the project lead, 4 Oct 2026: 0.3.1, 0.3.2 and 0.3.3 each took eight hand steps and an hour. The tool runs them in order, each step idempotent and resumable (--from): preflight, bump (six version files, one function, read back), push-inputs, commit and push, the windows.yml run polled with gh (auth switch before every call), fetch, DMG under the build lock, copy, signed manifest, one deploy, HEAD/GET verification with sizes and sha256, one console item. --dry-run prints the plan, --check compares the version files, --self-test bumps a scratch copy. Secrets never printed. Found by --check: Igneum-Miner.iss and Info.plist were left at 0.3.2 when 0.3.3 was cut (CI passed -Version from Cargo.toml, so the installer was right; the Mac bundle said 0.3.2 because build-dmg.sh's sed only matched 0.3.0). Both aligned to 0.3.3; build-dmg.sh now stamps the version with plutil. fetch-ci-artifacts.sh: CONSOLE_SKIP=1. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
4.5 KiB
Shipping an Igneum Miner version (packaging/README-ship.md)
One command cuts a version for both platforms. 4 October 2026: 0.3.1, 0.3.2 and 0.3.3 each took eight hand steps and
an hour; tools/ship-app.mjs is those steps in order, each one checked and resumable.
node tools/ship-app.mjs 0.3.4 --node vendor/igneum-node-v4 --notes "one line for the changelog"
Add --dry-run first: it reads everything, prints the plan and writes nothing.
What it does
| Step | What happens | Skips itself when |
|---|---|---|
| preflight | this tree clean and on master, the fork worktree clean (--node-commit <sha> pins it), tools, binaries, secrets present, gh account, what is live |
never (reads only) |
| bump | the six version files, written by one function and read back | the files already say the version |
| inputs | packaging/windows/push-inputs.sh with the fork's Windows exes (IGNEUM_WIN_RELEASE, IGNEUM_NODE_SRC) |
the live payload-inputs.json carries these exact files from this fork commit |
| commit | Igneum Miner <v>: <notes>, push master (the push starts the Windows build) |
committed and on origin/master |
| ci | the windows.yml run for that commit (dispatched when the push started none), polled every 30 s |
a green run for the commit exists |
| fetch | packaging/windows/fetch-ci-artifacts.sh <run>: installer and payload zip into the downloads folder |
the installer from that run is there |
| dmg | packaging/mac/build-dmg.sh under tools/lock/with-lock.sh build |
the DMG is newer than the bump (--rebuild forces) |
| copy | the DMG into the downloads folder | same sha256 already there |
| manifest | packaging/ota/publish-manifest.sh --no-deploy: signed, signature verified locally |
never (cheap) |
| deploy | the downloads folder, one Vercel deploy for the files and the manifest together | never |
| verify | HEAD and GET of the DMG, the installer and the zip (size and sha256 against the local copies); the live manifest through igneum-ota-sign verify |
never |
| console | one build item on the console (version, sizes, hashes, run, commit), then sync-dl |
never (upsert on ship:<v>) |
The six version files: app/igneum-app/Cargo.toml, app/igneum-app/Cargo.lock, app/windows/version.h,
app/igneum-app/resources/igneum-app.rc, packaging/windows/Igneum-Miner.iss, packaging/mac/app/Info.plist.
node tools/ship-app.mjs --check says whether they agree; --self-test runs the bump on a scratch copy.
Flags
| Flag | Meaning |
|---|---|
--node <dir> |
the igneum-node worktree the node and miner were built from (required); binaries from its target-integration/, else target/ |
--notes "..." |
the manifest's changelog line and the commit message |
--dry-run |
reads only, prints the plan (exit 1 when preflight would stop the real run) |
--from <step> |
resume at that step (preflight runs again first); the failure message prints this command |
--skip-windows, --skip-mac |
one platform only (the other entry is carried over when the live manifest is the same version) |
--node-commit <sha> |
the fork must be on this commit |
--win-release <dir>, --mac-release <dir> |
other binary folders |
--min-supported, --activation-height, --deadline-note, --channel |
passed to publish-manifest.sh |
--rebuild |
build the DMG again even when a fresh one exists |
--branch <name> |
accept another branch than master (a dry run from a worktree; the Windows build still runs on pushes to master) |
When a step fails
The tool stops, prints why and the --from command to retry. Nothing is skipped silently. State that is not a secret
(commit, run id, bump time, the hashes) is in ~/.cache/igneum/ship/<version>.json.
Secrets come from ~/.config/igneum (dl-token, dlsite-dir, ota-signing-key, relay token and key, the Vercel login) and are
never printed; every output line is scrubbed. gh auth switch --user igneum-labs runs before every gh call and before the
push.
What a cut needs before it starts
- The node fork built for both targets in
--node:target-integration/release/{igneumd,igneum-miner}andtarget-integration/x86_64-pc-windows-gnu/release/{igneumd,igneum-miner}.exe(proto-cuda/windows-node/cross-build.sh). - The prebuilt workers (
proto-cuda/nvrtc/igneum-worker-cuda.exe,proto-opencl/igneum-worker-opencl.exe) and the prover (proving/igneum-prove/target/release/igneum-prove-{host,export}); missing ones are noted, not fatal. - The Mac on mains, nothing else building (the DMG step waits for the build lock).