Commit graph

274 commits

Author SHA1 Message Date
igneum-labs
ebedff9b66 ember-tune.md: the next-cut note names the right commit
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:03:19 +00:00
igneum-labs
6de4827ccb a job that cannot mine never burns its budget silently: the elevated job path follows its output file while the script runs (the 5-minute progress reports carry the lines; 0.3.12), and the tune playbook's watchdog fails a run that mines nothing within 120 s of its first status line (the engine's last log line in the RESULT, the tree ended, mining restored by the runner)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:03:13 +00:00
igneum-labs
663fca4d76 bench log: run 2 (07:21 to 07:56Z): the BOM in the copied settings, no miner started, nothing set, mining paused 36 min 13 s, the hold released by the runner itself
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:59:21 +00:00
igneum-labs
f5dfdbf443 bench log: the 22:31 UTC installer run was a second install of 0.3.10 over 0.3.10 (PC 1 took 0.3.10 at 21:40:41Z through update-now), not how PC 1 got 0.3.10
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:03:26 +00:00
igneum-labs
3d505766d2 C35 named: PC 1's 22:31 UTC quit was the per-user installer launched by the second engine's own updater (0.3.9 under min_supported_version = urgent, beating auto_update = false); a second engine never runs the updater (IGNEUM_APP_NO_OTA=1, implied by --sweep; the playbooks set it; the CI check demands it); bench log and plan carry the named source
Source: the scratch engine's own log in collect ember-c35-collect-1 (06:59Z): 22:31:02Z '0.3.10 is available: downloading',
22:31:05Z 'update: starting the installer first ... ota-apply.ps1', and the installed app's 'quit:' at 22:31:06Z.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:01:57 +00:00
igneum-labs
f9d9805ae8 bench log + plan: C35 corrected (the quit was not the 0.3.11 update; what is established, the hang, the orphans, the prompt, the fixes)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:00:52 +00:00
igneum-labs
d19441c14d C35 class: a second engine gets no pipe (its output goes to a file the playbook tails) and its whole tree is ended at the end and on the budget; ember-tune-pc1.ps1 and sweep-5090.ps1 fixed; tools/ci/second-engine-check.sh fails any playbook without both; the rule in ember-tune.md
PC 1, 22:31 UTC: the installed engine's quit hung 24 minutes in the jobs runner's abort, waiting for EOF on the script's
stdout pipe whose write end the second engine and its miners had inherited (Process.Start with redirection inherits
every inheritable handle), while the orphaned miners mined on against the relaunched app.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:00:06 +00:00
igneum-labs
f76fca96e2 bench log + plan: PC 1 run 1 aborted by the 0.3.11 update 47 s in, the before snapshots of both cards, the AMD offset-range finding and its consequence per tier
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:44:46 +00:00
igneum-labs
dd37094a5b ember-tune.md: a signed prior is a starting point inside the card's own reported limits, never a memory clock; the tests that prove the clamp (consequences row C25)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:31:06 +00:00
igneum-labs
99f7836a81 bench log: Ember Tune, what PC 1 could measure tonight (elevated=False, the cancelled prompt at 20:09 UTC, the 9070 XT off the bus), the pipeline verified without a card, the tier consequences
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:26:31 +00:00
igneum-labs
5c808b89e0 Ember Tune: every card tuned for MH per watt out of the box, the fleet prior per card model in the signed manifest, the console and /miners priors table
the project lead, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (423936b, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (057f0ec). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.

- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
  (power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
  neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
  the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
  no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
  no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
  probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
  tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
  Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
  {json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
  control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
  query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
  switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
  median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
  make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
  tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).

Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt the project lead cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:25:09 +00:00
igneum-labs
fe852a4335 AMD telemetry: igneum-gpu-telemetry (ADLX on Windows, amdgpu sysfs on Linux, PDH utilisation fallback) feeds the card row's draw, temperature, fan, memory clock and MH/W; measured on PC 1: 9070 XT 198.9 W, 64 C, 657 rpm, 17.73 MH/s = 0.089 MH/W beside the 5090 at 307.6 W, 122.30 MH/s = 0.398 MH/W
the project lead watched the 9070 XT at 90% usage with its fans barely turning and the app could not say what it drew: the
draw, temperature and MH per watt line came from nvidia-smi only, and the earlier per-watt figure used the board
rating. proto-opencl/gpu-telemetry.c prints one line per AMD card per sample (bus from SetupAPI by the display
device's name, kind, name, watts, temp_c, fan_rpm, fan_pct, mclk_mhz, gclk_mhz, util_pct, source), built by
build-windows.sh against vendor/adlx (the SDK clone), shipped by make-payload.sh and push-inputs.sh. The engine
runs it with -l 5 beside nvidia-smi (Source::AmdTelemetry, tick_amd_telemetry), parse_amd_telemetry fills
power_w, temp_gpu, fan_pct, fan_rpm, mclk_mhz, util_pct and telemetry_at on the AMD card matched by kind and
ordinal, so eff_mhw and the dashboard's existing line show it; app.js shows fan and memory clock when present.
Tests: three on the parser with lines captured on PC 1 and the Mac fixture; the sysfs path ran on a fixture tree.

Measured over 20:27:45 to 20:29:41 UTC with both cards mining (docs/bench-log.md, under the 9070 XT ceiling table):
9070 XT 198.9 W (193 to 212), 64 C, 657 rpm, 2,505 MHz memory, 3,290 MHz shader, 100% busy, 17.73 MH/s =
0.089 MH/W; RTX 5090 307.6 W, 69 C, 44% fan, 122.30 MH/s = 0.398 MH/W.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:21 +00:00
igneum-labs
52d9a110be docs: Counter ASIC 2.0, the second set of chip-resistance layers and the plan to measure and decide them
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:40:33 +00:00
igneum-labs
e0fce822b6 docs/plans/explorer.md: Etherscan, Blockscout and Otterscan compared, Blockscout's requirements against the fork's RPC, the recommendation, the load and supply measurements, the pool item; screenshots
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
48d987cfb4 Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check
The numbers profitability sites and pool software read (WhatToMine's form: explorer or pool with an API, the halving
schedule, a source for total coins). Reward and supply from the emission rule at the node's DAA score; the halving table
(33 rows), the 30-day ramp and the observer's coinbase check. Cached 10 s, CORS open. FIELDS in each handler is the
contract; public-stats.test.mjs checks it from a fixture, tools/ci/public-api-check.mjs checks a deployment.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
995769d0e6 finality-v3-devnet-publish.md: the app nodes, the sweep (every live node on 1f4b4425), the Mac app's external-node finding, the checkpoint read 2026-10-05 18:19:03 +00:00
igneum-labs
2260a43053 docs/plans/finality-v3-devnet-publish.md: N3 = 135,200, digest 1f4b4425, the hand nodes, the seed and the three manifests 2026-10-05 18:09:05 +00:00
igneum-labs
135f67ab2a Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 17:55:57 +00:00
igneum-labs
c30b0c0f09 release-0.3.9 plan: the ship, the proving rollout, the fee switch (H 210,000, digest ab8847da) and the sweep; restart-hand-nodes.sh: grep -c instead of grep -q under pipefail, lines() never ends the script 2026-10-05 17:55:35 +00:00
igneum-labs
a96bcea470 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
addeb660fd Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
8d80195869 release-0.3.9 plan: the cut so far (branch, tests, node builds, hand nodes and seed on a24ab01a, DMG, package) 2026-10-05 16:51:20 +00:00
igneum-labs
8b4b1e500a Merge origin/master (974805b) into release-0.3.9: fud-a round 6, the entity imprint, the conflict-marker check; docs/bench-log.md both entries, the site taken from master and rebuilt (519 links, 0 broken) 2026-10-05 16:48:00 +00:00
igneum-labs
ee7cfa9c27 Merge entity: Igneum Labs LTD and the DIFC address as the entity and contact everywhere, repository public at the public testnet, ledger published with it, no team page
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/fud-ledger.md
#	site/bench.html
#	site/index.html
#	site/journey.json
2026-10-05 16:42:40 +00:00
igneum-labs
02b19ed761 Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
0c92c5faa1 Ledger and fixes: published with the repository at the public testnet, submissions to hello@igneum.network, no team page (decisions of 5 October 2026)
The ledger's header and submission lines, G3's status line, and the fixes file's legend, row 9, decision (b) note and section 5 record the four decisions. Two literal pattern mentions reworded so the identity check passes with both files on its export list.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
8703d9e731 Merge fud-a: ledger sweep round 6 (11 fixes closed with rollout evidence, M1/M11/M16/M21/P3/P9/P14/X5 measured, C4 finding, F16 options)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/bench-log.md
2026-10-05 16:33:15 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
ff6be6ccdb FUD sweep round 6, C4 measured: the overlay holds during a split and fails at the heal in the shipped node (a certificate over an off-chain block stays pending, GHOSTDAG never reorgs to it, the heavier side locks alone one window later); module-off control converges
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:32:04 +00:00
igneum-labs
ef3cbaf4f5 Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 16:30:47 +00:00
igneum-labs
3a96e7371c Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 16:28:21 +00:00
igneum-labs
4bfb5d3928 release-0.3.6 plan: why the PC-built Windows node died at start, answered and fixed in the fork (static libstdc++); the stale comments on the Windows DLLs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:26:05 +00:00
igneum-labs
24aaa0e254 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:24:35 +00:00
igneum-labs
142ca73731 Merge txgen: the devnet transaction generator, proving watch, exporter block reconstruction fix with node-plan fixtures, bench log and evidence
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:22:26 +00:00
igneum-labs
3be4e3ef2a txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
26d255737c FUD sweep round 6: bench-log entry (live rollout evidence, fleet codegen, 5090 race, verifier in a phone-sized tab, block sizes and k, weight window) and fud-fixes section 2.6
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:06:24 +00:00
igneum-labs
d9736b3c06 Merge testnet-infra: testnet seed profile, DNS and RPC installers, build-job watcher fix, docs/testnet, the go checklist
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:05:16 +00:00
igneum-labs
6621ec3b51 FUD sweep round 6: M1 program space counted, M11 fleet boundary and 5090 race measurements, M16 cost model, M21 block sizes and k, P3 certificate verify in a phone-sized tab, P9 parameter table, P14 one definition, F16 two options priced, X5 independence measurement defined; decision owners named on L1 to L5 and G3
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:04:48 +00:00
igneum-labs
97f0cf14ac docs/plans/testnet-go.md: the go checklist with the state of every line at 16:05 UTC, the final genesis, the cost
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:04:09 +00:00
igneum-labs
e6a3f8bab1 FUD sweep round 6 (evening, 5 October): eleven rolled-out fixes moved to Fixed with live measurement lines, F21/F22 shipped but switch not thrown, M20 closed on the 0.3.5 merge; P14 one base-fee definition in spec 05; M16 recompute-attacker cost model; C4 overlay-against-GHOSTDAG runner
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:02:02 +00:00
igneum-labs
53dae0ddf1 release-0.3.6 plan: the two finality tests under the parallel suite answered (fork 7003055b); build-job.mjs forwards --node-tests, --app-tests, --no-app
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:59 +00:00
igneum-labs
340553a4cc Testnet seeds: debian-13 images (the PC build's glibc 2.39), a glibc check before the upload, the final genesis in docs/testnet/README.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:58:18 +00:00
igneum-labs
6cecbd4c67 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
880f8aebac Merge fud-b: the conceded wording in the litepaper, site and ledger (31 entries)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:45:01 +00:00
igneum-labs
035afcd96a fud-ledger: evening sweep paragraphs on the 31 conceded wording items, each naming where the honest sentence now lives
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:44:18 +00:00
igneum-labs
9a204e2266 rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:37:02 +00:00
igneum-labs
3affba561a release-0.3.8 plan: the cut, the proving rollout, the first cross-verified shard 2026-10-05 14:08:31 +00:00
igneum-labs
60df95a300 Merge program-id: pinned shard and aggregator guests (elf/ + manifest), fast verify with the pinned key, CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	proving/igneum-prove/host/build.rs
2026-10-05 13:00:54 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
0cba49cfe0 Prover: the 5 October post-root assertion explained (stale build, empty-segment plan), fixture 58927, fixture test, source stamp
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.

The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit d6d6153 (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.

So the prover core needs no rule change: the fix is commit d6d6153, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:

- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
  statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
  segment's shard ends at the root after the rewards, never the pre-root. With the pre-d6d6153 rule put back
  the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
  untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
  printed on the first line of every run, so a stale build names itself in the log instead of in a line
  number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.

The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 11:50:40 +00:00