Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
50 lines
2.6 KiB
Batchfile
50 lines
2.6 KiB
Batchfile
@echo off
|
|
rem Igneum miner log uploader. Sends the last 256 KB of a log file to the Igneum log intake
|
|
rem so Claude on the Mac can read it (node tools/logs.mjs). Needs Windows 10 or 11 (curl.exe, PowerShell).
|
|
rem Usage: upload-log.bat <logfile> <label> [run_id]
|
|
rem run_id falls back to the IGNEUM_RUN_ID environment variable, then to <label>-<date>-<time>.
|
|
rem The key only authorises log uploads. It is not in the repository (rotation phase 2, 5 October 2026): it comes from
|
|
rem the IGNEUM_LOG_KEY environment variable, else from igneum-log-key.txt next to this script (one line; the packager
|
|
rem writes it from the file IGNEUM_INTAKE_KEY_FILE names), else the upload is refused with exit 3.
|
|
setlocal
|
|
set "IGNEUM_LOG_URL=https://igneum-six.vercel.app/api/log"
|
|
if "%IGNEUM_LOG_KEY%"=="" if exist "%~dp0igneum-log-key.txt" set /p IGNEUM_LOG_KEY=<"%~dp0igneum-log-key.txt"
|
|
if "%IGNEUM_LOG_KEY%"=="" (
|
|
echo upload-log: no intake key: set IGNEUM_LOG_KEY or put igneum-log-key.txt next to this script
|
|
exit /b 3
|
|
)
|
|
|
|
if "%~1"=="" goto usage
|
|
if "%~2"=="" goto usage
|
|
if not exist "%~1" (
|
|
echo upload-log: file not found: %~1
|
|
exit /b 2
|
|
)
|
|
set "LOGFILE=%~f1"
|
|
set "LABEL=%~2"
|
|
set "RUNID=%~3"
|
|
if "%RUNID%"=="" set "RUNID=%IGNEUM_RUN_ID%"
|
|
set "OUT=%TEMP%\igneum-upload-%RANDOM%.json"
|
|
|
|
powershell -NoProfile -ExecutionPolicy Bypass -Command "$ErrorActionPreference='Stop'; $fs=New-Object IO.FileStream($env:LOGFILE,[IO.FileMode]::Open,[IO.FileAccess]::Read,[IO.FileShare]::ReadWrite); $b=New-Object byte[] $fs.Length; [void]$fs.Read($b,0,$b.Length); $fs.Close(); $n=[Math]::Min($b.Length,262144); $t=[Text.Encoding]::UTF8.GetString($b,$b.Length-$n,$n); $r=$env:RUNID; if (-not $r) { $r=$env:LABEL + '-' + (Get-Date -Format 'yyyyMMdd-HHmm') }; $o=@{label=$env:LABEL;machine=$env:COMPUTERNAME;run_id=$r;lines=$t}; [IO.File]::WriteAllText($env:OUT,(ConvertTo-Json $o -Compress),(New-Object Text.UTF8Encoding $false)); Write-Host ('upload-log: run_id ' + $r + ', ' + $n + ' bytes')"
|
|
if errorlevel 1 (
|
|
echo upload-log: could not read or encode %LOGFILE%
|
|
exit /b 3
|
|
)
|
|
|
|
rem the key reaches curl through a config file (-K), never on its command line, where every local process can read it (X29)
|
|
set "CFG=%TEMP%\igneum-upload-%RANDOM%.cfg"
|
|
>"%CFG%" echo header = "x-igneum-key: %IGNEUM_LOG_KEY%"
|
|
curl.exe -sS --max-time 60 -K "%CFG%" -X POST "%IGNEUM_LOG_URL%" -H "Content-Type: application/json" --data-binary "@%OUT%"
|
|
set "RC=%ERRORLEVEL%"
|
|
echo.
|
|
del "%OUT%" "%CFG%" >nul 2>&1
|
|
if not "%RC%"=="0" (
|
|
echo upload-log: curl failed with code %RC%
|
|
exit /b %RC%
|
|
)
|
|
exit /b 0
|
|
|
|
:usage
|
|
echo Usage: upload-log.bat ^<logfile^> ^<label^> [run_id]
|
|
exit /b 1
|