Commit graph

285 commits

Author SHA1 Message Date
igneum-labs
7ed0d75160 A card never shows 0 MH/s without a reason word (the project lead, 6 October 2026, watching PC 1 during the table run): the Mine row reads 'tuning: step k of n · measuring W W' with the live rate, 'held for a remote job: <title>' while a job holds the miners, and the Tuned line at the end; the big button reads 'Tuning, mining again in about N min'; the strip carries one tune line; a measurement engine prints a TUNE progress line every 10 s and the playbook forwards it (and TUNE chosen as done) to the installed app's POST /api/tune-progress, a post of state, never quit, pause or resume; the rule in ember-tune.md 6a; UI tests for the three states
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:36:07 +00:00
igneum-labs
452d74c3c2 playbook-quit-check: the ruling of 6 October 2026 15:30 UTC (a job script never pauses or resumes the installed app's miners, not even as a fallback; --stop-miners is the way): the two agg-cost allow entries dropped, so the gate names tools/proving-v1/pc2-agg-cost.ps1 and pc2-agg-cost-restore.ps1 until they move to --stop-miners
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:05:37 +00:00
igneum-labs
92500f86ca release 0.3.13: merge ember-tune e9e1042 (master merged into the branch, the dry-run-3 bench entry, the playbook-quit gate's allow entry)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:05:00 +00:00
igneum-labs
e9e1042fc9 playbook-quit-check: pc2-agg-cost.ps1 and pc2-agg-cost-restore.ps1 allowed pending the rule owner's word (they pause and resume the installed app as the fallback of a card switch)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:04:35 +00:00
igneum-labs
4af1d66917 Merge master 017c7db into ember-tune (0.3.12's version files and the proving-v1 app merge; my own 27c2db6 came back as 4965220) 2026-10-06 15:03:37 +00:00
igneum-labs
7883ff17dd release 0.3.13: merge ember-tune 0cba030 (the Power Helper: one approval registers a per-user elevated scheduled task, no prompt after; the folder-lock ACL; the verbatim settings copy; the watchdog; no firewall prompt for a sweep engine; the jobrun follow_file)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 15:03:27 +00:00
igneum-labs
f225ccf842 run 4's cause: the playbook's PowerShell JSON round trip rewrote the copied settings (big integers as doubles), the engine read the file as defaults (no payout address, every card off, 96 old remote jobs run in the scratch root). Fix: the copies are verbatim and a --sweep engine applies Settings::for_measurement in memory (remote jobs, updates, proving and Power control off, not paused, tune on, every card due and unpinned); the CI check fails any playbook that rewrites settings.json through ConvertTo-Json; unit test
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 14:21:06 +00:00
igneum-labs
d0ac0d1ca4 tools/fleet: publish the rented-GPU fleet page's data to the downloads host
The page lives at an unlisted path on dl.igneum.network (name in ~/.config/igneum/fleet-path) and reads fleet.json
every 30 s; this script copies a fleet.json in and deploys, then checks the edge serves it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:52:18 +00:00
igneum-labs
280631fbc6 tools/ci/playbook-quit-check.sh: the standing rule of 5 October 2026 23:05 UTC as a gate (a playbook that reads the installed app's URL file and sends quit, pause or resume fails; the installer's own stop step is the one allowed sender; self-test on a bad and a good case); shard-test.ps1 loses its api/quit to the installed app; ember-tune-pc1.ps1's refusal guard reworded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 11:52:08 +00:00
igneum-labs
6afd307c29 pc2-agg-cost.ps1: pkill -f sp1-gpu-server at the end (the CI root-socket check); release 0.3.12: the PC 2 job, the Windows artefacts, the CI rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 09:04:33 +00:00
igneum-labs
f4478a8ee1 Merge branch 'ca3-reserve' into ca3-coord 2026-10-06 08:45:48 +00:00
igneum-labs
1d0cc97721 Merge branch 'ca3-shadow' into ca3-coord
# Conflicts:
#	docs/bench-log.md
2026-10-06 08:45:48 +00:00
igneum-labs
e651e281d4 release 0.3.12: merge proving-v1 app f0a40cd (the segment-aligned prover, the held fresh record, the fresh-record rule harness)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:37:18 +00:00
igneum-labs
a3adeb2ac8 Counter ASIC 3.0 items 6 and 7: PC 2 family playbook posts both card key forms from settings.json, confirms the card quiet by the process list, restores cards and prover in a finally block 2026-10-06 08:34:28 +00:00
igneum-labs
f380ccc7c7 proving v1 harness: under --fresh-rule the second offer of segment 3's record is a duplicate, not a chain-rule refusal
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:32:42 +00:00
igneum-labs
ea51a82d58 Merge branch 'ca3-detector' into ca3-coord 2026-10-06 08:29:09 +00:00
igneum-labs
ba4a9956f4 Counter ASIC 3.0 items 4 and 5: the epoch common factor is the median over steady core ids
The mean over every present id let one paused-and-resumed card (the Mac, a 178% step) push
every other residual the same way in the epochs it was off, which read as an r = 0.94 edge
between two honest 5090 keys on the merged tree (window 41 to 46). The factor is now the
median over ids that are steady and present in every window epoch (median over all present
when the core is under 3): the same window reads max r 0.10. README: the three calibration
readings (the edge, the factor-of-two from identities=2, the unsteady Mac) answered.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:28:55 +00:00
igneum-labs
53382993b2 Counter ASIC 3.0 item 8: the PC 2 playbook switches the prover back on in its finally block (the clear file's constraint)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:26:22 +00:00
igneum-labs
e3ee3049bd Merge branch 'ca3-reserve' into ca3-coord
# Conflicts:
#	docs/bench-log.md
#	tools/observer/observer.mjs
2026-10-06 08:24:29 +00:00
igneum-labs
27c2db64c3 app: every elevated launch through one hidden-console builder; CI check for Windows spawns; PC 1 console watchers
The console-window class (the project lead, 5 October 2026: "Windows Command Processor" windows on PC 1 whenever a remote job runs).
Measured on PC 1 (ae432dc7, Windows 11 Pro 26200, default terminal "Let Windows decide" = Windows Terminal 1.24) with
tools/windows/console-watch.ps1 (job run-20261005-182528): no child a job script starts from the app's headless
console opens a window (powershell, cmd, query, curl, nvidia-smi, wsl --status, a distro, interop cmd and powershell,
powershell -WindowStyle Hidden: 0 windows each); Start-Process in a new console opens a Terminal window (the known-failed
case: 2 windows), the same with -WindowStyle Hidden opens none (the known-finished case). The elevated path
(Start-Process -Verb RunAs -WindowStyle Hidden through the AppInfo service) is the one road left; its watcher
(console-watch-elevated.ps1, job run-20261005-184610) was cancelled at the UAC prompt.

- platform.rs: elevated_ps_line + elevated_command build the one PowerShell line every elevated launch uses (the NVIDIA
  power cap, the sweep helper, the clock sync, an elevated remote job), -WindowStyle Hidden by construction; unit
  tests on the line, the quoting and the Command.
- jobrun.rs: the elevated job path uses it; the relaunch helper's Start-Process carries the reason it has no
  -WindowStyle Hidden (igneum-app.exe is a windows-subsystem program).
- tools/ci/windows-spawn-check.mjs (+ ci.yml): fails when a Command::new in app/igneum-app/src is not quieted,
  a creation_flags is not CREATE_NO_WINDOW alone, a Start-Process the Rust code writes lacks -WindowStyle Hidden or
  -NoNewWindow, or host.cpp spawns without CREATE_NO_WINDOW / SW_HIDE; self-test on known-good and known-bad samples.
- tools/windows/console-watch.ps1, console-watch-bg.ps1, console-watch-elevated.ps1: the watchers (run jobs).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:21:46 +00:00
igneum-labs
563463b35f Merge release-0.3.12 (fda4684) into ember-tune: 0.3.11's six-section View and card order kept, Ember Tune's line and switches re-added on it; the tune fields move into hotplug::apply_pref; the power-cap plan keeps present(); both CI test lists; 132 app tests, 26 UI tests, every gate green
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:20:46 +00:00
igneum-labs
3959d66e55 Merge ca3-shadow (item 8's Mac rows) into ca3-coord: LoadClass carries derive_len and shadow; igneum-pow suite 96 passed 2026-10-06 08:11:03 +00:00
igneum-labs
4605314315 Counter ASIC 3.0 item 8: the Mac rows
The M5 Max ladder (Metal, packbench, IOReport GPU and DRAM watts without root): latency-bound to about 100,000 ops per
hash, the 5 percent point about 130,000, 11 to 27 W GPU at 100,000 ops, 0.78 to 1.40 microjoules per hash; the
verifier's law 2.06 ms + 3.2 us per 1,000 shadow instructions per warp on one core; every pack bit-exact. The
analysis file with the knob, the chip side (k = 1, 1.5, 0.3), the gates and the consequences; the bench-log entry;
the 5090 rows pending the PC 2 job (the playbook now carries the core-clock rows and the sh256x40 rung).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:08:26 +00:00
igneum-labs
f3a98cd291 proving v1 harness: --fresh-rule <daa> (default never keeps the known-failed line; set, case 3 expects a fresh record accepted while the previous segment is pending and freshAdmissible true)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 08:05:04 +00:00
igneum-labs
d1705e0e1b playbooks: the scratch settings.json is written without a BOM (PowerShell 5.1's -Encoding utf8 adds one, the engine's JSON parser refuses it, the copy read as defaults with no payout address and nothing mined in runs 1 and 2); the address is read back and the job fails at once if it is empty; the CI check fails any playbook writing JSON with Set-Content -Encoding utf8
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:58:39 +00:00
igneum-labs
51dba1ce76 Counter ASIC 3.0 item 8: the latency-shadow knob (LoadClass +sh<S>x<R>), its packs and the PC 2 playbook
A shadow block of S ALU instructions run R times at the end of every iteration, drawn from the program stream after
the 64 base instructions, behind LoadClass::shadow: v2 and v3 draw nothing and emit nothing (the pinned packs are
byte-identical, cargo test 54 + 4 + 19 + 7 green). The interpreter, the three kernel dialects (both kernels each),
program.h and program.json carry it; the acceptance rule interprets the base program only. Packs for seed
igneum-genesis over class mx8 at 4,096 to 180,224 shadow instructions per hash (proto-cuda/packs-ca3-shadow), and
the PC 2 bench playbook tools/ca3-shadow/pc2-shadow-bench.ps1 (passes the publisher's three checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:58:35 +00:00
igneum-labs
7bdc8a9060 pc2-segments: int64 segment keys (a double never matched the int64 hashtable keys, so job b claimed nothing in 88 passes); the work-list line; the log search widened
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:50:46 +00:00
igneum-labs
3087a01593 Counter ASIC 3.0 items 4 and 5: the share-pattern detector on the observer
tools/observer/detector.mjs: per-program implied rate per miner id from blue work over
wall seconds (the chain's own estimate rule restricted to one id), excess spread above
Poisson, epoch-start share, nonce chi-square and increasing-fraction tests, card bands
from the log intake, two-way residual correlations and cliques; a design_candidate clique
held 6 net windows is the alert, written to live_state.detector and live_events kind
detector. One hook in observer.mjs (every 60 s) and one jsonb column. node:test file
with a fabricated fixed design (fires) and a fabricated honest population (quiet); the
live devnet in --dry mode is quiet with its baseline recorded in the README.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:47:21 +00:00
igneum-labs
0f3b23d7a7 Counter ASIC 3.0 items 6 and 7: proposed reserve order and spec text (docs/plans/counter-asic-3-reserve.md), the vendor-share section on the benchmark page, the observer README row 2026-10-06 07:40:41 +00:00
igneum-labs
42abffe015 Counter ASIC 3.0 items 6 and 7: tools/observer/vendor-share.mjs (fleet-reported and chain-attributed hash rate by vendor), node:test on fabricated rows, one 60-s hook and live_state.vendor_share in the observer 2026-10-06 07:36:46 +00:00
igneum-labs
ea141f2a94 Counter ASIC 3.0 items 6 and 7: family step-cost probes (Metal, CUDA), the PC 2 playbook, the M5 Max rows in the bench-log 2026-10-06 07:36:12 +00:00
igneum-labs
9ea77aa2ae pc2-segments: the port probe sets the port before the call (the first run dialled an empty port and refused itself)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:19:15 +00:00
igneum-labs
8bb3c892d6 proving v1: the PC 2 segment-aligned prover job (tools/proving-v1/pc2-segments.ps1) and the CPU validation of --save-shards records and --prev
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:18:15 +00:00
igneum-labs
7dade79bcb Aggregation cost on the 5090 (5 October, night): the chained aggregation is 2.1 s alone and 9.7 s beside the miner, the batch-log2 curve (2^16 buys 1.6x for a fifth of the hash rate), batch and tree folds estimated, two streams and SP1 knobs closed; the host times the stdin build and names the knobs, --save-shards; the PC 2 job scripts and the readers
The statement and the pinned guests are unchanged; every fixture proof verifies as before. The defaults stay (batch-log2 22, SP1 defaults): the one knob that moves a mining card's prover costs a fifth of the hash rate; the plan carries the trade for the project lead and the batch fold for the next pin. Measured: docs/bench-log.md "aggregation cost on the RTX 5090"; the plan line: docs/plans/proving-v1.md "Aggregation cost (5 October, night)". Also: make-package's gate skips the exporter's .node-plan.json side files and takes the run lock for its execute step; the state-reply class (/api/state answering {} once paid_wei passes u64::MAX) found on the way and fixed on the app branch at 42f36b3.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit ea38ece9eaa5949dd657cbfea5308c4948177ff8)
2026-10-06 07:04:50 +00:00
igneum-labs
3d505766d2 C35 named: PC 1's 22:31 UTC quit was the per-user installer launched by the second engine's own updater (0.3.9 under min_supported_version = urgent, beating auto_update = false); a second engine never runs the updater (IGNEUM_APP_NO_OTA=1, implied by --sweep; the playbooks set it; the CI check demands it); bench log and plan carry the named source
Source: the scratch engine's own log in collect ember-c35-collect-1 (06:59Z): 22:31:02Z '0.3.10 is available: downloading',
22:31:05Z 'update: starting the installer first ... ota-apply.ps1', and the installed app's 'quit:' at 22:31:06Z.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 07:01:57 +00:00
igneum-labs
d3b44141d1 prover-floor: the three other PC 2 scripts test their kit file before the first use (C32)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:06:38 +00:00
igneum-labs
34b2fa0ff6 prover-floor: pc2-floor-sweep3-miner.ps1 tests its kit file before the first use (the kit-path check, C32)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:04:52 +00:00
igneum-labs
0059f12c98 Merge prover-floor (8e2686d) into release-0.3.11: docs and standalone probe sources the evidence rows cite (C38); nothing a built artefact reads 2026-10-05 23:03:46 +00:00
igneum-labs
d19441c14d C35 class: a second engine gets no pipe (its output goes to a file the playbook tails) and its whole tree is ended at the end and on the budget; ember-tune-pc1.ps1 and sweep-5090.ps1 fixed; tools/ci/second-engine-check.sh fails any playbook without both; the rule in ember-tune.md
PC 1, 22:31 UTC: the installed engine's quit hung 24 minutes in the jobs runner's abort, waiting for EOF on the script's
stdout pipe whose write end the second engine and its miners had inherited (Process.Start with redirection inherits
every inheritable handle), while the orphaned miners mined on against the relaunched app.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 23:00:06 +00:00
igneum-labs
b584e41e31 CI on the merged 0.3.11 tree: MacBook reworded in the analysis prose (the identity check's hostname pattern), a presence check before the kit's first use in the three proving-v1 PC 2 scripts (C32), pc1-cpu-prove.ps1 on the socket check's allow list (the CPU path starts no GPU server)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:44:09 +00:00
igneum-labs
8e2686d008 Prover floor: the beside-the-miner sweep playbook (sweep 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:42:31 +00:00
igneum-labs
830efc63e1 Prover floor patch v2: every trace buffer sized to its padded need (setup keys and shards), the sweep-2 points
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:41:37 +00:00
igneum-labs
8ad50d119b Merge branch 'bash-body-check' into release-0.3.11
# Conflicts:
#	.github/workflows/ci.yml
#	tools/ci/prover-socket-check.sh
2026-10-05 22:40:22 +00:00
igneum-labs
75a56182b2 Merge commit 'a2f08e3' into release-0.3.11
# Conflicts:
#	docs/bench-log.md
#	docs/evidence.md
#	site/litepaper.html
2026-10-05 22:39:34 +00:00
igneum-labs
629157b388 Merge branch 'ca2-coord' into release-0.3.11
# Conflicts:
#	docs/bench-log.md
2026-10-05 22:39:12 +00:00
igneum-labs
b2e6d6159e CI: run jobs test their fetched kit before use (the wiped-jobs-folder class)
The app's install clears the jobs folder on a PC, so a run job whose kit was fetched by an earlier fetch job finds
nothing after an update and fails in seconds (5 October 2026, 21:49Z, the AMD kit; bench-log 4df339f). Rule: a run
playbook that reaches a path under the jobs folder other than its own tests the kit is there before its first use,
and the fetch is republished under a new id after any app update.

tools/ci/kit-path-check.sh reads every *.ps1 under relay/playbooks/ and tools/. A kit root is a path derived from
the jobs folder (`$jobs = Split-Path $env:IGNEUM_JOB_DIR` then `Join-Path $jobs '<fetch id>'`, the race-5090.ps1
shape) or one carrying a literal `jobs\` (the amd-card-test.ps1 shape); every path built from it belongs to that kit.
A presence check (Test-Path, [IO.File]::Exists, [IO.Directory]::Exists, Get-Item or Get-ChildItem with -ErrorAction)
on the root or anything under it covers the whole kit. A use before that line fails with "kit path used before a
presence check: republish the fetch after any app update", as does a literal jobs\ path in a command with no check.
The job's own folder ($env:IGNEUM_JOB_DIR) is not a kit path.

Fixtures: kit-path-ok.ps1 (both shapes, checked; a sibling pack file covered by the worker's check) and
kit-path-unchecked.ps1 (the worker run before its check, a literal never checked); --self-test asserts the lines.
Wired into ci.yml after the bash-body step, and into publish-jobs.sh add --kind run beside the other two checks;
test-publish-jobs.sh gains the refusal (34 passed, 0 failed). The current tree: race-5090.ps1 is the one playbook
with a kit, checked before use. README-ship.md: the rule.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:37:29 +00:00
igneum-labs
19b30e31f0 Merge remote-tracking branch 'origin/master' into ca2-v3
# Conflicts:
#	docs/bench-log.md
#	proto-opencl/host.c
2026-10-05 22:34:07 +00:00
igneum-labs
393a8f831f Prover floor: the build recipe as it ran (Go pinned, the binary's sha256 and targets), the RISC Zero contingency figures with their source, playbook fixes
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:33:31 +00:00
igneum-labs
2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
igneum-labs
1402989cdd Prover floor: SP1 6.8.1 GPU server memory model from source (the 24 GB panic, the threshold-sized trace buffers), the floor patch for sp1-gpu, the PC 2 toolchain, build and sweep playbooks
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:11:24 +00:00
igneum-labs
c4da08d302 App: the resume path re-arms every stopped card, re-exports its pack and checks 90 s later that every enabled card mines (PC 2 at 21:25:11Z and the Mac that afternoon stayed at 0 MH/s after resume); the PC 2 socket-fix job
The known-failed case, from PC 2's 0.3.9 log (run win-1ccfe586-20261005-200114): 1791234223 pause -> 'stopping the
miners (paused)' (every slot's restart_at cleared, the 5090 'off'); 1791235511 '[ok] mining resumed'; then
'0.00 MH/s, waiting' at every 30-s status line until the 0.3.10 restart at 21:49:41Z. Cause: Cmd::Resume re-armed
only slots whose watchdog said faulted; the 5090's slot was healthy and stopped, so nothing restarted it. The test
the_pc2_resume_of_21_25_11z_restarts_under_the_new_rule_and_not_the_old encodes that slot (faulted false, live
false): the old rule returns [] (the defect), the new rule [0]. cargo test -p igneum-app resume: 3 passed;
provedefault: 6 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:56:20 +00:00
igneum-labs
a5533177d3 CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class)
Twice on 5 October 2026 a PowerShell job script carried a bash body inside a string, a quote was lost on the way
through PowerShell, and bash refused the body: pc1-cpu-prove.ps1 (first version) reported exit 0 having done
nothing, the 0.3.10 installer job failed in 4 s. tools/amd-prove/check-job-bash.sh covered only its own here-string.

tools/ci/bash-body-check.sh reads every *.ps1 under relay/playbooks/ and tools/, finds each bash body however it is
handed over (bash -c "...", bash -lc '...', bash -c $var, a + concatenation in parentheses, the Start-Process argument
list, a here-string written to a file that is later run with bash), unescapes it the way PowerShell would (backtick
escapes and "" in double-quoted strings, '' in single-quoted strings, here-strings verbatim; $var left as-is, a $(...)
subexpression replaced by ${PS_SUBEXPR}), and runs bash -n on it. One line per body with the file line of the error.
A body it sees but cannot read is "unextractable body" and fails too: a skip would be a hole in the class check.
bash 3.2 compatible; python3 for the extractor.

--self-test runs three fixtures under tools/ci/fixtures/: the correct shapes (8 bodies, must pass), the lost quotes
(the awk apostrophe, a dropped closing quote in a literal and in a variable; must fail with the line), and three
unreadable bodies (must fail). Wired into ci.yml next to the copied-sources check, self-test first. The current tree:
7 inline bodies in 3 playbooks, all parse. packaging/README-ship.md: the job-script rule (body to a file, bash <file>).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:38:41 +00:00
igneum-labs
54132959be Merge origin/master (the explorer pages, the public API check, the CLAUDE.md note) into release-0.3.10; docs, site, observer and ci.yml only 2026-10-05 21:32:17 +00:00
igneum-labs
5c808b89e0 Ember Tune: every card tuned for MH per watt out of the box, the fleet prior per card model in the signed manifest, the console and /miners priors table
the project lead, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (423936b, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (057f0ec). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.

- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
  (power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
  neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
  the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
  no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
  no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
  probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
  tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
  Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
  {json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
  control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
  query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
  switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
  median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
  make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
  tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).

Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt the project lead cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:25:09 +00:00
igneum-labs
36c5f13a5f fast-time: the proving v1 fields and pow_genesis_dataset_log2 in both override files (the fork's every-field test), README rows; class-v3.mjs reports the build time per epoch; docs/plans/counter-asic-2-node.md (the node side of Counter ASIC 2.0, gate result pending)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:04:39 +00:00
igneum-labs
ffa2633845 docs/analysis/amd-proving.md: no zkVM proves on AMD (SP1, RISC Zero, Jolt, OpenVM, ICICLE cited), the SP1 CPU prover measured on PC 1 beside the miners (282 s a shard at any size, 30 GB RSS: no CPU tier), the tier consequences and the public line; PC 1 job scripts with the bash -n gate; bench-log entry
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:02:59 +00:00
igneum-labs
28635b165f Metal worker compiles a class v3 program from the pack a prepare line names; igneum-pow chain_dataset_day seam; pow_genesis_dataset_log2 in the override files
main.swift: servePackProgram reads program.h with the packfile.h checks (generator 2 or 3, the class line against
the generator, the seed bytes, IGNEUM_SEEDW_INIT against attempt_words, class and era against the line) and
compiles program_bound.metal; the program store keys on (seed, class, era); a v3 job with no resident v3 pack
program answers need + error; v2 lines unchanged (Swift generation, the variant race); a pack program never races.
verify.rs: Epoch::chain_dataset_day(day, class, days_since_genesis, genesis_dataset_log2) and days_since_genesis,
the entry the node builds every day cache through (the ca2-mixer growth rule fills the body).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:51:24 +00:00
igneum-labs
192aa3b83c app: Power control setting (default off): the app never asks for administrator rights on its own
the project lead, 5 October 2026: "if we don't have to ask then don't ask". The NVIDIA power cap and the efficiency sweep need
administrator rights (one UAC prompt); PC 1 raised that prompt for cmd.exe at every app start and every sweep attempt
(17:00, 17:30, 18:12, 19:04 UTC today, each cancelled unanswered after 2 minutes; the "Windows Command Processor"
the project lead saw).

- config.rs: `power_control` (default OFF on every machine); `sweep` default becomes off and is implied by it (an
  install carrying sweep = true without power_control is migrated to off on load).
- engine.rs: `elevation_allowed(power_control, sweep_only)` gates the power cap (`power_cap_plan` builds nothing when
  off, the card note says so), the sweep scheduler, Sweep now, the sweep helper; no prompt on quit (the limits reset at
  the next reboot); no second prompt through PowerShell when the window host's prompt goes unanswered.
  Cmd::PowerControl(on): on = ONE prompt at that moment (every NVIDIA cap in one step), off = nothing asks;
  `power_control_after_prompt` turns a refused, cancelled or unanswered prompt into "power control off:
  administrator rights were not given" (switch back off, sweep off, no retries). Unit tests: off builds no elevated
  command; on + refusal gives the notice; rights given keeps it on.
- platform.rs: `elevated_failure` maps the launcher's exit 251 and the "canceled" wording to the prompt, any other
  code to the step itself.
- server.rs: POST /api/power/control {on}. ui: the Power control switch with the line "Windows asks for administrator
  rights once; the cap and the sweep need them", the note beside it, the sweep switch disabled while it is off.
- The clock-sync prompt stays behind the Sync clock button only (unchanged).
- tools/windows/power-prompts-off.ps1: the 0.3.9 job that switched PC 1's sweep off through the API it has
  (run-20261005-192313: sweep True -> False; the 0.3.9 cap has no off switch, it asks at an app start only).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:43:33 +00:00
igneum-labs
574cccd456 fast-time: program_class_v3_activation_daa in both override files (never), the README row, and class-v3.mjs, the rollout gate G4 script
class-v3.mjs: a 3-node private network (ports 29600 and up, igneum-devnet-960) on override-60x.json merged with
a CPU genesis difficulty (0x1f010000) and the class switch a few epochs ahead (default 150: inside epoch 2 at
60 DAA per epoch, so the switch rounds up to epoch 3 at DAA 180); one real CPU miner per node; reports blocks on
each side of the boundary, the class and program id of every epoch, rejected blocks (miners and nodes), the
sinks and block counts of every node, and every node's switch line; exit 0 when every check passes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:40:30 +00:00
igneum-labs
344cba8e8c Proving v1: the memory sweep and the miner-on peaks, the root-socket class fix (cleanup lines, tools/ci/prover-socket-check.sh in CI), the host's --budget re-plan and the S_p curve job, the RAM and aggregation-card gates, N = 8 in the fast-time file and spec 7.4
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:35:13 +00:00
igneum-labs
d4848453ae Proving v1: the chain of 8 on the 5090 measured (N = 2, 4, 8: 32.6, 66.8, 135.6 s; chained aggregation 9.7 s a block on a mining card), the fleet table re-cut on the measured rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
470b6a884f pc2-chain.ps1: the export goes through curl.exe to a file (Invoke-WebRequest's Content is a string; the first run failed on WriteAllBytes)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
3fcf4f705c Proving v1: the harness passes (21 checks), the bench-log entry with the step 1 GPU memory, RAM and SM-target numbers, the CPU chain of 2 and verify-segment
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:14 +00:00
igneum-labs
55ea10cc26 Proving v1: prover on by default, the aggregated segment record, host modes chain, aggregate and verify-segment, the app's aggregator step, spec 7.8, the fast-time harness and the coverage tool
Step 1: app/igneum-app/src/provedefault.rs decides once per install (NVIDIA 12 GB or more, WSL2 answering on
Windows, Linux native, Apple silicon off until measured), never switching an explicit on back off; the Settings
switch line and the tile line say why (5 unit tests). tools/proving-v1/pc2-prover-cost.ps1 is the PC 2 job
(5 min mining alone, 5 min with the prover, GPU memory and host RAM peaks, the sp1-gpu-server's SM targets).

Step 2: the host gains --mode chain (consecutive fixtures, each block aggregated with the previous block's
proof by recursion), --mode aggregate (the live aggregator over shard proof files, a run of blocks in one
process) and --mode verify-segment (the node's verifier against the pinned aggregator key); the app's prover
loop gains aggregate_once (spec 7.8). Eight consecutive live fixtures (blocks 81046 to 81053, node 1's export
at tip 81076) under proving/fixtures/chain/. tools/proving-v1/pc2-chain.ps1 is the PC 2 job (held).

Steps 3 and 4: tools/proving-v1/coverage.mjs (the proven-block share and the on-chain latency from one node's
RPC), tools/proving-v1/net.mjs (the fast-time 3-node harness on 29950+ with the known-finished and
known-failed cases of the chain rule and the unproven rule), the four proving_v1 fields in
infra/fast-time/override-60x.json. Spec 7.8, the 7.4 rows, the 5.3 sentence, docs/plans/proving-v1.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:21:04 +00:00
igneum-labs
84d6d28253 Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI
Fed by /api/explorer from the observer's tables. Latest blocks (hash, number, DAA, blue score, miner, txs, proof
records, time); a block's header, parents, children, mergeset, coinbase outputs, EVM transactions, shards, checkpoint
and certificate; an address's blocks, what they earned, vote keys and balance (eth_getBalance when EXPLORER_EVM_RPC is
set). Same tokens as live.html. vercel.json rewrites /block/:id and /address/:addr; the footer links the explorer; the
link checker skips template literals and resolves /api/<name> to its function. node tools/site-serve.mjs previews the
site with the functions in-process.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
48d987cfb4 Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check
The numbers profitability sites and pool software read (WhatToMine's form: explorer or pool with an API, the halving
schedule, a source for total coins). Reward and supply from the emission rule at the node's DAA score; the halving table
(33 rows), the 30-day ramp and the observer's coinbase check. Cached 10 s, CORS open. FIELDS in each handler is the
contract; public-stats.test.mjs checks it from a fixture, tools/ci/public-api-check.mjs checks a deployment.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
8ffcdd2182 Observer: explorer detail per block from the notification, chain block number from the shard plan, RPC load counter, hourly coinbase check against spec 2.5
site/lib/emission.mjs is the emission rule as igneum.rs computes it (block_subsidy, launch_ramp, an exact floor-sum for
minted-so-far); its tests reproduce the node's own test values and a devnet coinbase (block 2622db76: payload 454,486,399
at DAA 125,064, outputs 454,485,299 = E(125,063), what the merged parent declared). Every live_blocks row gains tx_count,
evm_miner (the IGNA tag, else the vote key's low 20 bytes), proof_records (IGNP section), subsidy_sompi, paid_sompi,
selected_parent, number, detail. No extra RPC per block: measured 282 against 283 wRPC and 785 against 776 EVM calls
per minute before and after. live_state.rpc_load and live_state.supply_check are new.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:35:40 +00:00
igneum-labs
18f244bcfb Merge miner-ui-2 (6acfaed) into release-0.3.10: the miner UI in six sections (Mine, Prove, Rewards, Node, Updates, Settings), the node's switches and digest in the state, the prover's program ids, the 900 x 600 window minimum, view.test.mjs in CI
# Conflicts:
#	packaging/windows/push-build-inputs.sh
2026-10-05 19:23:33 +00:00
igneum-labs
cbe031b39c Merge gpu-hotplug (bd21f2a) into miner-ui-2: the hot-plug card states on the six-section UI
The Notices block takes the hot-plug notices as on gpu-hotplug (card added, not usable, removed). The View block
and the Mine rows, the first-run rows and the Settings cards show a removed card (dimmed, no switch, the row goes
after five minutes) and a faulty card (named in ember, the OS problem code, the reboot hint, no switch); the big
button and the counts take only present cards; the name tooltip carries the tool's code, the device, the platform
and the PCI address. view.test.mjs covers the two states. host.cpp keeps both the WM_GETMINMAXINFO and the
WM_DEVICECHANGE cases.

Build tooling: push-build-inputs.sh and build-job.mjs take --no-node (the app engine only, no node source, no node
build, no node tests), for an app-only PC compile.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 19:20:16 +00:00
igneum-labs
1065b81d05 relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14)
Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:46:13 +00:00
igneum-labs
b36beeee5d Merge gpu-hotplug (bd21f2a) into release-0.3.10: cards re-enumerated every minute and on WM_DEVICECHANGE, one row per physical GPU, Code 43 cards marked, integrated GPUs off by default, the cards line in the console 2026-10-05 18:21:07 +00:00
igneum-labs
d905730d45 Merge c4-fix (3e129ee) into release-0.3.10: the certificate-driven reorg in spec 3.5, 3.2, 3.10, 3.11.7, ledger C4, bench-log; c4.mjs v2 mode; the signer never piped into head (signer-pipe-check); one build-inputs zip per job
# Conflicts:
#	docs/bench-log.md
2026-10-05 18:20:50 +00:00
igneum-labs
3e129eeb5c C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning)
Fork: vendor/igneum-node-c4 branch c4-fix on release-0.3.6 a24ab01a.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:17:36 +00:00
igneum-labs
948e20f2d0 Merge tx-gossip (fe635ed) into release-0.3.10: the EVM relay design note, rows 463 and 9 closed, the 3-node relay harness and its evidence 2026-10-05 18:00:03 +00:00
igneum-labs
135f67ab2a Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 17:55:57 +00:00
igneum-labs
fe635edcfb EVM transaction relay: design doc 1.4 "Relay", rows 463 and 9 closed, bench-log entry, 3-node relay harness
Fork tx-gossip e242acd0 adds the inventory relay of EVM transactions (protocol version 14) and replaces the
4-second hand-out cooldown with the hold on block-added. Here: the relay paragraph in execution-layer.md 1.4,
the 10.2 table row (hand-out cooldown, now the block-added hold) and 10.3 item 9 updated, the bench-log entry
with the PC 2 suites (igneum-exec 15 of 15, kaspa-p2p-flows 33 of 33), the digest check (unchanged,
9409dedac4bf...) and the 3-node fast-time run (A - B - C, generator on A at 2/s: 240 of 240 included, B 151
and C 105 over two hops, p50 1.5 s, 0 skipped copies, pools equal on all three nodes at every sample), the
result JSON under docs/benchmarks/evm-relay-2026-10-05/, and tools/txgen/relay-net.mjs (the harness: three
nodes in a chain on the fast-time profile, vmine on B and C paid to throwaway keys, txgen on A, inclusion
counted by miner from A's executed chain).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:53:07 +00:00
igneum-labs
d7049fdfda app: GPU hot-plug (re-detection every minute, WM_DEVICECHANGE on Windows), faulty cards listed with the problem code, integrated GPUs off by default, the card list in the console
5 October 2026: an RX 9070 XT went into PC 1 through a Sonnet USB4 box while the app ran and nothing noticed; the
app detected cards once at start. Now src/hotplug.rs compares every enumeration with the list (key, else vendor +
name when unique; a card whose tool did not answer is never called removed): a new usable card starts a worker,
enabled by default like a card at start, with "New card: <name>, mining" on the strip and in the log; a card
Windows lists with a problem code (Win32_VideoController Status / ConfigManagerErrorCode) is shown as "<name>: not
usable (Code 43)" with the reboot-or-reinstall hint and no worker; a card that disappears has its worker stopped
(quit, 8 s) and its row says removed for five minutes, then hides; an unchanged list touches nothing. The Windows
host sends "detect" on WM_DEVICECHANGE; the engine polls every 60 s (300 s on macOS, no GPU hot-plug there).

detect.rs: the Ryzen iGPU is "gfx1036" to the OpenCL worker, so the APU gfx codes count as integrated, plus the
adapter row's Intel processor string and a dedicated memory under 1 GB; integrated defaults to off with "integrated
GPU, off by default (2 to 3 MH/s for 30 W)" on the row, and the user's choice is kept across re-detections and
restarts (settings, found by key or by vendor + name when the index moved).

Console: the engine logs "cards: <name> [<kind>, <state>] | ..." at start, on every change and every 10 minutes;
relay/lib/parse.mjs reads it and the hot-plug events, the machines API and tools/console.mjs machines show them.

Tests: hotplug.rs (added, removed, moved, errored, recovered, revived, unchanged, twins, user override kept,
the console line), detect.rs (PC 1's adapter lines, the Mac, kind classification, the unusable row),
notices.test.mjs (card notices), relay parse.test.mjs (cards line). cargo test -p igneum-app: 91 passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:45:05 +00:00
igneum-labs
7d09857f91 observer: a watchdog forces a reconnect after ten failed ticks (the live page went stale for an hour after a node restart)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:22:22 +00:00
igneum-labs
a96bcea470 Merge key-custody: key inventory, encrypted offline backup and restore scripts, the two-signing-key plan, a no-secrets CI check
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:53 +00:00
igneum-labs
addeb660fd Key custody: inventory, encrypted backup and restore, no-secrets CI check
docs/security/keys.md: every key the project depends on (the folder, the gh
keyring, the Vercel env of three projects, the GitHub secrets) with where it
lives, what it unlocks, the blast radius lost and leaked, who rotates it and
the rotation status, written from the files and the scripts that read them.
No value, no private fingerprint. Section 4: the second OTA signing key kept
offline, the app change (a key list plus revocation in the manifest), 0.3.9
as the carrier, and the emergency path if the one key leaks today (a manifest
signed with a new key is useless to 0.3.x apps; the mitigation in order).

tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's
own prompt (never argv, history or a file), the folder minus build-slots,
dlsite-dir and pytools/, plus a README; attached read-only, every file
compared by sha256, listed, detached. --dry-run lists. restore.sh: --check
compares the image against the live folder without printing values, --to
copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a
scratch folder with a throwaway passphrase, 8 steps, passed.

tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of
~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside
tests and the allowlist (the OTA public key, the published Hardhat and Anvil
accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits.

Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 17:01:01 +00:00
igneum-labs
8b4b1e500a Merge origin/master (974805b) into release-0.3.9: fud-a round 6, the entity imprint, the conflict-marker check; docs/bench-log.md both entries, the site taken from master and rebuilt (519 links, 0 broken) 2026-10-05 16:48:00 +00:00
igneum-labs
974805b9df ci: no conflict markers in tracked files (check + pre-push hook that also builds the site)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:45:09 +00:00
igneum-labs
ee7cfa9c27 Merge entity: Igneum Labs LTD and the DIFC address as the entity and contact everywhere, repository public at the public testnet, ledger published with it, no team page
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/fud-ledger.md
#	site/bench.html
#	site/index.html
#	site/journey.json
2026-10-05 16:42:40 +00:00
igneum-labs
02b19ed761 Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:41:38 +00:00
igneum-labs
8703d9e731 Merge fud-a: ledger sweep round 6 (11 fixes closed with rollout evidence, M1/M11/M16/M21/P3/P9/P14/X5 measured, C4 finding, F16 options)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	docs/bench-log.md
2026-10-05 16:33:15 +00:00
igneum-labs
fb32312383 Merge remote-tracking branch 'origin/master' into release-0.3.9 2026-10-05 16:32:53 +00:00
igneum-labs
ef3cbaf4f5 Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	tools/build-job.mjs
#	tools/ship-app.mjs
2026-10-05 16:30:47 +00:00
igneum-labs
3a96e7371c Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000
Conflicts: proving/igneum-prove/export/src/main.rs (the two use lines: master's ensure kept, fee-switch's FeeParams and FeeSchedule taken, SHARD_PROVING_GAS_BUDGET gone), docs/bench-log.md (both entries), docs/testnet/README.md (both sentences), site/index.html and site/journey.json (master's, then node site/build.mjs: 518 links, 0 broken).
2026-10-05 16:28:21 +00:00
igneum-labs
24aaa0e254 Prover mirrors the fee switch: both tables and fees_v1_activation_daa in the shard input, guest re-pinned, devnet runbook for H = 210,000
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.

Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:24:35 +00:00
igneum-labs
142ca73731 Merge txgen: the devnet transaction generator, proving watch, exporter block reconstruction fix with node-plan fixtures, bench log and evidence
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:22:26 +00:00
igneum-labs
3be4e3ef2a txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed
tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.

Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.

Bench-log entry and evidence rows 15 and 21.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:18:32 +00:00
igneum-labs
d9736b3c06 Merge testnet-infra: testnet seed profile, DNS and RPC installers, build-job watcher fix, docs/testnet, the go checklist
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:05:16 +00:00
igneum-labs
f2416a39de build-job.mjs: the watcher reads the SUMMARY wherever it sits in the report (the closing report starts with the app header; two finished builds showed as still running on 5 October 2026)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:02:47 +00:00
igneum-labs
e6a3f8bab1 FUD sweep round 6 (evening, 5 October): eleven rolled-out fixes moved to Fixed with live measurement lines, F21/F22 shipped but switch not thrown, M20 closed on the 0.3.5 merge; P14 one base-fee definition in spec 05; M16 recompute-attacker cost model; C4 overlay-against-GHOSTDAG runner
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 16:02:02 +00:00
igneum-labs
a015f67eac Merge public-release: token-free public downloads, site buttons with live versions, HiveOS 0.3.8 package, the faucet (prepared)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

# Conflicts:
#	site/index.html
#	site/miner.html
#	site/wallet.html
2026-10-05 16:01:08 +00:00
igneum-labs
53dae0ddf1 release-0.3.6 plan: the two finality tests under the parallel suite answered (fork 7003055b); build-job.mjs forwards --node-tests, --app-tests, --no-app
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:59 +00:00
igneum-labs
3551069c51 Public testnet launch, the public side: dl/public downloads path, site download buttons, HiveOS package, faucet
Downloads: packaging/ota/publish-public.sh publishes the current installers, the HiveOS package and the two signed
manifests into dl/public/ with no token in any URL, writes the four /public/ aliases as vercel.json rewrites and an
unsigned index for the site; publish-manifest.sh --public and ship-app.mjs --public run it on every release (dry run
and self-test cover it). Nothing removed from the token folders.

Site: the miner and wallet buttons link the public aliases and show the version and size from the index, read at
build time (site/downloads.json is the offline snapshot); TESTNET_OPEN in build.mjs drops the "Public testnet: not yet
open" line on the go; the HiveOS Flight Sheet install line on the miner page; /faucet page.

HiveOS: igneum-hive-0.3.8.tar.gz from the 0.3.8 node (2b6d23ef, PC build job) and the zig-built Linux workers.

Faucet: site/api/faucet.mjs (10 IGN per address and per IP per day, Neon table faucet_grants, EIP-1559 transfer signed
by site/lib/eth.mjs with no dependencies: keccak, RLP, secp256k1 with RFC 6979), FAUCET_KEY and FAUCET_RPC from the
Vercel env only; 15 unit tests with a fake database and node, run in CI.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:59:31 +00:00
igneum-labs
6cecbd4c67 jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:52:34 +00:00
igneum-labs
72351e8270 Testnet seeds: NET=testnet profile for the seed scripts, seeds-testnet.tsv (3 Hetzner VMs), dns.sh (deSEC), the public RPC allowlist and nginx site, build-job.mjs forwards --node-tests
seed1.testnet nbg1 195.201.35.33, seed2.testnet ash 5.161.232.205, seed3.testnet sin 5.223.52.210 (5 October 2026). Ports 26810/26811/28810/26890
from seed.env; provision-seed.sh BUILD_WHERE=cross takes the PC build job's Linux igneumd from infra/cross/out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:46:22 +00:00
igneum-labs
9a204e2266 rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:37:02 +00:00
igneum-labs
7f1884290a ci: the pinned-guests check ignores comment lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:01:38 +00:00
igneum-labs
64009a676a Proving: pinned guest programs, the verifier on SP1's light verifier
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.

- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
  host/src/pinned.rs embeds and checks them at every start; the prove modes
  refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
  setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
  guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
  builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
  the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
  and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 12:54:31 +00:00
igneum-labs
9addfe672c Merge release-0.3.6: Igneum Miner 0.3.6 and 0.3.7 (instant jobs, verifier on every node, one notice strip, latency, packaged config, hidden windows, WSL scripts from files, runtime DLL gate)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 10:31:04 +00:00
igneum-labs
a0e092d109 Igneum Miner 0.3.7: the Windows runtime DLLs come from the toolchain that linked the exes, and a gate refuses a payload whose exe imports a symbol the shipped DLL lacks
0.3.6 on both PCs: igneumd.exe (built on PC 1 with GCC 13's mingw) shipped with the Mac toolchain's GCC 16
libstdc++-6.dll, which no longer exports seven symbols the exe imports (std::codecvt_utf8_utf16 and a
stringbuf::seekpos); Windows refused the node with Entry Point Not Found. -C link-arg=-static had never removed
the libstdc++ import (0.3.5's Mac-built exe carries it too).
- packaging/windows/check-runtime-dlls.sh: objdump imports per DLL against the DLL's exports; shown to fail
  the 0.3.6 pairing (7 missing) and pass 0.3.5's; run by push-inputs.sh before signing and by make-payload.sh
- push-inputs.sh: DLLs next to the exes first, then the Mac toolchain
- jobbuild.rs: the PC's windows stage copies its own toolchain's three DLLs into the pack (unit test);
  build-job.mjs accepts the small DLL PE files and places them next to the exes
- cross-build.sh: -static-libstdc++ added as a try (measured on the 0.3.7 build)
- the six version files: 0.3.7
2026-10-05 09:46:49 +00:00
igneum-labs
aa9b4da932 Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 09:12:38 +00:00
igneum-labs
0f6fc2ead5 Merge rotation-2 (7c9a939) into release-0.3.6: packaged config from files, --dl-both, logs --rotation; windows.yml keeps the G13 signed-inputs step after the packaged configuration step 2026-10-05 08:33:37 +00:00
igneum-labs
fc137257ed Merge origin/testnet-adopt (3be4501) into release-0.3.6: testnet identity, adopted fee table (spec 05 section 5.11 next to the security budget 5.10), G13 signed inputs; plan documents combined, site rebuilt 2026-10-05 08:32:40 +00:00
igneum-labs
2edc5f693c Merge job-wake: instant job wake-up (relay /wake long-poll, 2-minute fallback poll, publisher wake)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:26:07 +00:00
igneum-labs
7e0fc7da65 publish-jobs: wake the apps after a verified deploy; jobs.mjs status shows the woken latency; 0.3.6 plan
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.

tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.

docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:22:02 +00:00
igneum-labs
37c947beb9 lock: build slots open to new builds come from ~/.config/igneum/build-slots (1 to 3)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 08:19:52 +00:00
igneum-labs
fd07ef569f Merge origin/testnet-prep (28f6ccc) into testnet-adopt: testnet identity, fee floors and pgas table adopted 5 October 2026, G13 signed build inputs, release-0.3.6 plan
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.

Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.

Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).

Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:44:22 +00:00
igneum-labs
7c9a939260 Rotation phase 2: packagers read the intake key and the downloads token from files (IGNEUM_INTAKE_KEY_FILE, IGNEUM_DL_TOKEN_FILE, .next by default), no key literal in the tree, app header line with fingerprints, ship-app --dl-both, logs --rotation, tools/repo/fresh-repo.sh with the dry run, docs/plans/rotation-phase-2.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 07:43:44 +00:00
igneum-labs
d791efd4be Merge origin/fud-consensus into release-0.3.5
bench-log.md: both appended entries kept (the round-4 consensus items and the red team next to the branch's own).
2026-10-05 02:19:41 +00:00
igneum-labs
e12f768e3c Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:56:28 +00:00
igneum-labs
90478b5cf4 Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:49:46 +00:00
igneum-labs
a32b10aad8 Merge branch 'redteam' into fud-consensus
# Conflicts:
#	docs/fud-ledger.md
2026-10-05 01:34:21 +00:00
igneum-labs
2cb3d88bca fud.mjs: node logs kept per scenario, pre-F24 refusal wording counted, reorg criterion as the rule promises; first-pass and control results kept
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:34:04 +00:00
igneum-labs
d80b384360 Merge remote-tracking branch 'origin/master' into release-0.3.5 2026-10-05 01:14:23 +00:00
igneum-labs
d9182273ce Merge branch 'fud-memory' into fud-consensus 2026-10-05 01:12:27 +00:00
igneum-labs
be99cb3821 Lock: three run slots for functional runs; a measurement waits for all of them
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:10:17 +00:00
igneum-labs
4b26d04bc0 Red team 4 Oct 2026: every attack suite against the 0.3.4 finality-fixes build (rule v3 on, fast time); 30 scenarios, ledger F25 M30 M31 new, F21 F23 F24 measured
Report docs/review/redteam-2026-10-04.md: finality attacks s1-s8 plus 34% withholding, 50/50 long partition, F23 and
F24 custom runs, ordering harness, execution suite and EVM smoke, proving hostile tests and a proof flood, difficulty v2
timestamp forging in the simulator. New fails: the fast-time harnesses corrupt the u64::MAX sentinels of the override
(F25), a block or transaction flood grows the node by hundreds of MB in a minute (M30), the coinbase does not fit the
204-byte limit on mainnet, testnet and simnet parameters (M31). F23 and F24 reproduced on this build; F21's bound
measured at one window of the side's own DAA. Scenario scripts under tools/finality-attacks/redteam/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 01:03:08 +00:00
igneum-labs
af8ae429f8 Harness: port and data-dir overrides, per-load RSS deltas, cache-build counts; bench-log entry for ledger M30
tools/harness: IGNEUM_HARNESS_BASE_PORT and IGNEUM_HARNESS_TMP move the test
network's ports and data directory so two agents can run it at once; the u64
sentinel round-trip in overrideParams is fixed with the BigInt reviver from
tools/finality-attacks (ledger F25); s6 records rss_start, rss_delta and
cache_builds per load and reports per-load growth (the old row subtracted one
baseline taken before all three loads, which is how the mempool flood was
read as +270 MB); s7 counts "PoW cache built" lines beside every RSS sample;
--live-only skips the s7 simulator part.

docs/bench-log.md: the 4 October 2026 (night) entry: the floods' growth was
one 256 MiB PoW cache per epoch roll (the engine kept a cache per (epoch,
day) pair, KEEP 4), measured before and after the fork fix (fork branch
fud-memory, 796f758d): submit load +263/+257 MB with 1/1 builds before,
+9/+2 MB with 0/0 after; block flood 302 to 1,085 MB with 3/3 builds before,
300 to 315 MB with 0/0 after. Result JSON under
docs/benchmarks/memory-floods-2026-10-04/.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 00:38:33 +00:00
igneum-labs
22aa692779 Round-4 consensus items: the fud.mjs runner (digest, ban, reorg scenarios on the fast-time 3-node network, ports 29400+), per-node override files and --equivocate-at in the harness, spec 02 section 2.8, spec 03 C1/C4/3.6 and the 3.10 rows, spec 08 section 8.7
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 23:53:35 +00:00
igneum-labs
29e3a0c1d3 Merge origin/dev-fee (96270bd) into release-0.3.5
bench-log.md: both appended entries kept; the generated site pages rebuilt with node site/build.mjs.
2026-10-04 23:16:45 +00:00
igneum-labs
bfea36330e Dev fee: the test-network measurement in the bench log; run.mjs waits for the nodes and edits the override as text
9 fee blocks in the 785 blocks of the two fee-paying miners (1.15%, expected 1 in 100 templates), the miners' fee
counters equal the chain's count on both nodes, the control miner at --dev-fee 0 paid nothing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 23:15:27 +00:00
igneum-labs
7210fd4683 Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
  S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
  cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
  The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
  its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
  Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
  identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
  payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
  windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
  uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
  after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
  decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
  miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
  and the link check pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:54:56 +00:00
igneum-labs
cfb937b42d Merge origin/miner-reliability into release-0.3.5
Conflicts resolved keeping both: engine.rs carries the sweep state (miner-eff) and the node watchdog (reliability);
the STATUS line goes through watchdog::parse_status and still feeds the sweep's rate sample; main.rs declares both
modules; bench-log.md keeps both entries. site/build.mjs keeps master's partial-injected pages and adds the /miners
bench table through the same page() with active: 'miners'; the Miners link is in site/partials/nav.html; sitemap
gains /miners; every generated page rebuilt with node site/build.mjs.
2026-10-04 22:25:10 +00:00
igneum-labs
cad8aa0d96 Reliability measured: miner guards and the app watchdog on private test networks; M26, M27, X21 fixed in the ledger
docs/bench-log.md: the fake-worker measurements (slow start one trip and 2.0 s restart, fake-fast guard in under
0.1 s, exit 43 at 8.8 s, CPU re-check stop at 0.5 s, stall guard at 60.1 s with STATUS lines through the silence,
one prepare per epoch with refused retries held; app: zero-rate restart at 79.6 s and faulted at 75.4 s on the
repeat, no-status restart at 90.4 s, silent node restarted at 150.7 s and synced 7.2 s later; no double restart on
the miner's own worker restart). Two defects the harness found are named with their fork commits.
docs/fud-ledger.md and the round-4 review table: M26, M27, X21 Fixed with the commits.
engine.rs: the miner's restart note no longer hides the fault reason on the card.
tools/reliability: the harness matches the miner's stderr lines where they are printed there.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 22:22:16 +00:00
igneum-labs
ec843737c2 Merge origin/dev-fee into release-0.3.5
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
2026-10-04 21:48:04 +00:00
igneum-labs
1028c2579f Miner dev fee: app switch and UI line, HiveOS package, Linux worker cross-build, docs and public text
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.

- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
  "dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
  miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
  with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
  stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
  proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
  docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
  miner section note

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:46:41 +00:00
igneum-labs
1867a4819b Merge origin/build-job into release-0.3.5
Conflict resolved: publish-jobs.sh keeps master's verify command and --tries (the retrying live check) alongside the
build kind's arguments; the usage range covers the merged header.
2026-10-04 21:32:48 +00:00
igneum-labs
ca2ac6dfa8 Merge origin/miner-perf into release-0.3.5
Conflicts resolved: state.rs keeps both the sweep fields (miner-eff) and the race fields (miner-perf); bench-log.md
keeps both appended entries; publish-manifest.sh keeps master's --override implementation (8082576, the "every
height switch" rule, --verify-only, --tries, the retrying live check) and adds miner-perf's --tuning / --no-tuning
with the carry-over of consensus.override and tuning from the current manifest. One --override case, one parser.
2026-10-04 21:31:26 +00:00
igneum-labs
e24516934a Merge remote-tracking branch 'origin/app-ui' into release-0.3.5
# Conflicts:
#	app/igneum-app/ui/app.css
2026-10-04 21:28:59 +00:00
igneum-labs
cda444bbee READMEs: the console's Machines card as it is now (stale, stopped, OTA state, vendors), the parser tests, autosync's restart key and check mode, the observer's dependence on the app's node for proving
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 21:14:45 +00:00
igneum-labs
0d51aafee7 Observer: logs the seeded checkpoint states at start and names the earlier state when a lock is recorded over one (index 1319 re-recorded 14 min after its lock at the 20:15 restart)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:19:59 +00:00
igneum-labs
66c0bf2a6d Observer autosync: the restart key is observer.mjs and run.sh, not the whole tools/observer tree (an autosync.sh change restarted the observer for nothing)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:18:32 +00:00
igneum-labs
9f0c9036ea Build job: a PC builds the node and the app engine for Linux and Windows inside WSL2, mining untouched
New job kind `build` (jobs.rs, jobbuild.rs, jobrun.rs run_build): free-space check on both sides (20 GB), the
build-inputs zip by sha256, setup inside the distro as root (mingw-w64 posix, clang for bindgen, protoc, zstd, the
Windows rust target; idempotent), sources extracted with the target dir persisting under /root/igneum-build,
cargo build --release native and for x86_64-pc-windows-gnu, cargo test for the manifest's packages, binaries
zstd-compressed and sent to the relay (fn=upload, Blob PUT, fn=drop; 50 MB each) with sha256 in RESULT lines,
STAGE lines with UTC times, a 40-minute default budget and per-stage caps, the Linux side killed on a cap. The
app's runner stays serial (one Active at a time), so a build never overlaps a shard job; nothing stops the miners.
From this version an unknown job kind is skipped by the app (parse_lenient) instead of rejecting the whole file;
the signer stays strict.

Mac side: packaging/windows/push-build-inputs.sh packs a fork worktree, app/igneum-app, brand/icons and
proto-cuda with a manifest (branch, commit, dirty, builds, tests) and the sha256; publish-jobs.sh add --kind build;
tools/build-job.mjs packs, publishes, watches, fetches, checks both sha256 per file and the PE header of every exe
(plus verify-exe.py on igneum-app.exe), and places the binaries where push-inputs.sh, make-payload.sh and the
cloud-devnet scripts look. relay.mjs drop <file> --body carries the body.

Tested on the Mac: 33 app tests (6 new) and the signer's 21; cargo check for x86_64-pc-windows-gnu; the packer
(7.9 MB zip, no target dirs); the publisher against a scratch folder with the rebuilt signer, the old signer
refusing the kind, a bad job refused at signing; the fetch path against the live relay with a real exe (sha256
and PE pass, a wrong sha256 refused; test items deleted). Not run on a PC: the job itself. docs/plans/build-job.md
has the first job for PC 1 and the rollout order (0.3.4 must be on the PCs before a build job is published).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:17:55 +00:00
igneum-labs
2b3ce1c7e3 Observer autosync: a failed fast-forward names git's reason and the dirty files the incoming commits also touch
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:14:21 +00:00
igneum-labs
b98a528c9a Merge branch 'master' of https://github.com/igneum-network/igneum 2026-10-04 20:06:13 +00:00
igneum-labs
7d30c5f160 Merge branch 'igneum-wt-finality'
# Conflicts:
#	docs/bench-log.md
2026-10-04 20:06:11 +00:00
igneum-labs
21ccb65f40 Console: a machine whose app logged a clean quit or an update, with no status line after it, shows 'stopped (quit|update) N ago' instead of 'silent' (parseAppTail moved to relay/lib/parse.mjs, test)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:04:18 +00:00
igneum-labs
2bb0728eb2 Finality rule v3 (ledger F21, F22): simulator scenario M, spec 03 Q4/Q5, cloud vote-timing analysis, v3 harness runner, fast-time profile, bench-log entry, devnet rollout plan
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 20:04:12 +00:00
igneum-labs
c924e9d30a Miner app UI: log drawer rebuilt (open state, scroll to newest, time jump, last error and swap, search, copy, drag height, virtualised), every screen on one scale, canvas and polling idle when hidden
Log drawer: the Logs button shows its open state (Close logs, chevron); a Newest button appears when the user scrolls
up and follow re-engages at the end; a time ruler with error and swap marks, an HH:MM:SS jump box, last error and last
swap buttons; substring search with a match count and highlights; copy the lines in view; the height drags from a grip
(140 px to 70% of the window, remembered); a window under 700 px tall opens a 180 px drawer. The list is virtualised
(19 px rows, only the rows in view in the DOM; up to 20,000 lines kept; wrap mode under 5,000 lines). Polling runs only
while the drawer is open and the window is visible.

Screens: one type scale and spacing scale in app.css, tabular figures everywhere, the bottom bar in pieces (machine name
truncates first, address always short, uptime dropped under 1100 px), tile captions carry their full text as a title,
syncing shows an ETA from the measured block rate, the engine-away state names itself on the node tile, short-window
rules, the key sheet scrolls on a short window, compact settings card rows on two lines, only a block that just arrived
flashes (not the whole strip on first paint).

Performance: the minute grid is drawn once into an offscreen layer; the strip redraws twice a second and at the display
rate only during a flash; nothing draws and the state poll drops to every 5 s while document.hidden. ?debug=1 prints a
budget line every 5 s and exposes window.__igneumBench.

tools/ui-mock: a stand-in engine (node tools/ui-mock/server.mjs) replaying recorded, scrubbed API responses with
scenarios (syncing, nodedown, nocards, integrated, clock, paused, biglog, fresh, job, nvidia), so UI work never
touches a running miner.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:51:22 +00:00
igneum-labs
4a32962417 Observer autosync restarts the observer whenever the checked-out tools/observer tree changes (marker + check mode); console stale mark at 180 s (one missed upload is not stale); bugs.md rows
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:48:45 +00:00
igneum-labs
8e243dfd3e Observer: one checkpoint_locked event per index (the poll claims the state before its first await; the FinalityLock notification path raced it and the live feed showed two locked lines 30 ms apart); a lock claimed by the notification gets its votes_seen from the next poll
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:34:57 +00:00
igneum-labs
df5f144642 Relay: secrets compared in constant time (relay/lib/auth.mjs, unit test in CI), HSTS header, tools/relay.mjs prints /r/<token> in list and watch (round 4, X28 and X24 part)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:31:22 +00:00
igneum-labs
a601321481 App engine: watchdog per card and per node, WORKER FAULT and mismatched= read from the miner; public GPU bench table and the reliability test harness
Review round 4 X21 and the project lead's levers 5 and 6 (4 October 2026 evening):
- src/watchdog.rs: CardWatch (no status line for 90 s, or hash rate 0 for 60 s while the node is synced: one
  restart, then the card is marked faulted with the reason in the UI and the log; the miner's own worker restarts
  suspend both rules until ready, so there are no double restarts; exit 43 counts as a watchdog restart) and
  NodeWatch (our node silent for 120 s is restarted in-process through the restart kind the remote jobs use, with a
  growing delay). State machines with no clock; 11 unit tests replay recorded STATUS and WORKER FAULT lines.
- engine.rs reads STATUS mismatched=, faults= and the WORKER FAULT lines onto the card (faults, mismatched, message);
  a faulted card is not restarted until the user changes its settings or resumes mining; other cards keep mining.
- site/miners.html (build.mjs, scrubbed like /bench, rows from site/miner-bench.json): card, generator version, best
  MH/s, MH per watt where measured, miner version, date, source, measured by the team or reported by the fleet. In the
  navigation beside the engineering log on every page and in the sitemap. One line says there is no other miner to
  compare with.
- tools/reliability: fake-worker.mjs (the serve protocol, misbehaving on command), run.mjs (miner guards on a private
  test network, ports 29950+) and app-run.mjs (the app watchdog end to end, ports 29960+).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:20:49 +00:00
igneum-labs
9915c883b1 Bug hunt: console cards for other/intel workers and a stale mark on old STATUS lines (relay/lib/parse.mjs + test in CI); publish-jobs verifies the live file with retries and named reasons, a verify command, a failed deploy stops, a collect command without $_ is refused; the dl token masked in printed URLs; docs/bugs.md
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:15:05 +00:00
igneum-labs
b06ba68a4d Lock: three build slots, exclusive measure, run mode, status command; replaced atomically
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:12:26 +00:00
igneum-labs
713fb56cf4 CI identity grep: .log files get the generic scrub too; the 4 October difficulty record carried a home path (every master run red since c01b954)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 19:09:09 +00:00