igneum/docs/plans/testnet-go.md
igneum-labs 211ab85a96 base-unit gate: the miner takes --exec-rpc for node A's exec port, and block one on a fresh class v5 chain is printed and required (the missing test); go checklist: row 9v's fix landed, 6e04f7fc is the go commit
The gate's node A serves its exec RPC on 28190 while the miner's default is the network's port (26790 on the 0.3.24 line
everywhere, 26890 on the testnet from f41f48a7), so the miner never reached it; the pod run of 15:0x UK needed a relay. The
block-one lines: node A's genesis-stream line, the miner's first block, the first class v5 refusal if any, node A's exec
tip after mining; tip 0 fails the run (the known-failed case of 6e04f7fc, ba294c98's pair, must read FAIL here).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-08 14:22:01 +00:00

76 KiB

Igneum public testnet: the go checklist

Prepared 5 October 2026 by the infrastructure and consensus engineer for the 19:00 BST (18:00 UTC) opening. State of every line as of 16:05 UTC. Nothing mines until the owner says go; the seeds hold the chain at height 0.

RE-CUT 7 October 2026 (the testnet genesis lane, on the project lead's approvals of 09:3x UK, docs/plans/ledger-decisions.md "Decisions (7 October 2026, 09:3x UK)" row 5, and his words of the same morning on the two exec-side findings): the genesis is re-cut on the 18-decimal layout with EmissionSchedule::TESTNET_1 and every switch on from genesis; section "The genesis, re-cut" below is the object, "The seeds' cut-over" the runbook. The three seeds still hold the 5 October chain (genesis 87617621..., digest b7d8c915...) at height 0 and move only on the project lead's go. The hash and digest are FINAL as of 18:4x UK: mission item 8 (the genesis forward-compatibility fields, lane genesis-forward, daa61847 to f95178a1 and ff06c05c) is in the object.

What runs now

Piece Where State at 16:05 UTC
igneum-testnet-1 seed 1 seed1.testnet.igneum.network = 195.201.35.33, Hetzner cx23, Nuremberg (nbg1), Debian 13 up, unit igneumd active, p2p 26811 open, 2 peers, height 0, sink = genesis
seed 2 seed2.testnet.igneum.network = 5.161.232.205, Hetzner cpx21, Ashburn (ash), Debian 13 up, 2 peers, height 0
seed 3 seed3.testnet.igneum.network = 5.223.52.210, Hetzner cpx22, Singapore (sin), Debian 13 up, 2 peers, height 0
Public JSON-RPC https://rpc.testnet.igneum.network (seed 1: nginx, Let's Encrypt, 20 req/s per address with a burst of 40, 20 connections per address, bodies to 256 KiB, then rpc-filter.py on 127.0.0.1:8545, then the node's EVM RPC on 127.0.0.1:26890) live: eth_chainId = 0x116e (4462), eth_blockNumber = 0x0, net_version = 4462; admin_peers and igneum_submitProofRecord refused with -32601
DNS deSEC (ns1.desec.io, ns2.desec.org), A records for the three seeds and rpc.testnet, TTL 3600 all four resolve from the authoritative servers
Firewalls igneum-testnet-seed (22, 26811, icmp) on all three; igneum-testnet-rpc (80, 443) on seed 1 only applied
The node binary igneumd 1c19441d (fork branch testnet-infra), built on PC 1 by build job build-20261005-154330 (WSL2 Ubuntu 24.04, glibc 2.39), sha256 a9ea25f8ada29e3ee1dfc2ccced4e088a56237511be75d5d80f7bb7a72414b10 on every seed as /opt/igneum/bin/igneumd
Mining none nothing mines; no --enable-unsynced-mining, no miner process anywhere on the testnet

Each seed's start-up log, identical on the three:

Fees on igneum-testnet-1: pgas table v1, B_p 120000 pgas, S_p 30000 pgas, floors 100000000000 wei per gas and 10000000000000 wei per pgas; calibrated v1 from DAA score 0
Consensus params digest: b7d8c915f20f5af261e69e7f4aa9c3d03a9c4a462174776502b63fa1e9ec8447 (exchanged in the p2p handshake; a peer with another digest is refused)
igneumd/2.1.0
[igneum-exec] genesis 87617621714af1bf33bd17f291f90a7e0bff760a669bba53083ea8c0f7cbd840 executed: chain id 4462, registry at 0x0000000000000000000000000000000000000210

health.sh shows synced=False on all three: that is the no-blocks state (a node is synced once it has blocks past genesis), not a fault. The check: cd infra/seed-nodes && NET=testnet ./health.sh.

The go object (ruling of 7 October 2026, 19:2x UK): the 0.3.24 testnet object, re-cut with class v5 from genesis (0d05e795, 8 October)

By the coordinator's ruling of the evening of 7 October 2026, igneum-testnet-1 goes on the 0.3.23 testnet object (the Devnet 3 shape: byte 7 from genesis, every Devnet 3 activation at 0, the era VDF at 0, class v5 at 0 if its Devnet 3 crossing reads clean, the heights, the bonus's switch field) AT 18 DECIMALS (the project lead's word, 21:35 BST: the decimals lane's code merged, the schedule at 18, the 16-byte genesis payload on the final message, the scale factor tested known-failed first), cut and re-armed on the seeds by the build-server lane, which owns them; the interim re-arm is the release-0.3.22-node object (34a2dbaa, digest 87d103b6..., genesis 52a3e6a9...). Two orders ride with it: the testnet genesis carries the FINAL message (the 5 October payload that 87617621... carried, never the 4 October "proposed, not final" text that 52a3e6a9... hashes: a public node never starts on a proposal; the digest moves and the re-arm absorbs it), and the base unit is 18 by the project lead's word of 21:35 BST (the 8-decimal scratch form is no longer needed); nothing on a seed before the node lane names the cut and the build-server lane's dry run reads clean. The carry (22:1x UK): this lane's re-cut merged onto the 0.3.24 line as fork branch testnet-genesis-3-node 34892a36; LANDED 23:01 UK as the 0.3.24 node pin 47b9b229 (= the Devnet 3 object commit 774f16c9 + 34892a36); the pin moved at 23:39 UK to c9e385eb (Devnet 3's class v5 floor 28,800 to 32,400) at 00:54 UK on 8 October to dfbd1e10 (the floor at 39,600) and at 09:33 UK to 5b673577 (the floor at 68,400 from main's move minute 10:45 UK; nothing on the testnet side changed at any move), release-0.3.24-node at 5b673577 on both box mirrors, every gate green at 09:39 UK, the Devnet 3 canary set clean on its own binary. THE POST-CROSSING RE-CUT (row 9n) LANDED: Devnet 3 crossed its class v5 floor clean at 12:57 UK on 8 October (the first epoch-19 block on the v5 seed, 341 blocks in four minutes, seven stale-pack attempts refused, no state-wait or catch-up fault on build-1's three nodes), and the node lane cut 0d05e795 on release-0.3.24-node (13:32 UK, on both mirrors 13:48 UK): program_class_v5_activation_daa 0 and program_class_signal CLASS_SIGNAL_V5 (byte 6 from genesis), the identity test re-pinned, nothing else in the object (18 decimals, TESTNET_1, chain id 4462, every other switch from genesis as before). The digest is 1da30c10... (from b2e856ed...); the genesis hash is unchanged (the digest is not in the header). The node lane's gates on 0d05e795, all green by 14:04 UK: pow 19, exec 47, miner 28, consensus 134, p2p-flows 38, core 175; its testnet canary (13:50 to 13:51 UK): the digest 1da30c10... with no file, "stamps object version 6", the override refused, two empty nodes handshaking, the live old-object seeds refused; the Devnet 3 canary on that line unchanged (cc902690). This is the object the go uses.

Field Value on the 0.3.24 line at 0d05e795 (the post-crossing re-cut; read from its binary by the node lane's testnet canary, 13:50 UK, 8 October 2026)
Network igneum-testnet-1, chain id 4462 (never moves), address prefix igneumtest, ports 26810 / 26811 / 28810 / 26890
Genesis hash 01294fd322704dc28fbef0e7a5ef86d6ee260ac5efaf88891cdba661b5fd58ac, merkle bcd0e8fb1099aeb3cc1370b50e6dec9f615e204374b2097f25b2438e7d22f49f: the FINAL 5 October message on the 16-byte subsidy payload of 18 decimals, timestamp 2026-10-05T00:00:00Z, bits 0x1d100000
Consensus digest 1da30c10e164784ffbf5bf216ef3bf84a2d5da212317b1e535c9850fe14aba2f (pinned by igneum_testnet_identity at 0d05e795, consensus/core/src/config/params.rs; read from the 0d05e795 binary by the node lane's testnet canary, 13:50 to 13:51 UK, 8 October: the override refused, two empty nodes handshaking on it, the live seeds refused on their 5 October digest). The 5b673577 digest b2e856ed... (class v5 at never) is void, as are b7d8c915... (5 October), 87d103b6... (the 0.3.22 interim) and every earlier interim
Base unit, emission 18 decimals (the project lead, 21:35 BST); EmissionSchedule::TESTNET_1 at the unit
From genesis difficulty v2 and v3, proving v0, finality v3, the DAA-second rule, the leave item (delay 3,600), the signing bonus 0 at 1,000 bps (no burn), the per-block subsidy, class v3 and v4 under the Devnet 3 shape's one-day signal window (byte 6 stamped from genesis: class v5's signal; class v5 itself from DAA 0 by the post-crossing re-cut 0d05e795), the ladder at rung 0 (window 86,400; 27/35/53 admissible, 88/173/267 not), the era VDF (scheme 0, the reference T), proving v1 with the fresh rule (the Devnet 3 shape), fees v1, consensus proof verification under the manifest's ids (shard 0x2b1a81cb..., aggregator 0x474678f3...), sig_scheme 0 with its switch, the W5 succession, the cache rung (512 MiB inadmissible) behind its switch
Held at never the fork gate (window 600), the peer directory, the pool split, exec restart
Pairing igneum-pow at the class v5 freeze commit 1c420786
Where the 0.3.24 node pin release-0.3.24-node 0d05e795 (both box mirrors; 5b673577 is the object's base and void as the go pin, as are 47b9b229, c9e385eb and dfbd1e10): the gate artefact /srv/artefacts/0324-tn-0d05e795/node-lane/igneumd sha256 b76d867180c315958370e625ed72840ef909344e946f05d7cbd7e4284c257b8a, igneum-miner 0e67237f54d963aae5f2e2bf6c5e293cf42322274ae1d54b49b047916f30e11b (the seed-class pair and the hive come from the build-server lane's build of this pin on this sha, with their own shas); pairing igneum-pow at the freeze 1c420786 (fingerprint cbc5bd0a...); source branch testnet-genesis-3-node merged into the line

Suites on 34892a36 (bounded, build-2 and build-1): consensus-core 168, exec 47, p2p-flows 38, pow 19, kaspad 2; consensus 134 one test at a time with the pre-existing m20 red (9f); the parallel lib run aborts in the test-order race class the node lane owns, noted, not chased tonight. On the staging 47b9b229 (the node lane, 22:35 to 22:43 UK, against the freeze pairing): consensus 134, core 175, exec 47, miner 28, p2p-flows 38, pow 19, the build rc 0; the testnet canary on build-1: digest b2e856ed... on igneum-testnet-1, the genesis as cut, 18 decimals in the fee floors, object version 7 stamped, the override file refused (rc 1), two empty nodes handshaking on b2e856ed..., a Devnet 3 node reading its own digest beside it. During the handshake step seed 2 (5.161.232.205) dialled the canary and was refused on the digest; the gate pod of 8 October (09:49 UK) read the seeds' own answer: all three refuse on b7d8c915..., the 5 October object of 1c19441d, so the seeds carry the 5 October chain at height 0 until the project lead's go (no 0.3.22 binary reached them); the runbook's wipe stands. The digest lineage: b7d8c915... (1c19441d) to 87d103b6... (the 0.3.22 interim re-arm) to b2e856ed... (5b673577, class v5 at never) to 1da30c10... (0d05e795, class v5 at 0: THE GO DIGEST). The runbook's values: --genesis 01294fd3..., --digest 1da30c10..., --commit 6e04f7fc (the go pair on release-0.3.25-node: ba294c98 plus row 9v's genesis-state fix, by the coordinator's rulings of 14:2x and 15:1x UK on 8 October; its gates and the block-one line pending at 15:2x UK; ba294c98 is the known-failed base and --commit 0d05e795 the FALLBACK pair, neither the go pair), the seed-class pair the build-server lane builds from that commit (the 0d05e795 FALLBACK pair is built and dry-run clean, 14:26 UK: /srv/artefacts/0324-tn-0d05e795/seed/igneumd sha256 9b464158..., igneum-miner d5a5bc9e..., row 9q; the re-arm is each pair's pull-path dry run on the three seeds). The record of the first dry run, on 5b673577's pair, stands below and is NOT the go pair: the seed-class pair the build-server lane built from 5b673577 at 09:43 UK on build-1: /srv/artefacts/0324-5b673577/seed/igneumd sha256 3a204fd9d3a4840dcef430e73cbfa986881db915d5459533d395dc0563a597a8 (glibc 2.34, the commit string twice, igneum-pow 1c420786) and igneum-miner sha256 464dca078db54434b2ce4cdf8b5975a614141d20907a9d941cc88667b85144ba, --commit 5b673577, no override, --wipe-genesis; the read-back includes Base unit: 10^18. DRY RUN DONE 10:23 UK, 8 October 2026: rc 0 on seed1, seed2 and seed3 ("DRY RUN, nothing touched; the box answers as seedN, active a9ea25f8ada2", the 5 October binary still running), the pair's shas asserted; the same binary started bare on build-1 with --testnet prints igneumd/2.1.0-5b673577, the digest b2e856ed..., Base unit: 10^18, fees v1 from DAA 0, proving v0 from DAA 0, the follower at genesis (height 0). One hazard the read exposed: the [igneum-exec] genesis <hash> executed line is not a start line in this build (it was in the 5 October one), so the seeds mode's --genesis read-back must take the hash from getBlockDagInfo after the start (at height 0 the pruning point and the sink ARE the genesis, 01294fd3...), not from the journal, or it reads "not seen in 60 s" and the go run reports a false MISMATCH; the build-server lane adds that read before --go. Nothing mines. The gate rows 9g, 9h and 9j re-run on it; row 9c reads "re-arms on each cut". Everything below this paragraph in this section is the 7 October RE-CUT of this lane on the 0.3.18 line, the source of the carry, kept as the record of what was built and gated.

The 7 October re-cut (void by the ruling; the record)

Field Value
Network igneum-testnet-1, chain id 4462, address prefix igneumtest, ports 26810 (gRPC), 26811 (p2p), 28810 (wRPC JSON), 26890 (EVM JSON-RPC)
Coinbase message igneum-testnet-1 | 2026-10-05 | coins here have no value | resets are announced (unchanged from 5 October)
Coinbase subsidy field 16 little-endian bytes, one IGN = 10^18 base units (the 18-decimal layout, O-2.6)
Timestamp 1,791,158,400,000 ms = 2026-10-05T00:00:00Z (unchanged)
Bits 0x1d100000 (unchanged)
Hash 01294fd322704dc28fbef0e7a5ef86d6ee260ac5efaf88891cdba661b5fd58ac
Merkle root bcd0e8fb1099aeb3cc1370b50e6dec9f615e204374b2097f25b2438e7d22f49f
Consensus digest 63faee44f50eccd3d68c970efbc39edee2977a4f0fbf4baa833aa5ef5de3577a (18:4x UK, with the cache rung behind its own switch, the genesis-forward lane's ff06c05c after the Devnet 3 digest finding; 4fbb2152... at 15:0x UK with the genesis forward-compatibility fields under the ladder's arm, 80af8aa1... before them with subsidy_per_block_activation_daa 0, 9390d235... before that field)
Base unit 18 decimals (base_unit_decimals 18): one IGN is 10^18 base units, the EVM's wei; the bridge is the identity
Emission EmissionSchedule::TESTNET_1 at the unit: 100 IGN a block at 1 bps, a monthly glide with a two-year half-life, a 90-day ramp from 10 percent, a 1 percent of supply a year tail from the month the glide first pays under it; no hard cap
Switches on from genesis difficulty_v2_activation_daa 0, difficulty_v3_activation_daa 0, proving_v0_activation_daa 0, finality_v3_activation_daa 0, finality_daa_rule_activation_daa 0, finality_leave_activation_daa 0 (finality.leave_delay 3,600), signing_bonus_activation_daa 0 with signing_bonus_bps 1,000 (no burn; vote-or-burn is out of the tree, 420f9305), program_class_v3_activation_daa 0, program_class_v4_activation_daa 0 with signal window 0 (v4 unconditional), latency_ladder_activation_daa 0 at rung 0 with latency_ladder_window_daa 86,400 and the six rungs 27 (admissible), 35 (admissible), 53 (admissible), 88 (inadmissible: quiet-core re-measure 08:46 UK, 10.85 ms cold with the sibling loaded, over the 10 ms gate), 173 and 267 (inadmissible), fees_v1_activation_daa 0 (FeeParams::CALIBRATED_V1), proving_consensus_verify_daa 0 under shard program id 0x2b1a81cb413236cf063077b46ed3111628f6c41036bcf6e23ee4cbbf5679ef7a and aggregator id 0x474678f35f7545db28055d5e5bbc308231d84a5a072202087a2a8d5b09123896 (proving/igneum-prove/elf/manifest.json, pinned 2026-10-05T16:20:38Z), subsidy_per_block_activation_daa 0 (each merged block credited the subsidy of its own DAA on the EVM side, as the UTXO coinbase pays it), and mission item 8 (the project lead's order, 10:1x UK; docs/design/genesis-forward.md): sig_scheme 0 (BLS12-381) with sig_scheme_activation_daa 0 (every vote item and key reveal carries the scheme byte on the wire; any other scheme is refused by every node until a program class the 95 percent signal moves to names it), finality_succession_activation_daa 0 (the W5 item: a vote key hands its window weight and its forfeit term to a successor once), latency_ladder_cache_rung {mib 512, admissible false} beside the six N rungs with latency_ladder_cache_rung_activation_daa 0 (inadmissible until measured; its own digest arm after the ladder's, ff06c05c)
Left at never, by design fork_gate_activation_daa (window 600), proving_v1_activation_daa and proving_v1_fresh_rule_daa, exec_restart_*
Finality object FinalityParams::MAINNET: interval 30, depth 60, window 2,592,000 DAA, dust 100, presence 240, 8 aggregators, ban 2,592,000, min DAA 2,592,000, fold 6, leave delay 3,600
Fees CALIBRATED_V1 from DAA 0
DNS seeders in TESTNET_PARAMS seed1.testnet.igneum.network, seed2.testnet.igneum.network, seed3.testnet.igneum.network
--netsuffix defaults to 1 under --testnet
Override file refused on the testnet (as on mainnet): the object above is compiled into TESTNET_PARAMS; infra/seed-nodes/testnet-object.json is the same object as override-file JSON (print_testnet_object), for reading and diffing against the daemon's start-up lines, never loaded
Where it lives node fork branch testnet-genesis-2-node on the box mirror (release-0.3.18-node e69e8a39, the decimals branch df2fbd03 merged, the vote-or-burn removal 420f9305, the exec-side fixes c7ea1e21 and d840537b, the carried-proof gating dc141409, the proof archive aea0ca5c, the proof-hold fix 70e4601e, the genesis-forward commits daa61847 to f95178a1 and ff06c05c, the re-cut); repository branch testnet-genesis-2

Void: the 5 October genesis 87617621... (8-byte subsidy layout; the chain the seeds hold until the cut-over), its digest b7d8c915..., the proposals 52a3e6a9... and 494fc9a3..., and the interim digests 9390d235..., 80af8aa1... and 4fbb2152.... Any node built before the re-cut never completes a handshake with a re-cut node (different genesis, different digest; seen 7 October 2026, 08:05 UK: a box node on the re-cut tree dialled the three live seeds and each side refused the other on the digest).

What a node prints at start on this object (igneum-build-1, 7 October 2026, 08:05 UK, the two-node gate's node A):

Latency ladder active: rungs 27, 35, 53, [88], [173], [267] shadow passes, this node signals none (header version bits 15 and 14)
Fees on igneum-testnet-1: pgas table v1, B_p 120000 pgas, S_p 30000 pgas, floors 100000000000 wei per gas and 10000000000000 wei per pgas; calibrated v1 from DAA score 0
Base unit: 10^18 base units per IGN (wei, the EVM's unit); one base unit is 1 wei on the execution layer
Consensus params digest: <the digest above> (exchanged in the p2p handshake; a peer with another digest is refused)
Finality v2 (igneum-testnet-1): interval 30 depth 60 window 2592000 DAA dust 100 presence 240 aggregators 8 ban 2592000 fold 6; rule v3 (frozen table, certificate fold) from checkpoint DAA 0; ... C1 in DAA seconds
Proving: consensus proof verification from DAA score 0 (shard program id 0x2b1a81cb..., aggregator id 0x474678f3...); a carried record whose proof fails invalidates its block

Consequences of the object, per tier (the standing rule of 5 October 2026)

Number What it means Who it touches
18 decimals, 16-byte amounts a node holds about 8 percent more UTXO bytes on disk and 11 percent more in memory than at 8 (docs/design/base-unit.md section 5: +80 MB disk, +170 MB memory at 10,000,000 UTXOs); no tier changes class on 8 GB to 32 GB cards, Windows, Linux or macOS; wallets and exchanges see Ethereum's unit every node; nothing for hash rate, power or a miner's deadline
100 IGN a block, a 90-day ramp from 10 percent day-0 block pays 10 IGN (8 to the producer, 2 to the proving pool); the first full-rate block is above u64::MAX in base units, which is why every amount is u128 every miner's expectation of the first month
the signing bonus at 1,000 bps from genesis a vote key that stops signing while in the weight table earns 72 percent of the subsidy instead of 80; a home miner on one card who runs the app as shipped signs every checkpoint and is untouched; a pool user's key is the pool's silent keys only; both ledgers agree after c7ea1e21
proving_consensus_verify_daa 0 every node verifies carried proof records from block one; a Windows node verifies through the installed igneum-prove-host and refuses to start without it (the in-process SP1 verifier is Unix-only); the seeds are Linux and verify in process; PC 1 and every Windows miner need the host beside the node (the app ships it) Windows nodes; the go list below
the latency ladder from genesis at rung 0 the shadow block costs 27 passes as class v4 ships; a step to rung 1 needs 90 percent in each of seven day-long windows, so nothing moves in the first week; rungs 4 and 5 can never be entered every miner's hash rate is the class v4 rate; verifiers under 10 ms cold at rungs 0 to 2
the leave item from genesis, delay 3,600 a miner that stops cleanly sends a leave and is out of every denominator an hour later; one that stops without a word holds its weight in the table for the 30-day window pool operators and rigs that restart; the app sends the leave on a clean stop
FinalityParams::MAINNET the first lock needs 30 days of weight, so the testnet shows no lock in its first month and the exec-side identity under the bonus can only be read after it; the devnet-suffix fast-time line is the proof of that identity before go everyone reading the finality page in the first month

Branches and commits (nothing pushed, nothing merged)

Repository Branch Head What
node fork (vendor/igneum-node-testnet-infra, from release-0.3.6 2b6d23ef) testnet-infra 1c19441d final genesis message, hash and merkle root; --netsuffix default 1; the three DNS seeders; igneum_testnet_identity and test_genesis_hashes updated
app repository (igneum-wt-testnet-infra, from master 23d11d5) testnet-infra 358e565 infra/seed-nodes: NET=testnet profile, seeds-testnet.tsv, dns.sh, rpc/ (filter, unit, nginx site), node/install-rpc.sh, install-rpc-from-mac.sh, ports from seed.env, glibc check, debian-13 images, quoted env values; tools/build-job.mjs forwards --node-tests/--app-tests and its watcher reads the SUMMARY wherever it sits; docs/testnet/README.md final genesis; this file
app repository (igneum-wt-testnet-app, from testnet-infra 9fa2bb3) testnet-app c00df85 the app's network setting: Packaged.network/peers/public_rpc, Network enum with the testnet's ports, seeds and node directory, Runtime::from_env_and_packaged, the dashboard's chain label testnet-1 with the public RPC on its tooltip, the testnet node keeps its DNS seeders; packaged-config.sh IGNEUM_PACKAGE_NETWORK (default testnet; the fleet's devnet builds pass devnet)
node fork (vendor/igneum-node-testnet-genesis in igneum-wt-testnet-genesis, from release-0.3.18-node e69e8a39; on the box mirror) testnet-genesis-2-node see the branch the re-cut genesis and object (section "The genesis, re-cut"), the decimals branch df2fbd03 merged, 420f9305 (vote-or-burn out), c7ea1e21 and d840537b (the exec-side identity under the bonus and the per-block subsidy) carried in Amount, igneum_testnet_identity pins the hash and the digest, print_testnet_object prints the object
app repository (igneum-wt-testnet-genesis, from master ab99e5e3) testnet-genesis-2 see the branch infra/seed-nodes/testnet-object.json, tools/fleet/base-unit-gate.sh (from the decimals branch), infra/fast-time/testnet-object.mjs (the object at fast time: class v4, the ladder at rung 0, the first lock, the bonus split on both ledgers, a signed leave), igneum-pow at the 0.3.18 release line, docs/testnet/README.md, this file
app repository (igneum-wt-testnet-wallet, from wallet-v1 a238781) testnet-wallet fe6e5e8 igneum-common: Packaged.network, TESTNET_PUBLIC_RPC, chain_id, effective_public_rpc; the wallet engine reads the effective URL; the wallet's packaged config follows IGNEUM_PACKAGE_NETWORK

Tests: kaspa-consensus-core and igneum-app suites on PC 2, build job build-20261005-155547, both exit 0 (cargo's own status; the relayed log keeps only the last test result line). cargo test -p igneum-common on the Mac: 27 passed (the crate is not in the PC build inputs). The packager's self-test: all checks passed on both branches. cargo check --tests of the app on the Mac: clean.

The go: what the project lead presses, in order

# Step Who presses State at 16:05 UTC
1 Seeds up at height 0, peered, the public RPC answering nobody (done) DONE: three seeds, 2 peers each, RPC live
2 Merge testnet-genesis-2 (the repository branch: the object record, the gate, the fast-time harness, these docs) and testnet-app to master; the fork's testnet-genesis-2-node into the release branch the 0.4.0 cut uses (0.3.19 or later; testnet-infra on the fork is superseded by it) the release engineer, on the project lead's word NOT DONE: branches ready (7 October 2026), nothing merged; waits for mission item 8 (the forward-compatibility fields)
3 Cut 0.4.0 from testnet-app (tools/ship-app.mjs 0.4.0 --node vendor/igneum-node-testnet-infra ...); the Mac DMG, the Windows installer through the PC build job; the packaged file must say "network": "testnet" (the default) the release engineer NOT DONE: the packager writes the testnet by default; the fleet's devnet update, if any, needs IGNEUM_PACKAGE_NETWORK=devnet
4 The prover's fee-table mirror at CALIBRATED_V1 (proving/igneum-prove/core/src/config.rs, pgas.rs; docs/plans/release-0.3.6.md section 5 step 6): on the testnet fees are v1 from genesis, so a prover with the prototype table produces shard statements the node refuses. Needed before the first testnet proof, not before the first block the execution engineer NOT DONE
5 History rewrite (docs/plans/history-rewrite.md, G14: the 40 commits with a personal name) the project lead, then the repository goes public NOT DONE
6 Repository public (gh repo edit igneum-network/igneum --visibility public) the project lead NOT DONE
7 Downloads public: the 0.4.0 manifest in the downloads folder, publish-manifest.sh --deploy the release engineer NOT DONE
8 The site's buttons: the download section points at 0.4.0, site/wallet.html carries https://rpc.testnet.igneum.network and chain id 4462 in place of the placeholder, the terms card (#testnet-terms) stays; node site/build.mjs, push to master (Vercel deploys) the site agent NOT DONE: the placeholder is still in site/wallet.html
9 Announcement text the project lead PLACEHOLDER: "Igneum testnet-1 is open. Coins here have no value. Resets are announced seven days ahead. Download: igneum.network. RPC: rpc.testnet.igneum.network, chain id 4462." (the project lead's words replace this)
9a The seeds' cut-over to the re-cut genesis (the runbook below): the re-cut binary on the three seeds, each data directory wiped (the 5 October chain at height 0 has nothing to keep), the digest line read back on each, the mesh re-formed the infrastructure engineer, on the project lead's go NOT DONE: binaries built, nothing deployed; the seeds hold the 5 October chain
9b Proof retention: every node keeps proofs for the pruning window and the carried-proof rule applies only above the pruning point, so a node joining after the pool's horizon syncs from the pruning point (the coordinator's direction, 7 October 2026, 10:0x UK). Node side done: dc141409 (the rule, the IBD fetch and the relay retry apply from proving_consensus_verify_daa only) and aea0ca5c (ProofArchive: one file per proof under the exec db's proofs/, kept for the pruning window, served when the pool no longer holds the entry), both on testnet-genesis-2-node. The gate: infra/fast-time/tn-late-join.mjs --join-after 700 --prover "node infra/fast-time/tn-prover-loop.mjs ..." (a fresh node joins after the pool's 600-block window has passed, every proof it asks for from A's archive; the known-failed side is a binary before aea0ca5c, which stalls on "proofs this peer did not deliver in 20 s") the node lane (done), then this lane PASS at 14:36 UK, 7 October 2026 (pod os-latejoin-ylp1, RunPod 3070): node A on the archive binary 57ad7dc2... (fork 5c25c1fb) mined to DAA 6,297 at fast time (pruning 4,600, window 150) with a CPU prover beside it (igneum-prove-host, 37 records accepted and verified by A's pool in under 2 s each, 34 proofs in A's archive, one file per carrying DAA, the pool's 600-block window long past); A's miner and prover stopped; B fresh on the fixed binary fbed53cd... (fork 26e648ff, the node lane's 70e4601e: a served proof is held by hash before the native checks) joined through the headers proof and reached A's sink in 35 s, 4,618 blocks and headers, IBD completed, sink version 1026, 0 errors. Known-failed first, the same chain at 14:02 to 14:12 UK with B on the pre-fix binary 57ad7dc2...: B stalled at chain block f4f918f7 (DAA 1,828, above the pruning point at 1,679) six times on "carries 1 proof records whose proofs this peer did not deliver in 20 s" while A's archive held the file 00000000000000001828-6e3461a3...; the cause was B's fetch side (the served record refused against B's trailing exec state before the proof was held), not A's serve. Pod facts: a RunPod 3070 community pod gives about 19 vCPU and 24 GB; two CPU SP1 provers beside two nodes do not fit (every compressed proof killed at the cap), one does (7 of 36 proofs still died at the cap as the exporter's input grew with the chain); the harness's join-after target is in DAA (the unpruned block count plateaus once the pruning point moves) and a --resume mode attaches to a live A
9e The proving pin: TESTNET_PARAMS pins the shard and aggregator ids of proving/igneum-prove/elf/manifest.json as master holds it (shard 0x2b1a81cb..., pinned 2026-10-05T16:20:38Z). The fin-proof lane's worktree carries a re-pin (shard 0x39db9d96..., pinned 2026-10-07T08:03:43Z, not on master). If that re-pin merges before the go, the two ids and the digest move once more (one print_testnet_object run, this lane's) whoever merges the re-pin tells this lane OPEN
9i The suites on the final tree (fork bfcaf6a2, 15:1x UK, bounded on build-2): consensus-core 144, consensus 123 (plus the one pre-existing red of 9f), exec 31, mining 52, p2p-flows 37, pow 16, rpc-core 134, txscript 158, kaspad 2; the five gate tests (the identity test, the genesis hashes, the print, the genesis-forward digest test, the silent-split equality) 5 passed at the gate class on build-1, digest 4fbb2152.... Earlier in the day on the interim trees: grpc-core 14, p2p 23, miner 19, utxoindex 9, index-core 9, database 22, pskt 5 this lane GREEN
9f A pre-existing red, not the object's: processes::pruning_proof::igneum_m20_tests::witnesses_are_checked_in_epoch_order_under_their_own_seeds fails under --features igneum-pow on the untouched release-0.3.18-node e69e8a39 (08:52 UK, box load under 10) and on the decimals base eec34ac3 (that lane's record); no lane's suite compiles the feature-gated test. Owner: the m20 tests' lane the consensus engineer OPEN, recorded
9c Mission item 8: the genesis forward-compatibility fields (the sig_scheme byte, the W5 key-succession item, the cache rung on the ladder behind its own switch), lane genesis-forward (daa61847 to f95178a1 and ff06c05c on the fork; its gates: consensus-core 124, consensus 114 twice on build-2, the fast-time harness's known-failed FAIL and pass PASS on build-1). The testnet object RE-ARMS ON EACH CUT (the ruling of 19:2x UK): whatever the 0.3.23 object compiles for these four is what the seeds take lane genesis-forward, the build-server lane re-arms re-arms on each cut (this lane's re-cut had the four at 0, digest 63faee44...)
9k The genesis message: the go object's genesis carries the FINAL 5 October message, never the 4 October proposal's text (the coordinator's order, 19:2x UK, to the node lane through the build-server lane); the hash and the digest follow it the node lane, the build-server lane re-arms ORDERED 19:2x UK, not yet read back
9l The base unit on the testnet: 18 decimals, the project lead's word at 21:35 BST 7 October 2026 (through main). The go object is re-cut on the 0.3.23 line (7c7489ac's node pin 2720d8d2, or the 0.3.24 line if the v5 object lands first; the shipper names which) at 18: the decimals lane's code merged, the EmissionSchedule and every per-tier row at 18, the UTXO/EVM scale factor fixed and tested known-failed first on an 8-decimal fixture, the FINAL 5 October genesis message, the cache-rung field at 0, class v5 at 0 if its Devnet 3 crossing reads clean, chain id 4462. This lane's 7 October re-cut (fork testnet-genesis-2-node 59d05bf2) is that work on the 0.3.18 line and was handed to the node lane for the cherry-pick; its gates (9g, 9h, 9j) are the 18-decimal record until the re-runs on the go object the project lead (decided), the node lane re-cuts, the build-server lane re-arms DECIDED 21:35 BST: 18
9m GitHub: the igneum-labs (igneum-labs) account is suspended since 18:02 BST 7 October 2026 (pushes 403, "Your account is suspended"); the project lead's ticket is open; every lane lands on the box mirror (build) with the box gate as the verdict until it lifts; this file's branch is on the mirror and the Mac, GitHub at 1f4793c1 the project lead OPEN
9d Windows: igneum-prove-host beside every Windows node (verification from genesis); PC 1's node refuses to start without it the release engineer (the 0.4.0 package) NOT DONE: to check in the 0.4.0 Windows installer
9j The two-node 18-decimal gate on the FINAL binaries (fork e6dd3afd, igneumd 58f96049..., igneum-miner 5625caee...; tools/fleet/base-unit-gate.sh 72b02b48, the GPU form on a RunPod RTX A5000 rented and run by the fleet lane): PASS at 15:19 UK, 7 October 2026: 322 chain blocks in 600 s, both nodes on one sink and one exec tip (0x142), the 30 inspected payloads all the 18-decimal schedule, 491 segment rewards against the schedule at each blue block's own DAA with 0 wrong, eth_getBalance 3,929.11134259 IGN (3,929,111,342,592,592,592,602 wei) equal on both nodes and to the sum of the rewards; both node heads print Base unit: 10^18, the digest 4fbb2152... and igneumd/2.1.0-e6dd3afd, node B's exec line the genesis 01294fd3.... The known-failed form (the 8-decimal schedule, 420 s) FAILED as it must at 15:27 UK: payloads wrong 30 of 30, rewards wrong 305 of 305. The logs: ~/igneum-fleet/tn-gate/out/ on the Mac the fleet lane ran it, this lane reads it PASS (the cut's closing gate) ON THE 7 OCTOBER RE-CUT; RE-RUN ON THE GO OBJECT 5b673577 ON 8 OCTOBER, GREEN (row 9p)
9h The two-node 18-decimal gate on the re-cut binaries (tools/fleet/base-unit-gate.sh 72b02b48, the GPU form: RunPod RTX 3090, driver 580.65.06, the hive CUDA worker, rented and run by the fleet lane): PASS at 10:08 UK, 7 October 2026, on igneumd 8a6f1f56... and igneum-miner 726cf290... (fork commit f1717419): 577 blocks in 600 s, 421 chain blocks, both nodes on one sink and one exec tip (0x1a5), the 30 inspected coinbase payloads all the 18-decimal schedule (day-0 block 10 IGN = 10^19 base units), 80/20 exact on 18 of 18 single-payee coinbases, 577 segment rewards checked against the schedule at each blue block's own DAA with 0 wrong, eth_getBalance 4,617.53654629 IGN (4,617,536,546,296,296,296,298 wei) equal on both nodes and to the sum of the rewards; both node heads carry Base unit: 10^18, the digest 80af8aa1..., the ladder active at rung 0, fees v1 from DAA 0 and proof verification from DAA 0 under the pinned ids. The first run of the same form (09:4x UK) read 165 of 561 rewards one ramp step low: the gate's check 5 still priced every reward at the chain block's DAA, fixed in 72b02b48 (each blue block its own DAA, the per-block rule). On the testnet object itself no voter exists inside a run (the 30-day window), so this line shows the layout, the switches and the identity without the bonus; the devnet-suffix line (9g) is the proof of the identity under the bonus the fleet lane ran it, this lane reads it PASS; the known-failed form (GATE_EXPECT_DECIMALS=8, the 8-decimal schedule against the same chain, 420 s) FAILED as it must at 10:15 UK: payload subsidies wrong 30 of 30, every segment reward wrong; the pod destroyed on this lane's done line ON THE 7 OCTOBER RE-CUT; RE-RUN ON THE GO OBJECT 5b673577 ON 8 OCTOBER, GREEN (row 9p)
9p The pin's first pod run (8 October 2026, 09:45 to 10:00 UK, RunPod 3090 2rls7gfwii2d3g, the fleet hand): the fast-time line on 5b673577's pair read 14 of 16 checks true (start lines, one digest, class v4 at rung 0 ten epochs, 0 rejected, one sink on five nodes, the first lock at DAA 144, the silent key paid 72/28 on 127 blocks and the voters 80/20 on 318, the bridge identity exact for all five, a leave accepted and effective within the delay, no pause after it) and two false that were the harness's: the object-byte check expected 0 where the pin stamps byte 7 from genesis (the Devnet 3 shape), and "finality active at the end" sat on scenario arithmetic (one silent key of five at a quarter of the window held over a third of a 120-block window on a shared pod CPU, and the rule paused as designed); fixed at testnet-genesis-2 940d91de (the stamped byte read from the node's line; six keys). The two-node gate was void on that pod (its GPU dead for CUDA, cuInit 999: a host fault, the pod retired), and it showed base-unit-gate.sh dialling the public seeds (refused on the digest, harmless), fixed at 940d91de with --nodnsseed. Both gates re-run on pod 2 (tn-gate-0324b, RunPod A5000 secure yiu8x5dnh01g2y, driver 580.173.02, rented 10:29 UK after four 3090 hosts failed cuInit at rent; the hive 0.3.24 CUDA worker at 41.65 MH/s), the tree at 940d91de: the two-node 18-decimal gate form 1 PASS at 10:43 UK (340 chain blocks, 30 payloads at the 18-decimal schedule, 80/20 exact on 20 of 20, 512 rewards against the schedule at each blue block's own DAA with 0 wrong, eth_getBalance 4,097.20887963 IGN = 4,097,208,879,629,629,629,622 wei equal on both nodes and to the rewards' sum, both heads on b2e856ed..., no seed dialled); the fast-time line 15 of 16 true (six keys: the stamped byte 7 on 587 blocks and no ladder bits, class v4 at rung 0 ten epochs, 0 rejected, one sink on six nodes, the first lock at DAA 142 and lock 19 at the run's end, the silent key paid 72/28 on 91 blocks and the voters 80/20 on 352, the bridge identity exact for all six, a leave accepted and effective, no pause after it) with the one false check the harness's own stop order (its final read came after the voters had exited with the run; fixed at b8074151: the miners outlive the run and the read is taken as it ends); form 2 (the 8-decimal known-failed form, 420 s, 10:44 to 10:51 UK) FAILED as it must: 286 blocks, the sinks, the exec tips (0xbb) and the balances equal on both nodes, 30 of 30 payloads and 285 of 285 rewards wrong by exactly 10^10 (the 18-decimal chain read against the 8-decimal schedule), both heads on b2e856ed...; form 1's remaining lines: 513 blocks, exec tips 0x154 on both, exit 0. The object line's re-run on b8074151 (10:47 to 10:57 UK): SUMMARY PASS, every check true (eleven epochs at class v4 rung 0, the stamped byte 7, the first lock at DAA 141, the silent key 72/28 on 89 blocks and the voters 80/20 on 377, the bridge identity exact for all six keys, a leave accepted and effective, 0 rejected, one sink on six nodes at 613 blocks) the fleet hand ran, this lane read ON THE PIN 5b673577: form 1 PASS, form 2 FAIL as it must, the fast-time line PASS (rows 9g, 9h and 9j re-run and green on the go object as landed)
9g The fast-time line of the object (infra/fast-time/testnet-object.mjs, a devnet-suffix network on igneum-build-1 at the 60x profile: 5 nodes, four voting keys and one --no-vote key, every switch of testnet-object.json from genesis, the fast-time finality profile with leave delay 60, the testnet schedule at the devnet's unit): PASS at 11:12 UK, 7 October 2026, run 10 on the archive binaries (igneumd 57ad7dc2..., fork 5c25c1fb): the start-up lines and one digest on every node; class v4 at rung 0 (27 passes) through ten epochs, no ladder bits, the object byte 0 on 551 blocks; 0 rejected, one sink on five nodes; the first lock at DAA 142 (172 s); the silent key's 87 blocks paid the bonus split on the UTXO side (72 percent of the subsidy at each block's own DAA, 720,118,333 sompi at DAA 142 against 800,131,481 for a voter) and the voters' 320 blocks the plain split; the bridge identity exact for all five miners over the chain (UTXO payments x 10^10 = execution credits less the tip's own: 96,832,949,992 sompi against 968,329,499,920,000,000,000 wei for voter a, and so on); a signed leave accepted at DAA 212, its key out of the voter count (5 to 4) at DAA 351, no pause longer than one second after it, finality active at the end at lock 18. The road to it: run 1 (pre-fix binaries) showed the executor crediting 80 percent to the silent key while the coinbase paid 72 (the N7 finding), run 7 the side blues credited one ramp step high when the per-block switch was left out of the profile (the N8 shape), run 9 every check green but the harness's own pause reading (one-second reason flickers at each new lock, corrected to consecutive seconds). On the testnet object itself the weight window is 30 days, so this line is the proof of the bonus and the identity before the go this lane PASS; the known-failed forms are on record from the same morning: run 1 on the pre-fix binaries (the silent key credited 80 percent on the EVM side against 72 on the UTXO side, every other check green) and run 7 on the fixed binaries with the per-block switch left out of the profile (every miner's credit above its payments by the side-blue steps). A binary that carries the per-block field without the bonus fix does not exist (the pre-fix binaries refuse an override naming the field), so no third form runs ON THE 7 OCTOBER RE-CUT; RE-RUN ON THE GO OBJECT 5b673577 ON 8 OCTOBER, GREEN (row 9p)
9n THE LAST STEP BEFORE THE GO (the coordinator's planned step, 22:4x UK, 7 October 2026): the object above holds the class v5 floor at never because Devnet 3's v5 crossing has not happened; the ruling is class v5 at 0 on the testnet IF that crossing reads clean (at DAA 68,400, about 12:54 BST on 8 October after the floor's last re-cut; the go not before the evening of 8 October). After the crossing's read the node lane re-cuts the testnet object once more with program_class_v5_activation_daa 0 (a new digest, the genesis unchanged), this table's digest row and the runbook's --digest are updated from the new binary's print, and the build-server lane re-arms the seeds on the pull-path dry run with the new binaries and sha. That re-cut object is the one the go uses; the object above is not placed on a seed if the crossing reads clean. If the crossing does not read clean, the object above stands and the v5 floor stays at never the node lane re-cuts, this lane the table, the build-server lane re-arms DONE 8 October 2026: the crossing read clean at 12:57 UK; the re-cut 0d05e795 landed 13:48 UK (digest 1da30c10..., byte 6, genesis unchanged, the node lane's six suites green by 14:04 UK, its canary clean); this table and the runbook updated 14:10 UK; the seeds' re-arm on the pull-path dry run of 0d05e795's seed-class pair is the build-server lane's next step (row 9q)
9o Keyed payout addresses (the fleet lane's defect line of 8 October 2026, 09:4x UK, from Devnet 3: tools/fleet/fleet.py line 83 wrote a random payout address with no key for every rented box, so 578,000 IGN of Devnet 3 rewards by 22:28 UK sat on addresses nobody can spend from, and the load generator ran on the 432 IGN dev-fee key; the fleet's keyed-throwaway fix lands 8 October): before the go, every payout address in the testnet object and in anything the seeds or the first miner run has a key held by a named holder (the seeds mine nothing and name no payout; the first miner of step 10 pays the app's own keyed wallet or a named key; the dev-fee address is the app's). The faucet: the testnet genesis carries one IGN to OP_FALSE (unspendable) and no allocation, so a faucet is funded by the first keyed miner's blocks, never at genesis; a genesis allocation would be the project lead's word and a re-cut of the hash; the chain-side faucet or a funded key for load tests is logged for the 0.3.25 line (the node lane, 09:4x UK) the fleet lane (its fix), the miner-community lead (the first miner's key), the project lead (any allocation) OPEN; the node lane's line of 14:0x UK: no payout address goes in any object without a key behind it; keygen on the 0.3.25 miner prints the pair
9q The seeds' re-arm on the go object: the build-server lane builds the seed-class pair from 0d05e795 (glibc 2.34, the commit string twice, igneum-pow 1c420786) on build-1, runs the runbook's dry run on seed1, seed2 and seed3 with --digest 1da30c10..., --commit 0d05e795, --genesis 01294fd3..., the pair's shas asserted, the genesis read-back from getBlockDagInfo; --go only on the project lead's word the build-server lane FALLBACK PAIR DONE 14:26 UK, 8 October: the seed-class pair from 0d05e795 (zig glibc 2.35 ceiling, GLIBC_2.34, built on build-2 while build-1 holds quiet for Devnet 3's move; igneum-pow/src only, the freeze 1c420786's content) staged at /srv/artefacts/0324-tn-0d05e795/seed/: igneumd sha256 9b4641585e2caa5da4f81ee42ef624f826f70373922005a4efc44a41d63b7f19 (56,890,448 B, the commit string twice), igneum-miner d5a5bc9edee54c5b01b769985c42c407ee6c4d4cdd9f1b24cde7b642c7bf92dc (12,270,136 B); the bare start prints "stamps object version 6 into its headers (block version 1538)", Base unit: 10^18, the digest 1da30c10..., the follower at genesis; the dry run (--wipe-genesis --genesis 01294fd3... --commit 0d05e795, no override, nothing --go): seed1 195.201.35.33 rc 0, seed2 5.161.232.205 rc 0, seed3 5.223.52.210 rc 0, "DRY RUN, nothing touched", each box answering as its seed, active a9ea25f8ada2 (the getBlockDagInfo genesis read-back runs at the real pass). This pair is the FALLBACK by row 9r's ruling; the go pair's same chain (build about 13 minutes, the staging, the banner, the third dry run) runs on the 0.3.25-line commit when the node lane names it
9r The go seeds' node code: release-0.3.24-node at 0d05e795 carries none of the 0.3.25 node fixes (the ring check, the snapshot stamp, the proof-map window, the chain-id admission, rule 19's fingerprint). The node lane's line (14:0x UK): the go seeds should run the 0.3.25 pin's node code with this object, which is 0d05e795's one params change merged onto c9ad753a as one commit on release-0.3.25-node plus its gates (about 25 minutes), first thing after Devnet 3's move read-backs. The object does not change (TESTNET_PARAMS identical; the digest must read back 1da30c10... from that binary or the row moves); the seeds then take that pair, and rows 9g/9h/9j re-run on it. RULED by the coordinator (14:2x UK, 8 October): the go seeds run the 0.3.25 pin's node code, after Devnet 3's move read-backs; a seed without the chain-id admission, the ring check and the proof-map window is today's fault class and does not go out; 0d05e795's own pair stays armed as the fallback only. So the go pair is the build-server lane's seed-class build of that one commit on release-0.3.25-node, its dry run on the three seeds (the third dry run of this runbook), and rows 9g/9h/9j on it from a pod; the runbook's --commit becomes that commit when it lands, --digest stays 1da30c10... the node lane cuts, this lane reads the digest back and moves the rows, the build-server lane builds and dry-runs, the fleet hand gates THE CUT LANDED 15:0x UK, 8 October: release-0.3.25-node ba294c98 on both mirrors = c9ad753a + f8da7515 (the cold-restart fix, the Devnet 3 hotfix, its gates green 14:50 UK) + f41f48a7 (row 9t's miner fix: the state provider's default follows the node's network read over gRPC, 26790 devnet and simnet, 26890 testnet, 8545 mainnet; the refusal names the address and --exec-rpc; mine --help names the flag; the known-failed test exec_rpc_default_tests::the_state_provider_default_follows_the_nodes_network, the old devnet default on the testnet asserted wrong first; miner suite 30 on build-2 at 15:03 UK) + ba294c98 (0d05e795's params change cherry-picked with -x: class v5 at 0, CLASS_SIGNAL_V5, the digest constant 1da30c10...). Read back from the mirror by this lane: the pinned digest and genesis constants unchanged from 0d05e795, TESTNET_PARAMS class v5 at 0 with the v5 signal. Its gates dispatched 15:04 UK at gate priority (the artefact to /srv/artefacts/0325-ba294c98/node-lane, six suites, the Devnet 3 canary with the mixed-version step against f8da7515, the testnet canary reading 1da30c10... and byte 6), due by about 15:45 UK; the go pair is not shipped before they are green
9s The gates on the go object's pair (0d05e795: igneumd b76d8671..., igneum-miner 0e67237f...): the two-node 18-decimal gate (GPU form, tools/fleet/base-unit-gate.sh 940d91de, plus the known-failed 8-decimal form) and the fast-time line (infra/fast-time/testnet-object.mjs, --testnet-params as on 9p) on a fresh pod, the fleet hand; the node lane's six suites already green on it the fleet hand runs, this lane records RUN on 0d05e795's pair (pod 3, tn-gate-0324c, RunPod 7e2jbcma9apjne, RTX A5000, driver 570.211.01, USD 0.27/h, rented 14:50 UK): the two-node gate VOID on both forms (0 blocks: row 9v, the class v5 genesis bootstrap; the relay 26790 to 28190 of row 9t proven, both nodes printing byte 6 and the digest 1da30c10...); the object's fast-time line at b5925261 (the harness's class v4 network, row 9u) PASS 16 of 16 at 15:02 UK: epochs e0 to e10 v4 rung 0, first lock index 5 at DAA 144, silent rows 88 and voting rows 367 priced right, six bridges true, leave accepted 6 to 5 voters, blocks 605 chain 494, rejected 0 on six nodes, one sink at 604 on all six. The byte 6 run (c5fe28e4) on the same pod follows; the go pair's runs wait for row 9v
9t The miner's class v5 state lookup (found by the pod gate on 0d05e795's pair, 14:52 UK, 8 October): RpcStateProvider::new defaults to http://<node host>:26790, the DEVNET exec port, on every network (igneum/miner/src/main.rs 981-985 at 0d05e795), while the testnet node's exec RPC defaults to 26890 (igneum/exec/src/config.rs 86-91); the --exec-rpc override exists (main.rs 3226) but is absent from mine --help. On the pod (node A's eth_ RPC on 28190) the miner logged "class v5 needs the execution state after the epoch's seed block 01294fd3... (day 20734): connect 127.0.0.1:26790: Connection refused (os error 111) ... asking again every 2 s" and the worker never got a job; the hand ran the gate through a loopback forwarder 26790 to 28190, so the gate lines on this pair stand for the object. Impact: the seeds mine nothing, the cut-over is unchanged; a first testnet miner on a default node (step 10) cannot mine class v5 blocks at all, the plug-tune-play class. The call put to the node lane and main: the default follows the network (default_evm_rpc_port of the node's network), --exec-rpc documented, the refusal names the address and the flag, in the 0.3.25 go cut the node lane fixes in the 0.3.25-line go cut RULED by the coordinator (15:0x UK, 8 October): the go WAITS for the fix in the 0.3.25-line go cut: the default follows the network's exec port (26890 on the testnet), --exec-rpc documented in mine --help, a known-failed test on the default per network; a first miner that cannot mine on a default node does not ship. The cut not yet landed at 15:0x UK
9u The fast-time line does not exercise class v5: infra/fast-time/testnet-object.mjs copies only program_class_v4_activation_daa and the v4 window from the object onto the 60x profile (lines 89-90), so its network stamps 7 and runs class v4 while the go object stamps 6 (the pod's object run of 14:5x UK read "stamps object version 7" on every node and passed its 16 checks as a class v4 run). To close: carry program_class_v5_activation_daa from the object, read the stamped byte 6, and run the five one-box nodes' miners against their own exec RPC ports, which needs row 9t's miner default or the --exec-rpc flag per miner. Until then the two-node gate (through the forwarder) is the proof of class v5 mining on the pair, and the fast-time line proves the object minus byte 6 this lane (the harness), on the same cut as 9t by the ruling RULED 15:0x UK: closed on the same cut; the harness change (the v5 keys carried, --exec-rpc per one-box miner) landed at c5fe28e4 on this branch; its first run on the warm pod (15:05 to 15:08 UK, 0d05e795's pair) reached the object's class: the template at DAA 0 read "class 5 rung 0 (27 passes)" on every node, each miner reached its own node's exec port through --exec-rpc, and all six refused the genesis seed state (row 9v, reproduced with no relay); stopped by pid with no block. The line's PASS on byte 6 waits for row 9v's fix
9v GO BLOCKER (found 15:04 UK, 8 October, by the two-node gate on 0d05e795's pair with row 9t's relay in place): a chain with class v5 from genesis cannot mine its first block. The miner's class v5 path asks the node's exec RPC for the state after the epoch's seed block, which for epoch 0 is genesis, and a fresh chain's executor has published no stream after it; verbatim: "class v5 needs the execution state after the epoch's seed block 01294fd3... (day 20734): exec RPC http://127.0.0.1:26790 gave no stream for block 01294fd3...: no published state stream after chain block 01294fd3... (the executor has not passed that epoch's cut, or the block is not on its chain) (the node's exec RPC); this node cannot validate or mine class v5 blocks until its executor holds it; asking again every 2 s". Why no gate caught it: Devnet 3 crossed to v5 at 68,400 with state behind it; the 5b673577 object's green gates ran class v4 from genesis; the canaries handshake and do not mine; so byte 6 at DAA 0 had never been mined by anything. A pointer: the 5 October binary printed [igneum-exec] genesis <hash> executed at start and this build does not (the build-server lane's read of 10:2x UK). Routes put to the node lane and main: (a) the node publishes the genesis execution state as the stream after the genesis seed block on start-up (object and digest unchanged; a fix on the ba294c98 line plus a gate that mines block one on a fresh v5 chain); (b) class v5 from the first epoch boundary with class v4 for epoch 0 (a new digest, a re-cut, the seeds re-armed again). The go pair is nobody's until block one mines on a fresh v5 chain; the earliest-go time moves by the fix the node lane (the fix), this lane (the pod re-run), main (the route) RULED by the coordinator (15:1x UK, 8 October): ROUTE (a): the node publishes the genesis execution state as the stream after the genesis seed block at start-up, object and digest unchanged, on the ba294c98 line, with a gate that mines block one on a fresh class v5 chain (the test that was missing) and its known-failed run first; route (b) only if the node lane says (a) is not a same-day fix by 16:00 UK; the go pair is whichever mines block one on a fresh v5 chain; nothing mines until the founder's word. Reproduced with no relay by the byte 6 fast-time line at 15:05 UK (six one-box nodes on a devnet-suffix genesis 234e082d..., each miner with --exec-rpc, the same refusal on each, the template class 5 at DAA 0, no block in two minutes): the refusal is the node's on any port and any genesis. THE FIX LANDED 15:19 UK: release-0.3.25-node 6e04f7fc (both mirrors) = ba294c98 + one commit in igneum/exec/src/service.rs: ExecState::capture_genesis_state records genesis as epoch 0's capture and publishes its IGSD1 stream under the genesis hash the moment execute_genesis finishes (final by construction; the node prints "[igneum-exec] class v5: the state stream after genesis (epoch 0's reference) is published"), the capture under the same retention as every other; no params, object or digest change (1da30c10..., byte 6). The known-failed test service::class_v5_tests::the_state_after_genesis_is_published_at_once_for_class_v5_from_genesis (nothing served after genesis before the fix, asserted first); exec suite 56 on build-2 at 15:17 UK. Its artefact and gate set (six suites, both canaries) dispatched 15:19 UK, the pair at /srv/artefacts/0325-6e04f7fc/node-lane by about 15:32 UK. The block-one gate: tools/fleet/base-unit-gate.sh now passes the miner --exec-rpc for node A's own exec port and prints the node's genesis-stream line, the miner's first block and node A's exec tip after mining, failing on tip 0; the known-failed run is the same script on ba294c98's pair (/srv/artefacts/0325-ba294c98/node-lane: igneumd 74ae96c6..., igneum-miner bbabfa91..., the 0.3.25 miner's network default, refusing at genesis), then 6e04f7fc's pair for block one, both on the warm pod
10 The first miner: one app on the testnet (PC 1 or PC 2 with the 0.4.0 build, or igneumd --testnet plus igneum-miner --network testnet by hand) produces block 1; the seeds relay it, health.sh shows blocks=1 on all three, synced=True; note the young-window join fault: a node that joins a chain younger than its finality window sees synced=False until blocks pass genesis, which is the no-blocks state, not a fault the project lead says go, the miner-community lead starts it NOT DONE: nothing mines until the word
11 Watch: NET=testnet ./health.sh --watch, the RPC's eth_blockNumber, the DAA after 600 blocks (the launch difficulty 0x1d100000 is sized for a few hundred MH/s) the infrastructure engineer ready

Legal is out of scope here (the project lead: "all but legal").

The seeds' cut-over to the re-cut genesis (prepared 7 October 2026; runs only on the project lead's go)

Nothing below has been run against a seed. The seeds take no override file, so the cut-over is one binary and one wipe per seed. Order: seed 1 last (it serves the public RPC), the other two first, an hour between is not needed (the chain is at height 0 and no miner exists).

# Step Command (from infra/seed-nodes, NET=testnet) Read back
1 Build the seed binary from the fork branch testnet-genesis-2-node on the box for Debian 13 (glibc 2.41 on the seeds; a native 2.39 build also runs there, the 5 October seeds took a PC build at 2.39) cd vendor/igneum-node-testnet-genesis && ../../tools/build-remote.sh --ship seed (artefacts in target-remote/), copy igneumd and igneum-miner into infra/cross/out/ igneumd --version names the commit; sha256sum recorded in this file at the go
2 Stop the unit and wipe the data directory on seed 2 and seed 3 (the 5 October chain is genesis alone) ssh root@<seed> 'systemctl stop igneumd && rm -rf /var/lib/igneum/igneum-testnet-1' (the directory name is the network id under APPDIR; check with ls /var/lib/igneum first; wipe only that directory) the directory is gone
3 Install the binary and start NET=testnet BUILD_WHERE=cross ./provision-seed.sh seed2.testnet, then seed3.testnet (it uploads infra/cross/out/igneumd, refuses a glibc the seed cannot run, writes the unit and starts it) the unit's log: Base unit: 10^18, Consensus params digest: <the digest in "The genesis, re-cut">, genesis 01294fd3... in the [igneum-exec] line, Proving: consensus proof verification from DAA score 0, Latency ladder active
4 Seed 1: the same two steps, then the public RPC check NET=testnet ./health.sh; curl https://rpc.testnet.igneum.network -d '{"jsonrpc":"2.0","id":1,"method":"eth_blockNumber","params":[]}' reads 0x0; eth_chainId reads 0x116e three seeds, 2 peers each, height 0, every digest line equal
5 The cross-check that the old chain is gone a 5 October binary (igneumd 1c19441d) pointed at a seed is refused at the handshake on the digest one refusal line in the seed's log
6 Record the digest, the genesis hash and the three sha256 lines in this file and in docs/testnet/README.md; the announcement text carries the genesis hash

Steps 2 to 5 as one staged command (the build-server lane, 15:1x UK; infra/build-server/wave1-0320.sh on branch build-server, mode seeds, on master at 84155005; dry run by default, nothing touched; --go only on the project lead's word):

# from the build-server worktree; the seed-class binary from this lane's fork: cd vendor/igneum-node-testnet-genesis && tools/build-remote.sh --ship seed
infra/build-server/wave1-0320.sh seeds --igneumd <path to the seed-class igneumd of testnet-genesis-2-node> --sha256 <its sha256> \
  --miner <the seed-class igneum-miner> --digest <the FINAL digest the identity test pins> --wipe-genesis --genesis 01294fd322704dc28fbef0e7a5ef86d6ee260ac5efaf88891cdba661b5fd58ac
infra/build-server/wave1-0320.sh seeds ... --go      # the same line with --go, on the project lead's word

What it does with --go, on seed1, seed2 and seed3 in parallel: the binary put as /opt/igneum/bin/igneumd.new with the sha asserted on the box, the unit stopped, /var/lib/igneum/igneum-testnet-1 moved aside as igneum-testnet-1.prev-<UTC stamp> (kept), the binary swapped (the old kept as igneumd.prev), the unit started, then one RESULT line per seed: unit state and downtime, genesis <hash> MATCH from the [igneum-exec] genesis ... executed line against --genesis, the commit string count in the installed binary, the digest line against --digest, eth_syncing and net_peerCount over the loopback RPC, the first journal line, and "base unit 10^18 line seen" (the 5 October binary never prints it, the re-cut always does). No --override: the testnet takes none. The dry run of 15:1x UK read all three seeds on 1c19441d at height 0 (active a9ea25f8ada2). The digest passed as --digest is the one the final object prints (63faee44...), never a value from memory.

The route the shipper staged (0.3.20 cut, main's ruling (b), 14:4x UK, docs/plans/release-0.3.20.md 5e74fa2f): the three seeds stay on 1c19441d (digest b7d8c915...) through the 0.3.20 sweep and the public RPC filter's BLOCKED_UNTIL_FIXED_NODE set stays; at the go the build-server lane's wave1-0320.sh seeds mode puts the re-cut binary on the three seeds in parallel (the sha asserted, the commit string and the digest read back) and its lift-rpc-filter mode opens the RPC; steps 2 to 4 above are what that mode does, step 2's wipe included.

The digest lineage, so the move is read right at the go: 1c19441d b7d8c915... (5 October); the 0.3.20 pin c4459193 9537868d..., the whole move being five additions (finality_leave_activation_daa 0 with finality.leave_delay 3,600, program_class_v3_activation_daa 0, program_class_v4_activation_daa 0 with the signal window 0 left out, pow_genesis_dataset_log2 28, EmissionSchedule::TESTNET_1), the genesis, base params, finality table, fee table and pow schedule unchanged; this re-cut 80af8aa1... on top of those: base_unit_decimals 18 (and the genesis itself, re-laid), difficulty_v3_activation_daa 0, finality_daa_rule_activation_daa 0, the signing bonus 0 at 1,000 bps, latency_ladder_activation_daa 0 with the window and the six rungs, proving_consensus_verify_daa 0 with the two program ids, subsidy_per_block_activation_daa 0; then 4fbb2152... with the genesis-forward fields (sig_scheme_activation_daa 0 with sig_scheme 0, finality_succession_activation_daa 0, the cache rung in the ladder arm); then 63faee44... with the cache rung behind its own switch (latency_ladder_cache_rung_activation_daa 0, a fourth arm), the final object. No override pins any old value, so every testnet node swaps together or not at all; the digest is re-read on the re-cut's own binary at the go.

What the project lead's go needs from him, in order: (a) nothing on item 8 any more (it is in); (b) "cut the seeds over" (this runbook, about 20 minutes for the three); (c) the 0.4.0 cut from the merged branches (step 3 of the go table); (d) the first miner. Until (b) the seeds keep the 5 October chain and refuse every re-cut node, which is harmless: nothing mines on either.

Cost

Item USD per month, net (Hetzner API, 5 October 2026)
seed 1, cx23 nbg1 6.49
seed 2, cpx21 ash (4 GB; the only 4 GB type in the US at this price) 37.49
seed 3, cpx22 sin 30.99
three primary IPv4 1.80
total 76.77 net, about 92 gross; billed hourly, 20 TB traffic included per server

A cheaper US seed is cpx11 (2 GB, 20.49), rejected because the node keeps up to four 256 MiB lottery caches once the chain has epochs; the unit's MemoryMax=3200M would not fit. The devnet seed (igneum-seed-1, 6.49) is untouched.

What was not done, and what to watch

Item Note
The explorer not built; the public RPC serves the wallet and MetaMask
site/wallet.html RPC placeholder still a placeholder; step 8
The Windows WSL verifier wrapper, the prover's table mirror docs/plans/release-0.3.6.md section 7; step 4 above
The app's Windows side testnet-app compiles on the Mac and its suite passed on PC 2 (Linux); the Windows build is the 0.4.0 cut's job
Seeds and proofs the seeds run no proof verifier (verifier: Off); they relay and hold the chain. A seed never includes proof records, which is fine for a seed
Build inputs zip build-inputs.zip on the downloads host is ONE file for every agent: a second agent's push between a job's publish and its fetch fails that job's sha256 check. Both testnet jobs fetched the right zip (verified by sha256 before each fetch); the hazard stays until the zip carries the job id in its name
glibc a PC-built Linux binary wants glibc 2.39 (Ubuntu 24.04); the seeds are Debian 13 (2.41) for that reason, and provision-seed.sh now refuses a binary the seed cannot run. The Mac's zig cross-build (glibc 2.36) stays the route for a Debian 12 host

How to redo any part

cd infra/seed-nodes
NET=testnet ./health.sh                                   # one line per seed
NET=testnet ./dns.sh --check                              # the four A records
NET=testnet BUILD_WHERE=cross ./provision-seed.sh seed2.testnet   # re-install the node from infra/cross/out (a new binary)
NET=testnet ./install-rpc-from-mac.sh seed1.testnet       # the public RPC again (idempotent; certbot keeps its certificate)

The node binary for the seeds: node tools/build-job.mjs run --node /Users/joshm/Projects/igneum/vendor/igneum-node-testnet-infra --target ae432dc7 --targets linux --no-tests then node tools/build-job.mjs fetch <id> (lands in infra/cross/out/).

Launch gates (mission item 10, 7 October 2026, 10:1x UK)

Added by the launch-pack lane (branch launch-pack) from docs/analysis/mission/mission.md 2.10, with the owner's three decisions of the same morning written in: a signed proving customer is a MAINNET gate (not a testnet gate); the code-signing certificates are approved (Windows EV Authenticode and an Apple Developer organisation account, both under Igneum Labs LTD, executed the day the entity exists); the USD 50,000 disclosure prize is YES, staged until the entity address exists and the owner gives the publish word (docs/plans/cryptanalysis.md 3.3 on branch cryptanalysis). The runbooks, the signing-step specification and the text handed to the site lane are in docs/plans/launch-pack.md. Every row has its check; node tools/ci/launch-gates-check.mjs (in tools/ci/pre-push.sh) fails when a row loses it or names a script that is not there. "When" says which go the gate holds: T = before the testnet go (steps 1 to 11 above), C = a community gate after the go with no date (docs/analysis/mission/reinvent.md 4.1), M = before the mainnet go.

Gate What must be true Check When State at 10:1x UK, 7 October 2026 Who
LG-1 Per-tier income at three tariffs docs/analysis/income-tiers.md is published before the testnet: one 8, 12, 16, 24 or 32 GB card, a rig and a pool user, IGN a day at three network sizes from the measured bench rows and EmissionSchedule::TESTNET_1, electricity a day and per mined IGN at USD 0.05, 0.10 and 0.25 a kWh (cheap industrial, US retail, UK retail; decided 7 October 2026), each tier with what it means and what is being done (the consequences rule) node tools/launch/income-tiers.mjs --check (the page equals its inputs) and node --test tools/launch/income-tiers.test.mjs (the schedule arithmetic: 6,912 IGN a day for 100 MH/s on 100 GH/s at the launch rate, day 1 at 10 percent, one month step at 2^(-1/24)); the page is in the public export and passes tools/ci/identity-check.sh T DONE on the branch from the 6 October rented-card rows (ten-field class). OWED: re-generate at the testnet cut from class v4 rates; the RTX 4060 and Apple wall power; an Intel row launch-pack lane, then whoever cuts 0.4.0
LG-2 Hash-origin report on Devnet 2 for seven days before the go The daily report (keys with a block, keys above dust, attested pools and shared payouts, the project fleet's share, the ten largest keys, the network step) posts from the Devnet 2 observer's tables on seven consecutive days before step 10 node tools/observer/hash-origin.mjs --prefix dn2_ --dry prints a report; seven consecutive hash-origin:<date> keys in the poster's state for that prefix; node --test tools/observer/hash-origin.test.mjs (a known-finished day and a known-failed day) T The job exists and ran read-only on the live devnet tables today (113 keys, 0.76 GH/s). OWED: a Devnet 2 observer writing dn2_live_* (fleet lane), the fleet key file from the fleet registry, the systemd timer on the box (docs/plans/launch-pack.md section 3) launch-pack lane (job), fleet lane (observer, key file), build-server lane (timer)
LG-3 Signed and notarised installers The 0.4.0 DMG is signed with a Developer ID certificate of Igneum Labs LTD, notarised and stapled, and opens on a fresh macOS machine with no Privacy and Security visit; the Windows installer and every exe inside it carry an EV Authenticode signature of Igneum Labs LTD with a timestamp spctl --assess --type execute -vv <app> prints accepted and source=Notarized Developer ID; osslsigncode verify <installer> (or signtool verify /pa /v) prints the signer Igneum Labs LTD and a timestamp; the shipper's verify step writes both into the manifest (signed_by, notarized) and the download page shows the signer and the sha256 (docs/plans/launch-pack.md section 2.4) T NOT DONE: certificates approved 7 October; the entity's documents and the two enrolments are the owner's (section 2, items for the owner); the signing step is a specification for the shipper (docs/plans/launch-pack.md 2.4) the owner (enrolments), the shipper (the step)
LG-4 First-share time measured per release Every release's Devnet 2 gate measures download to first accepted share on a fresh Windows 11 VM and a fresh macOS VM, as three timed steps (download and install, sync, dataset build), and the numbers are published on /evidence; the mission's bar is under 10 minutes in 9 of 10 fresh Windows installs the gate log carries FIRST-SHARE <platform> download=<s> sync=<s> dataset=<s> share=<s> for both platforms (docs/plans/launch-pack.md 2.5 is the specification of the script that writes it, tools/fleet/first-share-time.sh, OWED: until it exists this row is OPEN); the /evidence row equals the log line T OWED: specification written, script not built; no fresh-machine time has been measured end to end (docs/analysis/mission/reinvent.md 3.1) fleet lane with the shipper
LG-5 The launch text on the site The front page leads with the three wants (hardware that stays useful, income without a cliff, a fair supply) and finality moves to page two; the litepaper carries "A block pays its miner whether or not anyone buys a proof that day"; the eight regulatory sentences of docs/analysis/mission/future.md 8.3 are on the litepaper under "not legal advice; counsel is engaged"; the journey's phase 4 gate no longer says a rollup signs for the testnet node tools/ci/launch-gates-check.mjs (the handoff block exists, carries no served-page pattern, no em dash, the eight sentences numbered in order); after the site lane lands it: grep -c "whether or not anyone buys a proof" site/litepaper.html is 1 and grep -c "automatically created as a reward" site/litepaper.html is 1 T Text handed over in docs/plans/launch-pack.md section 4 (branch launch-pack); nothing on the live site changed site lane
LG-6 First 100 keys 100 distinct vote keys with a blue block in the last 24 h the hash-origin report's gates.first_100_keys (node tools/observer/hash-origin.mjs --dry --json) C Devnet reading today: 113 keys with a block, most of them the project's multi-identity machines; the testnet counts from its own go the report
LG-7 First block from a card the project does not own A blue block whose vote key is in neither the intake-reporting workers' identity lines nor the fleet registry's key file the report's gates.first_block_outside_fleet, valid only with IGNEUM_FLEET_KEYS_FILE loaded (without the file the devnet reads its own rented boxes as outside: today 77 "outside" keys, which is the missing file, not outsiders); the post needs the owner's permission (reinvent.md 4.1 G-C2) C Void until the fleet key file exists (OWED, fleet lane) the report, the fleet lane
LG-8 First outside-reproduced benchmark A row on /miners measured by someone outside the project, with driver, OS and version (docs/benchmarks/repro.md) grep -c '"by": "reported by a miner"' site/miner-bench.json is at least 1 (today the rows are measured by the team and reported by the fleet) C No such row the community lead (the bench-table ingest)
LG-9 First pool not run by the project An attested outside pool (its operator published the signed member-key list X5 asks for) with 10 percent of blue blocks for 7 consecutive days the report's gates.first_outside_pool with the pool's payout address in IGNEUM_KNOWN_POOLS; a shared payout address nobody attested never passes it (the test's third case) C No attested outside pool; the devnet's 13 shared payout addresses are multi-identity machines and the project's pool-0 the report, the pool lane (the statement format)
LG-10 First 1,000 independent keys (X5) N_ind of at least 1,000 over 30 days, independent in autonomous system, machine fingerprint and pool attestation, top-10 share of window weight under 50 percent (docs/plans/ledger-decisions.md section 3) the report's independent block once the observer stores the autonomous system per announcing address and the fingerprint per key; until then the report prints the keys above dust as an upper bound and never passes the gate (gates.first_1000_independent is false by construction) C, and the gate of mainnet genesis The two observer columns are OWED (app-owner item, ledger-decisions.md section 3); today's upper bound on the devnet is 95 the observer owner
LG-11 A signed proving customer One customer paying for proofs at a published rate, or a signed letter of intent with a volume, before mainnet (the owner, 7 October 2026: a mainnet gate, not a testnet gate; the weight of the Devnet 2 gate: mainnet does not open without it) the contract or the letter in the entity's records, a redacted copy linked from docs/evidence.md, the rate on the site; for the paying case the job market's payout contract shows a paid job for that customer; grep -c "rollup signs for testnet" site/journey.json is 0 after the handoff lands M NOT DONE: Taiko is named as the first customer and nothing is signed; the brief and the pilot progression are ledger X13 the owner (the signature), the execution engineer (the paid job)
LG-12 Hash origin daily for 90 days The report posts every day for the first 90 days from the go, with no gap SELECT count(*) FROM hash_origin_reports WHERE day >= '<go date>' reaches 90 with consecutive days; the timer's journal on the box shows a run per day C The job and its --go <date> flag exist; the timer is OWED (section 3 of the pack) build-server lane (timer), the report
LG-13 The disclosure prize USD 50,000 for a reproduced break of the published hash class, paid in fiat by Igneum Labs LTD, announced only when escrowed and only when the entity's registered address exists on its documents and the owner gives the publish word docs/plans/funding.md rule 3 (escrow before announcement); the staged text in docs/plans/cryptanalysis.md 3.3 on branch cryptanalysis (43d9700b, not on master yet); until the word, grep -ci "50,000" site/*.html is 0 M (the announcement may come earlier, on the word) APPROVED by the owner at 09:5x UK on 7 October 2026; STAGED; nothing public mentions it the owner (escrow, the word), the cryptanalysis lane (the announcement)