F14, the founder's ruling of 19:57 BST (docs/analysis/review-2026-10-08-b, the shipper's and the relay lane's names):
one tree, two builds, by the cargo feature `lab` (src/edition.rs). The public miner (the default) runs no remote
jobs: no signing root for them, no jobs url, the routes /api/jobs/* compiled out, the wake listener compiled out, the
Settings switch hidden, POST /api/jobs/allow refused with a line; its update choice is honoured: with automatic
updates off nothing installs until Install now, an urgent manifest included (manifest::safe_to_apply, the first
rule), and an unsupported version pauses mining with the reason on every card (update.hold_mining, the engine's
unsupported_hold); a manifest's consensus override is ignored (the node's rules come from the node; a compromised
update key activates nothing). The lab build (our fleet, `IGNEUM_LAB_PUBLIC_KEY=<hex> cargo build --features lab`)
verifies its OTA manifest, its interface bundles and its jobs feed against the lab root the relay lane generated
(never in the repo; the build fails without the variable), reads channel igneum-2.0-devnet-lab, names itself
"Igneum Miner Lab"; the public build reads igneum-2.0-devnet (the 2.0.0 and 2.0.1 manifests' "devnet" accepted
until the publisher renames it) and refuses a manifest of the other channel before staging. api/state carries
edition, product and channel; the IGNEUM-APP intake line carries channel= and edition=. The update choice is asked at
install: the welcome screen's "Update automatically" switch (on by default) and the Windows installer's task, which
writes install-choices.json for the engine's first start (config.rs).
F07: src/device.rs, the per-device coordinator. The mode per NVIDIA card from the measured rows (coexist-rows.md,
8 October 2026): simultaneous only on a tested configuration (24 GB and up, with 10% headroom over the measured
peaks), time-share where the compressed shard proof (7,532 MiB) fits alone, mining-only where no complete paid proof
fits; a lease table across the miner, the prover, an aggregation, a benchmark and the next-epoch preparation, where
pausing dispatch is not releasing memory (a lease ends only after the holder's process exits and nvidia-smi reads the
device under 1,024 MiB), and admission counts transfer, startup, proof, aggregation, rebuild and the payment deadline.
Wired: provedefault reads the modes (16 to 24 GB alternates, no longer "together"), state.proving.modes carries one
line per card for the Proving section, and the time-share prover waits up to 60 s for the card to read free after the
miner steps off before a shard, leaving the shard for another prover with the reading when it does not.
F04: the window's block inspector reads "finalised by a recovery lock" and the strip "recovery lock" with its why,
from igneum_getProvingStatus's lockKind and lockWhy once the node lane's field lands; the pause word stands until then.
Tests: edition.rs (the roots and channels per build), manifest.rs (off stays off, known-failed first), config.rs (the
installer's choice taken once), device.rs (the modes per row, the full cycle with no leaked reservation, the
simultaneous and mining-only rules, the deadline), provedefault.rs (the modes and the refusal), detect.rs parse; the
public crate 327 green on build-1; the once-tests for the window (F14, F07, F04); 133 UI tests green on build-2.
Captures in ~/Desktop/igneum-previews-2026-10-08/reviewb-202. The lab build's test run needs the key in the box's
build environment (tools/build-remote.sh does not forward it yet); the public build is the gate's.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>