igneum/docs/plans/release-0.3.12.md
igneum-labs 7eed16a29a Pre-public scrub, the text pass (7 October 2026, 19:5x UK): no founder name, personal login, earlier business or personal address in any tracked text file, and a gate check that keeps it so
The sweep (main's item 1): 199 tracked text files, 783 lines. The founder's full name, first name and possessive become "the founder" (sentence starts capitalised); the lowercase operating-system user name in WSL paths and commands becomes <user>; the second owner login becomes "the second owner login"; the three earlier businesses and the two other brands become "the other business", "the earlier entity", "the earlier business" and "another brand"; the Chrome profile rule names the igneum.network profile, not the profile's label. The standing commit login igneum-labs is not a founder term here: the fresh-repository step renames it in the history (docs/plans/history-rewrite.md, tools/repo/fresh-repo.sh).

The patterns never appear in plain text in the tree (a plaintext list would be the hit): tools/ci/founder-strings.b64 (perl regex, tab, a sample per row) is read by tools/ci/founder-strings-check.sh (every tracked text file, perl, known-failed first: the self-test plants each row's sample in a fixture and the hit must name the file), by tools/community/discord-hooks.mjs (the guard's founder and business rows; the test takes its fixtures from the samples) and by tools/repo/fresh-repo.sh (the business names of the rewrite rules). site/forbidden-strings.txt carries the same patterns as b64: lines, decoded case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs (whose fixture now plants an encoded made-up name). The check runs in the gate's tree checks on every merge.

Not in this commit, by main's word: the 105 commit messages and 40 personal-identity commits that need the history rewrite (listed, not run), and the secrets found by gitleaks over the history (reported with owners).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:39:50 +00:00

32 KiB

Igneum Miner 0.3.12: the fresh-record rule switch (proving v1) and the app cut, prepared to the publish gate, 6 October 2026

Release engineer, from 08:05 UTC, on the coordinator's instruction ("prepare 0.3.12, APP ONLY, up to the publish gate and STOP there; the founder gives the go"), widened at 08:55Z on its clock: "no longer app only", the proving agent proved the segment record rule needs a consensus switch, so the node fork proving-v1 0f0dda95 (proving_v1_fresh_rule_daa: never by default, in the digest only once set; from it a fresh segment record is valid whenever the previous segment is not proven) and the app's segment-aligned prover (272b025, docs aea2f6a) ride in it. Worktree /Users/joshm/Projects/igneum-wt-ship0312, branch release-0.3.12 from master ddfcdac; vendor/ symlinked to the main checkout's (46 entries); the fork worktree vendor/igneum-node-0312, branch release-0.3.12-node = 0f0dda95 cherry-picked onto 89dfcb95 (its parent ece42979 is inside 89dfcb95, so the rebase is the one commit: params.rs, exec/proving.rs, exec/rpc.rs, daemon.rs) = 83089544. The 0.3.11 recipe (release-0.3.11.md) throughout; every Mac build under the main checkout's lock; igneum-labs commits. Times are UTC.

1. What 0.3.12 carries

Change Where State
/api/state never answers {} again: paid_wei (u128) is a decimal string, the error reply is logged; test proving-v1 app 6714a45 (the first item) merged 9bcf4cd (the docs/bench-log.md conflict: both sides kept, the log is append-only)
An update published over an hour before the engine started skips the hourly rollout slot; manifest::unix_from_rfc3339 + tests update-catchup 2207cd7 merged b984c17
The GPU list ordered by performance (usable, discrete before integrated, rate in 5 MH/s buckets, memory); 3 UI tests card-order ffb2bfa merged c6608c1
HiveOS local mode carries the override (OVERRIDE= in the Flight Sheet's extra config, written to data/override-params.json by h-run.sh, C41), rigs mine only until a Linux prover ships, IDENTITIES=auto by VRAM, the per-card README table hive-words 98271ff (packaging/hive only) merged b0a6231
Ember Tune: two-knob plans + priors + the UI line; every quit names its source (b671c8b); a second engine never runs the updater (e600e63, C35); no pipe into a second engine (8ab9068); jobrun.rs elevated follow_file (1e9550e); the BOM fix + CI check (8273494); Power control switch (49bbe14 = 3562f26); igneum-gpu-telemetry.exe (ADLX) built by build-windows.sh and carried in the Windows inputs ember-tune 9a6469f NOT MERGED: conflicts in seven files against the 0.3.10/0.3.11 app (its base ca8d9f3 predates both): ci.yml, config.rs, engine.rs (the detect path, the power-cap plan, the test module), ui/app.js (four hunks against miner-ui-2's View), ui/index.html (the settings panel 0.3.10 removed), proto-opencl/README.md, bench-log.md. Its agent is rebasing it onto release-0.3.12 (section 2)
The hidden-console builder for every elevated launch, windows-spawn-check.mjs, the PC 1 console-watch scripts job-console 13755b9 (+ 3562f26 Power control) NOT MERGED: conflicts in six files (ci.yml, config.rs, engine.rs, jobrun.rs, app.js, index.html), base a93199a; carried by the ember-tune rebase (it already holds 3562f26)
The miner's gRPC resubscribe after a node restart (C43, the 0.3.11 finding) no commit exists (the ledger entries b19fe5f, 0751dde, c8c831c only) OWED, listed in section 10
The fresh-record rule switch: proving_v1_fresh_rule_daa (Option, never by default; a node with the field set prints it and carries it in the digest; a fresh segment record is valid from it whenever the previous segment is not proven) fork proving-v1 0f0dda95 on ece42979 cherry-picked onto 89dfcb95 as 83089544 (release-0.3.12-node)
The segment-aligned prover: a segment record the chain rule refuses is held and offered again every pass until the segment closes; the fast-time harness on the fresh-record rule (both cases); the prover host and export; the WSL2 prover package script; infra/fast-time/override-60x.json (measured by its agent: 9 segments per 30 min on PC 2, 72 of 72 shards paid, 11% hash cost, 17.6 GB peak) proving-v1 app 272b025 + docs aea2f6a (on 6714a45) merged 49e0e2c (clean)
The packaged line (C34): the ten-field object of section 4 7dd3ff7 packaged-config.sh --test passes
The six version files 81e4ecb (--check: 0.3.12 in all 6)

Left out on the coordinator's word: prover-floor's server (its packaging row is 0.3.13), explorer d7e797c, pool-v0, rig-install, ota-k2, the ledger forks.

Changelog line (draft, for the manifest notes at the go): "Igneum Miner 0.3.12: the fresh-record rule for proving v1 from DAA 192,000 (a fresh segment record is valid whenever the previous segment is not proven) and the segment-aligned prover; the GPU list in performance order; an old update no longer waits for the hour; Ember Tune (every card tuned for MH per watt, Power control off by default, the app never asks for administrator rights on its own); a second engine never installs over the app; /api/state always answers; HiveOS rigs carry the override. Node 83089544."

2. The branch

Commit What
9bcf4cd, b984c17, c6608c1, b0a6231 the four merges above, in the coordinator's order (proving-v1 first)
81e4ecb Igneum Miner 0.3.12: the six version files
ebea8b6 the ember-tune rebase tip 7f6c4e6 (with job-console 13755b9 inside), merged as one branch (section 3)
11e8ca6, ab01f48, 01abcc2 the plan
062c3f8 node-source.pin 83089544 with the second inputs push (the Windows-build commit of 0.3.12)
37b6a7f tools/proving-v1/pc2-agg-cost.ps1: pkill -f sp1-gpu-server (the CI root-socket check)
88df58e master d3b64cb merged (docs only): the release tip, CI green
6532adf make-payload.sh: on CI the AMD telemetry helper is taken from the unpacked inputs (the worker glob igneum-worker-*.exe missed igneum-gpu-telemetry.exe, so the first payload, run 37435975425, shipped without it: the inputs had it, the zip did not). The CI commit of 0.3.12

Checks on 81e4ecb before the rebase landed: the app cargo test --release -p igneum-app under the lock: ok 115 (lib) + 28 (ota-sign) + 8 (prove-verify), 0 failed (08:19:22 to 08:19:28Z, warm target cloned from the 0.3.11 worktree); the UI tests notices, update-card, view: 23 of 23.

3. Builds and artefacts

What Command Result
The HiveOS package (first build, app-only cut) the 0.3.11 node and workers with hive-words' scripts 08:19:45Z: b0a20917... (24,501,272); superseded below once the node changed
The merged tree ember-tune 7f6c4e6 (release-0.3.12 b0a6231 merged INTO ember-tune as c5918c7, job-console 13755b9 cherry-picked on top; 0.3.11's six-section View and card order kept whole, Ember Tune's TuneLine block and the Power control switch added in 0.3.11's markup, engine.rs keeps the detect arm with the tune fields in hotplug::apply_pref, both test modules, jobrun.rs the hidden-console builder plus follow_file) merged as one branch ebea8b6, 08:22Z (the CI commit is 062c3f8); the version files still 0.3.12 in all 6; packaged line, node-source.pin and vendor/ untouched against master
The app cargo test --release -p igneum-app under the lock, then cargo build --release 08:22:56 to 08:23:06Z: ok 133 + 28 + 8, 0 failed; igneum-app 0.3.12 (2,273,664)
The UI and relay tests node --test notices, update-card, view, tune-line; relay/test/*.test.mjs 26 of 26; 23 of 23
The CI checks on the Mac identity, no-conflict-markers, copied-sources, signer-pipe, prover-socket, second-engine, bash-body (self-test + tree), kit-path (self-test + tree), windows-spawn (self-test + tree), pinned-guests, no-secrets, check-workflow-shell all ok; link-check passes after node site/build.mjs (as ci.yml runs it: the committed litepaper.html points at /bench#counter-asic-2-0-the-numbers, an id the site build creates from bench-log.md)
The Windows workers and the AMD telemetry helper proto-cuda/nvrtc/build-windows.sh (mingw) under the lock, 08:23Z the worker SOURCES are unchanged against master (git diff master HEAD -- proto-cuda proto-opencl proto-metal igneum-pow: only build-windows.sh, the new gpu-telemetry.c and its .rc), so the inputs carry the 0.3.11-verified workers that mined all night, igneum-worker-cuda.exe 2b3b8c92885442179f6bf2907c6f3eb453dc4a19908d90fd05981a09b7c2674c (1,536,512) and igneum-worker-opencl.exe edc4a75da3b93d814caa69fd635010780d63d5b622ec24c3741d433c584f91e3 (478,208), not this morning's rebuild of the same sources (12bfaa27..., e0fd7042...: mingw PE builds are not byte-reproducible); NEW igneum-gpu-telemetry.exe 8d679b52b19af3cbd6bf4fd6f77d337b2fb78af13d02627e7aa7e92507993459 (387,584; ADLX, SetupAPI, PDH; the Igneum resources, version 0.3.0 as the workers carry)
The Windows inputs IGNEUM_WIN_RELEASE=<fork>/target-integration/x86_64-pc-windows-gnu/release IGNEUM_NODE_SRC=vendor/igneum-node-0312 packaging/windows/push-inputs.sh, 08:24:29Z (a deploy of the downloads folder only; the manifest untouched) node 89dfcb95 (igneumd.exe be8e83c0..., igneum-miner.exe 1ba1a249..., PC 2's 0.3.11 build), the two workers above, the telemetry helper, the mingw DLLs and nvrtc; signed, verified, live (HTTP 200); node-source.pin unchanged 89dfcb95
The DMG (first build, app-only cut) the 0.3.11 node 08:24:33Z: ff630e9d... (41,630,620); superseded below once the node changed
The fork's Mac node, 83089544 CARGO_TARGET_DIR=vendor/igneum-node/target-0312 cargo build --release -j 4 -p kaspad -p igneum-miner --features kaspad/igneum-pow from vendor/igneum-node-0312, under the lock; the target dir cloned by APFS from target-0311; target-integration in the fork worktree links to it 08:38:13 to 08:41:31Z: igneumd 746a931fde9b840ca444a03cd757854e2e2ce7ebc4782ddd00ed161644d705f9 (41,386,160), igneum-miner 5381683e5717d91416c5a97456e0d050dd9645b1e27bce7d55808ce621cc1a26 (8,763,936); igneumd/2.1.0-83089544
The seed's Linux node (glibc 2.36 target, zig) NODE_SRC=<abs fork> TARGET_DIR=vendor/igneum-node/target-0312-linux OUT_DIR=<scratch>/cross infra/cross/build-linux.sh under the lock 08:38:21 to 08:41:18Z (175 s): igneumd 4f142d5148f218f1286e24e7c4a167aa2f54262336f96e7cf281f520c714fc6f (47,919,144), igneum-miner 38397ae66c265b63db8e5458b46e7feb942121a7dc5625919df0a8d35e7a1ba1 (9,861,072); version.txt names 83089544
The prover host and export (the pinned guests unchanged) cargo build --release -j 4 -p igneum-prove-export -p igneum-prove-host in proving/igneum-prove under the lock (the target cloned from the 0.3.11 worktree) 08:39:07Z: igneum-prove-host b90d58d0529ce29f0e7ca8ae780a6442f92edcf1c71752fc60fbc72bc5c11fd8 (58,626,560), igneum-prove-export b60056127d32bda363c0e305e73e9f699a5774c0988aee5bfd28a0fc61a56b9a (2,808,160); --mode id: shard program id 0x2b1a81cb413236cf063077b46ed3111628f6c41036bcf6e23ee4cbbf5679ef7a, the pin of 0.3.9 to 0.3.11; pinned-guests-check ok, proving/igneum-prove/elf/ untouched
The HiveOS package NODE_OUT=<scratch>/cross WORKERS_OUT=<the 0.3.11 Linux workers> VERSION=0.3.12 OUT=<scratch>/hive packaging/hive/make-hive-package.sh (the Linux workers 4aaff27f.../82d90890... unchanged: their sources are) 08:41:54Z: igneum-hive-0.3.12.tar.gz 7972af92e7cd9a032303eca4d95b533f53e0e68d1b9cae5bfe406a5b7c30a454 (24,506,282); h-run.sh writes data/override-params.json from OVERRIDE and starts the node with --override-params-file (the 0.3.11 open item closed); the node inside is 83089544
The DMG NODE=<fork igneumd> MINER=<fork igneum-miner> PROVE_HOST/PROVE_EXPORT=<this tree's build> packaging/mac/build-dmg.sh under the lock 08:42:49Z: Igneum-Miner-0.3.12.dmg 7a4a5f5f772956e983127280a5ec62a4fcfaf903b3afa38fe3a89a37cee23520 (41,702,535), engine 0.3.12, node 83089544 (igneumd 41,163,744 inside, stripped by the DMG build), the new prover host and export, igneum-bench from proto-metal/main.swift (unchanged, 66ec0e78...), packaged-config carries the ten-field object, hdiutil checksum valid
The node suites with the igneum-pow feature (the coordinator's ask; the PC runner's test units carry no features field, so this is the Mac's run; the PC 2 run is owed to the Counter ASIC 3.0 coordinator's window, section 3a) CARGO_TARGET_DIR=vendor/igneum-node/target-0312 cargo test --release -j 4 -p kaspa-consensus -p kaspa-consensus-core -p igneum-exec -p kaspa-pow -p igneum-miner -p kaspa-p2p-flows --features kaspa-consensus/igneum-pow,kaspa-pow/igneum-pow from the fork, under the lock, 08:39:31 to 08:45:01Z igneum-exec 17 of 17, igneum-miner 18 of 18, kaspa-consensus 97 passed, 2 failed, 4 ignored. The two: (1) pruning_proof::igneum_m20_tests::witnesses_are_checked_in_epoch_order_under_their_own_seeds (igneum_m20_tests.rs:122: the expected EpochSeeds.era is all zeros, the code draws 515e...: the test predates the era draw of class v3) FAILS THE SAME on 89dfcb95 (run 08:45:48Z on the 0.3.11 fork): the known M20 era fail, NOT fixed by 0f0dda95, still owed; (2) finality::tests::ban_is_decided_by_the_carrying_block_so_nodes_agree_on_every_voter_list (finality.rs:1883) failed inside the full crate run and PASSES alone on both 83089544 and 89dfcb95: order-dependent, not a regression of this cut, owed as flaky. kaspa-consensus-core 107 passed, 1 failed (config::params::tests::fast_time_60x_file_is_the_devnet_at_60x: infra/fast-time/override-60x.json does not parse into OverrideParams, "duplicate field proving_v1_activation_daa" at line 64: the file has carried a second proving-v1 block since c2544be on 5 October, so the test fails on master's file and on 89dfcb95 alike; not a 0.3.12 regression, the file is owed a dedupe), db_compat 7 of 7, kaspa-pow 14 of 14, kaspa-p2p-flows 33 of 33 (08:47:13Z, no fail-fast). Net: 3 failures, each present on 89dfcb95, none from 0f0dda95
PC 2 build-and-suite job IGNEUM_WIN_RELEASE=<scratch>/pc2-out node tools/build-job.mjs run --node vendor/igneum-node-0312 --target 1ccfe586 --targets linux,windows --node-tests "kaspa-consensus kaspa-consensus-core igneum-exec kaspa-pow igneum-miner kaspa-p2p-flows" --app-tests igneum-app from this worktree, published 08:54:56Z on the prover-floor agent's "PC 2 is yours" (its floor-core-alone and floor-core-miner closed 08:48:37Z and 08:53:13Z, after the Counter ASIC 3.0 coordinator's release at 08:43:24Z); CPU only, the prover on, nothing else touched. The coordinator's later order (after the prover-floor agent's SECOND pair) arrived once the job had run; the app's queue serialised them anyway: this job ended 09:02:04Z and floor-build-6 started 09:02:05Z, then floor-core2-miner closed 09:13:22Z with the prover on and the miners never stopped, so nothing ran beside a GPU row build-20261006-085456: started 08:55:24Z, done 09:02:04Z (400 s), every stage ok: Linux node 135 s (igneumd 34877b86..., igneum-miner c779777f...), Windows node 165 s (igneumd.exe 5bbcbd59f592fa31bf31c18516cef81cc0e7e537d398382fc8063e3402d80917, igneum-miner.exe af973318...; PC-built, NOT shipped: the inputs carry the Mac cross-build f580b4aa..., placed under the scratchpad), the app both targets; RESULT test node [the six crates] exit 0 44 s (without the igneum-pow feature, the runner's shape: the M20 era test and the fast-time file test are outside its reach there) and RESULT test app/igneum-app exit 0 6 s
The Windows node exes CARGO_TARGET_DIR=vendor/igneum-node/target-0312-win proto-cuda/windows-node/cross-build.sh <fork> 4 on the Mac (mingw, the 0.3.5/0.3.6/0.3.9 path; PC 2 is the Counter ASIC 3.0 coordinator's this morning), the target cloned from target-release-win, under the lock 08:40:43 to 08:48:05Z (6 min 42 s): igneumd.exe f580b4aad1e19a47742d0d836a56dad36b9380d3890ca115b1babced4d83a8db (52,177,920), igneum-miner.exe 06c17d4c23c8b1327793bebcd9b2cba115045ea91b68baea8cb92b232a94678b (11,040,768); static (KERNEL32, advapi32, api-ms-win-core only)
The Windows inputs, second push IGNEUM_WIN_RELEASE=<target-0312-win>/x86_64-pc-windows-gnu/release IGNEUM_NODE_SRC=vendor/igneum-node-0312 packaging/windows/push-inputs.sh, 08:48:28Z node 83089544 (the two exes above), the 0.3.11-verified workers 2b3b8c92.../edc4a75d..., the telemetry helper 8d679b52..., the mingw DLLs and nvrtc; payload-inputs.zip f8e567bd164b382d32a33fb488df658fa68555092ac6bdac85387d0a8bd5d547 (65,259,161), signed and verified, live (HTTP 200); node-source.pin 83089544 committed as 062c3f8, the CI commit of 0.3.12

| The Windows installer and zip, first runs | runs 37435975425 (ebea8b6, no telemetry helper) and 37436904041 (6532adf, the 0.3.11 node) | superseded | | The Windows installer and zip | windows.yml run 37438673235 on 062c3f8 (dispatched 08:49:12Z after the second inputs push) | Igneum-Miner-Setup-0.3.12.exe f11a296acf1ea3efa8a6151efa357cc5c222e3b2ffec5701ea4bcefe29307810 (45,270,093); igneum-windows-app.zip a6f33ef21bb1d1682f48ca22332d50c0302f4b4f552a99157581f3249c42ea3b (65,507,597): igneumd.exe f580b4aa... (the cross-build, 52,177,920), igneum-miner.exe, igneum-app.exe 0.3.12 (3,700,736), the two workers, igneum-gpu-telemetry.exe (387,584) this time, the mingw DLLs, nvrtc64_120_0.dll and nvrtc-builtins64_128.dll |

4. The override objects and the digests (the 0.3.12 Mac node 746a931f..., ports 60975/60976, 22 s each, under run)

Override file Lines Digest
none igneumd/2.1.0-83089544, no activation line c562d70e1428c9789823cc40067623b4767f7c555ce7ff4ea11c1498f013ef6c, EQUAL to 0.3.11's no-file digest: the new field is never by default and leaves the digest alone until set
the fleet's live nine-field object the six activation lines of 0.3.11, no fresh-rule line 0139ab9dc2992d449ec787d8f021974933631eb55740ab4b6ce9d5c226e72888, EQUAL to the fleet's digest today: publish 1 (the binary) changes no handshake, a 0.3.12 node and a 0.3.11 node on the nine-field file accept each other
the ten-field object at the FIRST pin (proving_v1_fresh_rule_daa 192000, void: the floor failed at the go) the six lines plus the fresh-rule line at 192000 bd786a4b521e87c05bce3da4c46b4f4696deb16dfbdc913f181c980a8eb51688 (never published)
the ten-field object as SHIPPED (proving_v1_fresh_rule_daa 198000) the six lines plus Proving v1 fresh-record rule from the override file: from DAA score 198000 a fresh segment record is valid whenever the previous segment is not proven 7bd98cc4118616455709d5e32a30b799e6e67caa42d2b5d09875cd49848a7ed7 (read 11:22:01Z on 746a931f...)

The ten-field object (the packaged line 7dd3ff7, the manifest of publish 2, the hand nodes' and the seed's files at step 2):

{"difficulty_v2_activation_daa":33000,"proving_v0_activation_daa":84100,"fees_v1_activation_daa":210000,"finality_v3_activation_daa":135200,"program_class_v3_activation_daa":154800,"proving_v1_activation_daa":154800,"proving_v1_segment_blocks":8,"proving_v1_unproven_daa":600,"proving_v1_aggregator_share_bps":1000,"proving_v1_fresh_rule_daa":198000}

N was first pinned at 192,000 (tip + 14,400 for a publish near 10:15Z; the floor would hold while the tip was at or under 181,200, about 11:15Z). The founder's go came at 11:20Z with the tip at 181,582: the floor read 10,418, under 10,800, so N was RE-PINNED to 198,000 (tip + 14,400 for publish 2 near 11:55Z; the floor holds until tip 187,200, about 12:55Z): the packaged line 8a6b133, the DMG rebuilt 11:22:08Z (7bcbb8a94038ea7a87ebfab514b6771f93b8fce2d991340bd5610713dc9548e5, 41,702,608), the installer rebuilt on CI (windows-ci 37455874734 on 8a6b133, green 11:27:33Z: Igneum-Miner-Setup-0.3.12.exe a6b3ea275373411e9f988ecd4ecc79f2cda5f68d54d681662dcbf7590689aef0, 45,275,988; igneum-windows-app.zip 7ab28e772670dc58428cda4c9ff584b35f70507057d525a85d04391ee145dc53, 65,507,595), the digest re-read, publish 1 delayed by 8 minutes. The lesson for the next cut: pin N at the go, not at the forecast, or pin with a 3,600 margin over tip + 14,400 when the go is more than an hour out. A 0.3.11 node given the ten-field file dies on the unknown field (deny_unknown_fields), which is why publish 2 comes only after every node runs the 0.3.12 binary (the reviewer's C39, the 0.3.11 order).

5. The publish gate: what runs at the founder's go, in which order (the 0.3.11 two-publish shape)

This was the plan at the gate; sections 6 and 7 record what ran. Runbook: the session scratchpad's r0312/rollout-0312.sh (every step a function; step_floor before each publish).

Step What Gate
0 the floor step_floor: 192,000 minus the tip's DAA at least 10,800 read before publish 1 and again before publish 2
1a the hand nodes, the seed the observer and node 1 on the 0.3.12 binary with the NINE-field file (IGNEUMD=<fork>/target-integration/release/igneumd IGNEUMD_COMMIT=83089544 infra/devnet/restart-hand-nodes.sh '<nine>'), then the seed (IGNEUMD_LINUX=<scratch>/cross/igneumd IGNEUMD_LINUX_SHA256=4f142d51... infra/devnet/restart-seed.sh '<nine>'); every one prints 0139ab9d..., nobody is refused; then step_mac_miners (the Mac's miner does not reconnect to a restarted node 1 by itself, C43) the founder's go
1b publish 1 node tools/ship-app.mjs 0.3.12 --node vendor/igneum-node-0312 --branch release-0.3.12 --public --activation-height 154800 --deadline-note "program class v3 + proving v1" --notes '<section 1>' --from ci: ci "already" (the green Windows run), fetch, dmg "already", copy, manifest with consensus CARRIED OVER (the nine-field object; the digest stays 0139ab9d...), deploy, verify (--from console after the public index settles at the edge), the console item; --public carries the HiveOS package 7972af92... after 1a
1c update-now the Mac (d937c69d) first; the laptop (37ba0461) with it if it is on the air; PC 2 (1ccfe586) on the Counter ASIC 3.0 coordinator's word (PC 2 is its this morning; the proving agent's constraints: the app's prover stays on, no quit or restart of anything but the update's own); PC 1 (ae432dc7) last, once the founder has relaunched its app (down since 22:31:06Z yesterday, on 0.3.10: it takes the nine-field object and 0.3.12 at its relaunch through the manifest; Power control is off by default so nothing asks for administrator rights) each machine's STATUS line back on 0.3.12 with 0139ab9d...
2a the floor again step_floor >= 10,800 or re-pin
2b the hand nodes, the seed the same two scripts with the TEN-field file; each prints bd786a4b... and refuses the nine-field side until it switches; step_mac_miners again every app node on the 0.3.12 binary (1c)
2b publish 2 publish-manifest.sh --version 0.3.12 --override '<ten>' --activation-height 192000 --deadline-note "proving v1 fresh-record rule" --notes '<section 1>' --public --deploy after the hand nodes
2b update-now (switch) the Mac and the laptop, then PC 2 on the 3.0 coordinator's word, then PC 1: each app writes the ten-field file at the manifest take and restarts its node at a safe moment (the Mac's node is node 1, already switched: nothing to restart)
the sweep every node prints bd786a4b521e87c05bce3da4c46b4f4696deb16dfbdc913f181c980a8eb51688; the fresh-record rule arms at DAA 192,000

One line for the founder, per machine, when he says go: the Mac and PC 2 each restart their engine once for 0.3.12 (under a minute, the miner back on the next template) and their node once more for the fresh-record switch (a few seconds, mining resumes on the same chain); PC 1 does the same at its relaunch and, with Power control off by default, never asks for administrator rights again (its 5090 runs uncapped until he switches Power control on in Settings); the observer, node 1 and the seed are restarted by hand twice; from DAA 198,000 (about 15:55Z) a prover may file a fresh segment record whenever the previous segment is not proven, so paid segments stop stalling behind an unproven one; until the switch nothing changes in consensus (digest 0139ab9d... through publish 1).

6. The rollout (the founder's go 11:20Z through the coordinator; two publishes)

Baseline 11:20:22Z: tip 181,582; the observer, node 1 and the seed on 89dfcb95 at 0139ab9d; the Mac app 0.3.11 (its miner PAUSED since 07:10Z on the founder's order "stop mining on the Mac", not the C42 class: I resumed it once at 11:26:11Z before the order reached me and the coordinator re-paused it; it stays paused, no restart-miners after the hand restarts); PC 2 0.3.11 at 113 MH/s; PC 1 0.3.11, relaunched by The founder at 11:17Z with the 5090 and a 4070 in the enclosure; the laptop and Sam's Mac off the air.

Step Time Result
0 the floor 11:20:22Z 10,418 < 10,800: FAILED at 192,000; re-pinned to 198,000 (section 4), publish 1 delayed to the installer rebuild
1a the observer, node 1 11:22:12Z (pid 92464), 11:22:24Z (pid 92624) igneumd/2.1.0-83089544 on the nine-field file, digest 0139ab9d... (unchanged, nobody refused)
1a the seed 11:22:45Z (MainPID 136418) the same binary 4f142d51..., the same digest
1a restart-miners, the Mac 11:22:56Z ran; nothing to restart, the miner is paused on the founder's order (above)
1b publish 1 the ship 11:28:30 to 11:31:55Z from cf1ad2b (master f11b02e merged first: the preflight refuses a tree behind origin/master) ci "already" (37455874734), fetch "already" (the re-pinned installer), dmg "already", copy ok, manifest 0.3.12 with consensus CARRIED OVER (the nine-field object, activation 154800), deploy ok, verify refused the public index at the edge (every cut); --from console 11:44:41Z: item #368
1c update-now, the Mac 11:32:18Z engine restart 11:32:56Z (run mac-d937c69d-20261006-113256), "updated to Igneum Miner 0.3.12 from 0.3.11", STATUS "0.00 MH/s, paused, node 5 peers, synced" (node 1)
1c update-now, PC 2 11:32:46Z (the 3.0 coordinator's mkdir lock /tmp/igneum-devnet/pc2-ca3.lock absent; pc2-ca3.clear is a note, not a lock) engine restart 11:33:41Z (run win-1ccfe586-20261006-113341), igneumd 83089544 started 11:33:45Z on the nine-field file (0139ab9d), worker ready 11:34:39Z, mining 11:34:42Z, 0 faults
1c update-now, PC 1 11:33:28Z (on the prover-floor agent's "PC 1 build closed" 11:31:34Z and the coordinator's "PC 1 back") the installer downloaded and verified 11:34:06Z, "per-user install, no administrator prompt", engine restart 11:34:12Z (run win-ae432dc7-20261006-113412), cards "RTX 5090, RTX 4070 [discrete], AMD integrated [off]", STATUS mining 11:35:13Z, the 5090's race base 140.2 MH/s, digest 0139ab9d
2a the floor 11:36:53Z tip 182,570; 15,430 >= 10,800 at 198,000
2b the observer, node 1 11:36:55Z (pid 13642), 11:37:07Z (pid 13777) the ten-field file, digest 7bd98cc4118616455709d5e32a30b799e6e67caa42d2b5d09875cd49848a7ed7
2b the seed 11:37:25Z (MainPID 136590) 7bd98cc4...
2b publish 2 11:37:36Z publish-manifest.sh --version 0.3.12 --override '<ten>' --activation-height 198000 --deadline-note "proving v1 fresh-record rule" --public --deploy; the HiveOS package 7972af92... served at /public/igneum-miner-hive.tar.gz and dl/public/igneum-hive-0.3.12.tar.gz (HTTP 200, 24,506,282), the 0.3.11 package removed
2b switch, the Mac 11:40:30Z ran 11:40:58Z: "consensus override changed; the node restarts with it at a safe moment"; its node is node 1 (external), already on 7bd98cc4, nothing to restart
2b switch, PC 2 11:40:56Z ran 11:41:23Z, "restarting the node with the new consensus parameters", igneumd started 11:41:25Z (pid 18732) on 7bd98cc4..., mining again 11:43:42Z, 113.0 MH/s at 11:44:42Z
2b switch, PC 1 (last) 11:42:54Z ran 11:43:28Z, node restarted 11:43:29Z (pid 5556) on 7bd98cc4..., "waiting" 11:43:44 to 11:44:14Z, mining 11:44:44Z, 100.95 MH/s ramping at 11:45:14Z: its miners read 0 MH/s for about a minute after the node restart before coming back (the C43 class: the miner waits out the restarted node instead of resubscribing at once; the coordinator's note); the Ember Tune run 3 on PC 1 (ember-tune-pc1-3, 11:44:58Z) then took the box, after this restart, not under it
the laptop, Sam's Mac off the air they take 0.3.12 and the ten-field object through the manifest when they return; no 0.3.11 app was on the air to take the ten-field file before its binary (C39)

7. The digest sweep (closed 11:45:20Z)

Node Binary Digest Since
the observer igneumd/2.1.0-83089544 (746a931f...) 7bd98cc4... 11:36:55Z
node 1 the same 7bd98cc4... 11:37:07Z
the seed 83089544 (4f142d51..., glibc 2.36 target) 7bd98cc4... 11:37:25Z
PC 2 the installer's igneumd.exe f580b4aa... (the Mac cross-build) 7bd98cc4... 11:41:25Z
PC 1 the same 7bd98cc4... 11:43:29Z
the Mac attached to node 1 node 1's 11:37:07Z
the laptop, Sam's Mac 0.3.10 / 0.3.9 pending off the air

Tip 183,154 at 11:45:20Z, no refusals on the hand nodes after the switch; the fresh-record rule arms at DAA 198,000 (about 15:55Z at 0.98 DAA/s). The fleet during the window: PC 2 and PC 1 mined on 0139ab9d while the hand nodes and the seed were on 7bd98cc4 (11:37 to 11:41Z); each rejoined at its switch; the Mac's miner paused throughout on the founder's order.

8. CI

Run On Result
ci 37435705568 ebea8b6 (the branch push, 08:22:40Z) green (pow tests and census build, simulators, site build + link check + identity, the PowerShell 5.1 parse job)
windows-ci 37435975425 ebea8b6 green 08:30:58Z (the parse job 08:25:16 to 08:25:56Z; engine, window host, payload, installer, smoke run 08:26:00 to 08:30:58Z); superseded by the run below (no telemetry helper in its payload)
ci 37436904569 6532adf (the branch push, 08:33Z) (pending)
windows-ci 37436904041 6532adf green 08:39:20Z; superseded by the run below (the node changed)
ci 37436904569 6532adf green
windows-ci 37438673235 062c3f8 (gh workflow run windows.yml --ref release-0.3.12, 08:49:12Z, after the second inputs push) green 08:54:27Z (the parse job 08:49:18 to 08:49:59Z; engine, window host, payload, installer, smoke run 08:50:02 to 08:54:27Z against the 83089544 inputs); fetched 09:03:17Z with OTA_SKIP=1 CONSOLE_SKIP=1 packaging/windows/fetch-ci-artifacts.sh 37438673235 into the downloads folder, NOT deployed
ci 37438674529 062c3f8 FAILED in one step, prover-socket-check.sh: tools/proving-v1/pc2-agg-cost.ps1 (in through the proving-v1 merge) ends its root prover with pkill -x sp1-gpu-server, and the check wants pkill -f; the line now reads pkill -f ... ; rm -f /tmp/sp1-cuda-*.sock (one playbook line, nothing the app or the packaging reads; git diff 062c3f8 <fix> -- app packaging proto-cuda proto-opencl proto-metal vendor is empty, so the Windows artefacts of 37438673235 stand, as 0.3.11's did across 3b0262f and 2a62735); the rerun is the row below
ci 37440456687 37b6a7f (the one-line playbook fix) green 09:07Z
ci 37440559793 88df58e (master d3b64cb merged in: the morning summary, docs only; the release tip) green 09:08:08Z. The 0.3.12 CI verdict is therefore run 37440559793 on 88df58e; the Windows build is run 37438673235 on 062c3f8, the same app, packaging and node sources (git diff 062c3f8 88df58e -- app packaging proto-cuda proto-opencl proto-metal vendor igneum-pow is empty)

The ship state file ~/.cache/igneum/ship/0.3.12.json carries sha = 062c3f8 (the Windows-build commit, which the ci step looks up by commit; the tree is 88df58e, docs and one playbook line later, as 0.3.11's was two docs commits past its build commit), forkCommit 89dfcb95, bumpedAt before the DMG's mtime (so the dmg step reads "already"), and runId once the Windows run is green.

9. Owed to the next cut (0.3.13)

Item What
C43, the miner's dead gRPC channel no commit exists; igneum-miner mine grpc:// must re-subscribe after its node restarts (the 0.3.11 finding: 11 min of 26 MH/s burned on the Mac); until then every hand restart of node 1 is followed by restart --what miners
prover-floor's server its packaging row is 0.3.13 (the coordinator's word)
explorer d7e797c, pool-v0, rig-install, ota-k2, the ledger forks left out on the coordinator's word
the Windows workers' reproducibility mingw PE builds differ byte-for-byte between builds of the same sources (12bfaa27 vs 2b3b8c92 today); a -Wl,--no-insert-timestamp (or SOURCE_DATE_EPOCH) in build-windows.sh would make G5's one-commit rule checkable by hash
the site build's non-idempotence and the pre-push flip unchanged from 0.3.10 and 0.3.11