igneum/app
igneum-labs 8951ed631f OTA: the second signing key (K2) with revocation, docs/security/keys.md section 4 steps 2 and 3
manifest.rs: OTA_PUBLIC_KEYS = [K1, K2] (K2 empty until tools/keys/keygen-k2.sh fills it; an empty slot is skipped),
verify_signature over the slice returning the key that verified, fingerprint8, the optional signed revoked_keys
list, the revoked.json record (load, save, trusted_keys) and check(): a key never revokes itself, a revoked key is
refused by name. ota.rs fetch_manifest goes through check() and writes <updates>/revoked.json; jobrun.rs verifies the
jobs file with the same trusted keys at every poll; jobs.rs, inputs.rs and ota-sign.rs take the slice; `embedded`
prints every key (K1 on lines 1 and 2 as before) and is accepted as the key argument of every verify command; the
engine logs "ota keys: trusted ...; revoked ..." at start and tools/logs.mjs --rotation shows it as the ota_keys
column with a K2 count.

Publisher side: publish-manifest.sh --revoke <fingerprint> (carried over until --no-revoke, the signer's own refused),
IGNEUM_OTA_KEY_FILE/IGNEUM_OTA_PUB_FILE in the three signing scripts, the embedded check accepts any embedded key.
tools/keys/keygen-k2.sh makes K2 straight into a new AES-256 image (private half never on disk), writes the .pub and
patches manifest.rs; tools/keys/with-k2.sh runs one publish with K2 from the image; tools/keys/test-keygen-k2.sh
proves both on a scratch folder with a throwaway key (25 checks).

Tests: manifest::tests second_key_verifies_third_key_fails_first_key_still_passes, revoked_keys_parse,
revocation_path; inputs sign_verify_and_tamper on the two-key slice; 79 igneum-app and 30 igneum-ota-sign unit tests
pass on the Mac; test-inputs-signing.sh 16, test-publish-jobs.sh 24, logs.mjs --self-test 12, no-secrets 0 hits.

Class fix: `"$SIGNER" embedded | grep -q` under pipefail failed on SIGPIPE once in three runs (grep exits at the
first match, the signer still has lines to write); the output is captured first in all four places, and
tools/ci/pipe-grep-q-check.sh (self-tested, wired into ci.yml) fails CI when the shape comes back.

K2 itself is not made here: the exact commands for the project lead are in docs/security/keys.md section 4. The wallet
(wallet-v1, app/igneum-common/src/manifest.rs, its own copy) is listed there as the follow-up.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:29:23 +00:00
..
igneum-app OTA: the second signing key (K2) with revocation, docs/security/keys.md section 4 steps 2 and 3 2026-10-05 20:29:23 +00:00
mac One-click miner app: Rust engine (node, miner and worker supervisor with a local dashboard), Mac WKWebView window with a menu-bar item, design screenshots 2026-10-04 10:00:22 +00:00
windows Igneum Miner 0.3.9: the prover mirrors the fee switch (new pinned guest, shard id 0x2b1a81cb...), node a24ab01a (igneum_exportSegments names the mergeset and every entry's block and body position), the devnet fee-switch runbook; the six version files 2026-10-05 16:28:36 +00:00