tools/txgen/run.mjs funds generated wallets from the devnet dev-fee key and sends transfers at a steady rate through
one node (nonce tracking from the pool's pending nonce, two-strike drop verdict, pool back-pressure counted as
deferred, spend cap, clean stop, summary JSON); tools/txgen/proving-watch.mjs watches the proving layer and builds the
per-block report. Two runs through the Mac node: 2,275 sent at 2/s, 2,161 included at 1.86/s (run 1), 1,650 sent,
1,633 included at 1.71/s with no failure (run 2, fixed code). Block 72704 shard 0 (29 transfers, 5,800 pgas) proven on
PC 2 in 34 s, verified on the Mac in 0.297 s, paid 1.7623 IGN.
Block 72803 (seven skipped copies, no executed transaction) failed the native-execution veto: the exporter rebuilt the
including blocks from an export that names no block, position or skipped copy's miner, sorting skipped copies out
of their block, merging consecutive blocks of one miner, dropping empty blocks (the node counts them in the link's
block index) and guessing the zero address. blocks_of now rebuilds from the 0.3.9 export's "blocks", "block" and
"position" fields (the fork change on vendor/igneum-node-txgen branch txgen-export), keeps an old export in its
order and refuses a skipped-only block without a miner. Fixtures block-72803-skipped-copies and
block-72854-empty-block-first with the node's shard plan beside each; the fixture test now checks the cut's links,
roots, gas, pgas and counts against the node's plan (shown failing on the old 72854 cut). No change under core/.
Bench-log entry and evidence rows 15 and 21.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 13:19:41Z refusal on PC 2: fetch_jobs took igneum-jobs.json and .sig in two requests while the edge was
still serving the previous deployment for one of them. The signer wraps the verified pair into one object and
reads it back; the app fetches that object (the pair only when none is published); publish-jobs.sh writes and
mirrors all three files and verifies every folder after the deploy; tools/jobs.mjs reads the envelope.
Tests: jobs.rs signed_envelope_binds_file_and_signature, packaging/ota/test-publish-jobs.sh (24 checks).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
logs.mjs --rotation reads the old fingerprints from the dated .old-* files once the .next files are gone; fresh-repo.sh scrubs the dated secret files too; ship-app.mjs mirrors payload-inputs.json.sig.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
On 5 October 2026 the Mac's host (shard program id 0x0559759b...) rejected every
proof from PC 2's host (0x05db1aca...). Both were built from the same guest
sources: host/build.rs compiled the guests on each machine and the ELF depends
on where it is built (cargo's -C metadata for a path crate includes the checkout
path; a worktree on the same Mac gave a third id, 0x0dfade07...). The node's
verifier also spent 114 s to 138 s per proof in the prover client and both key
setups before a 0.1 s to 0.4 s verify.
- elf/: both guest ELFs, their verifying keys and manifest.json (sha256, ids);
host/src/pinned.rs embeds and checks them at every start; the prove modes
refuse when SP1's setup does not derive the manifest's id
- --mode verify: LightProver with the pinned key, no prover client, no key
setup; prints the proof's own program id next to ours ("IS NOT OURS")
- --mode id; igneum-prove-pin and pin-guests.sh to re-pin; build.rs builds a
guest only under IGNEUM_BUILD_GUESTS=1
- tools/ci/pinned-guests-check.sh: elf/ must match its manifest, no script
builds a guest outside pin-guests.sh; make-package.sh and build-dmg.sh print
the pinned ids
- unit tests on the pinned set; bench-log entry with the three ids, the cause
and the timing: 127.0 s wall per verify before, 1.8 s to 2.4 s after
- rollout order in proving/README.md: every prover and verifier moves together
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The fact: PC 2's exporter failed blocks 58,752 to 58,843 (and the task's 58,584 to 58,984) at
shard.rs:175, "shard 0 post-root from the witness", while three empty shards were later proven, verified and
paid. Every failing block is empty: one blue block, one reward, the pool credit, no transactions, no payouts
(igneum_exportSegments 0x0..0xe738 from the Mac node, fork 2b6d23ef). The proven block 59,507 has the same
shape and the same miner as the failing 58,927. So the difference is not block content.
The rule that differed: the planner's post-root of an empty segment. The exporter on PC 2 was a stale build
whose core predated commit d6d6153 (the assertion sits at line 175 there and at 179 since). That planner
returned root_at(end) for a segment with no transactions, which is the pre-root; the statement applied the
rewards and the pool credit, as the node does (vendor/igneum-node-036/igneum/exec/src/executor.rs,
execute_segment) and as spec 7.7 item 8 says. Left = the root after the rewards (the node's), right = the root
before them; PC 2's export log for 58,752 shows exactly that pair. Reproduced here: master's core with that one
rule put back fires the same assertion on 58,927 with left 0x7886b9cf (the node's root) and right 0xea9db302
(the pre-root). Master's core as it is reproduces 58,927 and 59,192 with the node's roots, the host's native
mode matches the fixture, and the SP1 executor runs shard 0 to post-root 0x7886b9cf.
So the prover core needs no rule change: the fix is commit d6d6153, which PC 2 received with the 10:49 and
10:52 UTC rebuilds (job-rebuild-prover-pc2-037 and 037b), after which its proofs were paid. What this commit
adds is the regression and the guard for the class:
- proving/fixtures/block-58927-empty-reward.json: the failing shape cut from the devnet (33 KB).
- proving/igneum-prove/export/tests/fixtures.rs: every fixture in proving/fixtures reproduces (block
statement, plan, every shard statement from its witness, the chain of roots and links), and the empty
segment's shard ends at the root after the rewards, never the pre-root. With the pre-d6d6153 rule put back
the test fails. The test lives in the export crate so the core's manifest, part of the guest build, stays
untouched.
- export/build.rs and host/build.rs stamp each binary with a hash of the native sources it was built from,
printed on the first line of every run, so a stale build names itself in the log instead of in a line
number (the stale-build class of 4 and 5 October).
- docs/bench-log.md: the row under the first paid proofs.
The guest is unchanged: built in one directory, this branch and master give byte-identical loadable segments
for the shard program and the aggregator, so no prover needs a rebuild for this commit. Noted on the way and
left open: the same sources built in three directories on this Mac gave two different guest ELFs, so the
program id is not yet a pure function of the sources on a native build.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
publish-jobs.sh --deploy POSTs the new stamp (published_at plus 8 hex of the file's sha256) and the added id to the
relay's /wake once the live file verifies. The relay token goes in a 600-mode header file, never on the command line
or the screen. Prints "woke the apps (stamp ...)" or a one-line warning; the apps' 2-minute poll still catches it.
tools/jobs.mjs status reads relay_wake (one row per publish with the ids it added) and prints "woken +N s after the
publish" for a machine's latest job that a publish added; nothing when the table does not exist yet.
docs/plans/release-0.3.6.md: "Instant jobs" section with the design, the expected latency and a TODO row per machine
for the measured number once 0.3.6 is live. packaging/ota/README.md: the 10-minute poll is history.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Fork release-0.3.6 final tip 2b6d23ef = a11455e7 (testnet-params merged, the fee height switch) + cf369022 (the
release dev-fee address 0x7F45d7d7272e57639BeBb739A60B05bB2CD4C126, docs/design/miner-dev-fee.md updated here) +
the miner-latency merge, which landed only after the miner suite (15 passed), the 3-node fast-time run (243 blocks,
0 rejected, 0 red, sinks agree, switched p50 46 to 52 ms) and the dev-fee harness (8 of 8 fee blocks on chain,
control at 0) passed on the merged tree.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.
Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.
Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).
Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
s8-steady.mjs: two nodes, one honest vmine miner at 1 block/s, no flood,
RSS and cache-build count every 60 s, vmmap -summary at 0, 500, 1,000 and
1,500 blocks. Both builds ran 1,500 blocks on the 60x profile: before
41 to 1,342 MB by 514 blocks (9 cache builds, five 256 MiB chunks resident:
KEEP 4 plus one evicted chunk the allocator keeps) then flat, 27 builds in
1,529 blocks; after 319 MB at 510 blocks (1 build), 589 at 1,029 (the second
day's cache, by design), 603 at 1,526, 2 builds. Residual 30 MB per 1,000
blocks on both builds, read as the consensus database and caches filling,
not the PoW cache. JSON and vmmap files under
docs/benchmarks/memory-floods-2026-10-04/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
s6 +6/+3/+1 MB per load, s7 302 to 318 MB, 0 cache builds, epochs 0 to 3
rolled, 202 blocks accepted; the pass-1 column stays beside it. Result JSON
after-{s6-exhaustion,s7-flood}.json added. The s6 one-instant sink check is
noted as a harness flake.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Report docs/review/redteam-2026-10-04.md: finality attacks s1-s8 plus 34% withholding, 50/50 long partition, F23 and
F24 custom runs, ordering harness, execution suite and EVM smoke, proving hostile tests and a proof flood, difficulty v2
timestamp forging in the simulator. New fails: the fast-time harnesses corrupt the u64::MAX sentinels of the override
(F25), a block or transaction flood grows the node by hundreds of MB in a minute (M30), the coinbase does not fit the
204-byte limit on mainnet, testnet and simnet parameters (M31). F23 and F24 reproduced on this build; F21's bound
measured at one window of the side's own DAA. Scenario scripts under tools/finality-attacks/redteam/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/harness: IGNEUM_HARNESS_BASE_PORT and IGNEUM_HARNESS_TMP move the test
network's ports and data directory so two agents can run it at once; the u64
sentinel round-trip in overrideParams is fixed with the BigInt reviver from
tools/finality-attacks (ledger F25); s6 records rss_start, rss_delta and
cache_builds per load and reports per-load growth (the old row subtracted one
baseline taken before all three loads, which is how the mempool flood was
read as +270 MB); s7 counts "PoW cache built" lines beside every RSS sample;
--live-only skips the s7 simulator part.
docs/bench-log.md: the 4 October 2026 (night) entry: the floods' growth was
one 256 MiB PoW cache per epoch roll (the engine kept a cache per (epoch,
day) pair, KEEP 4), measured before and after the fork fix (fork branch
fud-memory, 796f758d): submit load +263/+257 MB with 1/1 builds before,
+9/+2 MB with 0/0 after; block flood 302 to 1,085 MB with 3/3 builds before,
300 to 315 MB with 0/0 after. Result JSON under
docs/benchmarks/memory-floods-2026-10-04/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
attacks.py scenario 2 under rule v2 and Kaspa's DAA: a pulse never earns more blocks per hash than steady mining
(weight per hash 0.26 and 0.98); the economy simulator at the devnet's 124 MH/s; finality_sim scenario A (the
window is full on day 35 to 41 from zero history). The first fast-time s5 attempt failed on an override field the
integration build does not know; the re-run on the finality-fixes build is queued.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
9 fee blocks in the 785 blocks of the two fee-paying miners (1.15%, expected 1 in 100 templates), the miners' fee
counters equal the chain's count on both nodes, the control miner at --dev-fee 0 paid nothing.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
and the link check pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Spec 06 rows O-3.1, O-3.14, O-5.9 and O-5.11 carry the sweep's evidence (fix row 124 done). M20: the devnet's pruning
point leaves genesis between DAA 108,000 and 151,200, about 14:00 UTC 5 October to 01:00 UTC 6 October, after which a
fresh node rejects the honest pruning proof under the stub. The ledger ends with the sweep's status-update section;
the review file carries draft counts and the three findings.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Status lines updated from the bench-log, sim/results_v2.md, sim/difficulty/attacks and sim/economy where the
evidence existed and the ledger still said Open (M15, M17, M19, M24 fixed and live; F1, F7, F19, E12, E15 answered
with evidence; M26, M27, X21 fix built on miner-reliability; the rest annotated with what the experiment needs).
New: sim/economy/security_budget.py (E15 fee grid, price paths, hashrate response), fud-fixes section 2.5 (rows
117 to 126), docs/review/ledger-sweep-2026-10-05.md (the running table).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflicts resolved keeping both: engine.rs carries the sweep state (miner-eff) and the node watchdog (reliability);
the STATUS line goes through watchdog::parse_status and still feeds the sweep's rate sample; main.rs declares both
modules; bench-log.md keeps both entries. site/build.mjs keeps master's partial-injected pages and adds the /miners
bench table through the same page() with active: 'miners'; the Miners link is in site/partials/nav.html; sitemap
gains /miners; every generated page rebuilt with node site/build.mjs.
docs/bench-log.md: the fake-worker measurements (slow start one trip and 2.0 s restart, fake-fast guard in under
0.1 s, exit 43 at 8.8 s, CPU re-check stop at 0.5 s, stall guard at 60.1 s with STATUS lines through the silence,
one prepare per epoch with refused retries held; app: zero-rate restart at 79.6 s and faulted at 75.4 s on the
repeat, no-status restart at 90.4 s, silent node restarted at 150.7 s and synced 7.2 s later; no double restart on
the miner's own worker restart). Two defects the harness found are named with their fork commits.
docs/fud-ledger.md and the round-4 review table: M26, M27, X21 Fixed with the commits.
engine.rs: the miner's restart note no longer hides the fault reason on the card.
tools/reliability: the harness matches the miner's stderr lines where they are printed there.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.
- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
"dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
miner section note
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflict resolved: publish-jobs.sh keeps master's verify command and --tries (the retrying live check) alongside the
build kind's arguments; the usage range covers the merged header.
Conflicts resolved: state.rs keeps both the sweep fields (miner-eff) and the race fields (miner-perf); bench-log.md
keeps both appended entries; publish-manifest.sh keeps master's --override implementation (8082576, the "every
height switch" rule, --verify-only, --tries, the retrying live check) and adds miner-perf's --tuning / --no-tuning
with the carry-over of consensus.override and tuning from the current manifest. One --override case, one parser.
The first Windows update over the air (0.3.3 to 0.3.4) sat on 'the installer is starting' with no helper log on
PC 2. The helper launched by a remote job with the same arguments ran at once. Fix in 0.3.5; the Windows machines
take 0.3.5 by hand once more.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Header: site/partials/nav.html, head.html, footer.html, injected by site/build.mjs between markers in every page (the bench template too) with the active link marked; the master mark in its black square, the wordmark, Litepaper, Live devnet, Engineering log, Evidence, GitHub and the miner button, in that order everywhere; one menu script (closes on a link, a tap outside, Escape with focus back on the button, a resize past 900 px); a skip link; one focus ring and one reduced-motion rule.
Litepaper: the hash routed by a click delegate and popstate instead of the browser's fragment jump. Root cause of the tabs fault: show() scrolled to the top of the article, never to the section; in whole-paper mode the fragment jump landed on the section and the smooth scroll then dragged the reader back to the Abstract; in one-section mode a deep link scrolled while the section was still display:none and landed on the cover. Now: every section and all 29 subsection headings reachable by URL in both modes, scroll-margin from the measured bar height (nav, plus the contents row on a phone), focus moved to the heading, a re-aim after a late font batch, mode buttons stacked in the sidebar.
Pages: homepage headline capped at 9cqw so it is two lines at 390 and 1440 (was four with "fire." alone), journey inlined by the build (no fetch, no shift), dates as "4 Oct 2026"; live page legend no longer forces 420 px of width at 390, the hash-rate unit as small mono, idle redraw at 30/s with a 1.5x backing store (0.7 to 1.2% of one core idle in Chrome for Testing, taken under load), the proving line wraps on a phone; evidence sort headings are buttons, chips carry aria-pressed, a scroll hint under 1,140 px; bench contents in a sticky scroll box, og.png?v=3; 404.html; sitemap with /evidence; vercel.json caches fonts a year and images a day.
Fonts: eight latin woff2 files in site/fonts (139 KB for all, 118 KB a typical page), preloaded first-paint faces, fallback faces with size-adjust and ascent overrides from the font tables; every page lost its render-blocking fonts.googleapis.com stylesheet and the gstatic origin.
HTML per page before to after (gzip): / 17,265 to 21,810 B; /litepaper 20,556 to 24,957; /live 15,640 to 17,777; /evidence 18,899 to 22,493; /bench 94,723 to 98,289. Third-party requests before to after: 3 to 1 (jsdelivr, light client), 1 to 0, 3 to 0, 1 to 0, 1 to 0. Lighthouse before and after is queued under the measure lock (held by reliability runs since 19:16Z, load average 258) and recorded in docs/design/site-polish-2026-10-04.md when it runs.
Checks: node site/build.mjs, tools/ci/link-check.mjs (246 links, 0 broken), identity grep, and a Chrome for Testing run over every page at 390, 768 and 1440 (no overflow, no console errors, menu, router in both modes, deep links on reload, keyboard).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
src/sweep.rs (new): the cap steps 100% to 50% in 10% steps clamped to the card's limits, per-step rows (mean draw
from nvidia-smi power.draw, mean worker interval rate), the choice (best MH/W, ties to the higher rate then the lower
cap), the nvidia-smi power parser, a state machine on an explicit clock (15 s settle, 60 s hold, 30 s cap readback
limit), the elevated helper scripts (one administrator prompt per sweep: a command file polled by one elevated
process, self-restoring after 20 idle minutes), the unsupported reasons (Apple silicon, AMD). 9 unit tests with
PC 1's recorded RTX 5090 numbers (575 W default, 460 W cap, 290 W draw, memory temperature [N/A]).
Engine: scheduler (once after install, then weekly; one card at a time; only while the card mines, after 120 s
steady, never under a remote job hold, a pause, or inside 600 s of the hour boundary), the cap-mode probe (direct
when the engine runs elevated, else the helper), abort on any fault (card leaves mining, worker error, GPU 90 C,
job, pause, quit) with the cap restored, the chosen cap held and recorded, SWEEP table lines in the app log,
--sweep mode (sweep every supported card, print the table on stdout, leave the caps, quit). Cap floor 50% (was 60).
A readback that matches the asked cap now counts as applied (PC 1 showed "cap NOT applied" for hours at 460 W).
Dashboard: live eff MH/W on each tile, the sweep line (phase, last result, or why unsupported), Sweep now / Stop /
Unpin, "pinned" and "chosen by the sweep" on the cap line, the Settings toggle, the cards-page note, slider min 50.
A cap moved by hand pins the card: the sweep records but does not change it.
PC 1 measurement: relay/playbooks/sweep-5090.ps1 (a run job, elevated, miners stopped; a second engine with --sweep
in a scratch data folder, RESULT SWEEP lines) and docs/plans/miner-eff.md with the publish command. Not published.
Untested on a card.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Under emulation (or --race with no other name) the race no longer times base alone: emu/test.sh passes again
(9 source checks, the serve protocol with prepare, swap and self-heal, 17 sampled hashes equal to igneum-pow).
Mac table: g256 (256 threads per threadgroup) +17.3% and +21.2% over the shipped 32-thread groups on two
programs, with the live app's worker sharing the GPU; the serve check found the unfair mutex (fixed in 123ee1a).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
New job kind `build` (jobs.rs, jobbuild.rs, jobrun.rs run_build): free-space check on both sides (20 GB), the
build-inputs zip by sha256, setup inside the distro as root (mingw-w64 posix, clang for bindgen, protoc, zstd, the
Windows rust target; idempotent), sources extracted with the target dir persisting under /root/igneum-build,
cargo build --release native and for x86_64-pc-windows-gnu, cargo test for the manifest's packages, binaries
zstd-compressed and sent to the relay (fn=upload, Blob PUT, fn=drop; 50 MB each) with sha256 in RESULT lines,
STAGE lines with UTC times, a 40-minute default budget and per-stage caps, the Linux side killed on a cap. The
app's runner stays serial (one Active at a time), so a build never overlaps a shard job; nothing stops the miners.
From this version an unknown job kind is skipped by the app (parse_lenient) instead of rejecting the whole file;
the signer stays strict.
Mac side: packaging/windows/push-build-inputs.sh packs a fork worktree, app/igneum-app, brand/icons and
proto-cuda with a manifest (branch, commit, dirty, builds, tests) and the sha256; publish-jobs.sh add --kind build;
tools/build-job.mjs packs, publishes, watches, fetches, checks both sha256 per file and the PE header of every exe
(plus verify-exe.py on igneum-app.exe), and places the binaries where push-inputs.sh, make-payload.sh and the
cloud-devnet scripts look. relay.mjs drop <file> --body carries the body.
Tested on the Mac: 33 app tests (6 new) and the signer's 21; cargo check for x86_64-pc-windows-gnu; the packer
(7.9 MB zip, no target dirs); the publisher against a scratch folder with the rebuilt signer, the old signer
refusing the kind, a bad job refused at signing; the fetch path against the live relay with a real exe (sha256
and PE pass, a wrong sha256 refused; test items deleted). Not run on a PC: the job itself. docs/plans/build-job.md
has the first job for PC 1 and the rollout order (0.3.4 must be on the PCs before a build job is published).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The engine turns a worker's race line into one TUNING {json} line in the app log (card model as the worker names it,
driver, arch, program class loads and wide loads, every variant's MH/s, winner, gain, the card's power cap and
draw, MH per watt), which the existing intake receives; the card state carries the variant for the dashboard and
one event per race. tools/tuning.mjs aggregates the records from miner_logs per card model (median MH/s or MH per
watt, at least 3 samples, de-duplicated per race) and writes tuning.json; publish-manifest.sh --tuning puts it in
the signed manifest (and now takes --override for consensus.override; both are carried over from the current
manifest when not given, --no-tuning drops it); manifest.rs parses it; ota.rs writes <app data>/tuning.json and
removes it when the manifest drops it; procs::spawn takes an environment and every miner starts with
IGNEUM_TUNING_FILE, which its worker reads at every prepare. Dry run of the publisher against a scratch folder:
tuning and override written, carried over, dropped, signature verified.
docs/plans/miner-perf.md: the signed jobs for PC 1 (fetch the race build of the NVRTC worker, then
relay/playbooks/race-5090.ps1 with the miners stopped: 17 variants, 3 rounds, twice) with the exact publish
commands for the main session; not published by the agent.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 4 Oct 2026 evening: "we need to make our miner better than anything else can be". The compile-ahead pipeline
built one kernel per program; it now builds a catalogue (unroll 2 or 8; the dataset load path __ldg, __ldcg, __ldcs
on NVIDIA; a register budget by --maxrregcount or __launch_bounds__, max_total_threads_per_threadgroup on Apple;
2, 4, 8 warps per block or 64 to 256 threads per threadgroup; combinations), self-tests each against the pack's
vector warps (NVIDIA) or the base kernel over 2^16 nonces (Metal), bit for bit or out, and times each for about two
seconds with the job loop paused (one mutex, mining resumes between variants). Base is the pack's text as shipped,
always first, never discarded; a race has a budget (default 120 s against the 600-DAA lead) and keeps the best so
far when it runs out, so the swap is never delayed. One line per race: variants, MH/s each, winner, gain, time.
A tuning file (--tuning, IGNEUM_TUNING_FILE) pins a variant or orders the candidates per card model.
NVIDIA: textual rewrites on the pack's own kernel_bound.cu with exact anchors from igneum-pow's emitter, so the
pack format, the miner and igneum-pow are untouched and old packs race. --race --pack <dir> runs the race alone.
Under IGNEUM_EMU the race is off (the stand-in checks the handed-over text is the pack's). Metal: the MSL hooks in
generateMSL, a lock-protected kernel slot per program, a pair compiled inline races after its first job,
--race-test --seed --day runs the race alone with a table. OpenCL is not raced yet. docs/design/miner-tuning.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The intake key sits in every miner package, so the relay now lets it report only (drop text and files, ack, done,
register, upload). Posting a run or task, or renaming and re-roling a machine, needs the console token.
The prove host wrote proofs through SP1's unbuffered save: on WSL2 under /mnt/c the 18 MB core proof of a shard
took longer to save than to prove. Proofs now go through a 4 MB buffer with a timed 'saved' line, and
prove-shard.sh keeps results on the Linux side and copies them per stage. Ledger P20 updated.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Observer (tools/observer/observer.mjs): reads the execution layer's JSON-RPC of a node on the proving build
(IGNEUM_EVM_RPC, default the Mac app's node 26800): every chain block's shard plan as it joins the chain
(igneum_getShardPlan by blockHash, one live_proofs row per shard, planned), the proof records of the chain
blocks of the last 10 minutes polled in rotation (igneum_getProofRecords, four in flight, 40 blocks per tick
while active, 10 before activation): proving (in the pool), verified (SP1 proof verified, or carried and checked
by consensus), paid (a carrying segment paid it), with the prover's id8, the carrier, lag in DAA and the payout.
live_state.proving = {supported, active, activation_daa, tip_daa, verifier, pool, blocks_10m,
blocks_fully_proven_10m, shards_proven_10m, shards_paid_10m, median_proof_lag_s, provers_10m}. A node without
the RPCs gives supported false (rechecked every 5 min); an unreachable endpoint is retried every 20 s. Events:
proving (activation, first paid shard), prover_seen. Additive schema (live_proofs, live_state.proving).
API (site/api/live.mjs): proving, and per block shards: [{i, n, state, prover, lag, payout (IGN), pgas}] and
proven; ?window=N (30 to 300 s) for the page's diagnostic long view; LIVE_TABLE_PREFIX reads a test observer's
tables.
Live page (site/live.html), the design change of 4 Oct 2026: three thin strips sharing one time axis, newest at
the right. BLOCKS keeps the per-miner lanes, chain path, blue/red/pending colouring, arrival glow and tooltips;
the lock ring, dashed lock line and final band leave it. FINALITY is an 18 px bar: ember wash = final (up to the
newest locked checkpoint on screen), molten tick = locked checkpoint, faint = proposed, one label at the newest
lock ("locked #522, 12 s ago"); while finality is not active it reads "finality paused: N% of weight silent" and
nothing else (R4.6.3). PROVING shows one cell per shard under each chain block, outline (planned), molten
(proving), prover colour (verified), tick (paid), a dashed "proofs land N s behind the tip" line, or the one
honest line before activation ("Proving layer: not yet activated on this devnet; activation at DAA N" / "node
without proving"). Header stats: on screen, chain, identities, last lock, proven. Legend: one line per strip.
Hover and tap tooltips on blocks and cells (block, shard, prover, lag, payout). Lanes snap on resize (they used
to ease from a zero-height layout). Phone width, no horizontal scroll; draw 0.6 ms avg, 1 ms max with 110 blocks
on screen (playwright, 1280 px).
Hero (site/index.html): a faint second glint behind a real block once every shard of it is verified, only while
the proving layer is active; pace and sampling untouched.
Verified on the private 3-node proving network (tools/proving-v0/run.mjs --network-only, activation 60) with a
CPU prover loop signing as v0/v1/v2: records relayed, verified on node 0, carried and paid (block 155 by 405,
lag 259 DAA, 0.634 IGN); screenshots in docs/design/live-proving (devnet before activation at 1280 and 375 px,
test network active, the ?window=300 view with paid cells). The live devnet shows the "not yet activated;
activation not set" line once the observer runs this build.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
rollout-v2.sh stages the Linux igneumd (gateways from the Mac, private nodes from their gateway), rolls one node at a time with
difficulty_v2_activation_daa in every override file, checks the common chain and watches the height; results/2026-10-04/
rollout-v2*.log and v2/ (the hash-rate step under v2 and the v1 comparison). docs/plans/difficulty-v2-rollout-devnet.md: the
binaries and their sha256, the activation rule (N = DAA at publish + 10,800; baked at the cut as DAA + 14,400), the exact
restart lines for the observer node, the seed and Mac node 1, the OTA path for the two PCs through NODE_OVERRIDE_PARAMS in
packaged-config.sh (the engine side landed in 0dd587d), the rehearsal record. Bench-log entry.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
partition.sh adapted to private-network mode: the cut sits on the region's gateway (INPUT, OUTPUT and FORWARD
against the far gateways' public IPs over 26611 and the DNAT ports 27001:27099), since a per-node port-26611 rule
leaves the DNAT links up. It now records the locks per side at cut, during, at heal and after convergence, the
first lock after the heal from the journals, and the heal time as each minority node's first chain removal of 5+
blocks (the sink-count criterion is tip churn on a healthy network). hop.sh and partition.sh hold the Mac awake
with caffeinate; analyze.py gains a 10-s hop series (difficulty, block count, 1- and 2-min rates, threads) and an
overshoot table; collect.sh writes hop-series.tsv and hop.md and gzips the journals.
Results 2026-10-04: partition 1 (window still filling) reorg 431/496 on the minority, 2 on the majority, healed in
10 and 14 s; partition 2 (locks active): minority locked nothing during the cut, majority locked every interval at
66.8% to 84.5% of total, 0 conflicting locks over 107 indices, healed in 11 and 15 s, first lock after heal 13 s.
Hash-rate steps x1.42, x0.70, x0.75, x1.32: difficulty overshoots x1.67, x0.66, x0.53, x1.60, settle 751 s,
never in 900 s, 241 s, 646 s. Failures stated in summary.md: the Mac hibernated during the hop (phase 2 ran 94
min), the first partition could not see locks, the script's heal and first-lock figures were artefacts (fixed),
and another agent's v2 rollout restarted every node during the second heal.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
relay/api/console.mjs reads the log intake (miner_logs) and console_items in Neon, the OTA manifest, the
CI json and the jobs file from the downloads host (DL_TOKEN in the project env, never in the client), and
igneum.network/api/live; 10 s cache per answer. tools/console.mjs: post --kind log|build|note, log, machines,
chain, jobs, builds, results, sync-bench, sync-dl, sync-hetzner, sync, url. The two Mac-side build scripts
post build events. Screenshots at 375 px and desktop in docs/design/console/.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Root cause from the uploads (bench-log entry): the app exported the pack while its node was in IBD inside the previous
epoch, the OpenCL worker started after the boundary with no next epoch within lead, so no prepare was ever sent and
every job was a seed mismatch; the CUDA worker on the same PC had swapped correctly. Both workers now print
need <epoch> <day> before the error; the devnet-v4 miner (3bfe346f) prepares the current pair on a need line or three
mismatches, exits 42 for a worker without prepare support, and restarts a ready worker that completes no job for
60 s with jobs queued. Package rebuilt with the guarded miner (ship build on dc749905), payload inputs published.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Live devnet v4: a second RTX 5090 joining 7 minutes into an epoch left the whole-epoch reference lane polluted for the hour; the short lane read 11 to 25% above it and the 25% trigger flipped between the two for 40 minutes (102M to 164M, 54 to 81 blocks a minute). Record and hash-rate truth under sim/difficulty/records/. sim.py gains a DAG model (miners on nodes with igneum-miner's template staleness, GHOSTDAG, the rule as the node runs it) and --live replay: std of log difficulty 0.115 against the record's 0.134, 4.3 peaks of 1.31x against 4 of 1.37x. The brief's candidates (short lane 240/360, ease clamp 3%, clamp once per DAA second, hysteresis, median of three) leave 0.09 to 0.13; capping the reference lane at the newest 600 blocks of the epoch gives 0.026 with no flips. Rule v2 = that cap, epoch lane only, behind difficulty_v2_activation_daa (devnet-v4 fork). Attack suite and synthetic set before and after, 3-node test network of the switch (testnet_v2.py), analysis document, spec 2.3, bench-log entry, ledger M24, fast-time file carries the new field.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's rule, 4 October 2026: the mark sits in a black square, never in a circle, never on another colour, 20% clear
space; the Mac app is the model. brand/master/igneum-mark-square.svg (1024, #0C0C0E, the exact header polygons at 62%)
and igneum-mark-square-rounded.svg (Apple's 824-on-1024 grid, DMG volume icon only). make-icons.py now rasterises the
masters (rsvg-convert if installed, else Pillow draws the polygons) into igneum.icns (plain square, 16 to 1024),
igneum-volume.icns, igneum.ico (each size from the vector), the Inno art, the DMG background, site favicons
(favicon.ico 16/32/48, favicon-32, apple-touch 180, 192, 512, maskable 512 + manifest entry), relay favicons, and
brand/profile (400/512/1024, github-org-512, X banner). Every page head's inline SVG favicon and the relay header lose
the ring. The .rc and Info.plist paths are unchanged (same file names). docs/brand/before holds the old set.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/fast-time/override-60x.json is the devnet with every clock-like consensus parameter divided by 60 and every
block count unchanged (finality window, ban and min_daa 120 DAA; merge depth 60; Kaspa finality depth 720; pruning
depth at the anticone bound 13,838; coinbase maturity 2; the hourly program epoch 60 blocks with a 10-block lead;
the dataset day 24 minutes). The epoch length, lead and day are consensus parameters of the node since devnet-v4
a5ef8b07, carried by the override file. README lists each field, why it scales or not, the flags and the numbers.
Measured (simnet.mjs, three devnet-v4 nodes, three vmine voters at 1 block/s, one real-hash CPU miner): next
epoch seed in the template at 56.1 s, program swap at 65.1 s wall (DAA 60), first finality lock at 185.5 s wall
(checkpoint 5, DAA 149). Both harnesses take --fast-time: finality-attacks s3 PASS in 113 s wall with 16 locks
per node (the devnet rule needs 20 min of warm-up at 6 blocks/s before any lock); harness s3 partition and heal
43 s wall for three cuts against 983 s for four on the devnet profile with the same binary. Bench-log entry.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
New Vercel project igneum-relay from relay/: one function (api/relay.mjs) over Neon tables relay_items and relay_machines,
files in Vercel Blob store igneum-relay (50 MB client uploads, 4 MB through the function), phone-first web page at /r/<token>/
with the site tokens. Mac CLI tools/relay.mjs (feed, read, drop, task, run, watch, inbox, machines, role, name).
Windows clients send.bat/send.ps1 and the igneum-agent (registers hostname, role, GPUs, WSL, nvcc; runs queued PowerShell
scripts, posts results, reboot-continue via scheduled task + RunOnce), bash twins send.sh and agent.sh (verified live),
playbooks for WSL setup, prover setup, prove-block, miner v4, one-click placeholder. make-clients.sh bakes the secrets
into a zip; the repo copies hold placeholders. Screenshots under docs/design/relay.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-common.ps1 uses igneum-worker-cuda.exe (with nvrtc64_*_0.dll next to it) and igneum-worker-opencl.exe when they
are in the folder, passes the exported pack with --pack, and only surveys the toolchain (Find-Toolchain) when a worker
is missing or FORCE_BUILD=1; the dashboard and the status block name the path per card; a prebuilt worker that is not
ready after 150 s falls back to the build path once when a toolchain exists; 90 s of seed mismatch errors re-export
the pack and restart the vendor; WORKER_ARCH overrides the NVRTC target. make-package.sh ships the two exes, the two
NVRTC DLLs, the licence texts, THIRD-PARTY.md and TEST.md (what the first RTX 5090 run should print and what to send
back). README.txt, the bats, proto-cuda/README.md (nvrtc/ section), WINDOWS-MINER.md and the bench log updated with
what the Mac measured.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One lane per miner ranked by share, overflow in an others lane with a count.
Lane labels in a left gutter in the miner's colour (3-character tag on phones).
No per-block labels: short id on the chain tip, the lock, and on hover or tap
with a canvas tooltip (id, blue, DAA, parents, chain or side). Same-lane
overlaps nudged in a fixed sequence. Chain as one path, side blocks linked to
their first parent only, clamped cubics so no edge becomes a tall loop. Block
size and time scale step down together at density. One rAF loop, DPR aware,
paused when hidden or scrolled out. Final band and lock marker. Before and
after screenshots in docs/design/live-dag.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A lock needs two thirds of all 30-day weight signing; finality pauses
whenever less than two thirds is connected and signing, the chain runs
on proof of work meanwhile and the node reports it. Spec 3.3, 3.3.1,
3.7, 3.9, 3.10 Q3 row, 3.11 rewritten with the new arithmetic (safety
one third in every view, liveness two thirds connected, the per-view
window bound stated as 3.7 item 9); O-3.15 decided, O-3.16 closed,
O-3.18 and O-3.19 narrowed. Simulator: --floor, the +local partition
mode, scenario L; A to L re-run at the 2/3 floor over five seeds with
the 0.85 deltas in results_v2.md. Litepaper finality sentences and the
'does not claim' item. Ledger F2, F9, F16, F18 restated, F21 added
(the window bound and the post-heal finality fork from the devnet).
Bench-log: node build and tests, simulator deltas, three-node six-voter
runs of 6A, 6B and 6A with a long heal on ports 29200 and up.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-pow 0.2.0: generator v2 draws exactly 16 load slots from instructions 1..63, a
load's source from the registers written earlier and not read by a load since, the other
48 ops from the ten non-load weights; accept.rs is spec 01 section 1.4.6 (static: no
stale load source, every register injected; dynamic: 64 units on the seed-keyed
closed-form dataset, no constant bit, no lane-constant site, under 164 saturated, bias
within 136 of 1024, distinct addresses above 245,760); a rejected candidate is replaced
by the next attempt of the seed (seed || k_le32), 32 a consensus fault. Packs carry the
generator version, attempt and program id. Version 1 kept as generate_v1 for the census.
Packs: igneum-genesis, igneum-hourly, igneum-genesis-mh regenerated by igneum-pow export;
new igneum-devnet-v4-epoch0 (devnet genesis hash, day bytes 20730). Checks: Rust 39 of
39 tests; Metal natively via the Swift port (export cross-check 3 of 3 warps, identical
programs and vectors on five seeds incl. three with attempt 1, fuzz 2,000 of 2,000);
CUDA emu 4 of 4 packs; OpenCL emu 2 packs x 2 configurations; Apple OpenCL 4 of 4 packs
at 27.9 Mhash/s. Census 20,000: 5.225 percent rejected, accepted distinct mean 127.887.
Spec 01 0.2 (1.4.2, 1.4.3, 1.4.6, 1.11, 1.15, 1.16, 1.17), igneum-pow README, the CUDA,
OpenCL and Metal test notes, bench-log entry, ledger M5 and M6 Fixed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Windows combined package 0.2.0 (proto-cuda/windows-app): v4 exes from target-integration, peers = seed then Mac,
fresh appdir devnet-v4, one miner and one worker per card with --identities 8, --evm-address (PAYOUT_EVM or derived
per vendor from the PC name), voting on (VOTE=0 opts out), --prepare-packs for the hot swap with --exit-on-seed-change
as the fallback, --yes on the node, STATUS regex tolerant of the v4 now= segment, version in the dashboard header.
Mac app 0.2.0 (packaging/mac): v4 binaries, Metal worker rebuilt for macOS 11, data folder devnet-v4, EVM payout,
identities in one process, synced= flag honoured. Seed (infra/seed-nodes): stage-v4.sh builds v4 on the VM as a
niced, memory-capped transient service and installs a disabled igneumd-v4 unit with a fresh data dir; switch-v4.sh
swaps the units (--back reverses); health.sh reports active-v4. Runbook: docs/plans/cutover-2026-10-04.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Spec 2.3: rule 1 measures every chain step on a sanitised clock stored per header
(c(b) = max(c(p) + clamp(t(b) - c(p), -20 T, +20 T), t(b) - 60 T), step min(c(b) - c(p),
20 T)); rule 4 bounds the output to [2^128, MAX_DIFFICULTY_TARGET]; the timestamp rules
are Igneum's own, 10 s ahead of the clock and 10 s behind the selected parent beside the
unchanged past-median rule; new parameter rows, the bounds paragraph rewritten (the old
"next honest block cancels it" was the attack), the attack and test-network results added.
sim/difficulty/sim.py: class Igneum carries the same clock, lag bound and floor, so the
rule as simulated is the rule as coded (attacks.py's igneum-san is now identical to it).
docs/analysis/difficulty-2026-10-03.md section 11: the attack, the three parts, before and
after tables (simulator seeds 7 to 9, base-profile regression within 10% on the 3-seed
means, pool hopping unchanged, the two 15-minute 3-node forger runs), unit tests, limits.
docs/bench-log.md: the 4 October entry. docs/fud-ledger.md: M23, status Fixed.
Node side: vendor/igneum-node branch difficulty, commit 52eacad9.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- spec 3.10: C5/3.8 (min_daa = weight window, window-filling report), Q4 (drawn aggregator at
once, fallback for anyone), S1 (draw by weight), 3.9 (finality_reason) rows for fin-fixes da1eb889
- fork-divergence: four rows for the fin-fixes files and the merge note against the difficulty
branch (hot swap is already in master)
- bench-log: unit tests and the scenario 2 and 5 re-runs before (master) and after (fin-fixes)
- fud-ledger: F17 and F1 status lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Simulator harness over sim/difficulty/sim.py with multi-miner attribution and in-rule timestamp forging, a 3-node CPU test network (ports 27700+), results and bench-log entry. Timestamp stretching inside Kaspa's rules drops the Igneum block rate 34 to 88% (the per-step clamp cancels forged and honest pairs to zero time); proposed 10 s timestamp bounds plus a sanitised running clock in the chain steps (+0.7% to +1.1% drift at 50% in the simulator). Block flood underflows the 192-bit work after 4,142 blocks; a 2^128 target floor proposed. Rule not changed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/finality-attacks: run.mjs drives a private igneum-devnet-800 network (ports 27800+,
/tmp/igneum-fin-attacks, skip_proof_of_work) with the test-only hostile flags of igneum-miner
(vmine, --equivocate, --sybil, --drop-votes, --pulse, fin-rpc-attack; worktree fin-attacks on
master c6d47547..2a00ff55). Seven scenarios in priority order 3,2,1,6,4,8,5 with a spec 03
criterion and a measured result each; README carries the catalogue, what needs a finality-aware
p2p probe, and a proposed diff for every FAIL.
Results (six voters): S3 dishonest aggregators PASS (35/35/35 locks, 0 conflicts, 1,018 ms);
S2 Sybil dust: weights PASS, aggregator sortition FAIL (per key, ledger F17); S1 equivocation
PASS (2/2/2 stripped, 0 conflicts); S6A 3/3 partition FAIL (floor is time-bounded, one side
crossed 56.7% at 84 s of a 90 s split, T* = 2F/13R, 9.2 days for a 50/50 split at mainnet
scale); S6B 4/2 PASS; S4 vote-dropping producer PASS (0 ms added); S8 malformed votes over
RPC PASS (9 cases, no crash); S5 pulse: no retarget amplification (ratio 0.999) PASS,
lock-alone FAIL (a 20 s burst locked checkpoints 1 to 10 alone on a young window, ledger F1,
spec 3.8 not implemented). S7 eclipse not run.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
No per-job growth in any worker or in the miner's memory. The STATUS rates are cumulative averages
(a fast first interval decays by construction), and the miner's Seeder walks the selected chain from
the sink to the epoch start on every memo miss (one getBlock per block, up to 3,600), a gap between
jobs that grew 0.10 s to 0.33 s across epoch 2 on the PC and reset at the epoch boundary while the
difficulty held. Reproduced on the Metal worker (churn on, off, on). One versus eight workers at two
fixed difficulties: 4% and 1% constant cost, no decay. Fix as a unified diff, not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
sim/economy/sim.py: 1,000 operators choosing MINE, PROVE, HYBRID or OFF per card class with their own clients; sortition by weight with the 10-s window then open claiming, external jobs with the 90/10 split, backlog rule, difficulty clamps, GBM price. Scenarios a to f, 5 seeds: no backlog, no window miss, hash floor 0.74 of pre-event. Traffic sensitivity finds the shortage oscillation only above the proving fleet's capacity (100 to 300 shards per block); at 100 the sortition window (10 s to 20 s) is the lever that removes it. docs/analysis/economy-2026-10-04.md holds the model, assumptions, results, worst case and the proposal (window = p90 shard time plus a swap, 25 s at today's targets; B_p tied to the live fleet), not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Adversarial robustness and conformance tests of the execution layer against a
throwaway 3-node simnet on ports 27600+. Six scenarios, each a runnable command
with a design-derived pass criterion and a measured result: malformed/boundary
txs, nonce games across parallel blocks, RPC fuzz, pgas exhaustion, reorgs under
execution, and developer-registry abuse. 98 checks, 0 failures, 0 node panics.
Two findings filed in the bench-log entry: the mempool admits txs with gas_limit
above B_e (low), and an over-pgas-budget tx is executed natively in full before
being skipped for no fee (medium, griefing).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Safety: X = 1/3 of total weight while honest votes reach every honest node within 41 min of median time; 4/30 = 13.3% across a longer partition, because only the 17/30 floor binds then (2 x 17/30 - 1). Liveness: Y = 17/30 connected and signing, T = P (1 - Y/(2(1 - Y))) + 107 s, 107 s at 2/3, 43 min at 17/30; below the floor finality pauses and the node reports it. Two certificates at one index: no verified lock is ever withdrawn, operators resolve (replaces the 3.5 re-evaluation). Seeds: uncertified checkpoint allowed (O-4.3 decided). Scenarios H (equivocator across a 50/50 split: conflicts at 12 to 16 min with 20%, none at 13%), I (40/40/20), J (signing stops 1, 6, 24 h), K (bought keys worth 20% and 40% against 30% hash), five seeds each. 3.10 rows for the gaps; open items O-3.15 to O-3.19.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/evidence.md and site/evidence.html: 28 public claims with one of five status labels (7 designed, 3 implemented, 18 tested by the team, 0 reproduced externally, 0 reviewed independently), version or commit, the reproducible test, the result with date and machine, and independent verification (none yet for every row). Evidence link in the homepage nav and the generated pages' nav.
docs/benchmarks/proving-e2e.md: replaces the 20-second shard gate with three fixed workloads, job-received-to-accepted-proof latency, cost per proof, the eligible card list with mining and proving reported separately, the verbatim acceptance standard and the three-unrelated-operator protocol.
docs/plans/funding.md: cost, what is funded (founder's means, the client's 1% fee once there is mining), what waits on revenue, what pauses.
docs/analysis/security-budget.md: emission through six halvings at three price inputs, miners and provers separate from burns, the USD 1M floor and the year it is crossed.
docs/design/payment-routes.md: Mermaid flowchart and table of every flow, with operator, app, team and protocol revenue labelled.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proving/igneum-prove: core (port of igneum-exec at fb33069 as the block statement), program (SP1 v6.8.1 guest),
host (execute, core, compressed; ProofSystem trait with the stub and the SP1 implementation), export (cuts a block
out of igneum_exportSegments and checks every state root against the node's). Fixtures block-78-increment and
block-56-transfers from the 3-node simnet. proving/windows-wsl2: SETUP-PROVER.bat, setup-wsl.sh, PROVE-BLOCK.bat,
make-package.sh. docs/plans/proving-v0.md: the devnet v4 shard plan, what tonight's proof shows and does not, the
morning acceptance line. Mac CPU baseline (block 78: 626 k cycles, core 22.0 s and 7.3 MB, compressed 55.7 s and
1.27 MB, both verified) appended to docs/bench-log.md, left uncommitted because that file carries another agent's
pending changes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-seed-1 (Hetzner cx23, fsn1, 188.245.5.161:26611): built on the VM in 1,530 s, synced to the live devnet
(12,204 blocks, same sink as the live node) through a non-mining relay igneumd on the Mac (the live node's addPeer
RPC is refused in safe mode); the live node and the Windows PC learned the seed's address by peer exchange and dialled
it. seeds.txt written. Hetzner prices corrected to USD (pricing API currency) in the plans, READMEs and scripts;
current-generation types per location (cx23 EU, cpx22 sin, cpx21 US) in the cloud-devnet config.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/harness runs the standard consensus-attack catalogue against a private
test network of our own igneumd nodes (127.0.0.1 ports 27200+, /tmp/igneum-harness,
never the live devnet or the PC node), with a pass criterion per scenario from the
spec and a measured result each. Built on the node fork's own crates
(igneum-harness-sim on kaspa_utils::sim as simpa does; igneum-p2p-probe for the
wire). Scenarios: 1 withholding, 2 timestamp edges and drift, 3 partition and heal,
4 eclipse, 5 malformed and boundary inputs on every p2p and RPC surface, 6 resource
exhaustion, 7 fast-miner flood. Finality and difficulty-controller scenarios are
stubs with their criteria written.
bench-log: one dated entry, a row per scenario (criterion, measured, pass or fail).
First run: 19 of 20 measured rows pass. Findings recorded in the entry: scenario 5
reproduces ledger M15 on HEAD (bogus past-day or DAA headers build a 256 MiB cache
before rejection; the r3-fixes branch removes it); scenario 1 at 45% hash with
burst withholding shows a selfish-mining blue-share gain (50.7% of blues), the one
failing row.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/design/execution-layer.md section 10: what the execution-layer branch implements
(D1 to D10, RPC, differential), the devnet rules fixed there, what is missing, the merge
plan with the finality branch. docs/bench-log.md: the 3-node simnet run with numbers.
tools/evm-smoke: viem 2.57 smoke test (fund, 50 transfers, duplicates in parallel blocks,
contract deploy and call, state roots across nodes, export for igneum-exec-diff) and the
solc build of DeveloperRegistry and the Counter test contract.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/cloud-devnet: hcloud (doctl variant) create, builder-VM provision from a git-archive source tarball,
systemd units for igneumd --devnet-suffix with a sparse --addpeer mesh and a CPU trickle miner per node,
stdlib wRPC client, experiments (latency, partition, hop, collect, observer hookup), README with the command
sequence and the Hetzner API prices of 3 Oct 2026.
infra/gpu-bench: RunPod image recipes (CUDA 12.8, ROCm), bundle, run.sh (vectors gate, 10-min raw, sweep,
inline shortcut ratio, nvcc/NVRTC/OpenCL recompile timings, results row, intake upload), bench-log template.
infra/seed-nodes: create-seed (persistent IPv4, firewall), provision on the VM, health check, addPeer from the
Mac over grpcurl, seeds.txt; igneum-seed-1 created at 188.245.5.161 (Hetzner cx23, fsn1).
docs/plans/cloud-devnet.md and docs/plans/seed-nodes.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/fork-divergence.md: "Finality v2" table (every file, risk, merge note), decisions
- docs/spec/03-finality.md: section 3.10 implementation notes, clause by clause
- docs/bench-log.md: test-network results (72 of 72 steady locks, median 0.80 s; equivocation
strip; partition: 0 locks at 39.6% of total with the floor binding, heal in 30 s), follower
- tools/observer: live_checkpoints table, FinalityLock subscription, "checkpoint N locked" events
- site: /api/live adds checkpoints and locked/final flags; /live draws the lock ring and final line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Pool protocol after Stratum V2 job declaration: member-checked or member-built templates, JSON over TLS, shares at target64 << s on the 32-lane unit, one vote key per operator held by the member, votes relayed and carried by the pool with a chain-only drop test. Light client: trust table, checkpoint-mode bytes per day, pinned seed list, the read-only node API, the homepage card's steps. Phone app: wallet, miner monitor, node card, store rules, build plan on journey.json.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
fork-divergence.md: a section for branch r3-fixes (the PoW-before-validation
reorder, the cache-build cap and the per-peer guard), the merge-overlap note for
the finality branch, and the updated "PoW before or after GHOSTDAG" and "Day
seed" open decisions. bench-log.md: the before-and-after attack numbers (50
bogus headers build 50 caches in 10.6 s before, 0 and all rejected in 14 ms
after), one cache builds in about 0.2 s, and the M16 Mac inline-dataset note.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proto-cuda/windows-node/: START-NODE.bat and start-node.ps1 (igneumd
--devnet with --addpeer to the Mac, status line every 30 s through
igneum-miner watch, keep-awake, random-delay restart, Ctrl+C),
BUILD-NODE.bat and build-node.ps1 (builds on the PC from the src.zip
snapshot; winget for Rustup, LLVM and protoc; MSVC default toolset),
ALLOW-FIREWALL.bat and allow-firewall.ps1, README.txt, cross-build.sh
(the mingw-w64 recipe that built igneumd.exe in 8 min 25 s; the exe
ships with the three mingw runtime DLLs) and make-package.sh.
WINDOWS-MINER.md gains "Run your own node"; bench-log records the
cross-compile and the two-peer sync test on the Mac (ports 27000 and
27010, live node untouched). The mining launcher's NODE_HOST=auto
edit stays uncommitted for the agent that owns start-mining.ps1.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Litepaper Finality: the reorg bound users rely on is the 12-hour finality depth in median time; Kaspa's one-hour merge depth is a merge limit, not a reorganisation bound; first-month sentence and "does not claim" item 4 say the same. Litepaper Speed: emission per block on a schedule keyed to difficulty-adjusted time, reds in the window paid, coins track blocks within the controller's accuracy.
Design 5.5 and D12: the native-execution veto is relative to the carrying block's own selected-parent chain; two-node reorg test added to 8.5.
Ledger P11, F15, E10 statuses and fixes rows 79, 82, 84 updated.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The four public sentences (F18, P13, E11, L7 in site/litepaper.html and site/index.html) were swept into the concurrent commit cd604db; this commit carries the rest.
Spec 02: finality depth (43,200 DAA s, 12 h of median time) named as the reorg bound, merge depth as a merge limit only, simnet reorg test for gate 2; emission follows the code (365.25-day year, 63,115,200-s halving, 31.688 IGN per DAA second, reds inside the DAA window paid to the merger, E paid per block so coins are blocks times E).
Spec 03: W2 and Q1 denominated in past-median time, weight as a share of each 60-s bucket; W6 keys are free, weight is the only Sybil-resistant quantity; 3.8 and 3.9 point exchanges at the finality depth.
Spec 06: O-3.14, the finality simulation with the DAA in the loop under a pulsed rental (gate 3).
Spec 07: shard sortition draws by weight (blue blocks drawn uniformly from the window); proof-record validity is relative to the carrying block's own selected-parent chain; 1-key-versus-1,000-keys test.
Spec 08: release-key chain, rotation signed by the current key, revocation signed by the previous key, both published in a block; policy before the client ships.
Ledger: status lines for F18, P13, E11, L7, P11, F17, F14, M14, F15, E9, E10, G9; P8 cross-reference. Fixes: section 2.2 rows 75 to 88, with M15, M20 and P12 marked code, owner consensus engineer.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Seven reviewers (Kaspa core, RandomX author, Ethereum client, GPU farm,
chip designer, exchange listing, regulator's analyst), three attacks each
against docs/spec, the execution design, the fork code and tonight's devnet.
0 fatal, 18 serious, 8 minor. New ledger entries M14 to M21, F14 to F18,
P11 to P15, E9 to E11, C13, L7, L8, G9, G10, X12; one cross-reference on P8.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/provenance.md: table of every component Igneum uses (origin, licence, what changed, why, how measured), what is new, what to adopt from upstream, own-code licence pending the project lead's decision. Licences verified on disk: rusty-kaspa ISC, chiavdf Apache-2.0, igneum-pow MIT, blake2b_simd MIT, blake3 CC0 or Apache-2.0, sha2 MIT or Apache-2.0, secp256k1 CC0, keccak Apache-2.0 or MIT. RandomX, SP1, revm, blst, ProgPoW, LWMA, Monero, GMP, sha3: approximate, not cloned.
site: litepaper gains the Built on the shoulders section and nav entry; index gains the two-line mention and footer link near the RandomX comparison; the block rate reads one block a second at launch, rising, where it read as permanent (litepaper diagram, index live section).
tools/upstream: README with the exact merge commands, expected conflict files from fork-divergence, the test list and the consensus-review rule; sync-upstream.sh fetches and opens the merge on a branch without committing. Not run against the fork.
docs/commercial/prover-customer-brief.md: one-page brief for a first proving customer at testnet, timeline from journey.json, risks, 10 candidates labelled approximate.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Records the 3 Oct 2026 rename pass in vendor/igneum-node (binary, process
name, user agent, data and log paths, env vars, address prefixes, DNS
seeders, default build set) and what stays Kaspa-named internally. The
Windows miner guide and the observer README now start igneumd.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proto-metal --serve compiles igneum_hash_bound at runtime and mines jobs from stdin (init words in buffer 3, program
and dataset cached per seed); proto-cuda and proto-opencl host serve modes from the pack's kernel_bound.cu / .cl with a
seed guard; --vendor device filter for OpenCL. windows-miner/: START-MINING.bat + start-mining.ps1 (GPU and tool
detection, pack export, cached builds, MINERS identities per vendor, status every 30 s, uploads every 60 s, rebuild on
seed change, Ctrl+C summary), README.txt, make-package.sh (igneum-mine-test.zip with a cross-compiled miner).
docs: fork-divergence devnet v1, bench-log entry with the CPU, Metal and overnight numbers.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Preliminary clearance across EUIPO, UK IPO, USPTO, WIPO and the UAE for
IGNEUM in classes 9, 36 and 42, with the hit table, crypto-name
collisions, handles, and the ADGM DLT Foundation filing strategy.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- 03-finality: Q2 participation from every vote seen in blocks (votes are
block payload); 3.3.2 the eclipse case closed by the 56.7% floor with the
sim v2 F2 numbers; 3.4.1 why aggregators cannot grind participation.
- 07-execution (new): EVM semantics on the DAG, shard sortition (8 provers,
10 s, then open, no shard bond), bridges (none official, no bridged
stablecoins at genesis, proof bridge with the consensus proof in phase two).
- 08-client-security (new): reproducible builds, release key in genesis and
in hardware, no silent updates, consensus only by 90% signalling, notarised
builds, official sources with the hash, seed confirmed before mining,
hardware wallet, the permanent seed line.
- 00, 02, 05, README, 06: cross-references, O-2.8 removed, O-3.3, O-3.7,
O-5.1, O-5.2, O-5.6 narrowed, O-8.1 added, counts kept at 60.
- Ledger: eight Status lines, status table, count table, overclaims 38, 40, 71.
- FUD fixes: rows 23, 26, 38, 62, 64, 66, 67, 70, 72, section 3 and 4.
- Site: bridge and stablecoin sentences no longer launch features; the seed
line wherever the app appears.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Every open, conceded and answered-with-remainder entry of docs/fud-ledger.md
as one row: fix, owner, timing, and whether it exposes the team. The 78
overclaims checked against the live site text. What the 3 October decisions
close. The pre-public-repo scrub, in order, including the history rewrite.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Decision of 3 October 2026: no fee to any team, foundation or fund.
Priority fee now splits 80% to the miners and provers of the block and
20% to the application called, attributed per call frame as before.
No burn of the tip; the base fee is still burned in full on both gas
dimensions. External proving jobs pay 90% to the provers who delivered
and burn 10%. The 60% signalling mechanism stays as a general tool for
parameters that genesis rules leave to miners; upgrades stay at 90%.
Ledger E4 closed by removal; E3, E5, G4, G5, G8, L1 and overclaims
45, 46 and 53 rewritten to the new rule.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The ledger stays in the repository as an internal working document while it carries open items. /ledger now redirects to the homepage. Promotion-rules entry rewritten without any founder location.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/spec/01 to 06 and the README index, alongside the existing overview. Section 1 is the normative
definition of the lottery hash with test vectors copied from the igneum-genesis-mh pack (cache fingerprint
48c4f5bf24166b2e, 96 hashes, mixer constants) and every prototype value marked with the measurement that
fixes it at gate 1. Sections 2 to 5 are the design as decided on 3 October 2026, labelled Designed. Section 6
lists 60 open items with the experiment or decision that closes each and its gate.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/fork-divergence.md: every rusty-kaspa file the fork changed (file, what,
why, risk, upstream-merge note), the decisions left open (8 vs 18 decimals,
temporary epoch seed, day seed, lane-to-target mapping, pool payee, depth
bounds, PoW after GHOSTDAG) and the per-second subsidy table.
docs/bench-log.md: 3 October 2026 entry for the 3-node igneum-devnet run at
0.84 blocks/s with the 80/20 coinbase and vote_key_hash verified on all nodes.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The chain animation scales its proving tempo to the canvas width, so a block is mined, proven and locked before it leaves a phone screen. Opening frame seeds proven and locked blocks on narrow canvases too. Repository links point at github.com/igneum-network/igneum.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Exporter writes kernel.cl next to kernel.cu (same instruction list; memory-hard core emitted in a third, OpenCL C
dialect with the same literals as memhard.h). Pack headers are now C99-safe so a plain C host can include them.
proto-opencl/host.c: C99 + OpenCL 1.2 API, device list, runtime build, cache fill and FNV check, dataset build and
self-test, 3 vector warps standalone and in batch, bench and sweep as host.cu, whole-batch fingerprint. The 32-lane
exchange is sub_group_shuffle_xor only when the queried sub-group size for a 32-item work-group is exactly 32;
otherwise a local-memory exchange with one barrier per exchange, so wave64 hardware cannot change the hash
(WAVEFRONT.md). build.sh (macOS, Linux), build.bat (MSVC), README with the exact AMD-rig commands.
Proven without AMD silicon: Apple OpenCL 1.2 on the M5 Max 96/96 on all three packs (45.0 Mhash/s at 1 GiB, Apple
number, not AMD); pocl 7.2 CPU device 96/96 on both exchange paths including the real sub_group_shuffle_xor text;
CPU emulator 7 configurations incl. 64-wide sub-groups, identical fingerprint f99fb375b3abeaf5 everywhere.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Class group (1024-bit prime discriminant from the checkpoint hash, chiavdf
construction, NUDUPL/NUCOMP/Lehmer xgcd ported from vendor/chiavdf) and an
RSA-2048 trusted-setup stand-in for timing. eval, block prover, verify,
epoch_seed/verify_epoch_seed, grinding model, README with measurements and
the parameter recommendation, bench-log entry.
M5 Max: class 163k sq/s (T 98 M for 10 min, 588 M for 1 h), verify 4.5 ms,
proof 516 bytes; full 10-min runs for both groups; grinding gain for a 30%
miner +3.62 blocks/epoch with no delay, 0 with it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
proto-metal: default dataset is now the memory-hard construction (MEMHARD.md), --closed-form keeps the original.
Cache fill 2 ms GPU / 185 ms one CPU core; dataset build 20.6 ms; GPU cache == CPU cache on all 2^26 words.
Shortcut ratio: inline kernel 111x faster than honest (closed form) to 4.8x slower (memory-hard), 1 GiB.
CPU verify 0.63 to 0.80 ms per warp at 104 loads, 1.21 ms at 144 loads (4,608 items): 10 ms gate met.
Levers --load-weight and --wide-frac implemented and measured, both off; default generator unchanged.
Fuzz 200/200, edge, determinism, memcheck, stats re-run on the new dataset, all PASS.
proto-cuda: host.cu handles both dataset modes; new pack igneum-genesis-mh with memhard.h; clang emulation PASS
including the three-way cache check. Old packs unchanged; closed-form export is byte-identical to them.
docs/bench-log.md: dated summary.
Note: a concurrent session running git commit -a swept earlier states of these files into its site commits
(7b28d5e through d6539fa); this commit carries the remainder.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>