packaging/linux/bin/igneum-rig-lib.sh: OTA_PUBLIC_KEYS (K1, the empty K2 slot), manifest_check = the app's manifest::check (ota-k2063b988): every embedded key not revoked is tried and the signer remembered, the manifest's revoked_keys except the signer's own are recorded in /var/lib/igneum/updates/revoked.json (igneum-revoked-keys/1), a signature only a revoked key verifies is refused as "manifest signature is by a revoked key (sha256:<8 hex>)", a corrupt record reads as empty; the installer and the hourly updater go through it. selftest.sh: the app's revocation_path cases on three throwaway keys. Prover gates from provedefault.rs at440fd59(bench-log "proving v1", the S_p curve): PROVER_MIN_VRAM_MB and PROVER_MINE_AND_PROVE_MB 23,552; the README table states each tier's consequence. README: the miner takes the prepare-ahead path (both shipped workers answer prepare 1; exit 42 only without prepare support or on a seed-mismatch fault), so a 10-minute epoch costs no restart. igneum-node.sh and selftest.sh without mapfile (bash 3.2 on the Mac). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
20 lines
1.7 KiB
Bash
Executable file
20 lines
1.7 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# igneum-node.service: the bundled igneumd with the flags the apps use (app/igneum-app/src/engine.rs node args) and
|
|
# the HiveOS package's override rule (packaging/hive/h-run.sh): --override-params-file carries the signed manifest's
|
|
# consensus.override, else a peer refuses the node ("consensus params digest mismatch", 5 October 2026).
|
|
# /etc/igneum/override-params.json is written by install-rig.sh and refreshed hourly by igneum-update.sh from the
|
|
# verified manifest; the package's own override-params.json is the offline fallback.
|
|
set -euo pipefail
|
|
# shellcheck source-path=SCRIPTDIR
|
|
# shellcheck source=igneum-rig-lib.sh
|
|
. /opt/igneum/bin/igneum-rig-lib.sh
|
|
load_conf
|
|
mkdir -p "$IGNEUM_VAR/node"
|
|
override=()
|
|
if [[ -s "$IGNEUM_ETC/override-params.json" ]]; then override+=("--override-params-file=$IGNEUM_ETC/override-params.json")
|
|
elif [[ -s "$IGNEUM_ROOT/current/override-params.json" ]]; then override+=("--override-params-file=$IGNEUM_ROOT/current/override-params.json"); log "using the package's override-params.json (no verified copy in $IGNEUM_ETC yet)"
|
|
else log "no consensus override file; the node runs the binary's defaults (fine for a fresh testnet, refused by the devnet)"; fi
|
|
peers=(); while read -r p; do peers+=("$p"); done < <(node_peer_args)
|
|
log "igneumd $NODE_FLAG, data $IGNEUM_VAR/node, RPC 127.0.0.1:$RPC_PORT, EVM RPC 127.0.0.1:$EVM_PORT, P2P 0.0.0.0:$P2P_PORT, peers ${peers[*]#--addpeer=}${override[0]:+, override $(tr -d ' \n' < "${override[0]#--override-params-file=}")}"
|
|
exec "$BIN/igneumd" "$NODE_FLAG" "--appdir=$IGNEUM_VAR/node" "--rpclisten=127.0.0.1:$RPC_PORT" "--evm-rpclisten=127.0.0.1:$EVM_PORT" \
|
|
"--listen=0.0.0.0:$P2P_PORT" "${peers[@]}" "${override[@]}" --nodnsseed --disable-upnp --nologfiles --yes
|