tools/ci/founder-strings.b64 was the founder check's pattern list base64-encoded: a grep could not read it, any reader of the public host could (git.igneum.network was public from 21:26 UK; read off at 21:36). The list now lives only in a private file (~/.config/igneum/founder-strings on the Mac, /srv/discord-hooks/founder-strings on build-1 for the Discord guard; $IGNEUM_FOUNDER_STRINGS overrides) and site/forbidden-strings.txt carries no encoded copy. Readers: founder-strings-check.sh (skips with a line where the file is absent; the Mac's hook is the guard), site/scrub.mjs and launch-gates-check.mjs (the private file's patterns added where it exists), discord-hooks.mjs (three locations; the test writes a fixture list and loads the module after it), fresh-repo.sh (the private file; drops tools/ci/founder-strings.b64 from every commit; rewrites the base64 of every list regex out of every blob and scans for it).
The check's second pass (main's addition): every base64 literal of 24 characters or more, every hex literal of 24 or more and every *.b64 file is decoded and scanned, so no encoding hides a term again; the self-test plants each fixture sample in plain text, in a .b64 file, as a base64 literal and as a hex literal, each caught and named, and a tree without the list skips with its line.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Ruling 2: every tracked text mention of the login's pre-rename spelling becomes igneum-labs (29 files); the commit identity in the scripts becomes igneum-labs <337424239+igneum-labs@users.noreply.github.com> (the same noreply id); the three scripts that hand the stored gh keyring name to gh (register.sh, fetch-ci-artifacts.sh, ship-app.mjs) read it from ~/.config/igneum/gh-user (never in the repository), default igneum-labs; fresh-repo.sh reads the login to rewrite from the encoded list's row 10; the old spelling joins the founder-strings list, so no tracked file may spell it; CLAUDE.md's GitHub paragraph rewritten. The red watcher's self-test fixtures use a neutral author.
Ruling 4: docs/ledger-public.md, one row per ledger item (id, the claim in one line, status, what was done in one line, the evidence link or the evidence in words), generated by tools/ledger/export-public.mjs from docs/fud-ledger.md: no round or status-update sections, no commit ids, no time of day, no lane, agent or branch names. 190 items. The gate runs its self-test (a fixture with a commit id, a time, a lane and a branch name comes out clean; --check fails on drift) and its --check on every merge; the founder check reads the output like every tracked file.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).
The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.
Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
mirror_master runs after the push to origin: one fast-forward push per mirror in IGNEUM_MIRRORS (default: the two box files' hosts at /srv/igneum.git), best effort, a line per mirror, a down or diverged mirror never fails the landing. Self-test: a bare mirror behind master is fast-forwarded; a non-fast-forward push leaves it and is reported.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
ci_gate: unknown prints the reason and asks again until --ci-wait runs out (CI_WAIT_SECS for the self-test). master_gate: three reads
over a minute before an unknown counts; a lasting unknown still refuses (no verdict, no merge). Self-test: a blip (unknown, then
green) merges; a lasting unknown is refused at the deadline; the same two shapes for master's read.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Thirteen failure emails between 15:26 and 16:53 UK. The classes and what closes them:
- the box-locks check on a hosted runner (10 runs): closed by e77cd823 and 0b4265ae earlier
- windows-ci's stale payload-inputs pin (3 runs): closed on master by 9983f9cf; update-return's dispatches still carry e69e8a39
- three hosted site jobs on master hung in the tree gate for over two hours (no timeout-minutes): ci.yml now carries
site 15, changes 10, pow 60, sims 45, the overlap sweep runs under a 10-minute wall clock where GNU timeout exists, and
tools/ci/workflow-timeouts-check.sh fails a job without a budget (self-test: a job without the key, a wrong budget)
- a branch merged with no ci run of its own (era-vdf be4db4f3, 16:31 UK): master's igneum-pow suite went red and five
docs-only merges landed green over it because their runs skip the compile job. tools/ci/ci-state.mjs reads the runs
API through gh (a commit's newest run, master's last COMPILED run, a branch's last red); merge-to-master.sh pushes an
unrun branch for a run, waits for a queued one printing the clock, refuses a red one and refuses any merge onto a red
master except the declared fix (--fixes-master); the pre-push hook refuses a push to master whose commit, or whose
merge's branch parent, has no green run on that exact sha; a feature-branch push prints the branch's previous red
first. Self-tests with a fake gh in all three.
- ci-red.yml fires on failure, cancelled and timed_out and hands the conclusion to red-watch.mjs, whose line names the
kind (CI red, CI cancelled, CI timed out); the self-test reads the workflow file for the three conclusions
- tools/ci/retry-once.sh: one retry before red for the box-locks check, the scene parity check and the live public API
check (each keeps its own skip line on a runner without the resource)
GitHub's branch protection cannot be applied: the organisation is on the free plan and the repository is private (the
API answers 403, "Upgrade to GitHub Pro or make this repository public"), so the two scripts are the enforcement; the
rule is one line in CLAUDE.md under the CI block.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Home row 03, the litepaper's chip section at /litepaper#chip-model (paragraph and table; the class v3 row last, "never the launch
state"), the miner page's line and evidence.md row 17 in its eight columns: 2.1x to 3.9x under class v4 from the first block,
class v5 removing the stored-dataset chip as a category, the 5x to 9x only as the class v3 baseline, the devnet's activation
height as a devnet fact. The litepaper's abstract carried the same claim in the old form ("5x to 9x today; class v4, now on
the vote") and now reads launch-first too. tools/ci/ledger-text-check.mjs follows the sentences (X35 on the home page and the
litepaper). No disclosure prize anywhere.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>