3.7 KiB
3.7 KiB
Release rules (the shipper's standing rules, as main set them)
Every cut of the Igneum Miner app and its node runs under these. The dated plan for each cut (docs/plans/release-.md) records how each rule was met.
- Versions are three-part. A hotfix takes the next number; the feature tree moves up. The app's parser returns None on a fourth part.
- Nothing is staged in the live downloads folder. Stage in a scratch copy with
IGNEUM_DLSITE=<copy> publish-manifest.sh --no-deploy; the live folder changes only in the deploy step.publish-jobs.sh --deployis jobs-only. No lane removes a scratch directory it did not create. - The deploy gate is a full canary on the fleet's pods: the fresh join through the headers proof on a WIPED datadir (decisive), synced, ten minutes mining, the hub holding a block, the relay and poison cases. Main may call the deploy on the decisive read plus a diff argument.
- The kept-datadir start is a named gate in every release (main, 7 October 2026, after ledger N13). Every canary runs both a wiped datadir and a KEPT one: a copy of a standing box's datadir from the live release, the pinned binary started on the copy on a scratch pod, "synced" or the store's rewrite line as the pass. The Windows shape too: the pinned Windows node once against a copy of PC 2's datadir (PC 2 only, never PC 1) before PC 1 gets the build. The miner-reliability register carries it as its own fault class. Why: every node build from 10db4b61 died at start on a kept 0.3.17 datadir (bincode ignores serde defaults) and no canary saw it because every canary wiped.
- Rollout is one box at a time: read back, a lock line from the hub between boxes; hold if the frozen table's signed share reads under 75. Miners first; the hands and the seed LAST, by the build-server lane on the shipper's line. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK).
- Read-back is by commit string plus digest plus engine: on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees
strings igneumd | grep -c igneum-pow/src/above zero. The miner embeds no commit string; its pairing is the build line and the sha. - igneum-pow pairing: a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file).
- glibc classes: HiveOS 2.31 (
--ship hive, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (--ship seed), fleet 24.04 boxes native 2.39. - The Mac builds only the macOS binaries and the DMG, one at a time under the build lock; every other build, suite and the Windows cross-build runs on the box or a PC; the app gate is
build-remote.sh -- test --releasefrom the crate dir. - A pin is green on its own suites and gates. Lines taken on one binary carry to another only when the code is byte-identical, stated in the tip. No known-red pins: a stale test takes a test-only commit on top.
- Kill by pid, never by name, on the shared Mac; a merge worktree never checks out master.
- The Discord card only when every platform is live. Live manifest changes beyond the binaries (a moved consensus floor) go out only on the project lead's explicit word, staged beside the release with their digest and a one-line diff.
- Ship on green: no calendar waits; when the gates are green, publish and state the clock time (UK). Checkpoints are for slips, not for waiting.