Igneum: the GPU-mined zkEVM L1. Node, miner, app, spec and site.
Find a file
igneum-labs 07c8380002 Key succession, the pin tool's half: elf/prior/ and the manifest's prior and succession blocks, the host embedding both pairs, the release-manifest check comparing both
docs/design/key-succession.md (the enforced-proving lane, 8 October 2026): the
object names the prior pair, a next pair, an activation height H and a window
W; the node embeds both pairs and verifies under the pair a proof claims when
that pair is accepted at the carrier's DAA (the node branch key-succession-node
on the fork carries that side).

The pin tool (igneum-prove-pin): a pin over an existing elf/ moves the four
files it holds to elf/prior/ and writes the manifest's `prior` block (the same
per-program fields plus the pinned_at of that pair) and a `succession` block
naming both pairs' ids; the top-level shard and aggregator stay the newest
pair; at most two pairs live (a pin over an elf/ that already carries prior/
replaces prior/); `--no-prior` keeps today's shape. The host (pinned.rs)
embeds elf/prior/'s four files, checks them against the `prior` block when the
manifest carries one and derives the prior ids from the keys (Pinned::prior,
PriorKeys), checks the `succession` block's four ids against both pairs, and
builds unchanged on a tree whose manifest names no `prior` (every tree now
carries elf/prior/ as a copy of the current pair, so the include_bytes
compile; the in-process verifier reads `prior` as absent). The release
manifest check refuses a served manifest whose `prior`, `succession`,
succession_daa or succession_window_daa differ from elf/manifest.json's, and
a `prior` present on one side only.

The node reads H, W and the next ids from its object, never from the manifest;
`succession` is for the served manifest and its check. The first real pin (the
live pair 0x2b1a81cb…/0x474678f3… into prior/, the re-pinned
0x282dcfce…/0x3fd721e8… on top) runs when main names H.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-08 17:34:55 +00:00
.claude/agents Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so 2026-10-07 18:39:50 +00:00
.forgejo/issue_template Builder programme (8 October 2026): /build, /grants, the Devnet 3 faucet on build-1, docs/build as the source 2026-10-08 10:24:07 +00:00
.github/workflows Merge branch 'ci-steward' into ci-steward-2 2026-10-07 17:02:55 +00:00
app Class v6 floor lane 4: the RX 7600 (8 GB) measured on PC 1 (13.88 MH/s at 113 W, 8.14 microjoules, the card-in job 15:50 UK) added to the tiers table and the AMD estimates re-based on it; 10 of 10 on build-3 2026-10-08 15:04:38 +00:00
brand site: share cards and metas from one source (site/og), rendered on a build box 2026-10-08 14:51:03 +00:00
contracts Bridge: one Devnet 3 account balance proven on the Sepolia verifier (547.8077 IGN under the state root of Devnet 3 block 28,462, three-node eth_getProof from the reader node; eth_call true on the live contract, the suite 10 of 10 green on build-3); the vector committed 2026-10-08 11:35:41 +00:00
docs Merge enforced-proving 9bf05c8b into master (gate: green on 9bf05c8b, recorded by tools/ci/pre-push.sh; landed on the box mirror) 2026-10-08 16:45:40 +00:00
igneum-census Counter ASIC 3.0 item 8: the latency-shadow knob (LoadClass +sh<S>x<R>), its packs and the PC 2 playbook 2026-10-06 07:58:35 +00:00
igneum-pow class-v6: drop the second copy of DatasetSource's leaves methods the master merge brought in (master's copy lacked the geom field) 2026-10-08 16:33:09 +00:00
infra class-v6: merge master 3a7592c52 (after the counter-asic-4 code revert eb2c21c0) into class-v6 so the frozen tree lands on master as one two-parent merge. Conflicts: igneum-pow memhard.rs, main.rs, tests/packs.rs keep class-v6's text (class v5's mixer-draw rule in the agreed AP-F4-1 form, cost 205 with w32; master carried the first form, NAF sum 163; the ds55 and reg64 arms of epoch_of; the window tests); site/litepaper.html takes master's (the site lane's text); docs/ledger-public.md and site/ledger.html regenerated from the merged docs/fud-ledger-2.0.md by tools/ledger/export-public.mjs and tools/ledger-page.mjs. 2026-10-08 16:31:19 +00:00
packaging Igneum Wallet: the Windows build chain (8 October 2026, main's order after 0.1.6: a Windows arm by the wallet's next OTA, PC 2 by job when it is back). The pieces, the miner's chain step for step with the wallet's names: packaging/windows/push-build-inputs.sh --wallet packs app/igneum-wallet and app/igneum-common into the build-inputs zip with vendor/igneum-node as a symlink to node/ (the wallet links the node's rpc crates by that path; unzip restores it inside the distro) and adds the build unit {app/igneum-wallet, igneum-wallet, windows} with its tests, so the PC's build job makes igneum-wallet.exe on the gnu target as it makes igneum-app.exe; packaging/windows/push-wallet-kit.sh publishes the kit zip (the host sources and BUILD-WALLET-APP.bat, build-installer.ps1, Igneum-Wallet.iss, stop-igneum-wallet.ps1, the icons, the wallet's packaged igneum-wallet.json from the token file) to the downloads host; relay/playbooks/wallet-kit-pc2.ps1 is the run job on PC 2: the host through BUILD-WALLET-APP.bat (MSVC, WebView2 SDK), the payload from the build job's engine and the node pin, the installer through build-installer.ps1 -Product wallet (Inno, rcedit), the smoke run with the host's version block, and, over a running older wallet, the installer end to end with the installed version read back (rule 14), every output dropped on the relay with its sha256; packaging/windows/build-installer.ps1 takes -Product miner|wallet (folder, engine, stop script, exes, .iss, setup name, the version-block stamping by product); packaging/windows/Igneum-Wallet.iss is rebuilt on release-0.3.25's detach-safe miner shape (install-close-23 and install-detach-25: the payload's own stop script with -Install, the install marker under igneum\wallet, the one-shot detached task under the app's job runner, the version-named file refusal, the stale-marker clear) with the wallet's names; packaging/windows/stop-igneum-wallet.ps1 is the miner's 0.3.23 stop script for the wallet (the host first by path, the engine through its API, the unlock wait with the STILL LOCKED line); make-wallet-payload.sh is the Mac-side payload maker for a hand build. release-0.3.25's installer-stop-check passes on the wallet pair (every rule holds); the check itself stays on the release line, whose miner installer carries the shape master's does not yet. Signing: as the miner's, deferred until the certificates exist (release-0.3.20 section 2.4). Untested on a PC until PC 2 returns: the first run is the known-failed run by design. 2026-10-08 11:59:16 +00:00
pool Pool v0 rebased onto master and the 0.3.14 fork: the program class and era seed ride with every seeds and job line; the re-check test for class v3 and class v4 2026-10-06 18:49:13 +00:00
proto-cuda igneum-pow, proto-cuda: counter-asic-4's research code comes off master (the revert of 31496f4e's code paths; documents untouched), the coordinator's order of 8 October 2026, 17:32 BST 2026-10-08 16:17:08 +00:00
proto-metal class v5 kits: every worker host uploads the pack's state leaves for igneum_build (the NVRTC worker, the OpenCL host for AMD, Intel and Apple, the Metal worker), checked against the pack's count and FNV first, freed after the build; a v5 pack without its leaves builds nothing 2026-10-07 18:36:17 +00:00
proto-newpow class v5: the pod bench's run script (proto-newpow/class-v5/run.sh: both packs, two passes, 20-s power windows) 2026-10-07 11:24:23 +00:00
proto-opencl ds55 hosts (research class, 8 October 2026): the CUDA worker and the OpenCL host size the dataset by the pack's word count (IGNEUM_DATASET_WORDS and IGNEUM_DATASET_ITEMS from program.h when present, 1 << IGNEUM_DATASET_LOG2 when absent, so every existing pack runs as before), build words / 16 items, and the OpenCL bench's random points go through the pack's own index mapping; the ready, check and summary lines name the count when it is not a power of two; packfile.h refuses a count off the 2^16 grid or a mulshift flag that contradicts it; known-failed test first (emu/packfile-test.c: the old reader sized the 5.5 GiB pack at 2^30 words) 2026-10-08 13:58:18 +00:00
proto-vdf proto-vdf: Wesolowski VDF between the certified checkpoint and the program seed 2026-10-03 16:39:01 +00:00
proving Key succession, the pin tool's half: elf/prior/ and the manifest's prior and succession blocks, the host embedding both pairs, the release-manifest check comparing both 2026-10-08 17:34:55 +00:00
relay Igneum Wallet: the Windows build chain (8 October 2026, main's order after 0.1.6: a Windows arm by the wallet's next OTA, PC 2 by job when it is back). The pieces, the miner's chain step for step with the wallet's names: packaging/windows/push-build-inputs.sh --wallet packs app/igneum-wallet and app/igneum-common into the build-inputs zip with vendor/igneum-node as a symlink to node/ (the wallet links the node's rpc crates by that path; unzip restores it inside the distro) and adds the build unit {app/igneum-wallet, igneum-wallet, windows} with its tests, so the PC's build job makes igneum-wallet.exe on the gnu target as it makes igneum-app.exe; packaging/windows/push-wallet-kit.sh publishes the kit zip (the host sources and BUILD-WALLET-APP.bat, build-installer.ps1, Igneum-Wallet.iss, stop-igneum-wallet.ps1, the icons, the wallet's packaged igneum-wallet.json from the token file) to the downloads host; relay/playbooks/wallet-kit-pc2.ps1 is the run job on PC 2: the host through BUILD-WALLET-APP.bat (MSVC, WebView2 SDK), the payload from the build job's engine and the node pin, the installer through build-installer.ps1 -Product wallet (Inno, rcedit), the smoke run with the host's version block, and, over a running older wallet, the installer end to end with the installed version read back (rule 14), every output dropped on the relay with its sha256; packaging/windows/build-installer.ps1 takes -Product miner|wallet (folder, engine, stop script, exes, .iss, setup name, the version-block stamping by product); packaging/windows/Igneum-Wallet.iss is rebuilt on release-0.3.25's detach-safe miner shape (install-close-23 and install-detach-25: the payload's own stop script with -Install, the install marker under igneum\wallet, the one-shot detached task under the app's job runner, the version-named file refusal, the stale-marker clear) with the wallet's names; packaging/windows/stop-igneum-wallet.ps1 is the miner's 0.3.23 stop script for the wallet (the host first by path, the engine through its API, the unlock wait with the STILL LOCKED line); make-wallet-payload.sh is the Mac-side payload maker for a hand build. release-0.3.25's installer-stop-check passes on the wallet pair (every rule holds); the check itself stays on the release line, whose miner installer carries the shape master's does not yet. Signing: as the miner's, deferred until the certificates exist (release-0.3.20 section 2.4). Untested on a PC until PC 2 returns: the first run is the known-failed run by design. 2026-10-08 11:59:16 +00:00
scene Live proving feed: the page says when its shard states are stale, and a chain block with an empty plan reads "no shards in this block" (8 October 2026, main's order: the project lead wants to watch proving and shards in real time; a stale snapshot must read as stale). Reading of the day: /api/live's proven and paid states come from the Devnet 3 observer's own node on igneum-build-1 (igneum-observer-node-dn3, EVM 26850), not from hub-1; that node stopped crediting payouts at 23:57Z on 7 October (paidShards frozen at 7,304 while blocks carried 8,457 proof records by 03:00Z and hub-1 counted 11,861 by 08:56Z), and the page kept showing the paid total as fresh. site/lib/proving-health.mjs (tests known-failed first: "Cannot find module", then 10 green on build-2): stale when the observer's last status read is over 60 s old (status_at, new in the observer's live_state.proving), when the node's tip trails the newest block by over 300 DAA, or when blocks carried proof records in the last 10 minutes and no shard moved to verified or paid for 10 minutes (the blind-to-records class); a quiet chain is not stale for lack of credits. /api/live carries stale, stale_reason, status_age_s, tip_lag_daa, records_10m and last_change_at on proving (two more indexed readings; scene/feed-contract.json lists the keys; the recorded fixture carries them). /live: the Proven tile's line reads "proving feed stale: ..." in ember, else "... last credit N s ago"; the inspector's count adds "feed stale". Scene 2.0.7: a chain block whose plan is known (block.number set, carried as plan on the normalised block) and empty reads "no shards in this block"; loading and late stay for an unread plan (shard-words test, known-failed on 2.0.6). Gate: the health test joins the site unit-test line. 2026-10-08 09:12:56 +00:00
sim D5 partition row: N1b and N2b (the recovery bound measured on build-4) and the harness known-failed line on real nodes (v3 split past the expiry: both sides lock alone, 8 disagreeing locks after the heal); results, spec test table and the plan's D5 block updated 2026-10-08 16:21:46 +00:00
site Merge class-v6 a7c2c082 into master (gate: green on a7c2c082, recorded by tools/ci/pre-push.sh; landed on the build mirror) 2026-10-08 16:44:21 +00:00
tools Key succession, the pin tool's half: elf/prior/ and the manifest's prior and succession blocks, the host embedding both pairs, the release-manifest check comparing both 2026-10-08 17:34:55 +00:00
.gitignore gitignore: infra/cross/out-workers-box/ (the workers tools/workers-remote.sh fetches from the box) 2026-10-06 19:11:39 +00:00
.vercelignore Commit identity rule and a deploy ignore file 2026-10-03 17:33:46 +00:00
CLAUDE.md Igneum: design docs, Metal lottery-hash prototype, CUDA test pack, finality simulation 2026-10-03 15:06:01 +00:00
rust-toolchain.toml rust-toolchain.toml: one pin for every side (1.99.0, the two cross targets); the mismatch refusal reads it 2026-10-06 23:44:20 +00:00