the project lead, 5 October 2026, 22:45 BST: "make sure we have ember tuning every single card for efficiency out of the box, the
more data = the better the tune, make an awesome system." Built on lever 3 (docs/plans/miner-eff.md), lever 2's signed
tuning section (docs/design/miner-tuning.md), the AMD telemetry helper (423936b, its --tune/--set-gmax/--set-plimit/
--reset contract) and the Power control switch (057f0ec). Design, data flow, tiers and the privacy line:
docs/plans/ember-tune.md.
- src/ember.rs (new): two knobs per card (power limit %, core clock cap MHz; memory clock never touched), the full plan
(power ladder 100..50%, then the clock ladder 90..60% at the chosen power), the confirm plan (the fleet prior and one
neighbour), the baseline plan (measure only), the marks (faulted, hot, memory_clock_dropped, unapplied, no_readings),
the choice (best MH/W within 1% of the top rate, then rate, then draw), the fleet record (a hash of the install id,
no address), the prior lookup and the kill switch (tuning.ember), the state machine on a fake clock. 9 unit tests.
- engine.rs: tick_sweep schedules every NVIDIA, AMD and Apple card (120 s steady, 600 s to the boundary, no job hold,
no pause, weekly, again after a driver major or program-class change, never under the manifest kill switch); the
probe (nvidia-smi clocks.max.gr + driver_version and the direct/helper mode; igneum-gpu-telemetry --tune for AMD);
tune_apply (nvidia-smi -pl / -lgc 0,<MHz> / -rgc directly or through the helper; the AMD helper per request);
Cmd::TuneProbe, Cmd::TuneSet; faults from rejected and mismatched hashes mark the step; the TUNE lines and the TUNE
{json} record, uploaded with the log; the Tuned line on the card state. The NVIDIA helper starts only with Power
control on: the --sweep job never counts as permission (no prompt on a PC with nobody there).
- sweep.rs: the helper protocol gains lgc/rgc (clock cap and reset) and resets the clocks after 20 idle minutes.
- state.rs, config.rs: the tune fields (clock cap, driver, class, source, the Tuned line); the nvidia-smi telemetry
query carries clocks.gr and clocks.mem; the AMD sample line's plimit_pct and gmax_mhz are parsed.
- ui: "Tuned: X MH/s at Y W (Z MH/W)" with the point, the source and when; measure-only cards say why; the Ember Tune
switch; tune-line.test.mjs.
- relay/lib/ember.mjs + relay/test/ember.test.mjs: the aggregation per (card model | driver major | program class):
median point, MH/W, spread, samples, machines; five samples converge, an outlier does not move the median, baselines
make no prior, de-duplication, the manifest merge keeps lever 2's cards. api/console.mjs fn=tuning and
tools/console.mjs tuning; tools/tuning.mjs --priors [--write tuning.json] [--site] [--tuning-off].
- site: the fleet priors table on /miners (site/miner-priors.json), the lever text.
- relay/playbooks/ember-tune-pc1.ps1: the PC 1 run (second engine with --sweep from a scratch copy of the install).
Measured tonight: see the bench log entry that follows the PC 1 run. The 9070 XT left PC 1's bus at 20:40 UTC and the
5090 needs the administrator prompt the project lead cannot answer asleep, so tonight's PC 1 run is the baseline plan on the 5090
through the whole pipeline; the two-knob tune on both cards is owed.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Fed by /api/explorer from the observer's tables. Latest blocks (hash, number, DAA, blue score, miner, txs, proof
records, time); a block's header, parents, children, mergeset, coinbase outputs, EVM transactions, shards, checkpoint
and certificate; an address's blocks, what they earned, vote keys and balance (eth_getBalance when EXPLORER_EVM_RPC is
set). Same tokens as live.html. vercel.json rewrites /block/:id and /address/:addr; the footer links the explorer; the
link checker skips template literals and resolves /api/<name> to its function. node tools/site-serve.mjs previews the
site with the functions in-process.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The numbers profitability sites and pool software read (WhatToMine's form: explorer or pool with an API, the halving
schedule, a source for total coins). Reward and supply from the emission rule at the node's DAA score; the halving table
(33 rows), the 30-day ramp and the observer's coinbase check. Cached 10 s, CORS open. FIELDS in each handler is the
contract; public-stats.test.mjs checks it from a fixture, tools/ci/public-api-check.mjs checks a deployment.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/lib/emission.mjs is the emission rule as igneum.rs computes it (block_subsidy, launch_ramp, an exact floor-sum for
minted-so-far); its tests reproduce the node's own test values and a devnet coinbase (block 2622db76: payload 454,486,399
at DAA 125,064, outputs 454,485,299 = E(125,063), what the merged parent declared). Every live_blocks row gains tx_count,
evm_miner (the IGNA tag, else the vote key's low 20 bytes), proof_records (IGNP section), subsidy_sompi, paid_sompi,
selected_parent, number, detail. No extra RPC per block: measured 282 against 283 wRPC and 785 against 776 EVM calls
per minute before and after. live_state.rpc_load and live_state.supply_check are new.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Verified by grep and moved to "stated": M2, M4, M7, M9, M10, M13, F5, F10, P1, P4, P6, P7, P10, E5, G1, G2, G3, G4, G6, C2, C3, C5, C6, C8, C10, C11, M18, X1, X2, X7, X8, X9, X10, D2.
Written tonight, then moved: P3 (overclaim 25 plus the certificate-half numbers), M29 (the app paragraph rewritten to Ember 0.3.9), E16 text half (the 20% is burned under igneum-proving-pool-v0, provers paid from the execution-state escrow), L9 (devnet no-value line beside every download control, the tiles), L2 text half (no "so" clause), E17 text half (100,000-gas calls, fleet-size dependence), E13 (the six-row payment-route table in the litepaper Economics and the customer brief, from docs/design/payment-routes.md), E6 (the schedule as a bet), C13 (Monero's record does not price the die), L8 (Circle's decision), X3 (August 2027 under the proofs feed), M10 (overclaim 14 applied).
docs/fud-fixes.md gains section 2.7 with one row per group. Site rebuilt with node build.mjs (the live downloads index moved the HiveOS package to 0.3.9; journey.json regenerated from the log).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Footer partial: imprint line with the registered address and the mailbox; Report a flaw mails hello@igneum.network with the spec issues as the second route. Litepaper: Who are you names the entity that ships the software, the team is pseudonymous with no team page, the ledger and the benchmark source are public with the repository at the public testnet, the last paragraph gives the mailbox and the address. Miner: the dev fee goes to Igneum Labs LTD. Evidence (md and page): repository private until the public testnet. Trademark FILING.md: applicant Igneum Labs LTD at the DIFC address. Identity check: the ledger and fixes file join the export list; the forbidden list notes that the registered address is allowed. Site rebuilt (bench page and journey picked up the txgen log entry).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.
Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Downloads: packaging/ota/publish-public.sh publishes the current installers, the HiveOS package and the two signed
manifests into dl/public/ with no token in any URL, writes the four /public/ aliases as vercel.json rewrites and an
unsigned index for the site; publish-manifest.sh --public and ship-app.mjs --public run it on every release (dry run
and self-test cover it). Nothing removed from the token folders.
Site: the miner and wallet buttons link the public aliases and show the version and size from the index, read at
build time (site/downloads.json is the offline snapshot); TESTNET_OPEN in build.mjs drops the "Public testnet: not yet
open" line on the go; the HiveOS Flight Sheet install line on the miner page; /faucet page.
HiveOS: igneum-hive-0.3.8.tar.gz from the 0.3.8 node (2b6d23ef, PC build job) and the zig-built Linux workers.
Faucet: site/api/faucet.mjs (10 IGN per address and per IP per day, Neon table faucet_grants, EIP-1559 transfer signed
by site/lib/eth.mjs with no dependencies: keccak, RLP, secp256k1 with RFC 6979), FAUCET_KEY and FAUCET_RPC from the
Vercel env only; 15 unit tests with a fake database and node, run in CI.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Home: hero and job-card buttons say what exists; the dev fee named beside the emission split; 0 admin keys in consensus; the log's day-one note. Miner and wallet pages: downloads open at the public testnet, the devnet is private. Nav CTA is The miner; footer gets the issues route. Journey phase 6 drops listings.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Precedents table replaces the firsts table, with state and sources; labels Measured, Implemented, Designed, Target, Open where the ledger asks; one Who paragraph; no listings; private repository until the public testnet; issues route.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
New sections "Ember, the miner" (features, the six levers with state and measurement, the
software dev fee, what Ember does not claim) and "The wallet" (Igneum Wallet 0.1.1) after
"For miners". "Igneum at a glance" gains the live devnet table (hourly swaps, difficulty v2
at DAA 33,000, finality v2 first lock at 77.4%, proving v0 from DAA 84,100) with the
one-verifier caveat. Roadmap phases 2 and 3 carry what is measured so far and a "What ships
next: Ember 0.3.6" table. Proving section carries the RTX 5090 shard figures; the stale
"Where is the miner?" answer now points at Ember. Every number cites its engineering-log
entry or plan in a source line. Version 0.2, status "devnet live, pre-testnet".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A tap or click on a block or a shard cell now pins its details. The panel stays until a tap or click lands
anywhere else, Escape, the close control, or the block scrolls out of the strip (then a 200 ms fade, no snap).
Another block switches the pin. The pinned block carries a molten ring. The pinned panel sits at a fixed
spot at the top left of the strip, so new blocks never move it, and shows a PINNED label and a 32 px close
control for a thumb.
Hover is unchanged on pointer devices: another block shows its floating panel for as long as the pointer is on
it, then the panel returns to the pinned block. Hover never clears a pin.
Pointer events only: one pointer, down to up, under 10 px of travel counts as a tap, so a scroll on a phone
never pins, and a touch tap fires once (the canvas ignores click). A touch gets a wider hit radius than a
pointer; the hover radius is as before.
Verified with real mouse, touch and key input through CDP on the cached headless Chromium against the local
page fed by igneum.network/api/live: 20 of 20 checks at 1200 px and 375 px, no console errors.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Pages
- site/miner.html (/miner): hero with the live dashboard, "Hash, prove, get paid", every feature in six groups with one
line each (one click and GPU detection, one client with identities and the hourly swap table, signed updates at a safe
moment, variant racing / fleet tuning / efficiency sweep / latency / remote signed jobs, watchdog and clock check with
the recoveries table, the log and the bench table), "Why Igneum Ember stays ahead" (the six levers of 4 Oct 2026 with
their measured state; the latency row labelled approximate, from the 0.3.6 plan), the dev fee section with the exact
wording of docs/design/miner-dev-fee.md, Get the miner. Every number links to its /bench entry.
- site/wallet.html (/wallet): hero with the wallet window, the three finality states with the verified-final transaction,
the four checks the wallet makes, features (create or import with Argon2id + XChaCha20-Poly1305, send with the fee
shown, QR drawn locally, history with rewards, node source order, MetaMask export), the timed first run on a test
network (5 Oct 2026, wallet-v1 log entry), Get the wallet.
- site/index.html: the miner and wallet sections become summaries, each with a framed screenshot, pills and a Read more
link; #mine and #wallet anchors kept.
- site/partials/nav.html: Miner and Wallet entries, the CTA to /miner#get; the Miners entry goes (the bench page is
linked from /miner, the footer and the Miner entry marks it current). The bar needs 941 px for eight items on one
line, so the menu now applies up to 940 px (head.html) and labels never wrap.
- site/partials/footer.html: a Run column (the miner, the wallet, the GPU bench table, the dev fee).
- site/build.mjs: PRODUCT table, the one place the miner's name lives (full "Igneum Ember", name "Ember", app "Igneum
Miner" for the bundle and window, caption for screenshots); every <span data-product> is stamped at build. miner.html
and wallet.html registered; /miners marks the Miner nav entry; journey entries lose a leading comma left by a
stripped bracket.
Visuals (site/img, WebP, 2x, under 101 KB each)
- miner-dashboard.webp: real screenshot of the miner app on this Mac (live devnet, Apple M5 Max), footer with the host
name and the address cropped, the machine id removed before capture.
- wallet-home.webp and wallet-final.webp: real screenshots of Igneum Wallet v1 (release build from wallet-v1) on a
private test network driven by tools/wallet-testnet/run.mjs; the throwaway addresses are replaced by example strings.
- Drawn in CSS: the device frames, the three finality states, the hash / prove / get paid steps, the dev-fee switch.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.
Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.
Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).
Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
and the link check pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflicts resolved keeping both: engine.rs carries the sweep state (miner-eff) and the node watchdog (reliability);
the STATUS line goes through watchdog::parse_status and still feeds the sweep's rate sample; main.rs declares both
modules; bench-log.md keeps both entries. site/build.mjs keeps master's partial-injected pages and adds the /miners
bench table through the same page() with active: 'miners'; the Miners link is in site/partials/nav.html; sitemap
gains /miners; every generated page rebuilt with node site/build.mjs.
docs/bench-log.md: the fake-worker measurements (slow start one trip and 2.0 s restart, fake-fast guard in under
0.1 s, exit 43 at 8.8 s, CPU re-check stop at 0.5 s, stall guard at 60.1 s with STATUS lines through the silence,
one prepare per epoch with refused retries held; app: zero-rate restart at 79.6 s and faulted at 75.4 s on the
repeat, no-status restart at 90.4 s, silent node restarted at 150.7 s and synced 7.2 s later; no double restart on
the miner's own worker restart). Two defects the harness found are named with their fork commits.
docs/fud-ledger.md and the round-4 review table: M26, M27, X21 Fixed with the commits.
engine.rs: the miner's restart note no longer hides the fault reason on the card.
tools/reliability: the harness matches the miner's stderr lines where they are printed there.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Conflicts resolved keeping both: Settings and SettingsState carry the sweep fields (miner-eff) and dev_fee /
fee_total (dev-fee); the engine's settings snapshot sets both and the DevFeeState line stays.
Decision of 4 October 2026 (evening): the Igneum Miner software takes a visible, switchable 1% dev fee, the norm
for GPU miners; the protocol stays fee-free. The miner side (--dev-fee, the 1-in-100 template counter, the audit
command) is on branch dev-fee of the node fork.
- app: settings.dev_fee (default on) passes --dev-fee 0 to igneum-miner when off; Settings shows the miner's own
"dev fee 1% (1 block in 100) to 0x..." line next to the rewards address with a switch; the engine parses the
miner's start line and its dev-fee block lines (fee_session, lifetime fee_total, an event per fee block)
- packaging/hive: h-manifest.conf, h-config.sh, h-run.sh, h-stats.sh, make-hive-package.sh (igneum-hive-<v>.tar.gz
with the Linux igneumd, igneum-miner and both GPU workers), README with the Flight Sheet, selftest.sh (bash -n,
stub binaries, the three hooks the way Hive runs them, the stats JSON parsed). Hive itself is untested
- infra/cross/build-workers-linux.sh: the NVRTC and OpenCL workers cross-compiled for Linux with zig;
proto-opencl/cl_dynamic.h gains the Linux dlopen branch (libOpenCL.so.1)
- tools/dev-fee/run.mjs: the fee-block test network (two nodes on 29900+, three CPU miners, payouts audit)
- docs/design/miner-dev-fee.md (mechanism, flag, lines, the DEV_FEE_ADDRESS placeholder and the devnet address),
docs/fud-ledger.md E18 and the E5/L9 status line, litepaper "What a miner's hour looks like" paragraph, homepage
miner section note
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Header: site/partials/nav.html, head.html, footer.html, injected by site/build.mjs between markers in every page (the bench template too) with the active link marked; the master mark in its black square, the wordmark, Litepaper, Live devnet, Engineering log, Evidence, GitHub and the miner button, in that order everywhere; one menu script (closes on a link, a tap outside, Escape with focus back on the button, a resize past 900 px); a skip link; one focus ring and one reduced-motion rule.
Litepaper: the hash routed by a click delegate and popstate instead of the browser's fragment jump. Root cause of the tabs fault: show() scrolled to the top of the article, never to the section; in whole-paper mode the fragment jump landed on the section and the smooth scroll then dragged the reader back to the Abstract; in one-section mode a deep link scrolled while the section was still display:none and landed on the cover. Now: every section and all 29 subsection headings reachable by URL in both modes, scroll-margin from the measured bar height (nav, plus the contents row on a phone), focus moved to the heading, a re-aim after a late font batch, mode buttons stacked in the sidebar.
Pages: homepage headline capped at 9cqw so it is two lines at 390 and 1440 (was four with "fire." alone), journey inlined by the build (no fetch, no shift), dates as "4 Oct 2026"; live page legend no longer forces 420 px of width at 390, the hash-rate unit as small mono, idle redraw at 30/s with a 1.5x backing store (0.7 to 1.2% of one core idle in Chrome for Testing, taken under load), the proving line wraps on a phone; evidence sort headings are buttons, chips carry aria-pressed, a scroll hint under 1,140 px; bench contents in a sticky scroll box, og.png?v=3; 404.html; sitemap with /evidence; vercel.json caches fonts a year and images a day.
Fonts: eight latin woff2 files in site/fonts (139 KB for all, 118 KB a typical page), preloaded first-paint faces, fallback faces with size-adjust and ascent overrides from the font tables; every page lost its render-blocking fonts.googleapis.com stylesheet and the gstatic origin.
HTML per page before to after (gzip): / 17,265 to 21,810 B; /litepaper 20,556 to 24,957; /live 15,640 to 17,777; /evidence 18,899 to 22,493; /bench 94,723 to 98,289. Third-party requests before to after: 3 to 1 (jsdelivr, light client), 1 to 0, 3 to 0, 1 to 0, 1 to 0. Lighthouse before and after is queued under the measure lock (held by reliability runs since 19:16Z, load average 258) and recorded in docs/design/site-polish-2026-10-04.md when it runs.
Checks: node site/build.mjs, tools/ci/link-check.mjs (246 links, 0 broken), identity grep, and a Chrome for Testing run over every page at 390, 768 and 1440 (no overflow, no console errors, menu, router in both modes, deep links on reload, keyboard).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Review round 4 X21 and the project lead's levers 5 and 6 (4 October 2026 evening):
- src/watchdog.rs: CardWatch (no status line for 90 s, or hash rate 0 for 60 s while the node is synced: one
restart, then the card is marked faulted with the reason in the UI and the log; the miner's own worker restarts
suspend both rules until ready, so there are no double restarts; exit 43 counts as a watchdog restart) and
NodeWatch (our node silent for 120 s is restarted in-process through the restart kind the remote jobs use, with a
growing delay). State machines with no clock; 11 unit tests replay recorded STATUS and WORKER FAULT lines.
- engine.rs reads STATUS mismatched=, faults= and the WORKER FAULT lines onto the card (faults, mismatched, message);
a faulted card is not restarted until the user changes its settings or resumes mining; other cards keep mining.
- site/miners.html (build.mjs, scrubbed like /bench, rows from site/miner-bench.json): card, generator version, best
MH/s, MH per watt where measured, miner version, date, source, measured by the team or reported by the fleet. In the
navigation beside the engineering log on every page and in the sitemap. One line says there is no other miner to
compare with.
- tools/reliability: fake-worker.mjs (the serve protocol, misbehaving on command), run.mjs (miner guards on a private
test network, ports 29950+) and app-run.mjs (the app watchdog end to end, ports 29960+).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Observer (tools/observer/observer.mjs): reads the execution layer's JSON-RPC of a node on the proving build
(IGNEUM_EVM_RPC, default the Mac app's node 26800): every chain block's shard plan as it joins the chain
(igneum_getShardPlan by blockHash, one live_proofs row per shard, planned), the proof records of the chain
blocks of the last 10 minutes polled in rotation (igneum_getProofRecords, four in flight, 40 blocks per tick
while active, 10 before activation): proving (in the pool), verified (SP1 proof verified, or carried and checked
by consensus), paid (a carrying segment paid it), with the prover's id8, the carrier, lag in DAA and the payout.
live_state.proving = {supported, active, activation_daa, tip_daa, verifier, pool, blocks_10m,
blocks_fully_proven_10m, shards_proven_10m, shards_paid_10m, median_proof_lag_s, provers_10m}. A node without
the RPCs gives supported false (rechecked every 5 min); an unreachable endpoint is retried every 20 s. Events:
proving (activation, first paid shard), prover_seen. Additive schema (live_proofs, live_state.proving).
API (site/api/live.mjs): proving, and per block shards: [{i, n, state, prover, lag, payout (IGN), pgas}] and
proven; ?window=N (30 to 300 s) for the page's diagnostic long view; LIVE_TABLE_PREFIX reads a test observer's
tables.
Live page (site/live.html), the design change of 4 Oct 2026: three thin strips sharing one time axis, newest at
the right. BLOCKS keeps the per-miner lanes, chain path, blue/red/pending colouring, arrival glow and tooltips;
the lock ring, dashed lock line and final band leave it. FINALITY is an 18 px bar: ember wash = final (up to the
newest locked checkpoint on screen), molten tick = locked checkpoint, faint = proposed, one label at the newest
lock ("locked #522, 12 s ago"); while finality is not active it reads "finality paused: N% of weight silent" and
nothing else (R4.6.3). PROVING shows one cell per shard under each chain block, outline (planned), molten
(proving), prover colour (verified), tick (paid), a dashed "proofs land N s behind the tip" line, or the one
honest line before activation ("Proving layer: not yet activated on this devnet; activation at DAA N" / "node
without proving"). Header stats: on screen, chain, identities, last lock, proven. Legend: one line per strip.
Hover and tap tooltips on blocks and cells (block, shard, prover, lag, payout). Lanes snap on resize (they used
to ease from a zero-height layout). Phone width, no horizontal scroll; draw 0.6 ms avg, 1 ms max with 110 blocks
on screen (playwright, 1280 px).
Hero (site/index.html): a faint second glint behind a real block once every shard of it is verified, only while
the proving layer is active; pace and sampling untouched.
Verified on the private 3-node proving network (tools/proving-v0/run.mjs --network-only, activation 60) with a
CPU prover loop signing as v0/v1/v2: records relayed, verified on node 0, carried and paid (block 155 by 405,
lag 259 DAA, 0.634 IGN); screenshots in docs/design/live-proving (devnet before activation at 1280 and 375 px,
test network active, the ?window=300 view with paid cells). The live devnet shows the "not yet activated;
activation not set" line once the observer runs this build.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
make-icons.py make_social(): og-small.png (256 square, the compact card index/live/litepaper declare), og-square.png
(1024), og-coin.png and og.png (1200x630: mark left, IGNEUM wordmark, tagline, subline; same layout as before, no ring,
no glow). bench.html, evidence.html and build.mjs referenced /og.png, which did not exist; they now get the 1200x630 card
with width/height 1200x630 and twitter:card summary_large_image. Every og:image and twitter:image carries ?v=2 so
Slack, X and iMessage refetch. brand/profile: github-social-1280x640.png (repository social preview) and
vercel-avatar-512.png. bench.html edited by hand for the meta only (a build.mjs run would publish uncommitted log entries).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
After the 4 Oct 2026 stall (no block stored from 11:57 to 13:15 UTC, then 7,022
blocks in two minutes). Notifications only enqueue; a drain loop handles them
in bounded batches. Block flush, colour marking and certificate work each run
on their own timer and never wait on one another. Mergesets come from the
notification's verbose data (bounded cache); getBlock only on a miss, four at
a time. live_state gains observer_lag_s and queue_depth; the API serves them;
the page shows "observer N s behind" past 30 s instead of waiting for the
first block. blocks_per_minute and blocks_60s are bucketed by the block's own
timestamp and reseeded from the table on start, so a catch-up fills past
minutes instead of painting a spike. If no blockAdded arrives for 60 s while
the node's block_count advances, the observer resubscribes; after two failed
attempts it exits 2 and tools/observer/run.sh restarts it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's rule, 4 October 2026: the mark sits in a black square, never in a circle, never on another colour, 20% clear
space; the Mac app is the model. brand/master/igneum-mark-square.svg (1024, #0C0C0E, the exact header polygons at 62%)
and igneum-mark-square-rounded.svg (Apple's 824-on-1024 grid, DMG volume icon only). make-icons.py now rasterises the
masters (rsvg-convert if installed, else Pillow draws the polygons) into igneum.icns (plain square, 16 to 1024),
igneum-volume.icns, igneum.ico (each size from the vector), the Inno art, the DMG background, site favicons
(favicon.ico 16/32/48, favicon-32, apple-touch 180, 192, 512, maskable 512 + manifest entry), relay favicons, and
brand/profile (400/512/1024, github-org-512, X banner). Every page head's inline SVG favicon and the relay header lose
the ring. The .rc and Info.plist paths are unchanged (same file names). docs/brand/before holds the old set.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/fast-time/override-60x.json is the devnet with every clock-like consensus parameter divided by 60 and every
block count unchanged (finality window, ban and min_daa 120 DAA; merge depth 60; Kaspa finality depth 720; pruning
depth at the anticone bound 13,838; coinbase maturity 2; the hourly program epoch 60 blocks with a 10-block lead;
the dataset day 24 minutes). The epoch length, lead and day are consensus parameters of the node since devnet-v4
a5ef8b07, carried by the override file. README lists each field, why it scales or not, the flags and the numbers.
Measured (simnet.mjs, three devnet-v4 nodes, three vmine voters at 1 block/s, one real-hash CPU miner): next
epoch seed in the template at 56.1 s, program swap at 65.1 s wall (DAA 60), first finality lock at 185.5 s wall
(checkpoint 5, DAA 149). Both harnesses take --fast-time: finality-attacks s3 PASS in 113 s wall with 16 locks
per node (the devnet rule needs 20 min of warm-up at 6 blocks/s before any lock); harness s3 partition and heal
43 s wall for three cuts against 983 s for four on the devnet profile with the same binary. Bench-log entry.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The selected chain runs along one horizontal rail; crowded chain blocks
stagger to three rows around it. Side blocks hang above and below in time
order, packed into rows so none overlap. The miner is the ring colour; the
gutter lists active miners with their on-screen block counts. A ruler under
the blocks ticks every 5 s with clock labels and now at the right edge. New
blocks slide in from the right. Red blocks are a dim ember tint. Header stats
gain a pending count. Density steps, tooltips, final band and the one-rAF
loop are unchanged.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Observer: additive live_blocks.color (pending by default). Every chain block's
mergeset marks its blues blue and its reds red, from the notification's verbose
data or getBlock for chain blocks learned via virtualChainChanged; a reorg puts
the removed chain blocks' mergesets back to pending. API serves color. Page:
blue side blocks filled in the miner's hue at 70% with the ring, pending the
faint outline, red a dark outline with a strike; tooltip and legend name the
state.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One lane per miner ranked by share, overflow in an others lane with a count.
Lane labels in a left gutter in the miner's colour (3-character tag on phones).
No per-block labels: short id on the chain tip, the lock, and on hover or tap
with a canvas tooltip (id, blue, DAA, parents, chain or side). Same-lane
overlaps nudged in a fixed sequence. Chain as one path, side blocks linked to
their first parent only, clamped cubics so no edge becomes a tall loop. Block
size and time scale step down together at density. One rAF loop, DPR aware,
paused when hidden or scrolled out. Final band and lock marker. Before and
after screenshots in docs/design/live-dag.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A lock needs two thirds of all 30-day weight signing; finality pauses
whenever less than two thirds is connected and signing, the chain runs
on proof of work meanwhile and the node reports it. Spec 3.3, 3.3.1,
3.7, 3.9, 3.10 Q3 row, 3.11 rewritten with the new arithmetic (safety
one third in every view, liveness two thirds connected, the per-view
window bound stated as 3.7 item 9); O-3.15 decided, O-3.16 closed,
O-3.18 and O-3.19 narrowed. Simulator: --floor, the +local partition
mode, scenario L; A to L re-run at the 2/3 floor over five seeds with
the 0.85 deltas in results_v2.md. Litepaper finality sentences and the
'does not claim' item. Ledger F2, F9, F16, F18 restated, F21 added
(the window bound and the post-heal finality fork from the devnet).
Bench-log: node build and tests, simulator deltas, three-node six-voter
runs of 6A, 6B and 6A with a long heal on ports 29200 and up.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/evidence.md and site/evidence.html: 28 public claims with one of five status labels (7 designed, 3 implemented, 18 tested by the team, 0 reproduced externally, 0 reviewed independently), version or commit, the reproducible test, the result with date and machine, and independent verification (none yet for every row). Evidence link in the homepage nav and the generated pages' nav.
docs/benchmarks/proving-e2e.md: replaces the 20-second shard gate with three fixed workloads, job-received-to-accepted-proof latency, cost per proof, the eligible card list with mining and proving reported separately, the verbatim acceptance standard and the three-unrelated-operator protocol.
docs/plans/funding.md: cost, what is funded (founder's means, the client's 1% fee once there is mining), what waits on revenue, what pauses.
docs/analysis/security-budget.md: emission through six halvings at three price inputs, miners and provers separate from burns, the USD 1M floor and the year it is crossed.
docs/design/payment-routes.md: Mermaid flowchart and table of every flow, with operator, app, team and protocol revenue labelled.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Measured at 375, 768, 1280 and 1680 with headless Chrome. One token set in
all four stylesheets: container 1200 px with a clamp(16px,4vw,32px) gutter,
section rhythm clamp(56px,8vw,96px), cards clamp(18px,3vw,28px) padding and
18 px radius, tiles 18 by 20 px padding and 14 px radius, 24 px card gap and
12 px tile gap, headings h1 clamp(32,5.5vw,56) h2 clamp(28,4.2vw,44) h3
clamp(18,2vw,22), tile values clamp(20,2.2vw,26).
Home: the live strip spans the full hero width with economics-spec tiles;
stat strip and economics tiles share one spec; journey phases and log take
the tile and card boxes; inline padding-top overrides removed, consecutive
dark sections share one gap; every nav anchor lands the heading 11 px under
the sticky bar at every width (padded sections subtract their own padding).
Live: head, strip, cards and gaps on the tokens; four tiles a row, two on
phones; network name no longer clips. Litepaper: real gutter instead of a
fixed 16 px, cover, layout, tables, figures, pull quotes and stat tiles on
the tokens, pager stacks on phones. Engineering log: same tokens, long code
tokens wrap so phones no longer scroll sideways, duplicate h1 hidden.
Copy shortened so no label orphans at any width: stat strip labels, the
economics tiles, the strip tile labels, the litepaper stat tiles, the
mining-program eyebrow. The light-client card block is untouched.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
site/verify/core.js recomputes every header hash (keyed BLAKE2b, the
node's field order), checks the parent links from the previous locked
checkpoint, hashes each voter's G1 key to its vote_key_hash, verifies the
BLS aggregate over "igneum-vote-v1/" || chain_id || 0 || index_le64 ||
checkpoint under the vote tag with the bitmap's keys, and applies Q3
(2/3 of active, 17/30 of total). verify.js drives it from /api/checkpoint
with @noble/hashes 2.4.0 and @noble/curves 2.4.0 pinned from jsdelivr and
fills the homepage card; the badge says LIVE only after a pass in the tab.
site/api/checkpoint.mjs ships the data: certificate bytes, voter table
with public keys, header chain. tools/observer stores every certificate a
block carries (new table live_certificates, voter table read at the lock,
selected-chain headers back to the previous lock, one-off backfill of the
newest lock on start) and keeps header nonces exact; the FinalityLock
write no longer fails on a missing votes_seen.
Tested on the igneum-devnet-7 test network: checkpoint 95 verifies in
Chrome in 103 ms; a flipped signature bit, a dropped voter, an altered key,
an altered header and a removed header all fail with the reason named.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/fork-divergence.md: "Finality v2" table (every file, risk, merge note), decisions
- docs/spec/03-finality.md: section 3.10 implementation notes, clause by clause
- docs/bench-log.md: test-network results (72 of 72 steady locks, median 0.80 s; equivocation
strip; partition: 0 locks at 39.6% of total with the floor binding, heal in 30 s), follower
- tools/observer: live_checkpoints table, FinalityLock subscription, "checkpoint N locked" events
- site: /api/live adds checkpoints and locked/final flags; /live draws the lock ring and final line
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The hero canvas now has a live path fed by the same 2 s fetch as the chain scene (one poller, three subscribers: hero, stats strip, chain scene). When the observer is fresh each dot is one miner seen in the last ten minutes (at most 24, no id drawn), it flashes ember when that miner finds a sampled block, and faint lines reach the miners of the block's parents for a moment. Dots join on a new miner and fade out when one leaves the ten-minute set. The drift, colours and pace are the simulation's; the simulation runs unchanged when the observer is off or stale.
A live stats strip under the hero buttons (miners active, blocks / s, network hash rate, blocks on the devnet) shows only while the observer is fresh and hides again when it goes stale. Two tiles per row at phone width.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Litepaper Finality: the reorg bound users rely on is the 12-hour finality depth in median time; Kaspa's one-hour merge depth is a merge limit, not a reorganisation bound; first-month sentence and "does not claim" item 4 say the same. Litepaper Speed: emission per block on a schedule keyed to difficulty-adjusted time, reds in the window paid, coins track blocks within the controller's accuracy.
Design 5.5 and D12: the native-execution veto is relative to the carrying block's own selected-parent chain; two-node reorg test added to 8.5.
Ledger P11, F15, E10 statuses and fixes rows 79, 82, 84 updated.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Body sections go from 880 to 433 words. Every section keeps its heading,
animation, counters, the devnet switch, the program ticker and the journey
feed, and gains one link to its litepaper tab. RandomX comparison is a
four-row table; the full table already lives in the litepaper.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/provenance.md: table of every component Igneum uses (origin, licence, what changed, why, how measured), what is new, what to adopt from upstream, own-code licence pending the project lead's decision. Licences verified on disk: rusty-kaspa ISC, chiavdf Apache-2.0, igneum-pow MIT, blake2b_simd MIT, blake3 CC0 or Apache-2.0, sha2 MIT or Apache-2.0, secp256k1 CC0, keccak Apache-2.0 or MIT. RandomX, SP1, revm, blst, ProgPoW, LWMA, Monero, GMP, sha3: approximate, not cloned.
site: litepaper gains the Built on the shoulders section and nav entry; index gains the two-line mention and footer link near the RandomX comparison; the block rate reads one block a second at launch, rising, where it read as permanent (litepaper diagram, index live section).
tools/upstream: README with the exact merge commands, expected conflict files from fork-divergence, the test list and the consensus-review rule; sync-upstream.sh fetches and opens the merge on a branch without committing. Not run against the fork.
docs/commercial/prover-customer-brief.md: one-page brief for a first proving customer at testnet, timeline from journey.json, risks, 10 candidates labelled approximate.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Titles, descriptions, canonical URLs, Open Graph and Twitter cards on index, litepaper, live and bench (bench through page() in build.mjs). og.png 1200x630 from the brand wordmark and tagline, PNG icons, apple-touch-icon, favicon.ico, site.webmanifest, robots.txt and sitemap.xml. Organization JSON-LD on the homepage only. Rebuilt bench.html.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
tools/observer: Node 22 observer on the node's wRPC JSON port (blockAdded and
virtualChainChanged subscriptions, 2 s state ticks) writing live_blocks,
live_state and live_events to Neon, miner address decoded from the coinbase
payload, events for new or quiet miners, peers and difficulty steps.
site/api/live.mjs: three indexed queries, max-age=1.
site/live.html: status strip, DAG stream with real parent edges and a lane per
miner, miners table, events feed, blocks-per-minute sparkline, OFFLINE freeze.
The homepage live path and the /api/live cache header went in with 408c968.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- 03-finality: Q2 participation from every vote seen in blocks (votes are
block payload); 3.3.2 the eclipse case closed by the 56.7% floor with the
sim v2 F2 numbers; 3.4.1 why aggregators cannot grind participation.
- 07-execution (new): EVM semantics on the DAG, shard sortition (8 provers,
10 s, then open, no shard bond), bridges (none official, no bridged
stablecoins at genesis, proof bridge with the consensus proof in phase two).
- 08-client-security (new): reproducible builds, release key in genesis and
in hardware, no silent updates, consensus only by 90% signalling, notarised
builds, official sources with the hash, seed confirmed before mining,
hardware wallet, the permanent seed line.
- 00, 02, 05, README, 06: cross-references, O-2.8 removed, O-3.3, O-3.7,
O-5.1, O-5.2, O-5.6 narrowed, O-8.1 added, counts kept at 60.
- Ledger: eight Status lines, status table, count table, overclaims 38, 40, 71.
- FUD fixes: rows 23, 26, 38, 62, 64, 66, 67, 70, 72, section 3 and 4.
- Site: bridge and stablecoin sentences no longer launch features; the seed
line wherever the app appears.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
POST /api/log stores a log snapshot in Neon table miner_logs over the HTTP SQL
endpoint with no dependencies. upload-log.bat posts the last 256 KB of a log from
Windows with the curl.exe that ships with it. tools/logs.mjs lists runs and prints
the latest lines on the Mac.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Decision of 3 October 2026: no fee to any team, foundation or fund.
Priority fee now splits 80% to the miners and provers of the block and
20% to the application called, attributed per call frame as before.
No burn of the tip; the base fee is still burned in full on both gas
dimensions. External proving jobs pay 90% to the provers who delivered
and burn 10%. The 60% signalling mechanism stays as a general tool for
parameters that genesis rules leave to miners; upgrades stay at 90%.
Ledger E4 closed by removal; E3, E5, G4, G5, G8, L1 and overclaims
45, 46 and 53 rewritten to the new rule.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The ledger stays in the repository as an internal working document while it carries open items. /ledger now redirects to the homepage. Promotion-rules entry rewritten without any founder location.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The chain animation scales its proving tempo to the canvas width, so a block is mined, proven and locked before it leaves a phone screen. Opening frame seeds proven and locked blocks on narrow canvases too. Repository links point at github.com/igneum-network/igneum.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>