The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh). The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge. Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| node | ||
| rpc | ||
| .gitignore | ||
| addpeer-from-mac.sh | ||
| config.sh | ||
| create-seed.sh | ||
| dns.sh | ||
| health.sh | ||
| install-rpc-from-mac.sh | ||
| lib.sh | ||
| provision-seed.sh | ||
| README.md | ||
| seeds-testnet.tsv | ||
| seeds-testnet.txt | ||
| seeds.tsv | ||
| seeds.txt | ||
| stage-v4.sh | ||
| switch-v4.sh | ||
Igneum seed nodes
A seed is a small VM with a fixed public IPv4 that runs igneumd with p2p open, no mining, RPC on loopback, and
serves peer exchange (the address manager stays on; --connect is never used). seeds.txt lists one <ip>:26611
per seed and is the file the consensus engineer bakes into the network parameters and every package reads as
SEED_PEERS. The plan, the client path and the rotation procedure are in docs/plans/seed-nodes.md.
The first seed, igneum-seed-1, was created on 3 Oct 2026 (Hetzner cx23, Falkenstein, USD 6.49 per month net plus
the IPv4). It runs the shared devnet (--devnet, no suffix).
cd infra/seed-nodes
./create-seed.sh # one VM, persistent IPv4, firewall 22 + 26611 + icmp, appends seeds.tsv, rewrites seeds.txt
./provision-seed.sh igneum-seed-1 # source tarball -> build on the VM (about an hour on 2 vCPU) -> unit igneumd, started
./health.sh # one line per seed: p2p port, unit, RPC, synced, blocks, peers, known addresses
./addpeer-from-mac.sh relay start # a non-mining relay igneumd on the Mac peers with the live node (LAN) and the seed; the
# live node runs in safe RPC mode, so addPeer over grpcurl is refused (see the script)
SEED_NAME=igneum-seed-2 SEED_LOCATION=ash SEED_TYPE=cpx11 ./create-seed.sh # the next seed; provision adds the first as --addpeer
./stage-v4.sh igneum-seed-1 # devnet v4 (4 Oct 2026): source tarball of vendor/igneum-node-v4 -> detached, niced, memory-capped
# build on the VM into /root/v4 -> /opt/igneum/v4/bin, /var/lib/igneum-v4 (fresh), unit igneumd-v4
# installed DISABLED; the v3 unit keeps running. `wait` and `status` modes.
./switch-v4.sh igneum-seed-1 # the cut-over: stop+disable igneumd, enable+start igneumd-v4, print its sync state; --back reverses
Devnet v4 is a new chain from the same genesis (docs/fork-divergence.md, "Compatibility"), so the seed runs it from a
fresh data directory, /var/lib/igneum-v4, with its own launcher (node/run-seed-v4.sh, same flags, binary from
/opt/igneum/v4/bin), env file (/etc/igneum/seed-v4.env, a copy of seed.env) and unit (node/igneumd-v4.service,
Conflicts=igneumd.service: the two bind the same ports). The v3 database in /var/lib/igneum stays as it is for the
rollback. health.sh reports unit=active-v4 once the v4 unit serves. The runbook is docs/plans/cutover-2026-10-04.md.
Settings in config.sh: provider, name, type, location, image, ssh key (~/.ssh/igneum_ed25519), SSH_SOURCE
(any, me or a CIDR for port 22), NETWORK_ARGS (--devnet; a private network: --devnet --devnet-suffix=20),
SEED_PEERS, BUILD_WHERE (seed builds on the VM; bin reuses ../cloud-devnet/build/bin). BIN_SOURCE=mac ./stage-v4.sh (4 Oct 2026) skips the VM build: infra/cross/build-linux.sh cross-compiles the devnet-v4 worktree
on the Mac with cargo-zigbuild (x86_64 Linux, glibc 2.36) in minutes, uploads the binaries to /root/v4/out and
installs them exactly as a VM build would (the seed's own build took 55 minutes on its 2 vCPU). The Hetzner token is
read from ~/.config/igneum/hetzner-token and never printed.
Node flags (node/run-seed.sh): --devnet --appdir=/var/lib/igneum --rpclisten=127.0.0.1:26610 --rpclisten-json=127.0.0.1:28610 --listen=0.0.0.0:26611 --externalip=<ip> --nodnsseed --disable-upnp --nologfiles --yes --maxinpeers=128 --outpeers=8 [--addpeer=<other seeds>]. No --enable-unsynced-mining (nothing mines here) and
no --connect (it would set the inbound limit to 0 and switch the address manager off).
Files: create-seed.sh, provision-seed.sh, health.sh, addpeer-from-mac.sh, stage-v4.sh, switch-v4.sh, config.sh,
lib.sh, node/{install-seed.sh,run-seed.sh,igneumd.service,build-v4-on-seed.sh,run-seed-v4.sh,igneumd-v4.service},
seeds.txt, seeds.tsv, build/ (logs and the v4 source tarball, git-ignored).