igneum/proto-cuda/windows-app
igneum-labs 1065b81d05 relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14)
Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:46:13 +00:00
..
ALLOW-FIREWALL.bat Windows app: node and miners in one window, NODE card on the dashboard 2026-10-03 21:19:22 +00:00
allow-firewall.ps1 Windows app: node and miners in one window, NODE card on the dashboard 2026-10-03 21:19:22 +00:00
igneum-common.ps1 OpenCL worker fault guard, miner-side fault state in the launcher, NVRTC annotation rule in the emulation 2026-10-04 10:42:36 +00:00
make-package.sh Windows package 0.3.0: prebuilt one-click workers first, nvcc/cl.exe build path as the fallback 2026-10-04 09:55:05 +00:00
README.txt Workers answer a job they have no pair for with a need line; the miner prepares the current pair (PC 2 stuck on the previous epoch) 2026-10-04 13:32:58 +00:00
START-IGNEUM.bat Windows launcher: MACHINE_NAME override for cloned PCs; litepaper and homepage carry the honest builder text (Canto/Blast line removed) 2026-10-04 10:10:03 +00:00
start-igneum.ps1 Windows CI: the one-click app built on GitHub runners, no PC needed 2026-10-04 10:32:20 +00:00
START-MINING.bat Windows launcher: MACHINE_NAME override for cloned PCs; litepaper and homepage carry the honest builder text (Canto/Blast line removed) 2026-10-04 10:10:03 +00:00
start-mining.ps1 Release: devnet v4 cut-over staged (Windows 0.2.0 packages, Mac app 0.2.0, seed igneumd-v4 unit, runbook) 2026-10-04 01:48:56 +00:00
START-NODE.bat Release: devnet v4 cut-over staged (Windows 0.2.0 packages, Mac app 0.2.0, seed igneumd-v4 unit, runbook) 2026-10-04 01:48:56 +00:00
start-node.ps1 Release: devnet v4 cut-over staged (Windows 0.2.0 packages, Mac app 0.2.0, seed igneumd-v4 unit, runbook) 2026-10-04 01:48:56 +00:00
STOP-IGNEUM.bat Windows app: node and miners in one window, NODE card on the dashboard 2026-10-03 21:19:22 +00:00
stop-igneum.ps1 Windows app: node and miners in one window, NODE card on the dashboard 2026-10-03 21:19:22 +00:00
TEST.md Workers answer a job they have no pair for with a need line; the miner prepares the current pair (PC 2 stuck on the previous epoch) 2026-10-04 13:32:58 +00:00
upload-log.bat relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14) 2026-10-05 18:46:13 +00:00

Igneum devnet v4 for Windows (package 0.3.0, 4 October 2026): the node and the miners in one window. Nothing to install but the graphics driver. Extract the whole zip to a fresh short path such as C:\igneum-v4 (a new folder, not over an old package), then double-click START-IGNEUM.bat.
What is new in 0.3.0: the GPU workers come prebuilt. igneum-worker-cuda.exe drives an NVIDIA card through the driver (nvcuda.dll) and compiles each hourly lottery program on the card itself with NVIDIA's runtime compiler, which ships next to it (nvrtc64_120_0.dll and nvrtc-builtins64_128.dll, see THIRD-PARTY.md); igneum-worker-opencl.exe drives an AMD (or any OpenCL) card and lets the driver's own compiler build the program. No CUDA Toolkit, no Visual Studio, no SDK. The old build path (proto-cuda\build.bat with nvcc, proto-opencl\build.bat with cl.exe) is still in the package and is used only when a prebuilt worker is missing from the folder or FORCE_BUILD=1 is set at the top of the bat; the dashboard says which path each card runs on.
Devnet v4 is a new chain from genesis. The node keeps its database in %LOCALAPPDATA%\igneum\devnet-v4; the old chain's folder (%LOCALAPPDATA%\igneum\devnet) is not touched and can be deleted. Every node and miner on the network moved to v4 together; an old igneumd.exe or igneum-miner.exe cannot follow this chain.
1. START-IGNEUM.bat. It starts igneumd (RPC 127.0.0.1:26610, p2p 0.0.0.0:26611, peered to the seed node 188.245.5.161:26611 and the Mac 192.168.68.64:26611), waits until the node is synced, finds the GPUs, exports the current hourly program from the node (a "pack", proto-cuda\packs\devnet) and starts ONE miner per GPU vendor with MINERS=8 identities inside it (one worker owns the card; each identity has its own vote key and payout label). The worker reads the pack, compiles it on the card, builds the 256 MiB cache and the 1 GiB dataset, checks them and the program against the pack's expected values (a self-test printed in the miner log) and then says ready. On the RTX 5090 that takes a few seconds. Settings are at the top of the bat.
   Firewall: the first time, Windows Defender Firewall asks about igneumd.exe. Tick Private networks and click Allow access (that lets the other nodes dial this PC). If you clicked Cancel, run ALLOW-FIREWALL.bat once.
2. The window is a dashboard, redrawn every 2 s, with the version in the header: the NODE card first (state in colour: starting, syncing, synced, restarting, stopped; blocks, headers, blue score, peers, the chain's blocks per second, the difficulty direction, the node's uptime), then one card per GPU (hash rate in big digits, blocks found, identities, which worker path the card runs on: "prebuilt worker, NVRTC compiles on the card (driver only)", "prebuilt worker, the OpenCL driver compiles (driver only)" or "worker built here with ..."), the network share line, the last events (node started, synced in N s, peer joined or left, node restarted, blocks found, worker ready, the next hourly program compiled, miner restarted, upload failed) and a footer. Set PLAIN=1 at the top of the bat for a scrolling log instead; the launcher uses it by itself when the window is not a real console.
3. Ctrl+C in the window stops the miners first, then the node, then uploads the logs one last time; the window stays open with a summary. If the window was closed instead, STOP-IGNEUM.bat stops everything cleanly.
Payout: block rewards go to an EVM address. PAYOUT_EVM at the top of the bat sets one for the whole PC; left empty, the launcher derives one address per GPU vendor from this PC's name (the same on every run; it is printed in the launcher log and the status block). Finality voting is on: every identity signs every checkpoint (VOTE=0 switches it off).
The hourly program change: every hour the lottery program changes. About ten minutes before the boundary the node announces the next program; the miner writes its pack (proto-cuda\packs\prepare\<epoch>-<day>) and tells the worker, which compiles it on the card in the background, builds its cache and dataset, self-tests it and keeps it ready; at the boundary the worker swaps with no pause (the dashboard says "the next hourly program is compiled and resident"). If that ever fails, the CUDA worker finds the pack by itself when the first job on the new program arrives and compiles it then (a pause of a few seconds); and if a worker keeps erroring on the new seeds for 90 s, the launcher re-exports the pack and restarts that card's miner. --exit-on-seed-change stays on as the last fallback: a worker that cannot prepare at all exits with code 42 at the boundary and the launcher restarts it on a fresh pack.
Worker faults (added after the first field run on 4 October 2026, when an integrated AMD card's OpenCL runtime stopped running kernels after 600 s and kept answering every call with success): the OpenCL worker now treats any OpenCL error in a job as fatal, checks that each dispatch really completed, that it did not finish 20x faster per nonce than before and that its output changed, and exits with code 3 so the miner restarts it; every 200 jobs it prints a stats line with the live event and buffer counts. The miner itself kills and restarts a worker whose jobs finish in under 1/20 of the mean time per hash or whose rate jumps over 10x, drops the fake numbers, and prints "WORKER FAULT ..."; the dashboard then shows "worker fault" and "restarting" for that card instead of a rate, and the status block counts faults.
A worker started on a pack of an epoch that has just ended (the node was still catching up when the pack was exported) used to answer every job with a seed mismatch for the rest of its run. Now it asks for the pair it lacks ("need"), the miner writes that pack and sends it a prepare, and mining starts within seconds; a worker that cannot prepare is restarted on a fresh pack (exit 42). A worker that says ready but completes no job for 60 s while jobs are queued is restarted as well.
If a prebuilt worker never reports ready (150 s), the launcher says so in the events; when a CUDA Toolkit and Visual Studio happen to be installed it builds a worker from source with them instead, otherwise look at the miner log named in the event (the worker prints the reason: a missing DLL, a compile error, a driver too old for CUDA 12).
A node crash is restarted after a random 5 to 60 s; the miners are restarted once the node is back and synced (their connection dies with the node). The PC is held awake while the window runs; for the night also set Sleep to Never in Settings > System > Power.
Logs land next to the bat (igneum-<stamp>.log for the launcher, node-<stamp>.log for the node, nvidia-<stamp>.log and amd-<stamp>.log per miner process; the worker's ready, info and self-test lines are in the miner log) and are uploaded every 60 s with upload-log.bat under the labels igneum-<PC>, nodelog-<PC>, nvidia-<PC>, amd-<PC>.
Separate entry points, same code (igneum-common.ps1): START-NODE.bat runs the node alone (its card and events), START-MINING.bat runs the miners alone against a node that is already up (NODE_HOST=auto picks 127.0.0.1 when one runs here, else the Mac).
The node also serves the execution layer's Ethereum JSON-RPC on 127.0.0.1:26790 (chain id 4463); --evm-disable in EXTRA_ARGS turns it off.
If the node exits at once with a database error, delete %LOCALAPPDATA%\igneum\devnet-v4 and start again; it resyncs from the seed node and the Mac in seconds.
TEST.md says what to look for on the first run of this package (the lines the dashboard and the miner log should show) and what to send back.
Files: START-IGNEUM.bat, START-NODE.bat, START-MINING.bat, STOP-IGNEUM.bat, ALLOW-FIREWALL.bat and their .ps1 files, igneum-common.ps1, igneumd.exe with libstdc++-6.dll, libgcc_s_seh-1.dll and libwinpthread-1.dll (keep them next to it), igneum-miner.exe, igneum-worker-cuda.exe with nvrtc64_120_0.dll and nvrtc-builtins64_128.dll (keep them next to it), igneum-worker-opencl.exe, LICENSE-NVIDIA-CUDA-EULA.txt, LICENSE-Khronos-OpenCL-Headers.txt, THIRD-PARTY.md, TEST.md, upload-log.bat, proto-cuda\ and proto-opencl\ (the worker sources and build.bat, for the build path only).