the project lead's 6 October 2026 ask: deep backward and forward research across the hash, finality,
economy, network and every shipped surface. This commit carries the first three lanes.
- docs/analysis/horizon/algorithm.md: the chip model on the 6 October numbers (f = 1 GDDR7
chip 5.7x per joule against the 5090 at class v3, 2.1x at class v4 with k = 1), the FPGA
lane tightened to 0.30x to 0.47x per watt, the reserve R0 to R8, the reconciled shadow-N
ladder (section 5.3a) with HBM4 and three verifier brackets, the first measured verifier
proxy on igneum-build-1 (class v4 5.06 ms cold, dr736 10.51: out), the dataset schedule
to 2030; model sim/horizon/algorithm/model.py.
- docs/analysis/horizon/frontier.md: sixteen ideas ranked by payoff over difficulty with the
Monero and Kaspa attacks, prior art cited, the honest never column; model
sim/horizon/frontier/frontier_model.py.
- docs/analysis/horizon/new-pow.md sections 0 to 4: three new proof-of-work schemes defined,
reviewed in two personas, scheme A (mining is proving) ruled out on bytes and
sampleability, B and C in prototype on two rented 4090s; measured rows follow.
- docs/analysis/horizon-2026-10.md: the summary skeleton and the lane table.
Every rental cost cites docs/bench-log.md "Rental cost of hash, 6 October 2026".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The rebase onto e69117a kept master's captions and build scrub and this branch's wheel handler, chip and note. The build
re-inlined the journey feed from master's journey.json. A code comment in site/live-dag.js named the owner; master's
identity grep now covers every served file and caught it, so the comment says the owner.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026: the miners table and the events feed were too long for the story. The miners card is now a strip:
the count ("66 vote keys in 10 min"), the top five lanes by blocks with a bar each and the last-seen time, and "and N more"
with the bench table linked. The events card shows the last five, one line each, with the count of the rest in the note.
Two columns from 900 px. Measured headless: at 1440 both cards end at 1.9 screens (the scene fills the first); at 390 the
miners card ends at 2.5 screens and events at 2.95; no horizontal overflow, no console errors. Captures replaced in
docs/plans/site-ui-3-shots/after/live-1440-dark.jpg and live-390-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 6 October 2026: scrolling past the DAG zoomed it. The module's wheel listener took every vertical wheel. Now a plain wheel
or a trackpad's two-finger scroll is never captured: the handler returns before preventDefault unless ctrl or cmd is held or
the scene is engaged. A click into the scene engages it (the canvas takes an ember outline and a chip reads "scroll to zoom,
Esc to release"); Escape, a click outside the scene or the chip releases it. Pinch zoom is unchanged. Same module on / and
/live; both pages carry the chip and the note says how to zoom. opts.chip and opts.onEngage are new, optional; dag.engage(bool)
is exposed.
Proved headless on both pages: a plain wheel over the scene scrolled the page 300 px and left the window at 120 s; engaged, a
wheel zoomed the window from 120 to 138 s with the default prevented; the chip showed on click and hid on Escape; no console
errors. Link check 884 links 0 broken.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copy, from origin/master 0a63474 (site audit). The home and miner pages named "PC 1" in the figure captions, the
page-by-page lead, two alt texts, the Ember Tune table title, the Ember row's source line and the home pill; they now
say "a Windows rig with an RTX 5090, RTX 4070 and RX 9070 XT" at the first mention on each page and "the Windows rig"
after. The generated pages carried the same names from the bench-log (80 on /bench, 7 on /evidence, the inlined
journey on the home page): site/scrub.mjs now maps PC 1 to "the three-card Windows rig (RTX 5090, RTX 4070, RX 9070
XT)" and PC 2 to "the RTX 5090 Windows rig", build.mjs re-scrubs the stored journey entries, two /bench anchors on the
miner page follow the renamed headings, and \bPC [12]\b joins site/forbidden-strings.txt so the build fails if a number
returns. The scrub also covers the audit's other page-leak shapes (a pid, 0.0.0.0:port, ~/.config paths, --rpclisten=),
which the bench page carried and which now fail the build if they return.
CI: tools/ci/forbidden-strings.txt's appended audit block sat on one physical line with literal \n text, so none of its
patterns was active; \bPC [12]\b is now a real line there and the identity check's export scrub maps the two machines
the same way (igneum-public/tools/sync.sh must carry the same two rules). The other four audit patterns moved to
site/forbidden-strings.txt, since the public export carries simulator schedule logs where a pid is a pid. The identity
check gains a second pass over every served file under site/ (html, json, txt, xml, webmanifest, css, js; not api/ or
the build scripts), unscrubbed, with both pattern lists; dl\.igneum is narrowed to the tokened path so the public
download buttons pass. Shown to fire on a page naming PC 1 (exit 1) and to pass on the tree (0 hits over 232 export
files and 32 served site files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- provision.sh step_runner: actions/runner 2.338.0 (sha256 checked) at /opt/actions-runner under a dedicated user `runner`
(no sudo, not in build's group), rustup 1.99.0 pinned with both targets, sccache against /srv/sccache in READ_ONLY mode
on its own server port, Node 22 and mingw from the system, GitHub's svc.sh unit with a Nice 10 drop-in; registered on
igneum-network/igneum as igneum-build-1 (labels self-hosted, linux, x64, igneum-build-1) through
infra/build-server/runner/register.sh (gh as igneum-labs, the token on ssh stdin, never logged). Idempotent after
the env files moved behind svc.sh install (its env.sh rewrites them). libicu74 and python3-numpy added to APT.
- main's slots ruling: SLOTS default 2; remote-run.sh sets CARGO_BUILD_JOBS 90 when it holds the only taken slot and 45
when both are held, BR_MEASURE=1 takes the `measure` file exclusively and excludes builds (builds hold it shared),
lock files open in append mode (the old `exec {fd}>` truncated a busy slot's holder line on every probe), env
IGNEUM_BUILD_SLOTS_DIR and IGNEUM_BUILD_LOG_DIR win over the profile, `--self-test-slots` with five cases (the old
script fails it with JOBS=none); build-remote.sh and cross-remote.sh pass -j only when --jobs is given.
- infra/build-server/prover/cpu-trial.sh: the SP1 CPU prover on one fixture shard under the measure hold with a VmHWM
poller; 6 Oct 2026 run: core 34.2 s, compressed 85.9 s, peak RSS 28.2 GB on 96 threads, so no standing CPU prover.
- docs/plans/ci-self-hosted.md: the proposed runs-on change for ci.yml behind the repository variable IGNEUM_CI_RUNNER
(GitHub-hosted is the fallback), and why windows.yml cannot move to a Linux box. Workflows untouched.
- docs/plans/build-server.md section 7.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Rebased onto origin/master. Resolved: site/miner.html and site/miners.html taken whole from master (the site-miner copy,
the PC 1 images, the 42-character h1, lever 4 dated, the ember-tune "Measured by the team" row) and re-dressed in the shared
chrome by the build; site/build.mjs is master's (the shipper's downloads rule: the snapshot is written only on
SITE_DOWNLOADS_REFRESH=1, --refresh-downloads or CI; the priors team rows) plus the generated-page template on site.css and
the per-page eyebrow; site/index.html is the one-screen page with master's content ported in: the hero's proving sentence
(today's app on 24 GB, the 6 October rented-card measurement with its log link, "ships when the packaging row lands"), the
mine lead, the "Four pages" and "Ember Tune, measured" rows, the PC 1 figure and caption. The ledger generator's section
heading balances its lines and sits at 20 to 28 px so "Launch and operations" no longer leaves a word alone at 390 px.
Checks on this tree: identity grep 0 hits over 232 files, link check 884 links 0 broken, ledger text 43 of 43, contrast
32 pairs 0 under 4.5:1, orphan check 0 site headings (14 log titles reported), ledger page 0 leaks. Proof captures at 1440
dark: docs/plans/site-ui-3-shots/after/index-1440-dark.jpg and miner-1440-dark.jpg.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/site.css: the tokens of the miner app's third redesign in light and dark (a darker light-mode ember and molten for text
so every pair passes 4.5:1, checked by tools/ci/site-contrast-check.mjs), the type scale on Unbounded, Plex Sans and Plex
Mono, the nav with one primary, the footer with a System/Light/Dark control, cards, tiles, tables that scroll on a phone,
buttons, pills, notes, callouts, the state words, focus rings, reduced motion, print. Partials rebuilt; the head loads the
stylesheet and applies the stored theme before paint. Every page's own style block is reduced to its page rules.
site/live-dag.js: the shared DAG view for / and /live (docs/plans/site-ui-3.md section 6): blocks by header time and
miner lane, parent edges with the selected chain as one heavier path, blue lit, red dim, pending grey, proven filled,
checkpoint bands with their lock weight (locked solid, pending dashed), new blocks arriving with a glow, hover and tap
details in the ledger's words, wheel and pinch zoom of the window (30 to 300 s), a pause button, device-pixel sharpness,
a still frame under reduced motion; opts.mine marks the user's own blocks (the miner app embeds the same file),
opts.poll:false with dag.push(reply) lets a host feed it. Every pixel is a block the observer stored.
site/index.html: the one-screen story (what it is, the live scene with chain block, shards proven, last lock, vote keys and
hash rate as state words, three things a sceptic checks, the download, how it works, the wallet, the journey, economics),
every tick-list row kept, the chip model's numbers moved to the sceptic card, the testnet terms behind a chevron, the
scroll-reveal gone, the Open Graph set on the 1200 by 630 image, no horizontal overflow at 390.
site/litepaper.html: dark like the site with light on request, whole paper by default (the section mode kept, deep links
intact, print prints the paper), repository paths off the surface, the cover dated 6 October, the wallet at 0.1.4, the
roadmap's verifier figure aligned with the Mining section, the proof lag stated as measured (about 380 s against the 60 s
gate), the 0.3.6 plan dated with 0.3.14 stated, the two "tonight" placeholders said as not yet measured. Every ledger
sentence verbatim (tools/ci/ledger-text-check.mjs, 43 sentences).
site/live.html: the lane chart replaced by the module; "proven A/B in 10 min", "finality paused, last #N", "pending" for
"n/a"; the fee sentence true on both sides of DAA 210,000. site/metamask.html: its own canonical, the explorer linked, the
wallet's state said true. site/404.html: the page count and section count said true. site/build.mjs: the generated pages
on the system, each with its own eyebrow, the miners page's source notes as sentences. downloads.json refreshed from the
host (0.3.14). tools/ci/site-orphan-check.mjs: no site heading leaves one word alone at 390 px (log titles reported).
Checks: identity grep 0 hits, link check 854 links 0 broken, ledger text 43 of 43, contrast 32 pairs 0 under 4.5:1,
no horizontal overflow at 390 on 14 pages (the wallet page's timed table overflows by 5 px, for the wallet-ui-3 owner),
orphan check 0 site headings (the miner h1 at 96 characters is the site-miner agent's copy). After captures beside the
audit's: docs/plans/site-ui-3-shots/after/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/site-ui-3-audit.md: the project lead's ask of 6 October 2026 ("run the website and all pages and litepaper through the same
apple lens as the miner app", "leave no stone unturned") against the miner-ui-3 standard. Method, screen by screen with the
10-point scale (home 6, litepaper 5, live 6, miner 5, wallet 6, miners 5, explorer 7, block and address 6, faucet 7,
metamask 6, 404 6, bench 5, evidence 6, ledger 5), links and downloads (914 attributes followed, four installers hashed
against the host), the live elements' loading, failed and stale states, contrast of every token pair in both themes,
keyboard focus, phone width, the litepaper's print, the top ten findings, and appendix B listing the stones turned.
docs/plans/site-ui-3-ticklist.md (appendix A): 502 rows across 17 inventories, every claim, number, date, link and
feature with its source and today's verdict (MATCH, STALE, UNSOURCED, APPROX), the ledger's stated sentences and their
presence, the thirteen "does not claim" sentences verbatim, the scrub rules.
docs/plans/site-ui-3.md: the design: one stylesheet (tokens light and dark, type on Unbounded, Plex Sans and Plex Mono,
the card and table rules, state words, nav, footer), the home page as one screen, the litepaper as a readable paper
with a sticky section nav and the whole paper by default, per-page notes, and the live DAG module brief (the project lead's "can this
look more advanced and cool?").
docs/plans/site-ui-3-shots/before/ and before-states/: every page at 1440 and 390, dark and light, the failed-fetch and
stale-observer captures, the litepaper print PDFs, the focus captures; headless Chromium (Playwright's build, never
Chrome.app), one browser at a time, niced.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copy only, from origin/master c077caa (the fleet's record: docs/analysis/prover-tiers-real-cards.md and the bench-log
entry "Prover tiers on real cards"). The miner hero lead, the proving feat and the homepage lead each carry two
sentences: today's app with the stock SP1 server (a 24 GB NVIDIA card proves the full shard, RTX 4090 5.6 s and
RTX A5000 6.4 s; a 32 GB card mines and proves, RTX 5090 8.4 s; the stock server refuses 16 GB and under), and the
6 October 2026 measurement on eleven rented cards with the patched server (every NVIDIA card from 8 GB proves; 10 GB
and up mine and prove), linked to the bench-log entry and marked "ships when the packaging row lands".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Audit fixes, copy only. (1) "every NVIDIA card from 8 GB proves" cited docs/analysis/prover-tiers-real-cards.md, which
is not in the repository, and contradicted evidence row 16; the hero lead, the proving feat, the three meta descriptions
and the homepage lead and h2 now say what row 16 and docs/analysis/amd-proving.md state: measured on an RTX 5090 with the
shipped SP1 server (13.9 GB floor), a 32 GB card mines and proves, a 24 GB card proves the full shard alone (from the
5090's allocation, not yet run on a 24 GB card), 16 GB empty shards only, 12 GB and under nothing on this build; the
eleven rented cards of 6 October are "measured, record pending". Each links /evidence#claims. (2) The h1 was 96
characters and seven lines on a phone; it is "Install. Start. The card mines and proves." (42) with the tiers in the lead.
(3) Lever row 4 said "Ships in 0.3.6" at 0.3.14; it now says shipped in 0.3.6 (the miner-latency merge, release-0.3.6.md
section 2), the app at 0.3.14.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
provision.sh step_cuda: NVIDIA's ubuntu2404 apt repository, cuda-nvrtc-dev-12-8, cuda-cudart-dev-12-8, cuda-driver-dev-12-8
(the libcuda stub) and opencl-c-headers; no nvcc (no build file calls it), no driver. tools/workers-remote.sh builds
igneum-worker-cuda and igneum-worker-opencl on the box from proto-cuda and proto-opencl with clang++ (static libstdc++),
prints sha256 and the glibc ceiling (2.38: fine for Ubuntu 24.04 hosts, not for 22.04 containers or HiveOS, where the Mac's
zig build stays). Proof: igneum-worker-cuda 1,613,992 B sha256 6db8a9ad..., igneum-worker-opencl 124,904 B sha256 0dea75bb...
remote-run.sh evaluates the command string in a subshell (a leaked set -e killed the runner after a successful build).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The public /ledger page (site/ledger.html) carried ~/.config/igneum paths five times, "pid 33114", --rpclisten=0.0.0.0:26610,
"PC 2" fifteen times, "the Mac" nineteen times and 202 repository file paths, because tools/ledger-page.mjs scrubbed with its
own short list and never ran the forbidden-strings hard stop (found by the site audit of 6 October 2026, docs/plans/site-ui-3-audit.md).
Now: the generator's scrub replaces every config or home-directory path with "a config file" or "a home-directory file", a pid with
"the process", a listen flag or 0.0.0.0 address with its plain words, "PC 1" and "PC 2" with "the Windows machine", "the Mac" with
"the Apple M5 Max" (the bench log's rule), and every repository file path with "a repository file"; the page's own source note
names no path. After rendering, the page is grepped with tools/ci/forbidden-strings.txt plus the leak classes and the render
exits 1 on a hit. The pattern list gains ~/.config, pid N, 0.0.0.0:port, PC 1 and PC 2 and --rpclisten=, and the identity grep
now covers site/ledger.html (html added to its file types). Regenerated: 167 entries, 0 leaks, identity grep 0 hits over 231
files, link check 0 broken.
Consequence per reader: the ledger keeps every criticism, status and answer; what a reader loses is the exact repository path
of a fix, which meant nothing outside the private repository. Nothing else on the site changes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Main's ruling (6 October 2026, 20:1x UK): the box installs with the NUMBERS key alone so the 21:00 UK pulse comes from
it. install.sh accepts at least one key and names the missing ones; every tick's log line ends with "missing <keys>"; the
watcher without an incidents webhook logs its open or resolve and still advances its state, so the key landing later
does not flood the channel. Test added (31 passing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/community/discord-hooks.mjs (Node 22, standard library): one ember embed per post to #numbers, #announcements and
#incidents. Network pulse every 6 h (03/09/15/21 UK) from /api/stats, /api/live, /api/supply with the 6 h window from its
own snapshot and a Devnet 2 line that uses the fleet file's numbers and gate word only; a 24 h digest and the reddit kit's
weekly template at 09:00 UK; a release subcommand for the shipper (three downloads with sha256, node commit, digest, up to
five plain "what changed" lines read from the release plan); incident open and resolve by hand; a watcher that opens one
incident per condition (finality paused 5 min, median proof lag 15 min, observer silent 3 min) and resolves after 2 clear
minutes, and never opens on a condition already firing when it first looks (the pulse says "finality paused since" instead).
Guards before every post: the founder's name and logins, hosts, machine ids, paths, IP addresses, standalone 32-hex
tokens, dl.igneum.network outside /public/, webhook URLs, mentions, the tools/ci/forbidden-strings.txt patterns; Discord's
limits refused rather than cut; idempotency keys per slot in a state file; exponential backoff on 429; dry run by default
with a Discord-like preview in tools/community/out/preview.html. 30 tests on fixtures cut from the live API.
infra/build-server/discord-hooks: a tick every minute on igneum-build-1 (the Mac sleeps). install.sh copies the webhook file
to /srv/discord-hooks/env (mode 600, over ssh stdin) and refuses without IGNEUM_SECRET_ON_BOX_OK=1; the recorded exception
to rule R6 is in docs/plans/build-server.md (main's ruling, 6 October 2026).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's decision of 6 October 2026: the Mac runs nothing the network depends on. docs/plans/hands-on-build-1.md plans node 1
and the observer (its node and tools/observer) as systemd units on the box, one hand at a time, with ports, DNS names,
exec recovery, rollback and the decisions for main; infra/build-server/hands/install-hands.sh writes users, dirs, run
scripts and units (inert, run on the box); move-hand.sh (dry run by default) builds 0.3.15 on the box, copies the override
and snapshot, rsyncs each data dir hot then stopped, starts the unit and prints the hand's first executing line, copies the
observer env by scp (mode 600), stops the Mac's observer first, unloads the launchd agents last. CLAUDE.md's running-agents
rule carries the decision. lib.sh: a per-worktree lock on the box across sync, build and fetch (the shipper's collision at
18:48:56Z). remote-run.sh: the clean-tree test excuses stamps and target dirs at any depth with --untracked-files=all (a
nested stamp failed every checkout of /srv/builds/igneum for twenty minutes) and removes a stale .git/index.lock; the
self-test covers both. Plan rows for the three and the cuda prover pair built for the shipper.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The second build of every repo-kind crate in a subdirectory failed (6 October 2026, 18:51 UTC, the pool build: "tree not
clean after reset: ?? pool/.build-remote-sha-target"): checkout_tree keeps the stamps with `git clean -e` at any depth but
its status check matched them at the root only. The check now reads `git status --porcelain --untracked-files=all` (an
all-untracked directory is listed file by file, not as "?? sub/") and accepts target dirs, sccache and both stamps under
any path. The self-test carries the subdirectory case (stamp and target dir kept, overlay file removed) and the known-failed
case (a stray untracked file still fails the check).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fleet's 10-member load run (6 October 2026, 18:14Z to 18:24Z) accepted 0 shares: the pool fork's miner re-checked GPU
shares with a fixed class v2 program while the 0.3.14 workers hashed class v3 (docs/plans/pool.md section 9).
pool: node.rs builds the share verifier's seeds from the template's pow_epoch with the class and the era, installs the
node's genesis day, dataset size and class v3 activation beside the schedule, and sends program_class, next_program_class,
era_seed, era_index, genesis_day_index, genesis_dataset_log2 and program_class_v3_activation_daa in `seeds` and
program_class and era_seed in `job` (protocol.rs, additive fields); verify.rs tests through EpochSeeds::v2. Protocol,
vardiff, PPLNS, stats API and page otherwise unchanged. Suite 22 of 22 on igneum-build-1.
igneum-pow tests/recheck.rs: for class v3 (packs-ca2-mixer/mx8-devnet-epoch0) and class v4 (packs-ca3-v4/v4-devnet-epoch0)
the pack's program reproduces the pack's 96 vectors (the worker's reference), the chain seam the node engine calls
(Epoch::chain_program, chain_dataset_day) builds the same program, one known nonce hashes equal through both paths, and
the fixed-v2 program of the same seed disagrees; the pinned v3 and v4 program ids differ. 2 of 2 on igneum-build-1.
packaging/hive: the pool:// mode merged with master's per-card IDENTITIES=auto and OVERRIDE handling (selftest passes).
pool/README.md and pool.md: building on igneum-build-1 (the vendor/igneum-node symlink on the box).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proving/igneum-prove depends on vendor/igneum-node-exec/igneum/evm-types, a member of the fork's workspace that inherits
from the fork's root manifest; syncing that one directory left cargo without a workspace root on the box. lib.sh now groups
path dependencies by git top level: a repository under vendor/ is pushed to its mirror (a fork worktree to
/srv/igneum-node.git, a repository of its own to /srv/<name>.git, created on first use), checked out whole at
/srv/builds/<worktree>/vendor/<name> and overlaid whole; run-from-mac.sh wires every vendor repository the Cargo.toml files
reach. libprotobuf-dev added (sp1-prover-types imports google/protobuf/empty.proto). build-remote.sh no longer fails on a
default artefact the caller's own -p selection did not build. Proof on the box: igneum-prove-host 71,943,192 B, sha256
e9213e3a6c979512d7859f6d8e848105bab53f4355e99fb0d30fb4a72c2d5714, 1 min 05 s warm. Plan: gotcha rows for the case, the
protoc miss and one lost ssh session (collector cleared by test).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Mine, Earnings and Settings on igneum.network/miner are now the installed 0.3.14 app on PC 1 (RTX 5090 at 122 MH/s,
222 W, 0.55 MH/W, 56 C; RTX 4070 at 28.7 MH/s, 76 W; RX 9070 XT at 18.9 MH/s, 198 W; 169 MH/s at 532 W; Ember Tune
and Power control on), shot read only by the signed run job site-capture-pc1-1 with Edge headless and brought back
over the relay. Masked in pixels: the job's own strip cut out of the content column, the rail foot and the Settings
name field (hostname, address) painted over, the Earnings address box painted over. Captions say PC 1, the time, that
no electricity price is set and that the tune lines are stopped tunes from before that afternoon's Power Helper fix.
Prove, light and the phone width stay the Mac's (PC 1's Prove shows an exporter error line that belongs in a bug
report; headless Edge followed the Windows theme so its light set is dark; its 390 px window clipped the right edge).
The contact sheet is refreshed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
On 6 October 2026 the pre-push hook's site build fetched the live downloads index (0.3.14 since 17:47Z) and rewrote site/downloads.json and the stamped pages in five worktrees that had nothing to do with the release, as uncommitted edits to tracked files. A plain build and the hook now read live and warn when the snapshot lags; the ship step refreshes it with the flag and commits it. tools/ci/no-foreign-tree-writes.sh fails a script that builds a path from a worktree name, a glob over Projects or a worktree-list loop that writes; the eight absolute defaults into the shared checkout are listed as warnings until they move to env-only defaults. The journey, bench and index rebuilt from the merged tree.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The node pin moves to 4c6b129d (release-0.3.14-node), which is what the live payload inputs carry, so windows-ci's payload-inputs step is green again (red since e9eca23 on master's 0.3.13 pin against the 0.3.14 inputs).
Conflicts: infra/fast-time/override-60x.json keeps master's side (the fresh-rule field was already there at u64::MAX; the release line would be a duplicate key); tools/ci/playbook-quit-check.sh keeps master's rule 2 and pre-rule list with the release side's Ember allow entry and the 0.3.15 expiry check.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
remote-run.sh gains a checkout mode used by lib.sh: git checkout -- . and git clean -fd (target dirs, the sha stamps and
ignored files kept), fetch, branch at the commit, then a clean-tree check; the overlay follows. Before this, the rsync of
uncommitted files stayed in the box's tree and the next commit's git checkout -B refused with 'local changes would be
overwritten'. remote-run.sh --self-test reproduces the dirty tree (edited tracked file, untracked file, target dir, sha
stamp), shows the plain checkout refusing and the mode landing clean on the new commit; it runs in ci.yml and passed on the
Mac and the box; a live dirty-then-clean pair on the fork worktree passed too. Plan: section 5, gotchas of the first day.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>