Commit graph

391 commits

Author SHA1 Message Date
igneum-josh
d89acf095a release-0.3.6 plan: the DMG hash 2026-10-05 10:19:49 +01:00
igneum-josh
5b2856ef40 release-0.3.6 plan: PC 2 suite result (M30 pow-cache queue under full-suite parallelism), the two follow-up jobs, the DMG with the 0.3.5 prover 2026-10-05 10:19:14 +01:00
igneum-josh
a7e1181a8b release-0.3.6 plan: the PC 1 build failure (cargo mtime freshness over the persistent target dir), the fix, take 3, the PC 2 suites job 2026-10-05 10:13:59 +01:00
igneum-josh
021a7158d5 build job: the extract stage stamps every unpacked file (the PC's persistent target dir judged 0.3.6 sources unchanged since the 0.3.5 build and linked new callers against stale crates); the packer stamps too, this guard holds if it regresses 2026-10-05 10:12:27 +01:00
igneum-josh
c26d6bef72 build inputs: every staged file is stamped now before zipping (the PC's cargo cache judged 0.3.6 sources older than its 0.3.5 build)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit ea9794d8d1)
2026-10-05 10:12:07 +01:00
igneum-josh
822b53fc82 release-0.3.6 plan: section 8, the cut (merges, changes, tests, secrets, binaries, digest, live manifest) 2026-10-05 09:53:28 +01:00
igneum-josh
a98be3583b push-build-inputs: the live sha256 check retries for a minute (the edge served the previous file right after the deploy; the 0.3.6 build job failed here on 5 October 2026) 2026-10-05 09:50:53 +01:00
igneum-josh
7d7570a5ef Igneum Miner 0.3.6: instant jobs, a proof verifier on every node, one notice strip, lower miner latency, packaged configuration, hidden helper windows, WSL scripts from files; node 2b6d23ef: testnet identity and fee table behind a height switch, signed build inputs 2026-10-05 09:48:57 +01:00
igneum-josh
3811d8edc6 app: every WSL script runs from a file, never inline on the command line (src/wslhost.rs: write_script, bash_line, command)
5 October 2026, PC 2 on 0.3.5: the prover probe's inline script (double quotes, a path with a space) reached bash
mangled and the app said proving needed the WSL2 setup while /opt/igneum held the host. Now the probe, run_tool, the
setup launch, igneum-prove-verify (probe and run; the wslpath round trip dropped) and jobrun's six inline scripts
write a UTF-8, LF, no-BOM file under %LOCALAPPDATA%\igneum\wsl and run wsl -d <distro> -- bash [-l] '<file>' '<arg>'...
with every word single-quoted, placed raw on the command line; arguments reach the script as $1, $2. Unit tests pin
that the line never carries a double quote or a newline and that the file has LF endings and no BOM.
2026-10-05 09:47:40 +01:00
igneum-josh
954154306f app: every process the engine starts on Windows is hidden (platform::quiet on the window host, icacls, reg, the setup's cmd; igneum-prove-verify is a windows-subsystem exe, the node starts it with no console of its own)
The four helpers (detect::run_timeout, jobrun::run_capture, jobrun::run_streamed, procs::spawn) already set
CREATE_NO_WINDOW; the direct .output()/.spawn() sites did not. 5 October 2026: a console window on both PCs.
2026-10-05 09:39:49 +01:00
igneum-josh
50920da7b6 Merge rotation-2 (5317305) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 09:33:37 +01:00
igneum-josh
ada90aa768 Merge proving-app (010a372) into release-0.3.6: verifier env for the node, igneum-prove-verify.exe wrapper, WSL probe through wslhost (hidden, as master 31c1b34), tile shows the verifier 2026-10-05 09:33:13 +01:00
igneum-josh
356b3e60d0 Merge app-ui (ce31cbb) into release-0.3.6: one notice strip under the header; CI runs both the wake and the notice tests 2026-10-05 09:32:52 +01:00
igneum-josh
c9bc6d4b85 Merge origin/testnet-adopt (09baf8e) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 09:32:40 +01:00
igneum-josh
31c1b34fe7 app: the prover's WSL probe runs hidden (it opened a console window on PC 2 once a minute)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:30:00 +01:00
igneum-josh
dccdabdedb app: the job relaunch helper starts with CREATE_NO_WINDOW only (DETACHED_PROCESS exits powershell without a console, the OTA stall class)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:28:19 +01:00
igneum-josh
73fff4fe3f Merge job-wake: instant job wake-up (relay /wake long-poll, 2-minute fallback poll, publisher wake)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:26:07 +01:00
igneum-josh
7481bcbc96 app jobs: wake long-poll on the relay, fetch within seconds of a publish; safety-net poll 2 minutes (was 10)
Josh, 5 October 2026: "why is it taking so long for pc2 and pc1s tasks to spin up?". The PCs have no inbound ports
and one miner is off the LAN, so one thread per app now long-polls the relay's public /wake with the last stamp
(GET <url>?since=<stamp>, held up to 45 s there). A changed stamp sends Event::Wake and the engine fetches the jobs
file at once (signature check unchanged); a wake during a fetch in flight fetches again right after it. The first
reply only seeds the stamp. Backoff 5, 15, then 60 s while the relay is unreachable, a 10 s floor between requests,
a full hold when the relay has no stamp yet: never a busy loop. One log line per wake, one when it falls back, one
on recovery. IGNEUM_APP_JOBS_WAKE_URL overrides the URL (set and empty: no waker).

CHECK_EVERY_S 600 -> 120: the poll is the fallback now; the first poll stays 40 to 60 s after start. An unchanged
file is no longer logged on every poll. Remote jobs off stops the waker too.

Unit tests: the stamp logic (seed, same, changed, empty), the backoff sequence and the recovery flag, the floor,
the URL and query. cargo test -p igneum-app: 60 + 22 pass; cargo build --release -p igneum-app: finished.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:25:29 +01:00
igneum-josh
7a174ecdfb relay: the packaged intake key reports too (build job uploads got 'no token' after the key split)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:24:31 +01:00
igneum-josh
3da3c88184 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:22:02 +01:00
igneum-josh
5ee7909d5c relay: /wake long-poll for the apps' remote jobs (public GET held 45 s, authenticated POST of the stamp)
GET /wake?since=<stamp> is public (the apps hold no token) and rate limited (30 a minute per IP). It holds up to
45 s, re-reading the stamp every 2 s, and answers {stamp, at, added, changed, held_ms} the moment the stored stamp
differs from since, else the unchanged stamp at the deadline. POST /r/<token>/wake {stamp, added} (the relay's
auth, also x-relay-token or x-igneum-key on /wake) records a stamp; one row per stamp in relay_wake, created by the
first POST. maxDuration 60 s for api/wake.mjs in vercel.json. api/relay.mjs is untouched.

The handler lives in lib/wake.mjs with its dependencies injected; relay/test/wake.test.mjs drives it with a fake
database, a fake clock and a fake sleep (the hold, the change, the deadline, the rate limit, the hold cap, auth, a
database error). CI's site job runs it with the other relay tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:22:02 +01:00
igneum-josh
010a372f44 docs: release 0.3.6 done notes for the app-side proving items
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:13 +01:00
igneum-josh
063a9e7573 app: the node gets a proof verifier, the WSL2 probe checks both layouts, the tile shows the verifier state (0.3.6 items 1 to 3)
Spec 7.7 item 4: a node without a verifier relays proof records and never includes them. On 5 October no app node ran one.

1. src/verifier.rs decides once per node start and engine.rs passes it to the igneumd spawn. macOS and Linux: igneum-prove-host
   next to the engine's binaries. Windows: the new igneum-prove-verify.exe (src/bin/prove-verify.rs, a bin target of this crate,
   shipped by make-payload.sh) is set only when its --probe finds a host inside WSL2; it rewrites --proof with wslpath -a,
   runs the host in the order of src/wslhost.rs and returns its exit code, 2 when there is no host. Trust mode is never the
   default: the setting proof_verify_trust (Settings, "devnet only") sets IGNEUM_PROOF_VERIFY=trust only when no verifier was
   found; changing it restarts the node. After the WSL2 setup runs, the prover thread asks for one node restart.
2. The prover's WSL2 probe looks at the payload's wsl2/bin, ~/igneum-prove/proving/igneum-prove/target/release (what
   setup-wsl.sh builds), ~/igneum-prove/target/release and /opt/igneum, in that order (one list in src/wslhost.rs, shared
   with the wrapper); the tile's message names every path it looked at.
3. The prover thread reads igneum_getProvingStatus().verifier every 30 s, proving on or off; /api/state carries
   proving.verifier, verifier_mode, verifier_set, verifier_reason, verifier_note and the pool counts; the tile has a
   verifier row and says when this node relays proofs but does not verify them.

Tests: cargo test -p igneum-app, 89 passed. The wrapper cross-compiles with --target x86_64-pc-windows-gnu on the Mac.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:13 +01:00
igneum-josh
09baf8e15d release-0.3.6 plan: the fork results, miner-latency in after its three gates, the release dev-fee address
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:21:00 +01:00
igneum-josh
ecc286de96 lock: build slots open to new builds come from ~/.config/igneum/build-slots (1 to 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:19:52 +01:00
igneum-josh
ce31cbbe84 Miner app UI: one notice strip under the header replaces the three stacked banners (updates, jobs, clock)
One notice at a time, the most important first (app/igneum-app/ui/app.js, Notices; pure, unit tested):
  0 update installing, urgent or failed   1 job failed   2 clock   3 job running
  4 update available, downloading, ready, waiting for permission, manual   5 job done   6 updated
Lower notices wait their turn. Every notice has a close control; closing hides that notice's key until the
state moves on (a new status, version or job id).

States and their rules:
  update available      "Igneum Miner X is available." Install now, Later. Key update:X:pending.
  update downloading    "Downloading Igneum Miner X: 43%." (no percent when unknown), progress bar; same key as
                        available and checking, so Later hides the whole download until it is ready.
  update checking       "Checking Igneum Miner X." (the engine's staging step).
  update ready          "Igneum Miner X is ready. It installs by itself at a quiet moment." (auto on) or just
                        "... is ready." Install now, Later. Key update:X:ready.
  update waiting        Windows, nobody answered the administrator prompt: "... is waiting for permission. It
                        installs the next time someone is at this PC. Mining continues."
  update manual         "... is downloaded. Open it and drag the app over the old one." Open the download.
  update installing     "Installing Igneum Miner X. The app restarts itself. Mining continues until then."
                        (on a Mac, where the engine quits at once: "The app restarts itself in a moment.")
                        Also while the engine says "installing now" after Install now.
  update urgent         the engine's consensus-deadline text, ember, downloading percent when it downloads.
  update failed         "The update to X failed." plus one line of cause and Try again; rolled back:
                        "Igneum Miner X did not stay up and was rolled back." A dev build with no manifest
                        configured shows nothing (Settings still says it).
  updated               "Updated to Igneum Miner X from Y." Gone 60 s after the new version started.
  job running           "Job: <title> running, N min. <Stage>." with the last RESULT line underneath.
  job done              "Job: <title> done after N min. Report uploaded." Gone after 5 minutes.
  job failed            "Job: <title> failed after N min, exit C. Report not uploaded." plus the first error
                        line (BUILD FAILED / error / failed / panic among the result lines, else the summary).
                        Stays until closed. Timeout and aborted are "hit its time cap" and "was stopped".
  clock                 as before: the engine's words, Sync clock, the manual hint; on the setup screens only
                        (the node card carries it on the dashboard). Jobs show on the dashboard only.

Layout: the strip reserves no height while empty; when a notice appears or goes, main's top moves once with a
150 ms transition (none under prefers-reduced-motion). Existing tokens only, nothing newer than 2022 CSS.
Screenshots: ?update=<state> as before, ?job=running|done|failed added (packaging/ota/README.md).

Test: node --test app/igneum-app/ui/notices.test.mjs (ordering, dismissed keys, wording, the 5-minute and
60-second timers); added to the CI site job. Built once with cargo (include_str) and checked against the
ui-mock scenarios and a scratch engine instance (IGNEUM_APP_DATA in a temp dir, fake worker).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:16:29 +01:00
igneum-josh
ae9e326134 build inputs: ship igneum-pow beside the zip root and the coin image the engine embeds
The first PC build (job build-20261005-075300) failed in 52 s: the node's crates depend on ../../../../igneum-pow,
which the zip did not carry, and the engine embeds brand/igneum-coin-1024.png, which the staged brand/ lacked.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:01:17 +01:00
igneum-josh
21e896373d site: Igneum Wallet on the home page (section, buttons, nav link on every page)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:54:01 +01:00
igneum-josh
1d382db113 app ui: a finished job's banner stays 5 minutes when it succeeded, 30 when it failed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:50:57 +01:00
igneum-josh
3763da77c4 docs: release 0.3.6 plan from the proving activation (verifier gap, payload, lessons)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:45:45 +01:00
igneum-josh
4aaff887bb Merge origin/testnet-prep (beed743) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:44:22 +01:00
igneum-josh
53173057f7 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-josh
c8b7852efd Ledger: merge conflict markers removed, both sides kept 2026-10-05 08:25:45 +01:00
igneum-josh
eabeed7bd7 Site: rebuilt after the E15 and ledger-sweep merge 2026-10-05 08:25:30 +01:00
igneum-josh
236fd47800 E15 decided: the 4 billion cap stays, no tail emission; spec 5.10 with the measured security-budget table and the review trigger, O-5.11 closed, litepaper and homepage state the cap and the years
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:24:38 +01:00
igneum-josh
2054ae3a2a Igneum Miner 0.3.5: Pruning proofs on the lottery hash (M20), memory fix (M30), coinbase limit on every network (M31), chain-decided equivocation bans (F23), re-determination after reorgs (F24), params digest in the handshake (G12, X18), miner fee 1% switchable, efficiency sweep, variant racing, reliability watchdog, log panel and screens, PC build job, Windows updater launch fix 2026-10-05 07:33:18 +01:00
igneum-josh
a130c6361f release-0.3.5 plan: the final fork suites and totals filled in
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 04:16:42 +01:00
igneum-josh
e68ac6bbdb release-0.3.5 plan: final round from fork 20139145, every suite green, header and digest confirmed
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 04:16:14 +01:00
igneum-josh
8e8b739bc0 release-0.3.5 plan: fud-consensus fork results, the scratch run, m20-pruning merged (final-round hashes to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:43:56 +01:00
igneum-josh
5695424e6b release-0.3.5 plan: fud-consensus on both repos (fork results to follow)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:21:12 +01:00
igneum-josh
7abce72165 Merge origin/fud-consensus into release-0.3.5
bench-log.md: both appended entries kept (the round-4 consensus items and the red team next to the branch's own).
2026-10-05 03:19:41 +01:00
igneum-josh
0420c887e2 Round-4 consensus items: final runs on 977db931 (reorg-final2, the red team's f23 / f24b / f24c), the M31 and un-determination entries, result files
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 03:17:49 +01:00
igneum-josh
6332f7aa92 Ledger F23, F24, G12, X18, M30, M31, F25 to 'Fix built, pending rollout' with the measured runs; bench-log entry for the round-4 consensus items; red team branch merged
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:57:24 +01:00
igneum-josh
eee7030321 Merge branch 'fud-memory' into fud-consensus 2026-10-05 02:56:28 +01:00
igneum-josh
afb2ce38d5 Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:49:46 +01:00
igneum-josh
2ca10df22d Merge branch 'redteam' into fud-consensus
# Conflicts:
#	docs/fud-ledger.md
2026-10-05 02:34:21 +01:00
igneum-josh
815c659b0b fud.mjs: node logs kept per scenario, pre-F24 refusal wording counted, reorg criterion as the rule promises; first-pass and control results kept
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:34:04 +01:00
igneum-josh
ca813aa372 FUD ledger sweep, round 5: s5 and s4 on the finality-fixes build (F1 burster locks nothing alone, F3 vote-dropping adds 0 ms), F2 floor note, final counts
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:17:45 +00:00
igneum-josh
9a3583461a release-0.3.5 plan: master merged once more
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 02:14:24 +01:00
igneum-josh
619cf30690 Merge remote-tracking branch 'origin/master' into release-0.3.5 2026-10-05 02:14:23 +01:00