igneum/docs/plans/launch-pack.md
igneum-labs 8bb638f843 Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).

The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.

Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:39:50 +00:00

32 KiB

The launch pack: gates and text, no protocol (mission item 10)

7 October 2026, 10:1x to 11:xx UK, the launch-pack lane (branch launch-pack, worktree igneum-wt-launch-pack, from master b92a5fd4). Mission item 10 of docs/analysis/mission/mission.md 2.10, built from past.md sections 3 and 4, future.md section 8, reinvent.md 3.1 and 4.1, docs/plans/testnet-go.md and the litepaper. This is an operations document: docs/plans is not on the public export list, so it may name the owner; the text handed to the site lane in section 4 may not, and tools/ci/launch-gates-check.mjs greps it.

The founder's three decisions of this morning, written in everywhere below:

Decision the founder's word (7 October 2026, 10:1x UK) Where it lands
The proving customer A signed proving customer IS a mainnet gate: one signed customer paying for proofs at a published rate, or a signed letter of intent with a volume, before mainnet, not before the testnet testnet-go.md LG-11; the journey's phase 4 gate loses "one rollup signs for testnet" (section 4, item E); ledger X13 status (section 4, item F)
The certificates APPROVED: Windows EV Authenticode and an Apple Developer organisation account, both under Igneum Labs LTD, executed the day the entity exists LG-3; the runbook in section 2; the signing step in 2.4
The disclosure prize YES, USD 50,000; payer Igneum Labs LTD; staged until the entity address exists on its documents and the founder's publish word (docs/plans/cryptanalysis.md 3.3, branch cryptanalysis, 43d9700b) LG-13; nothing public until the word

1. The gates

The thirteen gate rows are in docs/plans/testnet-go.md, section "Launch gates", each with its check, its state today and its owner. The check that keeps them honest: node tools/ci/launch-gates-check.mjs fails when a row has no check, when a check names a repository path that does not exist, when the handoff text in section 4 carries a served-page pattern or an em dash, or when one of the eight regulatory sentences is missing or out of order. Its --self-test fires on each of those. Both run in tools/ci/pre-push.sh.

What this lane built, and what each gate still needs:

Gate Built here Still owed, by whom
LG-1 income per tier tools/launch/income-tiers.json (the measured rows, each with its source), tools/launch/income-tiers.mjs (the generator, --check), tools/launch/income-tiers.test.mjs, docs/analysis/income-tiers.md (public) re-generate at the 0.4.0 cut from class v4 rates (the shipper); the RTX 4060 and Apple wall power, an Intel row (the fleet lane)
LG-2, LG-6, LG-7, LG-9, LG-10, LG-12 the hash-origin report tools/observer/hash-origin.mjs (the job: --dry, --write, --post, --fixture), its fixture and test; ran read-only on the live devnet tables today the Devnet 2 observer with a table prefix (fleet lane); the fleet registry's key file (fleet lane); the systemd timer (build-server lane); the two X5 columns (the observer owner); the pool statement format (the pool lane)
LG-3 signed installers the runbook (section 2) and the signing-step specification (2.4) the founder: the entity's documents, the two enrolments (section 5); the shipper: the step
LG-4 first-share time the measurement specification (2.5) the fleet lane: tools/fleet/first-share-time.sh
LG-5 the text the handoff block (section 4) the site lane: land it, rebuild, deploy
LG-11 the customer the gate line and its check the founder: the signature; the execution engineer: the paid job
LG-13 the prize the gate line pointing at the staged text the founder: escrow, the address, the word

2. The certificate runbook

Two enrolments, both in the entity's name, both the day Igneum Labs LTD exists on paper. Neither names the founder publicly: an Apple Developer ID certificate reads Developer ID Application: Igneum Labs LTD (TEAMID) and an EV Authenticode certificate reads the entity's registered name; the person who enrols is known to Apple and to the certificate authority, not to the public.

2.1 Apple: the Developer Program as an organisation

Item Value Source
Provider Apple Developer Program, organisation membership https://developer.apple.com/programs/ (read 7 October 2026 by lane 5: USD 99 a year, notarisation included)
Cost USD 99 a year the same page
What the entity supplies (1) a D-U-N-S number for Igneum Labs LTD at its registered address (free from Dun and Bradstreet; Apple has its own D-U-N-S lookup and request form; a new entity's number can take days to weeks to issue, approximate); (2) the legal entity name exactly as the DIFC registrar records it; (3) a person with legal authority to bind the entity (a director) who enrols with an Apple ID on an entity mailbox (for example developer@igneum.network) with two-factor on; (4) a website on a domain the entity controls (igneum.network); (5) a phone number Apple can call for verification Apple's enrolment requirements for organisations, from memory, approximate; the exact list is on the enrolment page at the time
What comes out A Team ID; a Developer ID Application certificate (and a Developer ID Installer certificate if a .pkg is ever shipped); notarisation through notarytool with an app-specific password or an App Store Connect API key Apple's notarisation documentation, from memory
Where the key lives In the login keychain of the Mac that runs packaging/mac/build-dmg.sh, exported once to an encrypted .p12 kept with the entity's records; never on igneum-build-1 (CLAUDE.md: the box holds no secret that signs releases) this lane
Time Enrolment review by Apple: days, approximate; D-U-N-S first from memory, approximate

2.2 Windows: an EV Authenticode certificate

Item Value Source
Provider One of the public CAs that issue EV code-signing certificates: DigiCert, Sectigo, GlobalSign, SSL.com (the four this lane knows; from memory). The choice that matters: the CI runner must sign, so pick one whose private key lives in the CA's cloud HSM with a client for Windows (SSL.com eSigner with its CodeSignTool, DigiCert KeyLocker with smctl; Sectigo and GlobalSign have hardware-token and cloud options; from memory, approximate). Azure Trusted Signing was considered and set aside: its public-trust tier wants three years of verifiable organisation history (from memory, approximate), which a new DIFC entity cannot show lane 5 (reinvent.md 3.1) for the SmartScreen facts; this lane for the provider notes
Cost USD 300 to 700 a year for EV, approximate, from memory of list prices; cloud signing may add a monthly fee or a per-signature count approximate
Why EV and not OV Both are hardware-bound since the CA/B Forum's June 2023 rule (private keys in a FIPS 140-2 level 2 token or an HSM; from memory). EV used to grant SmartScreen reputation at once; SSL.com's page says Microsoft "moved away from automatic instant reputation" (reinvent.md 3.1, read 7 October 2026), so even EV may show the interstitial until the file earns reputation. The founder chose EV; the download page states the two clicks until the 1,000-download mark either way reinvent.md 3.1
What the entity supplies (1) the DIFC certificate of incorporation or commercial licence showing the registered name and address; (2) proof the address is the one on the registrar's record; (3) a telephone number the CA can verify (a public directory listing, or a letter from the entity's accountant or lawyer when there is none); (4) the government ID of the person signing the subscriber agreement and a director's letter authorising that person; (5) the D-U-N-S listing from 2.1, which shortens the CA's organisation check the EV code-signing guidelines' identity requirements, from memory, approximate; the CA's own checklist governs
What comes out A certificate in the CA's HSM (or a USB token posted to the registered address), a signing account for CI with a short-lived credential, and a timestamp URL approximate
Where the key lives In the CA's HSM; the CI credential in the repository's GitHub secrets (rotatable); a USB token, if that route is taken, stays with the Mac and signs through osslsigncode with a PKCS#11 module; never on igneum-build-1 this lane
Time Validation 1 to 5 business days after the documents, approximate from memory

2.3 Mailboxes and records to create with the entity

Item Why
developer@igneum.network (or the name the founder picks) The Apple ID of the organisation account and the CA's subscriber contact
security@igneum.network The disclosure address of the prize (cryptanalysis.md 3.3; the founder's call on the name)
The D-U-N-S number Apple requires it; the CA uses it
An encrypted record of the Team ID, the certificate serials, the expiry dates and the renewal month Renewal is a calendar item the way a domain is

2.4 The signing step in the shipper's cut (specification; the shipper ae892a8b0f78fe31c implements)

Today packaging/mac/build-dmg.sh signs ad hoc (codesign -s -), the app strips its own quarantine on start, and the Windows exes and installer are unsigned (.github/workflows/windows.yml, step "installer"). The step below adds signing where each binary is built and verification where the shipper already verifies, so tools/ship-app.mjs keeps its step list (preflight bump inputs commit ci fetch dmg copy mirror manifest deploy verify console) and gains checks inside fetch, dmg and verify rather than a new step.

Where What changes Check
.github/workflows/windows.yml, step "installer", before ISCC Sign igneum-app.exe, igneumd.exe, igneum-miner.exe, the window host and the worker exes with signtool sign /fd SHA256 /td SHA256 /tr <timestamp url> through the CA's KSP (the cloud client logs in from two GitHub secrets: the account credential and the TOTP or API key the CA gives); then the Inno script's SignTool= directive signs the installer and its uninstaller with the same command. The secrets are absent on a fork or a pull request: the step then builds unsigned and marks the artefact unsigned, and the shipper refuses it (next row) signtool verify /pa /v dist\*.exe in the same job prints the signer and the timestamp; the smoke-run step reads it
tools/ship-app.mjs, fetch After packaging/windows/fetch-ci-artifacts.sh, run osslsigncode verify <installer> on the Mac (Homebrew osslsigncode): the signer CN must equal Igneum Labs LTD, the digest SHA-256, a timestamp present; an unsigned or wrongly signed installer fails the step with the line the step's own exit
packaging/mac/build-dmg.sh Replace codesign -s - -f with codesign --force --options runtime --timestamp --sign "Developer ID Application: Igneum Labs LTD (TEAMID)" on every binary under Contents/Resources/bin and Contents/MacOS, then the app bundle (with an entitlements file only if a binary needs one; none is known today); xcrun notarytool submit <zip of the app> --keychain-profile igneum-notary --wait must print Accepted; xcrun stapler staple the app, then build the DMG, then xcrun stapler staple the DMG; remove the app's own quarantine strip (it exists for the ad-hoc case only) spctl --assess --type execute -vv <app> prints accepted and source=Notarized Developer ID; codesign --verify --deep --strict <app> exits 0
packaging/ota/publish-manifest.sh and the manifest Two fields per platform file: signed_by (the signer CN as verified) and notarized (true or false); publish-manifest.sh refuses --public when either is missing tools/ship-app.mjs --check and the manifest's signature check already run; add the field check there
tools/ship-app.mjs, verify Besides size and sha256: download the live installer and run osslsigncode verify; mount the live DMG and run spctl --assess; both results must match the manifest fields the step's own exit
The download page (site/miner.html, the site lane) and the Discord release post (tools/community/discord-hooks.mjs release) Show "Signed by Igneum Labs LTD" and the sha256 only when the manifest says so; keep the "what your antivirus may say" line (reinvent.md 3.1) and the exact SmartScreen text and two clicks until the 1,000-download mark tools/ci/launch-gates-check.mjs greps nothing here; the site's own build grep runs
tools/ci/signed-release-check.sh (new, with the implementation) A manifest in dl/public/ without signed_by on every file fails; --self-test with a manifest missing the field in tools/ci/pre-push.sh

Order of work for the shipper once the certificates exist: the Mac side first (one machine, one keychain, one release), then the CI side (the cloud-signing client in the runner), then the manifest fields, then the download page. Until the certificates exist nothing in this table runs, and the 0.4.0 cut ships unsigned with the page saying so (funding.md section 2, the client audit row: "the one-click app ships at testnet unaudited and says so on the download page").

2.5 The first-share time, measured per release (specification; the fleet lane builds tools/fleet/first-share-time.sh)

reinvent.md 3.1: the time from download to the first accepted share has never been measured end to end on a fresh machine. The measurement is a Devnet 2 gate step, one run per platform per release:

Step What Where
1 A fresh Windows 11 VM (Hyper-V on the RTX 5090 Windows rig, or a rented Windows box) and a fresh macOS VM (Tart or UTM on the Mac) from clean images; no Igneum files on them the fleet lane's box library (tools/fleet/lib/) for the rented case; a Mac job for the macOS case
2 The script downloads the release from the public URL, runs the installer (Windows) or opens the DMG and copies the app (macOS), starts the app with the Devnet 2 network setting, and reads the app's own log for three stamps: install done, node synced, dataset built, then the first accepted share or block the app's log lines are the clock; the script never reads a reported rate
3 One line into the gate log: FIRST-SHARE <windows or mac> download=<s> sync=<s> dataset=<s> share=<s> version=<v> ~/Desktop/fleet/devnet2-gate-<stamp>.log, the same file devnet2-gate.sh writes
4 The numbers go to /evidence as a row per release ("download to first share, fresh Windows 11: N min M s; fresh macOS: N min M s"), with the date and the version the site lane
Gate Under 10 minutes in 9 of 10 fresh Windows installs (mission item 6), measured across releases the /evidence rows

3. The hash-origin report: what it is and how it runs

tools/observer/hash-origin.mjs. Once a day, from the observer's tables, who found the blocks. It reads live_blocks (24 h: vote key, payout address, colour), live_state (the node's hash-rate estimate), miner_logs (the vote keys the project's intake-reporting workers logged) and, with --fleet-keys <file> or IGNEUM_FLEET_KEYS_FILE, the fleet registry's key list. It writes, only with --write, its own two tables (hash_origin_days: one row per key per day for the 30-day dust and independence counts; hash_origin_reports: the day's report as posted) and the jsonb column hash_origin on live_state for the site. With --post it posts to #numbers through tools/community/discord-hooks.mjs's poster (its guard refuses any post with a machine id, a path, an IP or a 32-hex token; key hash-origin:<date>, so a day posts once).

Command What
node tools/observer/hash-origin.mjs --fixture tools/observer/fixtures/hash-origin-day.json The fabricated day; no database
node tools/observer/hash-origin.mjs --dry [--go 2026-10-20] The live tables, read-only (ran today)
node tools/observer/hash-origin.mjs --dry --prefix dn2_ The Devnet 2 observer's tables, once that observer runs with LIVE_TABLE_PREFIX=dn2_
node tools/observer/hash-origin.mjs --write --post --live --go <date> The daily run on the box
node --test tools/observer/hash-origin.test.mjs The known-finished and known-failed days; in tools/ci/pre-push.sh

Today's read-only reading on the live devnet (7 October 2026, 11:xx UK), and what it means (the consequences rule):

Line Reading What it means, and what is done about it
Keys 113 with a block, 95 above the dust line, ten largest 45.0 percent The devnet runs the project's machines with several identities each (ledger-decisions.md decision 13 moves the default to one key per machine), so 113 keys is not 113 miners; the independent count is the X5 definition and its two owed columns
Fleet 36 keys, 38.4 percent "fleet"; 77 keys, 61.6 percent "outside" False: the rented boxes do not upload identity lines, so the job cannot see them as the project's. The fleet registry's key file fixes it (IGNEUM_FLEET_KEYS_FILE); until the fleet lane exports it, LG-7 is void and the report says so by its numbers
Pools 13 shared payout addresses (68.4 percent); attested pools 0 A shared payout is a pool or one machine with several identities; the job counts a pool only when attested (the project's own, or an operator's signed key list), so no devnet machine is mistaken for an outside pool and LG-9 cannot pass on a multi-key machine
Network 0.76 GH/s, no yesterday The step line needs two days of its own table; the first run with --write starts the series

The runbook for the box (build-server lane; infra/build-server/hands/ holds the observer's units):

Item Value
Unit igneum-hash-origin.service (oneshot) and igneum-hash-origin.timer, OnCalendar=*-*-* 08:30:00 UTC (before the 09:00 UK digest), Persistent=true so a missed day runs at boot
Command node tools/observer/hash-origin.mjs --write --post --live --go <go date> from the box's checkout, as the observer user
Environment EnvironmentFile=/srv/observer/env (DATABASE_URL) and /srv/discord-hooks/env (the webhooks, already on the box by the 6 October exception); IGNEUM_PROJECT_POOLS=<pool-0 payout address>; IGNEUM_KNOWN_POOLS= (empty until a statement exists); IGNEUM_FLEET_KEYS_FILE=/srv/observer/fleet-keys.txt (written by the fleet lane's export, one 64-hex key per line, mode 600)
Devnet 2 The same unit with LIVE_TABLE_PREFIX=dn2_ once the Devnet 2 observer runs; seven days of posts before step 10 is LG-2
90 days The timer runs for ever; LG-12 counts the first 90 days from the go in hash_origin_reports
Gate The unit is trusted after one run that posted and one run with the database string removed that failed loudly (the watcher rule)

4. The text, handed to the site lane

Everything between the two markers is for the site lane (a4b202cabca2d95c0 deploys). It is written to the copy law and tools/ci/launch-gates-check.mjs greps it against site/forbidden-strings.txt and tools/ci/forbidden-strings.txt. The site lane lands it in site/index.html, site/litepaper.html, site/journey.json, rebuilds (node site/build.mjs) and pushes; the ledger owner takes item F into docs/fud-ledger.md (tools/ledger-page.mjs renders it).

A. The front page: the three wants lead (site/index.html, the hero and the first block under it)

The miners' own words asked for three things (twenty posts and launch texts, 2018 to 2026, docs/analysis/mission/past.md section 2: hardware that keeps its value, 10 of 20; income above electricity that does not fall off a cliff, 6; a fair supply, 4). Nobody asked for finality, a DAG or proofs. The front page answers the three in order; finality moves to page two. The h1 stays as it is. Under it, three cards, each with one heading and three to four short lines:

1. Your card stays a card. The hash is a new random program every hour over a dataset the chain draws from its own state. No scheduled fork, no release a team must ship. The chip model and its number are published with every era on /evidence. When you stop, the card still games.

2. Income with no cliff. 100 IGN a block, falling 2.9 percent a month. No halving day. Then 1 percent of supply a year, for ever. A block pays its miner whether or not anyone buys a proof that day. What each card mines, and what its electricity costs, is one table: the income page.

3. A fair supply. No premine. No fund, no foundation, no fee to any team. Nobody holds a coin before block one. The founders mine from genesis with disclosed addresses and the same software as everyone else. The first 90 days ramp from 10 percent, so the launch weeks are worth less to a private farm.

Under the three cards, one line and a link: "Blocks are final by miners alone, with no stake and no other chain. How, on page two." (the link is the litepaper's "Speed and finality" section).

The income page: render docs/analysis/income-tiers.md as /income (or link the public mirror's copy) and link it from card 2 and from /miner. The page is generated; the site lane does not edit its numbers.

B. Page two: finality (site/litepaper.html, "Speed and finality")

No change to the section's text. The change is placement: the front page's hero no longer carries a finality claim; the "Igneum at a glance" block keeps its one finality line and links down to the section. The explorer and the wallet keep their finality state words.

C. The block sentence (site/litepaper.html, "Three income streams, one balance", directly under the table)

"A block pays its miner whether or not anyone buys a proof that day. The lottery pays 80 percent of every block from emission; proving is the second income, never the only one. Every useful-work chain on record dropped its miners the day the work stopped paying; Igneum's miners are paid for the block first."

Each sentence is docs/analysis/mission/future.md 8.3, verified against the file on 7 October 2026 and re-worded to the copy law where the file's own line was a note; the number in brackets is the file's. The heading sentence: "Not legal advice; counsel is engaged. These are the facts of the design that the rules of each region turn on; nothing here is a promotion of anything."

  1. No issuer, no offeror, no sale. Every coin is created automatically as a reward for the maintenance of the distributed ledger or the validation of transactions, and in no other way. (8.3 sentence 1; the quoted words are MiCA Article 4(3)(b)'s, verbatim, as the file asks)
  2. The sustainability indicators of Delegated Regulation 2025/422 (energy in kWh a year from the network's hash rate and the measured microjoules per hash, intensity per transaction, the regional mix when it is known) are published by the project every era, so a service provider in the EU can list the coin without asking. (8.3 sentence 2)
  3. No financial promotion. No price, no "buy", no "invest", no return language anywhere. The earnings screen shows hash and IGN, never a currency. (8.3 sentence 3; the income page shows electricity in dollars as a cost, never the coin's price, which is this sentence kept)
  4. The reference pool never holds a member's balance. Payouts come straight from the coinbase split; the pool coordinates, it does not keep custody. (8.3 sentence 4)
  5. The job market settles peer to peer on the chain. There is no operator account and no dollar leg in the protocol: the dollar figure is a quote, the settlement is IGN. (8.3 sentence 5)
  6. The software is published under an open licence by a company that holds no coins by right and runs no service the chain's consensus depends on. There is no dev fund. (8.3 sentence 6; the file's line reads "runs no service the chain depends on"; "consensus" is added because the company does run seeds, a public RPC and a log intake, none of which consensus needs; counsel reads both)
  7. Mining may be restricted where you are; you are responsible for checking. The miner asks your region at first run and refuses the regions where mining is banned (the file's list on 7 October 2026: ten regions of Russia and Moscow from 15 August 2026, and China). (8.3 sentence 7)
  8. No privileged key. No key can mint, pause or upgrade the chain; the only way a rule changes is miners signalling for it, and nothing requires them to. (8.3 sentence 8)

E. The journey (site/journey.json)

Phase Today Change
phase-4, gate "Finality design passes external review and one rollup signs for testnet" "Finality design passes external review"
phase-5, gate "1,000 independent miners run 30 days and rollup proofs are delivered on time" unchanged
phase-6 (mainnet), when "After the testnet has passed its gate: 1,000 independent miners for 30 days and rollup proofs on time" "After the testnet has passed its gate (1,000 independent miners for 30 days, rollup proofs on time) and one proving customer has signed: a customer paying for proofs at a published rate, or a letter of intent with a volume"

F. The ledger rows (docs/fud-ledger.md; ids provisional, the ledger owner renumbers on merge)

X13 (existing), status update. Decided (7 October 2026, 10:1x UK, by the owner): a signed proving customer, paying for proofs at a published rate or a letter of intent with a volume, is a MAINNET gate (testnet-go.md LG-11). The phase 4 gate drops "one rollup signs for testnet". The pilot progression in the answer stands: a signature opens mainnet, repeat purchases and a second unrelated customer are the evidence after it.

X37. Your installer is a warning screen. "Windows says 'Windows protected your PC' and the Mac refuses to open it. A miner's first screen on your chain is an operating-system warning, and you call that one click." Status: Open, certificates approved (7 October 2026): an EV Authenticode certificate and an Apple Developer organisation account, both in the entity's name, enrolled the day the entity exists; the signing step is specified for the release tool and runs from the first signed cut. Until then the download page shows the exact warning text and the two clicks. Answer: True today. The DMG is signed ad hoc and the Windows installer is unsigned. SmartScreen warns on any file without reputation and reputation is use, so the interstitial may outlive the signature by some downloads; the page says so. The measured time from download to the first share on a fresh machine is published per release. Evidence: testnet-go.md LG-3 and LG-4; launch-pack.md section 2.

X38. Nobody will know whose hash the launch is. "On launch week your own rented cards will be most of the hash, and the chart will look like Nervos in 2020 or Iron Fish in 2023: a step nobody can explain." Status: Open, the report built (7 October 2026): a daily hash-origin report from the observer, posted in public for the first 90 days and on the staging chain for seven days before the go: keys with a block, keys above dust, the project's own fleet share, attested pools, the ten largest keys, and any 2x step in the estimate with the keys that carry it. Answer: Right that the first weeks are the project's own cards plus whoever shows up, and that a chart alone cannot tell them apart. The report names the project's share every day, from the project's own key list, so the step is explained the day it happens. What it cannot do yet: count independent miners (the autonomous-system and fingerprint columns are owed), or tell a pool from a machine with several keys without the pool's own signed statement. Evidence: testnet-go.md LG-2, LG-6, LG-7, LG-9, LG-12; tools/observer/hash-origin.mjs.

E23. You will show a number that makes someone buy a card. "Every GPU chain's launch page had an earnings number, and every one was wrong inside six months." Status: Stated (7 October 2026): the income page shows IGN a day per measured card at three network sizes, electricity a day at three tariffs, and the electricity cost of one mined IGN; no coin price appears, every rate is a measurement with its source, and the page says what each tier should expect from the record of other chains. Answer: Agreed, and the record is the argument: income halves within 60 to 120 days of a peak and falls under power within 6 to 18 months on every chain in the sample. The page shows the arithmetic the miner can redo with the live network figure, and nothing else. Evidence: docs/analysis/income-tiers.md; testnet-go.md LG-1.

L10. The eight sentences. "You say 'not legal advice' and then write eight sentences of it." Status: Open, counsel engaged (the owner, 6 October 2026); the eight sentences are the design facts the rules turn on, each cited to its regime in the research file, and they go to counsel with the litepaper before mainnet. Answer: The sentences state what the design does (no issuer, no custody in the pool, no dollar leg, no privileged key, the region refusal) and what the project publishes (the energy indicators); they do not say what any law concludes. Counsel decides the wording for each region. Evidence: docs/analysis/mission/future.md section 8; testnet-go.md LG-5.

5. What needs the founder

# Item What exactly Blocks
1 The entity's documents Igneum Labs LTD's certificate of incorporation or DIFC commercial licence, proof of the registered address, a director's government ID, a director's authorisation letter naming who enrols and signs LG-3 (both certificates), LG-13 (the payer's address on the prize text)
2 The D-U-N-S number Request it for Igneum Labs LTD at the registered address (free; days to weeks, approximate) the Apple enrolment; the CA's organisation check
3 The Apple Developer Program enrolment As an organisation, on an entity mailbox with two-factor, USD 99 a year, the founder as the person with authority; Apple may call LG-3 (the Mac side)
4 The EV certificate order Pick the CA (a cloud-HSM one so the CI runner signs: SSL.com eSigner or DigiCert KeyLocker, approximate), pay (USD 300 to 700 a year, approximate), take the validation call, receive the signing account; the CI credential goes into the repository's secrets LG-3 (the Windows side)
5 The proving customer's signature One customer paying for proofs at a published rate, or a signed letter of intent with a volume (Taiko is the named first customer; the brief is ledger X13's) LG-11, mainnet
6 The prize Escrow USD 50,000 with the entity; confirm the registered address on the staged text; give the publish word; pick the disclosure mailbox name LG-13
7 Two mailboxes developer@igneum.network (or the founder's name for it) and security@igneum.network items 3, 4 and 6
8 The three tariffs DECIDED (the coordinator for the founder, 7 October 2026, 11:xx UK): electricity tariffs per kWh, never a coin price; the triple is USD 0.05 (cheap industrial), 0.10 (US retail) and 0.25 (UK retail at today's rate), and the table was regenerated on it. Nothing left here none
9 Permission to post the first outside block reinvent.md 4.1 G-C2: the "first outside block" post needs the owner's permission LG-7's post, not its check

6. Not done here, and why

Item Why not Who
Any change to a live page or to site/ The site lane deploys; this lane hands text (section 4) site lane
The signing step's code A specification only (2.4); the shipper implements when the certificates exist shipper
tools/fleet/first-share-time.sh A specification only (2.5); it needs the fleet library and a Windows VM job fleet lane
The Devnet 2 observer and the fleet key file Fleet-side; without them LG-2 and LG-7 cannot fire fleet lane
The systemd timer on the box Box-side; the unit is specified in section 3 build-server lane
The X5 observer columns The app-owner item of ledger-decisions.md section 3 observer owner
Ledger edits Handed as rows (item F); the ledger owner merges and renumbers ledger owner
The litepaper artifact (the Claude doc) The site's litepaper.html is the public copy the handoff targets; the doc follows the site site lane