header.
2026-10-04 21:32:48 +00:00
igneum-labs
ca2ac6dfa8 Merge origin/miner-perf into release-0.3.5
Conflicts resolved: state.rs keeps both the sweep fields (miner-eff) and the race fields (miner-perf); bench-log.md
keeps both appended entries; publish-manifest.sh keeps master's --override implementation (8082576, the "every
height switch" rule, --verify-only, --tries, the retrying live check) and adds miner-perf's --tuning / --no-tuning
with the carry-over of consensus.override and tuning from the current manifest. One --override case, one parser.
2026-10-04 21:31:26 +00:00
igneum-labs
e24516934a Merge remote-tracking branch 'origin/app-ui' into release-0.3.5
# Conflicts:
#	app/igneum-app/ui/app.css
2026-10-04 21:28:59 +00:00