igneum/packaging/linux/bin/igneum-node.sh
igneum-labs cf716a6910 Rig installer for Ubuntu 24.04: install-rig.sh, the six units (node, miner@card, prover, telemetry, update timer), rig-status, the signed-manifest and package checks, the self-test; console accepts linux labels
packaging/linux: preflight (Ubuntu 24.04, NVIDIA driver 580 floor with libcuda and libnvrtc.so.12, AMD ROCm OpenCL ICD, Intel compute runtime, nvidia-smi and the OpenCL list printed, RAM, free disk, ports, ufw), the wallet and rig name asked once, the igneum system user, the Ed25519 check of dl/public/igneum-app-latest.json with the OTA public key (OpenSSL 3 pkeyutl -rawin, python3 cryptography fallback, never skipped), consensus.override written from the verified manifest and refreshed hourly (the HiveOS override rule without a package republish), the HiveOS package downloaded with size and sha256 checked (the signed linux entry when the manifest has one, else the .sha256 sidecar behind --allow-sidecar-sha256, said in capitals), releases under /opt/igneum with a current symlink and a 90-s rollback, one miner unit per card with CUDA_DEVICE_ORDER=PCI_BUS_ID and the OpenCL ordinal mapping, the integrated GPU and the BMC VGA excluded by the inventory, the prover unit as the proving-v1 loop in bash (12 GB gate, 20 GB mine-and-prove line with the card's miner paused per shard through a sudoers rule, idles in state setup while no Linux prover binary is published), telemetry in the app's line shapes with the relay upload under nodelog-linux/miner-<vendor>/linux labels, the identities rule with its 8 GiB threshold.

Tested on the Mac: shellcheck -x -S style clean, bash -n, check-units.sh (6 units, the systemd-analyze stand-in; no systemd or Docker here), the inventory on a fake sysfs tree, the rules, the live manifest verified by both verifiers and tampered copies refused, the installer dry run with the 0.3.9 package downloaded and verified. Untested until a rig exists: listed in README.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 20:37:51 +00:00

20 lines
1.7 KiB
Bash
Executable file

#!/usr/bin/env bash
# igneum-node.service: the bundled igneumd with the flags the apps use (app/igneum-app/src/engine.rs node args) and
# the HiveOS package's override rule (packaging/hive/h-run.sh): --override-params-file carries the signed manifest's
# consensus.override, else a peer refuses the node ("consensus params digest mismatch", 5 October 2026).
# /etc/igneum/override-params.json is written by install-rig.sh and refreshed hourly by igneum-update.sh from the
# verified manifest; the package's own override-params.json is the offline fallback.
set -euo pipefail
# shellcheck source-path=SCRIPTDIR
# shellcheck source=igneum-rig-lib.sh
. /opt/igneum/bin/igneum-rig-lib.sh
load_conf
mkdir -p "$IGNEUM_VAR/node"
override=()
if [[ -s "$IGNEUM_ETC/override-params.json" ]]; then override+=("--override-params-file=$IGNEUM_ETC/override-params.json")
elif [[ -s "$IGNEUM_ROOT/current/override-params.json" ]]; then override+=("--override-params-file=$IGNEUM_ROOT/current/override-params.json"); log "using the package's override-params.json (no verified copy in $IGNEUM_ETC yet)"
else log "no consensus override file; the node runs the binary's defaults (fine for a fresh testnet, refused by the devnet)"; fi
mapfile -t peers < <(node_peer_args)
log "igneumd $NODE_FLAG, data $IGNEUM_VAR/node, RPC 127.0.0.1:$RPC_PORT, EVM RPC 127.0.0.1:$EVM_PORT, P2P 0.0.0.0:$P2P_PORT, peers ${peers[*]#--addpeer=}${override[0]:+, override $(tr -d ' \n' < "${override[0]#--override-params-file=}")}"
exec "$BIN/igneumd" "$NODE_FLAG" "--appdir=$IGNEUM_VAR/node" "--rpclisten=127.0.0.1:$RPC_PORT" "--evm-rpclisten=127.0.0.1:$EVM_PORT" \
"--listen=0.0.0.0:$P2P_PORT" "${peers[@]}" "${override[@]}" --nodnsseed --disable-upnp --nologfiles --yes