7.3 KiB
7.3 KiB
Release rules (the shipper's standing rules, as main set them)
Every cut of the Igneum Miner app and its node runs under these. The dated plan for each cut (docs/plans/release-.md) records how each rule was met.
- Versions are three-part. A hotfix takes the next number; the feature tree moves up. The app's parser returns None on a fourth part.
- Nothing is staged in the live downloads folder. Stage in a scratch copy with
IGNEUM_DLSITE=<copy> publish-manifest.sh --no-deploy; the live folder changes only in the deploy step.publish-jobs.sh --deployis jobs-only. No lane removes a scratch directory it did not create. - The deploy gate is a full canary on the fleet's pods: the fresh join through the headers proof on a WIPED datadir (decisive), synced, ten minutes mining, the hub holding a block, the relay and poison cases. Main may call the deploy on the decisive read plus a diff argument.
- The kept-datadir start is a named gate in every release (main, 7 October 2026, after ledger N13). Every canary runs both a wiped datadir and a KEPT one: a copy of a standing box's datadir from the live release, the pinned binary started on the copy on a scratch pod, "synced" or the store's rewrite line as the pass. The Windows shape too: the pinned Windows node once against a copy of PC 2's datadir (PC 2 only, never PC 1) before PC 1 gets the build. The miner-reliability register carries it as its own fault class. Why: every node build from 10db4b61 died at start on a kept 0.3.17 datadir (bincode ignores serde defaults) and no canary saw it because every canary wiped. 4c. The proving ids gate (main, 7 October 2026, after the 0.3.20 blocker). On every candidate, a node started on the LIVE override file reports both proving ids (the shard program id and the aggregator id) on its proving v1 start line, and a prover's first statement against it is accepted; a zero-id statement is the known-failed shape. It runs beside the kept-datadir read, since both share the warm pod. Why: c4459193 read the ids as unknown, built statements with zeros and refused every proof; a sweep would have stopped every prover's pay. 4a. Every gate starts on every candidate the moment its binary builds, never after the pin (the founder, 7 October 2026). The digest and mixed-version gates, the kept-datadir start, the relay and poison cases and the wipe canary all begin on each candidate binary as it lands; a struck candidate's runs are stopped and its successor's begin. The post-pin wait is then the longest single form (about 80 minutes, the wipe), not the sum. 4b. Warm pods per gate class (the founder, 7 October 2026, ordered to the fleet lane). The fleet keeps synced pods warm for each gate class so a case form's target starts at the tip (a kept copy of the live line, caught up), never from a kept copy far behind it; the wipe canary is the only full IBD in the set.
- Rollout in waves, each box read back (the founder, 7 October 2026, replacing one-box-at-a-time): PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). The wave list is written, not remembered: every sweep's first wave names each Hetzner seed by address (188.245.5.161:26611 for the shared devnet; the testnet seeds when they move) beside the hands and the fleet, and the seed's row closes only on its own read-back line (string, digest, first accepted block) from the lane that holds its key (the build-server lane, infra/devnet/restart-seed.sh). Added 7 October 2026 after the 0.3.20 sweep left the seed on the old object for one hour forty, found by the 0.3.21 wipe canary's reject lines.
- Read-back is by commit string plus digest plus engine: on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees
strings igneumd | grep -c igneum-pow/src/above zero. The miner embeds no commit string; its pairing is the build line and the sha. - igneum-pow pairing: a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file). Extended 7 October 2026 (the Devnet 3 pool pair, three WRONG HASH rounds each a tree a step behind the chain): the rule binds every crate that embeds kaspa-pow, the node, the pool daemon (igneum-pool) and the app's CPU re-check alike, each built against the pinned igneum-pow by path from the release worktree (017e7037 on 0.3.22 and 0.3.23), and the packs pin travels with the generator (the proto-cuda packs are the pin's export, never an older one); the read-back is the paired miner's "class v4 program id <16 hex>" line equal to the node's per epoch, and the daemon accepting its shares.
- glibc classes: HiveOS 2.31 (
--ship hive, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (--ship seed), fleet 24.04 boxes native 2.39. - The Mac builds only the macOS binaries and the DMG, one at a time under the build lock; every other build, suite and the Windows cross-build runs on the box or a PC; the app gate is
build-remote.sh -- test --releasefrom the crate dir. - A pin is green on its own suites and gates. Lines taken on one binary carry to another only when the code is byte-identical, stated in the tip. No known-red pins: a stale test takes a test-only commit on top.
- Kill by pid, never by name, on the shared Mac; a merge worktree never checks out master.
- The Discord card only when every platform is live. Live manifest changes beyond the binaries (a moved consensus floor) go out only on the founder's explicit word, staged beside the release with their digest and a one-line diff.
- Ship on green: no calendar waits; when the gates are green, publish and state the clock time (UK). Checkpoints are for slips, not for waiting.
- The version bump is the release branch's first commit (7 October 2026, after the 0.3.23 miss). When a release-0.3.N branch opens, its first commit moves the six version places (app/igneum-app/Cargo.toml and Cargo.lock, app/windows/version.h, app/igneum-app/resources/igneum-app.rc's four fields, packaging/mac/app/Info.plist, the installer's AppVersion), never left to the cut: release-0.3.23 opened at 4cdcab31 and carried 0.3.22 in every place until 21:26 BST, so the app exes and the window host crossed from its first closed tip read 0.3.22 and were void. Gate check: on a push to release-0.3.N the pre-push gate (tools/ci/release-version-check.sh, self-test on tonight's shape first) reads all six places against the branch name and goes red on any mismatch; the .rc was the second layer of the same miss (the box cross failed in build.rs at 21:30 BST).