diff --git a/docs/fud-fixes.md b/docs/fud-fixes.md index d969ca607..114a7a0d7 100644 --- a/docs/fud-fixes.md +++ b/docs/fud-fixes.md @@ -385,3 +385,4 @@ Nothing below is optional. The history, not just the working tree, carries the n 9. Put the GitHub links back on HP and the /bench page (row 1) on the day the repository opens, at the public testnet. What is already clean: `docs/bench-log.md` and the /bench page name machines, not people (commit 1769eda); the live site returns 404 for everything under `docs/` and 307 for `/ledger`; `site/.env.local`, `site/.vercel/` and `vendor/` are ignored; no tracked file carries a home-directory path; no connection string or token appears anywhere in the history. +| 128 | P23 | The EVM pool has `on_chain_block` and no reorg hook, so a transaction unwound by a selected-chain reorg leaves the node until its sender resends (found by the P17 conformance run, 6 October 2026) | A reorg hook: unwound transactions handed back to the pool as pending with the usual checks; unit test; the conformance driver's `reorged out` case ends in `executed` without a resend (2 h) | execution engineer (round 3 `ledger-rebase` carries it) | before a public RPC | no | diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index cd59feeea..7a2f6bea4 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -2131,6 +2131,15 @@ Evidence: the commits above. Experiment: `curl https://igneum.network/api/live` - **Open, needs hardware, a person or the devnet:** M1, M11 (a rig), M16 (the 5090), M22, X19 (the node line; `faketime`), X23 to X28 (the relay owner and PC 1; the token is rotated, the run-task binding is not), E13, E14, E16, E17 (the draw lines), F16, F20 (the devnet test), C4 (module off), P3, P14, P16, P17, P21, P22, X13, X15, X17, G10, L1 to L5, L8, D5, D6. - **Nothing became worse.** Two things are closer than they look: M20 becomes a live failure for every fresh node once the devnet's pruning point leaves genesis, which at the devnet's 1.05 DAA/s (DAA 33,000 at 17:37 UTC on 4 October) is between DAA 108,000 (`PRUNING_DURATION`, about 14:00 UTC on 5 October) and DAA 151,200 (the first finality point a full pruning depth below the tip, about 01:00 UTC on 6 October), approximate; X23's operational half (a run task on the PCs needs only the relay token) is unchanged after the rotation. +### P23. An unwound transaction leaves the node's view until its sender resends it +"Your pool learns about chain blocks (`on_chain_block`) and about nothing else. A selected-chain reorg unwinds a transaction out of the executed set and the pool never gets it back. The RPC can say `reorged out` all it likes; the transaction is gone unless the wallet resends, and most wallets do not." + +Status: Open, found in round 2 (6 October 2026, night, the P17 conformance run on `ledger-fixes-2`); fix named, owner the execution engineer; round 3 (`ledger-rebase`) carries it with the fork rebase. Found by: the ledger-pc2 agent's O-7.2 conformance driver (`tools/p17-conformance/run.mjs`, the "reorged out" path), recorded as finding (1) in the P17 round-2 paragraph. + +Answer: Correct. `igneum/exec/src/pool.rs` has `on_chain_block` and no reorg hook, so a transaction unwound by a selected-chain reorg is neither re-queued nor re-executed; the new `state` word reports `reorged out` with `reorgedFrom`, which tells a wallet to resend and tells nobody else. Fix: on every `virtualChainChanged` removal the executor hands the unwound transactions back to the pool as pending (nonce order kept, the same validity checks as a fresh submission, the 10,000-hash memory of P17 cleared on re-inclusion); a unit test that unwinds a block and sees its transactions re-queued; the conformance driver's `reorged out` case then ends in `executed` again without a resend. + +Evidence: `igneum/exec/src/pool.rs` (`on_chain_block`), `docs/bench-log.md` "ledger close round 2: P17 conformance", the P17 paragraph above. Fix row: `docs/fud-fixes.md` section 2.7. + ## Count by status, 5 October 2026 (night, round 1 of the ledger close merged into `fud-close`) The earlier count table above is kept as history (it counts the 80 entries of version 0.1). This count reads the first Status line of every entry and buckets it by its leading words; a status that carries two halves is counted by its first words. @@ -2149,3 +2158,20 @@ The earlier count table above is kept as history (it counts the 80 entries of ve Total 166. +## Count by status, 6 October 2026 (00:10 UTC, rounds 1 and 2 of the ledger close merged into `fud-close`) + +Same rule as the count above. 167 entries (P23 added by round 2). + +| Bucket | Count | Entries | +|---|---|---| +| Fixed, rolled out, rule written, or designed | 56 | the 54 of the count above plus P17 (four-state RPC on `ledger-fixes-2`) and X17 (spec 8.8, phone-app 4.1) | +| Conceded, stated, or terminal | 52 | unchanged; D6 now carries its review (`docs/review/d6-forged-job-result-2026-10-05.md`) and D5 its owner and gate | +| Answered by design or with evidence | 26 | the 27 above less P17, with X14 now answered for all four concentrations | +| Decided or closed by rule | 12 | unchanged; F3 and F17 carry the spec 3.4.2 proposals for gate 3 | +| Open, decision owner the project lead (`docs/plans/ledger-decisions.md`, items 1 to 13) | 11 | M1 M22 F16 E14 X13 L1 L2 L4 L5 P21 X5 | +| Open, blocked on hardware, a customer or a later phase, blocker and next date in the Status line | 5 | P3 (phase 2 wrapper) P16 (a 12 GB card) X15 (public testnet) P22 (phase 2 consensus proof) M16 (the kernel is written and bit-exact on the Mac; the PC 2 run is queued behind the 0.3.11 rollout) | +| Conceded, scheduled or mitigation in progress | 2 | L3 D5 | +| Open, minor | 1 | E17 (the draw lines ride in the queued M16 job) | +| Open, found tonight, fix in round 3 | 1 | P23 | +| Another agent's tonight | 1 | C4 | + diff --git a/docs/plans/ledger-close-status.md b/docs/plans/ledger-close-status.md index e57473c11..d108ac35a 100644 --- a/docs/plans/ledger-close-status.md +++ b/docs/plans/ledger-close-status.md @@ -37,3 +37,16 @@ The 0.3.11 cut closed at 23bc2b2 before `fud-close` reached the ship order; `fud ## 23:20 UTC: the fork rebase, sized A trial merge of the 0.3.11 fork tip 89dfcb95 into `ledger-fixes` (worktree `vendor/igneum-node-ledger0311`, branch `ledger-fixes-0311`, aborted and left clean) conflicts in two files. `protocol/flows/src/ibd/proof.rs`: two trivial test hunks (the tuple shape of `receive_pruning_point_proof`). `igneum/miner/src/main.rs`: seven hunks, substantive, because Counter ASIC 2.0 restructured `EpochSeeds` (class and era fields), made `template_seeds` return a value instead of the `Option` that X22's "no expect on the node's answers" introduced, and replaced the export path with `write_pack_checked`, inside which M28's `stamp_kernel_hashes` must now be called. That is a round-3 item for a fork agent with PC 2 suites (`ledger-rebase`), after `ledger-pc2` has finished on `ledger-fixes-2`, so the two fork branches rebase once. + +## 00:10 UTC, 6 October 2026: round 2 merged (ledger-tails 1544c63, ledger-design 1c56ec6, ledger-observer 013c591, ledger-pc2 bf960b0) + +Counts (167 entries, P23 new): Fixed, rule written or designed 56. Conceded and stated or terminal 52. Answered 26. Decided or closed by rule 12. Decision owner the project lead 11 (items 1 to 13 in `docs/plans/ledger-decisions.md`; item 13 added for the three gate-3 parameters of spec 3.4.2). Blocked with the blocker and next date in the Status line 5 (P3, P16, X15, P22, M16). Scheduled 2 (L3, D5). Open minor 1 (E17). Found tonight 1 (P23). C4 another agent's. + +What closed in round 2, with its evidence pointer: +- F7: 2 and 5 blocks/s on the fast-time 3-node network (`tools/finality-attacks/f7.mjs`): reorg depth max 3 and 7 blocks against d = 20, 0 conflicting locks, propagation p99 under 1 s at every rate; only the WAN run at those rates stays under O-3.2. F3: the hostile aggregator simulated (`sim/finality_v2.py` scenario O): the attack works under the certificate reading and does nothing under the block reading of spec 3.3 Q2; the per-block vote bound and the bitmap bound proposed in spec 3.4.2. F17: the client's one-key default and the bitmap bound proposed in spec 3.4.2; O-3.3, O-3.5, O-3.12 point at it; decisions item 13. +- D6 reviewed (`docs/review/d6-forged-job-result-2026-10-05.md`, three devnet checks named). X17 designed (spec 8.8 proving jobs and the keys; phone-app 4.1 display rules). D5 owner and gate named. P3, P16, P22, X15 Status lines carry the blocker and the next date. P21's litepaper sentence labelled Open. +- X14 answered for all four concentrations (signing read from the certificates and votes in the coinbase finality section: top-1 10.0%, top-3 29%, see the bench-log "round 2: X14"); the observer's ASN, fingerprint, pool-statement and nightly-table code on `ledger-observer` with unit tests, not deployed (O-X.1), N_ind labelled a proposed definition (decisions item 3). +- P17 fixed on fork `ledger-fixes-2` b1e98b79 (one state word of four, `finality not active`, a failure field naming skipped, reorged out, finality paused; igneum-exec 16 of 16 on the Mac, labelled; the O-7.2 conformance run passed on a fast-time network, `tools/p17-conformance`). Finding P23 from that run: the pool has no reorg hook; entry added, fix in round 3. +- M16: the inline-cache bench kernel written beside the CUDA worker (`proto-cuda/inline-bench`), bit-exact against the emulation on the Mac; the PC 2 run (64 MiB and 256 MiB caches against the honest 1 GiB kernel, with E17's draw lines) is a kit and playbook queued behind the 0.3.11 rollout under the Counter ASIC coordinator's "go PC 2" rule. + +Round 3 starting: `ledger-rebase` (the fork branches `ledger-fixes` and `ledger-fixes-2` rebased onto the 0.3.11 fork tip 89dfcb95 as `ledger-fixes-0311`, the M28 stamp inside `write_pack_checked`, the P23 reorg hook, suites on PC 2 under the coordinator's go or on the Mac labelled).