igneum/tools
igneum-labs 2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
..
ci Jobs publisher: the class checks run on the script before it is signed (row C27) 2026-10-05 22:14:19 +00:00
dev-fee Dev fee: the test-network measurement in the bench log; run.mjs waits for the nodes and edits the override as text 2026-10-04 23:15:27 +00:00
evm-smoke Execution layer devnet v3: implementation notes, bench entry, viem smoke test 2026-10-03 22:05:33 +00:00
exec-attacks exec-attacks: execution-layer attack suite (tools + bench log) 2026-10-03 22:57:19 +00:00
finality-attacks FUD sweep round 6 (evening, 5 October): eleven rolled-out fixes moved to Fixed with live measurement lines, F21/F22 shipped but switch not thrown, M20 closed on the 0.3.5 merge; P14 one base-fee definition in spec 05; M16 recompute-attacker cost model; C4 overlay-against-GHOSTDAG runner 2026-10-05 16:02:02 +00:00
harness Harness s8 steady state and the bench-log paragraph: RSS per 1,000 blocks before and after the M30 fix 2026-10-05 01:49:46 +00:00
keys Key custody: inventory, encrypted backup and restore, no-secrets CI check 2026-10-05 17:01:01 +00:00
lock lock: build slots open to new builds come from ~/.config/igneum/build-slots (1 to 3) 2026-10-05 08:19:52 +00:00
observer Observer: explorer detail per block from the notification, chain block number from the shard plan, RPC load counter, hourly coinbase check against spec 2.5 2026-10-05 19:35:40 +00:00
prove-fixtures Merge fee-switch into release-0.3.9: the prover mirrors both fee tables and fees_v1_activation_daa (new pinned guest), the devnet runbook for H = 210,000 2026-10-05 16:28:21 +00:00
proving-v0 Packaging for proving v0: the Mac DMG carries igneum-prove-host and igneum-prove-export, the Windows payload carries the Linux host and exporter under wsl2/bin with the WSL2 scripts and the fixtures; the prover probes the shipped WSL2 binaries first and runs helpers by absolute path; push-inputs takes IGNEUM_NODE_SRC; the test script's --network-only mode 2026-10-04 14:36:59 +00:00
reliability Reliability measured: miner guards and the app watchdog on private test networks; M26, M27, X21 fixed in the ledger 2026-10-04 22:22:16 +00:00
repo rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist 2026-10-05 15:37:02 +00:00
txgen txgen: real transactions on the devnet, the first non-empty shard proven and paid, the exporter's block structure fixed 2026-10-05 16:18:32 +00:00
ui-mock Miner app UI: log drawer rebuilt (open state, scroll to newest, time jump, last error and swap, search, copy, drag height, virtualised), every screen on one scale, canvas and polling idle when hidden 2026-10-04 19:51:22 +00:00
upstream Provenance: credit every borrowed component, upstream merge procedure, prover customer brief 2026-10-03 20:02:16 +00:00
build-job.mjs build-job.mjs: the watcher reads the SUMMARY wherever it sits in the report (the closing report starts with the app header; two finished builds showed as still running on 5 October 2026) 2026-10-05 16:02:47 +00:00
console.mjs Console: a machine whose app logged a clean quit or an update, with no status line after it, shows 'stopped (quit|update) N ago' instead of 'silent' (parseAppTail moved to relay/lib/parse.mjs, test) 2026-10-04 20:04:18 +00:00
jobs.mjs jobs: one signed object (igneum-jobs.signed.json) so a file and a signature from two deployments can never pair 2026-10-05 15:52:34 +00:00
logs.mjs rotation phase 2, executed: old folder stripped to the 0.3.5 manifest, local files renamed, relay on the new key, DL_TOKEN rotated; 7 October swap and the owner's rewrite checklist 2026-10-05 15:37:02 +00:00
relay.mjs Merge origin/build-job into release-0.3.5 2026-10-04 21:32:48 +00:00
ship-app.mjs Merge housekeeping: the signed jobs envelope, build-job test flags, the PC-built node cause and the parallel finality tests recorded 2026-10-05 16:30:47 +00:00
site-serve.mjs Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI 2026-10-05 19:35:40 +00:00
tuning.mjs Fleet learning for the kernel race: the TUNING record, the aggregator, the manifest's tuning object, the PC 1 race job 2026-10-04 19:08:45 +00:00