diff --git a/docs/analysis/class-v6/floor/shadow-k.md b/docs/analysis/class-v6/floor/shadow-k.md index a5c561c52..1b8667439 100644 --- a/docs/analysis/class-v6/floor/shadow-k.md +++ b/docs/analysis/class-v6/floor/shadow-k.md @@ -104,7 +104,7 @@ stock and at the 1,300 MHz lock, and 6.9 pJ per counted op on the Apple M5 Max ( | lop3 (8-bit truth table) | 7,274 | 1.42 | 0.99 | 0.72 | 0.52 | 24.1 / 13.0 | 0.030 / 0.055 | | 0.11 | | | 32-lane xor-mask shuffle (butterfly over the 1 KB window), per lane-op | 181,580 | 1.24 | 0.87 | 0.63 | 0.45 | 55.8 / 29.4 | 0.011 / 0.021 | | 0.042 | routed with SPEF; 15:1x UK | | 32-lane general crossbar, per lane-op | ROW_XBAR | -| 8 KB scratch, one random read (flop array: the pessimistic form) | ROW_SCRATCH | +| 8 KB scratch, one random 32-bit read of a 2,048 x 32 flop array (the pessimistic form of a chip's L1; an SRAM macro reads lower) | 868,159 | 207 | 145 | 104 | 75 | 2,400 / 1,400 per L2 hit | 0.043 / 0.074 | | 0.15 | routed with SPEF, 19:4x UK; the card's shared-memory read is unmeasured (owed) | | int8 8x8x8 tile, per MAC | ROW_TILE | Reading the floors: a lane's add costs the chip about 2.2 pJ at ASAP7 and 1.1 at N3, against the 5090's 6.2 @@ -138,7 +138,7 @@ draws 13.9 mW, the run phase 36.9 mW for 8 lanes at 1.5 ns). | core, 8 lanes, 32 registers | synthesis only (no wires, no clock tree) | 186,443 | 6.9 | 4.8 | 3.5 | 2.5 | 11.3 / 6.2 / 6.9 | 0.31 / 0.56 / 0.50 | 0.22 / 0.40 / 0.36 | 1.1 | synthesised; 14:0x UK | | of which the sequential term (register file, imem and IR clock pins, no clock gating) | | | 2.4 | 1.7 | 1.2 | 0.9 | | | | | | | of which the units, the read muxes and the butterfly | | | 4.5 | 3.1 | 2.3 | 1.6 | | | | | | -| core, 8 lanes, 32 registers | placed and routed, SPEF | ROW_CORE8_PLACED | +| core, 8 lanes, 32 registers, ungated | placed and routed, SPEF, clock tree (one run length of 300 cycles, the load phase subtracted, about plus or minus 10 percent) | 444,478 | 11.3 | 7.9 | 5.6 | 4.1 | 11.3 / 6.2 / 6.9 | 0.50 / 0.91 / 0.82 | 0.36 / 0.66 / 0.59 | 1.8 | placed 16:0x UK on a rented pod; +64 percent over synthesis (wires, and a clock tree of 2.5 pJ per lane-op that gating removes) | | core, 32 lanes, 32 registers | synthesis only (steady state from 150 and 400 run cycles) | 600,381 | 5.55 | 3.9 | 2.8 | 2.0 | 11.3 / 6.2 / 6.9 | 0.25 / 0.45 / 0.41 | 0.18 / 0.32 / 0.29 | 0.90 | synthesised; 15:2x UK | | core, 32 lanes, 16 registers | synthesis only | 443,258 | 4.2 | 2.9 | 2.1 | 1.5 | 11.3 / 6.2 / 6.9 | 0.18 / 0.34 / 0.30 | 0.13 / 0.24 / 0.22 | 0.68 | synthesised; one run length, about plus or minus 10 percent; 15:0x UK | | the bare ARX lane (section 3, the floor) | routed | 11,631 | 2.2 | 1.5 | 1.1 | 0.8 | 11.3 / 6.2 / 6.9 | 0.10 / 0.18 / 0.16 | 0.07 / 0.13 / 0.11 | 0.35 | the lower bound | @@ -203,6 +203,128 @@ takes back on the card's own node (3.6x to 2.4x), which is the design. Node-for- k 0.78 and the 64-register core at 1.09, so "near 0.9" is reached node-for-node by the window alone; what it does not survive is the node step a chip project would buy (an N3 core gives back 0.4x, an N2 core 0.8x). +### 4c. The adversary's 64-register core: is the window a defence? (the coordinator's order, 15:3x UK) + +Every row in this section is a MODEL of a chip core, never a lower bound on what a chip maker can build; the +synthesis gives the cost of the circuit as drawn, and a better circuit is always possible. + +**The live-state analysis** (`tools/chip-model/rtl/flow/livestate.py`, run on build-3: programs drawn as the +core testbench draws them, the class v4 op weights, a load on one instruction in 16 as the dependent memory wait, +dst and src uniform over the window, the result fold reading every register at the end of the block; 64 drawn +programs, 1,024 waits per row): + +| Window R | Live values at a wait (mean, min to max) | Of which necessary (reach a later address or the result, transitively) | Dead writes per block | +|---|---|---|---| +| 8 (the class ISA) | 7.0 of 8 (6 to 7) | 6.9 | 2.9 percent | +| 32 | 30.5 of 32 (29 to 31) | 30.0 | 2.9 percent | +| 64 | 61.7 of 64 (59 to 63) | 61.0 | 2.8 percent | +| 64 at a 1,024-instruction block | 61.5 of 64 (58 to 63) | 60.6 | 3.1 percent | + +So under a fold that reads every register, 95 percent of the window is live AND necessary across every memory +wait: the adversary cannot shrink the state it keeps by liveness, and recomputing a value instead of keeping it +costs the dependent chain that produced it (every value feeds the result transitively). The window is a +defence ONLY because of the fold rule; a fold that read 8 of the 64 registers would let the chip drop the rest +(the dead fraction would rise toward the fraction never read before the fold), so the fold-reads-all rule is the +design rule that goes with the window. + +**What the adversary can do with the state it must keep** is make it cheaper per access, not smaller. The +GPU-shaped row (4a, 64 registers in flops, every flop clocked every cycle, three 64:1 read muxes) is 9.7 pJ per +lane-op at ASAP7. The forms a chip maker would use: + +| Form of the 64-register state (per lane, 256 bytes) | pJ per lane-op ASAP7 | N3 | k at the lock (N3) | Label | +|---|---|---|---|---| +| flops, no clock gating, 64:1 read muxes (the 4a row) | 9.7 | 4.9 | 0.78 | synthesised; a model | +| flops with the register-file clock gated (one of 64 registers written per cycle; the ICG cells allowed back in and inferred by Yosys, 320 gates) | 6.2 (225,441 cells; sequential 0.2) | 3.1 | 0.50 (0.70 node-for-node) | synthesised 16:0x UK; a model | +| the same gating on the 32-register base, for the penalty | 4.5 (156,833 cells; sequential 0.15) | 2.3 | 0.37 (0.51 node-for-node) | synthesised 16:0x UK; a model | +| the gated 32-register base PLACED AND ROUTED (SPEF, clock tree, 379,633 cells; steady state solved from 150 and 600 run cycles) | 6.7 (+49 percent over synthesis) | 3.4 | 0.54 (0.76 node-for-node) | placed 19:5x UK; the GDDR7 board at the lock 2.4x node-for-node, 2.8x a node ahead: the morning's headline figures to the digit | +| the gated 64-register window core PLACED AND ROUTED (563,339 cells; parasitics estimated from global routing, the SPEF lost to a full disk; steady state solved from 150 and 600 run cycles; plus or minus 15 percent) | 9.45 (+52 percent over synthesis; N5 6.6, N2 3.4) | 4.8 | 0.77 (1.07 node-for-node, 0.55 at N2) | placed 21:3x UK; the GDDR7 board at the lock 2.0x node-for-node, 2.45x a node ahead, 2.9x two ahead; the window's residual against the placed base +2.75 pJ per lane-op, +0.23 of k at the lock | +| latch-based register file (the clocked element halved; about 30 percent under the gated flop file, approximate) | about 0.7 x the gated row | | | modelled | +| SRAM-banked state shared across time-multiplexed lanes (one execution port serving many lanes' streams in turn, each lane's 256 bytes in a bank): modelled 8.5 to 10.5 from the access energies; BUILT as `core_tm` (8 lanes x 64 registers in banks, one port, round-robin, ungated): 8.8 pJ per lane-op synthesised (173,426 cells), against the SIMD ungated 9.7 | 8.8 (built) | 4.4 | 0.71 | synthesised 16:2x UK: port sharing saves 0.9 pJ of units and the bank-select muxes take most of it back; NOT the lever; the multi-family adversary lane's macro-window core reads 5.9 (its FakeRAM term modelled 2.0 to 7.0 pJ per access), within 5 percent of the gated flop row, so the file's form is not the lever either | +| values recomputed instead of kept | not available: 95 percent of the window is necessary (above) | | | measured on drawn programs | + +The defence, then, is the penalty that remains after the adversary's best form: the gated 64-register file +against the gated 32-register file (the two synthesised rows above when they land; measured: 6.2 against 4.5 pJ per lane-op at ASAP7 synthesised, a penalty of 1.7 pJ; PLACED 9.45 against 6.7, a +penalty of 2.75 pJ, 1.4 at N3, +0.23 of k at the lock, 0.54 to 0.77 at N3 and 0.76 to 1.07 node-for-node; the +analytic estimate had been 1.5 pJ). So on placed rows the window takes the GDDR7 board at the lock from 2.4x to +2.0x node-for-node and from 2.8x to 2.45x a node ahead, for at most 5 percent per load on the card. Two corrections this +forces: the honest adversary's BASE core is the gated one (k 0.37 at N3, 0.51 node-for-node), under the ungated +0.56 and 0.78 of section 4, which are the GPU-shaped core a maker would not build; and placement costs more than +the +20 to +40 percent estimated (the ungated placed base reads 11.3 against 6.9 pJ: wires plus a 2.5 pJ clock tree +that gating removes), so the placed gated rows (on a rented pod, 17:30 UK) are the figures to serve. On the 32-lane core the same +penalty applies per lane (the register file does not amortise), so the window moves the 32-lane core from k 0.45 +to about 0.57 at the lock at N3 (0.63 to about 0.80 node-for-node). + +**The GPU side** (the hash lane's hand): the compiled allocation of the 64-register measurement pack (ptxas +registers per thread, local-memory spill bytes, occupancy) and the rate beside the 8-register base, clock +18:00 UK; until then the modelled reading stands: about 110 of 255 registers per thread, occupancy about half, +the rate expected to hold under the latency-bound chain (the 5090 hides about 330,000 ops per hash before compute +binds) and the energy to move little, the per-lane register traffic the unmeasured term. + +The measured GPU side (the hash lane, 16:1x to 16:4x UK, RunPod secure pods, driver 580, the kit worker, 250 x +2^24, nvidia-smi 1 Hz; ptxas from nvcc 12.8 -Xptxas -v on the pack's kernel; pods destroyed, USD 1.22): + +| Card, pack | MH/s | W | microjoules per hash | registers per thread (ptxas) | spill | blocks per SM (occupancy) | per load | Label | +|---|---|---|---|---|---|---|---|---| +| 5090, the base (mx8-devnet-epoch0) | 141.74 | 303.1 | 2.139 | 30 | 0 B | 24 (4,080 warps) | 16.7 nJ | measured | +| 5090, the window, arithmetic-only (hl-reg64, twice the base's work by construction) | 80.38 | 308.6 | 3.839 | 96 | 0 B | 20 (83 percent) | 15.0 nJ | measured: level per unit of work | +| 5090, the window, full chain (hl-reg64c: every load's address mixes all 64 registers) | 70.96 | 320.3 | 4.513 | 88 | 0 B | 20 (83 percent) | 17.6 nJ (+5 percent) | measured | +| 4090, the base | 62.67 | 208.9 | 3.333 | 29 | 0 B | 24 | 26.0 nJ | measured | +| 4090, the window, arithmetic-only | 31.57 | 210.3 | 6.663 | 104 | 0 B | 16 (67 percent) | 26.0 nJ | measured: level | +| 4090, the window, full chain | 31.38 | 216.5 | 6.898 | 87 | 0 B | 20 (83 percent) | 27.0 nJ (+4 percent) | measured | + +So the card's side of the window defence is at most 5 percent per load: no spill on either card in either form, 88 +to 104 registers per thread, occupancy 67 to 83 percent, and the rate per unit of work held within 5 percent under +the latency-bound chain. The sound class form is the full chain (the arithmetic-only fold fails the liveness rule; +class string `+reg64c`, pack hl-v6-win with `check_window_liveness` in its suite). The chip's side (this section's +gated rows) therefore carries the whole defence. + +### 4d. The connected-state variant (cs64s27x16, the connected-state lane's structure) on the adversary's core + +The connected-state lane's program (a 64-register window; per step a load whose address register is the previous +block's last dst, the word landing in m_j, then a 27-instruction block whose first instruction reads m_j and every +later one draws its src from the block's last four dsts, the last instruction injecting; 16 steps of text, 448 +instructions, 16 passes per block; its liveness tool: 63 of 64 live at every address, about 11 registers in the +per-step dependent chain, about 20 touched per block) priced on the gated 64-register core with a 512-entry imem, +the program drawn by those rules in the testbench (`CS` mode of `tb_core_common.vh`), synthesis-only: + +| Row | Cells | pJ per lane-op ASAP7 | N5 | N3 | N2 | k at the lock N5 / N3 / N2 | k at stock N5 / N3 | +|---|---|---|---|---|---|---|---| +| cs64s27x16 on the gated 64-register core, 512 imem | 253,059 | 6.3 | 4.4 | 3.2 | 2.3 | 0.71 / 0.51 / 0.37 | 0.39 / 0.28 | +| the class v4 draw on the gated 64-register core, 256 imem (4c) | 225,441 | 6.2 | 4.3 | 3.1 | 2.2 | 0.70 / 0.50 / 0.36 | 0.38 / 0.27 | + +The chip's shadow for the program is 55,296 x 3.2 pJ = 0.18 microjoules per hash at N3 (0.24 node-for-node) +against 0.13 for the genesis window on the same core; the card pays +0.6 percent for the window on the 5090 (the +connected-state lane's measurement). The structure's other knobs do not reach the chip: the 16-pass loop and the +448 text cost the shared imem about 0.1 pJ per lane-op, hot-set banking is not needed (the gated file charges only +the written register), and the chain's width sets lane count, which is free. On the GDDR7 board at the lock the +window moves the chip's edge by about 1.1x (3.6x to 3.3x node-for-node), under the 1.25x gate that lane set. + +### 4e. The mixed-resource lane's FP32 units (class-v6-mixedfp) on the adversary's lane + +The mixed-resource lane's candidate adds four FP32 families (fadd, fmul, ffma, fcvt) to the shadow's draw, every +result injected by xor, with inputs masked to a 7-bit exponent range (never zero, denormal, NaN or Inf). The +adversary's simplified units (`rtl/fp32_units.v`): an FMA with the 24 x 24 mantissa multiplier, a 100-bit +alignment window, a full normaliser and RNE; a separate adder and multiplier; the int32 to float converter; the +exponent path narrowed to the range; no NaN, Inf, denormal or flag logic. The lane: an 8 x 32-bit window, the +four units, `d ^= bits(result)`. Routed with SPEF, random-input VCD, 42,936 cells, a 2 ns clock. + +| Op (every unit evaluating each cycle: an UPPER bound per op, no operand isolation) | pJ per op ASAP7 | N5 | N3 | N2 | 5090 fp32_fma stock / lock | k at N3 vs stock / lock | +|---|---|---|---|---|---|---| +| fadd | 6.6 | 4.6 | 3.3 | 2.4 | 9.2 / 5.2 | 0.36 / 0.64 | +| fmul | 7.0 | 4.9 | 3.5 | 2.5 | 9.2 / 5.2 | 0.38 / 0.68 | +| ffma | 6.7 | 4.7 | 3.4 | 2.4 | 9.2 / 5.2 | 0.37 / 0.65 | +| fcvt | 6.9 | 4.8 | 3.5 | 2.5 | 9.2 / 5.2 (cvt unmeasured on the card) | 0.38 / 0.67 | +| random mix | 7.1 | 4.9 | 3.6 | 2.6 | | 0.39 / 0.68 | + +Reading: the four read alike because all four units switch every cycle on the same operands, so each row is the +upper bound for its op (a chip isolates the idle units; by cell share about ffma 3.5 to 4, fmul 2.5, fadd 2, fcvt +1 pJ at ASAP7, approximate). Even on the upper bound the FP family is the chip's dearest per op relative to the +card: k 0.65 at N3 at the lock against 0.18 for the integer ARX lane floor, because the card does an FMA for 5.2 +pJ (under its own int add at 6.2) while the chip's multiply, alignment and normaliser cost about three int ops. +On the units' floors the shadow's k_eff rises from 0.097 (class v4) to about 0.14 at the fp12 mix and 0.17 at +fp24 (0.20 and 0.24 with isolation taken as half), the core's per-op overhead on top. The GPU-cost budget (10 +percent of energy per hash) is the binding side, and the vendor-rounding question is the class's, not the chip's. + ## 5. The chip edge at the measured k `E_chip = E_mem + N_ops x e_chip` (absolute: the chip's shadow cost is 102,100 x 3.5 pJ = 0.36 microjoules per hash @@ -270,7 +392,7 @@ to 2.3x and the strongest chips at 2.6x to 4.2x. | 6 | prmt, lop3 | 0.64, 0.72 | 11.5, 13.0 | 0.056, 0.055 | not drawn (RTL rows only) | | 7 | mulhi | 0.68 | 21.0 | 0.032 | yes (6) | | 8 | 32-lane shuffle (butterfly) | 0.63 | 29.4 | 0.021 | yes (8) | -| 9 | L1 scratch read (8 KB flop array) against the card's L2 hit | ROW_SCRATCH_K | 1,400 | pending | not drawn | +| 9 | L1 scratch read (8 KB flop array) against the card's L2 hit | 104 (pJ per read) | 1,400 | 0.074 | not drawn | | 10 | int8 8x8x8 tile, per MAC | ROW_TILE_K | 2.2 | pending | not drawn (the tensor lever is dead on other grounds) | The order is set by the card's price, not the chip's: the chip pays 0.6 to 1.7 pJ for everything, and the card diff --git a/docs/analysis/class-v6/multi-family-adversary.md b/docs/analysis/class-v6/multi-family-adversary.md index f8b62baf1..6d0ee3e61 100644 --- a/docs/analysis/class-v6/multi-family-adversary.md +++ b/docs/analysis/class-v6/multi-family-adversary.md @@ -27,11 +27,15 @@ population, Apple reported and not headlined; every defence is scored after the 2. The rows (ASAP7, placed and routed, SPEF, gate-level VCD; the SRAM term modelled, bands shown; node factors claimed): the full core 9.36 pJ per lane-op at ASAP7 on the class v4 draw (8.6 to 11.1), 6.55 at N5, 4.72 at N3; k 0.64 node-for-node and 0.46 a node ahead at the 5090's lock; the reserve families k 0.33 to 0.86 placed; the - genesis-only core 7.78 (k 0.53 / 0.38); the 32-lane genesis core 10 percent under (synthesis). + genesis-only core 7.78 (k 0.53 / 0.38); the 32-lane cores 10 to 13 percent under their 8-lane forms (synthesis: + the full core 5.73, k 0.39 / 0.28), so the adversary's cheapest row is the 32-lane placed core at about 5.7 pJ + per lane-op at N5 (k 0.55 same-node), a sixth under the headline row. 3. The complete machine (memory, controller, host share, power train, cooling) on the card's own GDDR7: 1.5x the - 5090 at its lock per joule node-for-node (1.3x to 1.7x), 1.8x a node ahead (1.5x to 2.0x); 3.3x per dollar; HBM3 - buys it nothing; the N2 SRAM die 2.3x and 3.1x; the stored-half hybrid (section 13) 1.9x and 2.4x at USD 2.80 per - MH/s. Capex per MH/s is the larger half of the chip's edge; the project cost is its hold. + 5090 at its lock per joule node-for-node on the placed 8-lane full core (1.3x to 1.7x), 2.1x on the placed + 32-lane core's floor (1.7x to 2.4x); 1.8x and 2.4x a node ahead; 3.3x per dollar; HBM3 buys it nothing; the N2 + SRAM die 2.3x to 4.2x same-node; the stored-half hybrid (section 13) 1.9x to 2.6x at USD 2.80 per MH/s. The + same-node honest bracket across the adversary's choices is 1.5x to 2.1x on the DRAM board. Capex per MH/s is the + larger half of the chip's edge; the project cost is its hold. 4. Data-local execution cannot pay (the live state is 26x the read, section 11); memory sharing is the baseline; recomputation loses; selective participation gains 2 to 5 percent for 50 to 90 percent of revenue (section 13). 5. Class v7 should take the epoch-defined bounded dataset with a published support horizon and keep the floor @@ -348,10 +352,28 @@ under the class v4 draw (shfla and mm8 live -1.2 percent, all eight live -9.2 pe hash and pays +29 percent of shadow energy, and the card's premium rises by the same +29 percent (its tile at 70 pJ per lane against the draw's 10.3): the ratio does not move, the lane count does (section 14, row 1). -The 32-lane genesis core (synthesis only; four window macros, one imem pair shared by 32 lanes): 261,440 cells, -5.29 pJ per lane-op at ASAP7 (4.65 to 6.77) on the class v4 draw, 3.70 at N5, k 0.36 at the lock: 10 percent -under the 8-lane core, the imem and the sequencer amortised over four times the lanes. The 32-lane full core -(synthesis) and its placed form are in the flow (adv-a and adv-f at 16:4x BST) and land as a delta. +The 32-lane cores: the genesis comparator PLACED AND ROUTED (adv-g, 20:1x BST; SPEF, gate-level VCD at the +30 ns constraint, four window macros and one imem macro, 717,268 cells with fill): 4.80 pJ per lane-op at ASAP7 on +the class v4 draw (4.17 to 6.28), 3.36 at N5, 2.42 at N3, k 0.33 node-for-node and 0.24 a node ahead at the +5090's lock. That is 9 percent UNDER its own synthesis row (5.29), where the 8-lane cores read 32 to 42 percent +over theirs: the 32-lane core is routed under a 30 ns constraint (its unpipelined crossbar path is 27 ns) and the +flow's resizer downsizes every cell to it, so the placed figure carries smaller cells and lower capacitance than a +chip clocked at 1.5 ns with its pipeline registers would. The honest 32-lane row is therefore a band, not a point: +3.36 pJ at N5 (the relaxed-clock placement, the floor) to 5.7 (the synthesised 32-lane full core 5.73 at ASAP7 +times the 8-lane cores' measured placement factor 1.42, the ceiling), k 0.33 to 0.55 same-node and 0.24 to 0.40 a +node ahead. The synthesis rows beside it: the genesis core 261,440 cells, 5.29 (4.65 to 6.77), 3.70 at N5; the +full core 393,036 cells, 5.73 (5.09 to 7.20), 4.01 at N5, 2.89 at N3, k 0.39 / 0.28; the bank's cost at 32 lanes +8 percent of the energy on the draw and 50 percent of the cells. The placed 32-lane FULL core runs on adv-g (from +synthesis at 19:58 BST, the same 30 ns constraint) and lands as a delta; its placed figure will sit inside the +same band for the same reason. + +The complete machine at the 32-lane band (the genesis comparator's placed 3.36 pJ at N5 as the floor; the ceiling +is section 6's placed 8-lane full core less a sixth): the GDDR7 board 2.1x the 5090 at its lock per joule +node-for-node at the floor (1.7x to 2.4x) and 2.4x a node ahead (2.0x to 2.7x), against 1.5x and 1.8x on the +placed 8-lane full core; the N2 SRAM die 4.2x and 5.7x at the floor. So the same-node honest bracket across the +adversary's lane count, core and sizing choices is 1.5x to 2.1x per joule on the DRAM board (1.3x to 2.4x on the +bands), 1.9x to 2.6x with the stored-half hybrid, USD per MH/s unchanged (the core is a tenth of the board's capex +at 32 lanes). The board rows of section 6 restated at the placed energy (the full core at 6.55 pJ per lane-op at N5, band 6.01 to 7.77; 4.72 at N3): the complete GDDR7 machine 1.53 microjoules per hash, **1.5x the 5090 at its lock per joule @@ -726,7 +748,14 @@ percent (5th to 95th percentile 1.45x to 1.58x on the placed rows); a specialist gains 2, 3 or 5 percent of ratio and loses 50, 75 or 90 percent of revenue, because difficulty follows the fleet it joins and it earns in proportion to the time it mines; downtime and re-entry cost it the DAA window's lag each way and buy it nothing. The GPU-cost budget of 10 percent at the lock (set before these results) is untouched: -no honest energy is spent in this section. Served sentence for the bracket: against a chip on the same node the +no honest energy is spent in this section. (5) "Layer 8 off" (the hash lane's D2 experiment of 18:12 BST: the era layout's window-layer draw removed, every +window the whole dataset): the hottest half then serves exactly 50 percent of the reads at every program, so the +uniform-store row becomes the hot-set row: the hybrid reads 1.85x (1.58 to 2.03) same-node and 2.27x (1.95 to +2.50) a node ahead at USD 3.34 per MH/s and 273 MH/s per board, against 1.93x / 2.40x at USD 2.80 on today's mean +program (hit 0.581) and 2.09x / 2.65x at USD 1.88 on Devnet 3's p98 program (0.72): the window layer's removal +takes 4 percent off the hybrid's per-joule edge at the mean program and 11 percent at the tail, and its capex edge +from 5.7x to 4.8x of the card's, for one and-or per load on the honest side. The rows are in +`tools/chip-model/mf/results/d2b-n5.md` and `d2b-n3.md`. Served sentence for the bracket: against a chip on the same node the honest floor is the stored-half hybrid at 1.9x to 2.1x per joule and 6x to 9x per dollar (1.65x to 2.3x on the band), not the DRAM board's 1.5x and 3.3x; the lever on it is the dataset floor as a capex ticket. @@ -751,7 +780,131 @@ Reading: no row loses competitiveness; the cheapest adaptation is firmware for e sequence for an entry outside it (row 2, 1.3x to 1.45x same-node while live), and a respin only if the chain adds a family the sequence cannot carry, which it has 360 days' notice of. The stress life of three years holds in full. -PENDING with clocks: the 32-lane full core's synthesis row (adv-a, in ABC at 17:0x BST; by 19:30) and its placed -row (adv-f, at floorplan; by 21:00); the k lane's crossbar, scratch and tile rows (its pod); a real memory +PENDING with clocks: the 32-lane full core's placed row (adv-g from 19:58 BST on a 64-core host, adv-f since 18:12 +on a slower one, whichever lands first, by 22:00; the 32-lane genesis comparator's placed row landed at 20:1x, +section 5, and brackets it); the k lane's crossbar, scratch and tile rows (its pod); a real memory compiler's figure for the two macros (owed, no clock: FakeRAM gives area and pins only); the per-family rows on the 32-lane placed core (by 21:30 if adv-f lands, else the next pass). + +## 15. The SRAM die's ticket reconciled (the research lane's and the coordinator's ask, 17:2x BST; floor lane 3's USD 0.6 against this file's USD 2.94 per MH/s) + +The two figures price different machines. Lane B's USD 0.25 to 0.4 of silicon per MH/s (chip-model-v3 5.12, +hardware-future) is the die at ZERO SHADOW: 2,100 MH/s per 2 GiB reticle at 300 W, no shadow core at all; with a +board it reads about USD 0.6. This file's USD 2.94 is the same die carrying the class v4 shadow on the placed mf core +(6.55 pJ per lane-op at N5), with the machine held at lane B's 270 to 300 W: the shadow is 13x the die's own energy +per hash, so at that budget the machine makes 383 MH/s and the fixed tickets (die, package, board, host) divide by +383 instead of 2,100. Neither is the adversary's choice. The designer sets the power budget to minimise dollars per +MH/s; the die's read ceiling (floor lane 3: about 1,060 G reads per second, 8.3 GH/s) is never reached because the +core's silicon and the power train bind first. Line by line, every term with its source and label: + +| Component | This file at 270 W (section 6) | The optimised machine (this section) | Source and label | +|---|---|---|---| +| The 2 GiB SRAM die: 452 mm^2 of macro on a 550 to 650 mm^2 N2 die, a USD 30,000 wafer, lane B's yield model | USD 500 (400 to 600) | the same | lane B 4.9 (claimed density and wafer price; the yield approximate) | +| The shadow core's silicon: this core's placed floorplan 0.0036 mm^2 per lane at ASAP7, x0.55 to N5 (0.002 mm^2), one lane-op per 7.5 ns (the 5-phase slot), 770 lanes per MH/s; USD 0.36 per mm^2 of N5 (sram-mirror's yield model) | USD 0.55 per MH/s (590 mm^2 at 383 MH/s) | USD 0.11 to 0.55 per MH/s: a core pipelined to one op per cycle per lane is five times denser (0.0004 mm^2 per lane; about +0.1 to 0.2 pJ per op for the pipeline registers, inside the band); the record's USD 25 to 40 per 166 MH/s (0.15 to 0.24) sits inside | this file's placed floorplan (measured), the pipelining factor approximate | +| The package: two reticle-class dies (the SRAM die and the core die) with a wide link between them | USD 200 (an interposer, approximate) | USD 60 to 200: an organic flip-chip substrate carries a UCIe-class link at the hash's 80 bits per read (floor lane 3's hop, 0.5 pJ per bit); the interposer only if the link must be wider | approximate; the interposer price chip-model-v3 5.1 (claimed) | +| The board, assembly, PSU and cooling | USD 200 flat (board 150, assembly 50; PSU and cooling inside) | USD 150 plus USD 0.15 per watt of PSU and cooling (approximate): USD 240 at 600 W, 375 at 1.5 kW | approximate | +| The host (one full node per 100 machines) | USD 15 | USD 15 | section 6 | +| The sustained rate | 383 MH/s at 270 W (power-bound on the core) | 852 MH/s at 600 W, 1,420 at 1 kW, 2,130 at 1.5 kW, 2,840 at 2 kW (the die's own ceiling 8.3 GH/s, never reached) | board.py on the placed core (modelled) | +| **USD per MH/s** | **2.94** | **1.63 / 1.20 / 0.98 / 0.88 at 600 W to 2 kW on this core; 1.07 / 0.73 / 0.56 / 0.47 with the pipelined core and the organic package** | modelled | + +The reconciled figure: **about USD 1.0 per MH/s for the SRAM-die machine carrying the class v4 shadow (0.5 to 1.6), +at 1 to 1.5 kW per machine**, set by the power train and the core's silicon and not by the die; lane B's USD 0.6 +holds only at zero shadow, this file's USD 2.94 only at a 300 W budget, and both stand in the record with those +labels. Per joule the optimised machine is unchanged (the energy per hash does not depend on the budget: 2.3x +same-node, 3.1x a node ahead at the placed core). + +What a maker's first batch of 1,000 dies would actually pay: not the unit ticket. A thousand 2 GiB dies at 1 to 2 +GH/s each are 1 to 2 TH/s, several times the chain's whole hashrate at the rental equilibrium (floor lane 3's +section 4: a third of the network is under two dies at every price in its table), so the batch's cost is the +project (USD 100 M to 500 M at N2, claimed) spread over a hashrate the chain cannot absorb: USD 50 to 250 per MH/s +of NRE against USD 1 of unit cost, and the first dies' yield (a 600 mm^2 die with 452 mm^2 of macro, redundancy +untested) adds USD 100 to 400 per die, approximate. The die's economics are project economics: the coexistence +verdict should take USD 1.0 per MH/s (0.5 to 1.6) as the unit ticket of a fleet that exists and the project cost +as the gate on whether it ever does. + +## 16. The formal memory model: the class v6 evaluation in capacity, bandwidth, energy and amortisation terms (the 2.0 register's row, drafted 18:1x BST for the 12:00 delta) + +One evaluation (a hash) under class v6: 128 dependent loads of a 4-byte word (W = 1; 16 bytes at W = 4) from a +dataset of D bytes (2 GiB at genesis, the floor schedule 5.5 / 8.5 / 11.5 GiB), each address the fold of the lane's +live state (64 registers, 61 necessary), each load returning into that state; between loads the shadow block (6,912 +instructions per iteration, 102,100 per hash) and the base program (512); the dataset rebuilt once per window from +the chain's state (class v5 and v6) or from the epoch's seed (the class v7 default), 157 G ops per GiB. The terms, +each with its bound and whether the bound is closed-form or rests on physical design: + +| Term | Per evaluation | Across N evaluations on one machine | The bound | Closed-form or physical | +|---|---|---|---|---| +| Capacity, the dataset | D bytes must be addressable at the hash's latency: every item is reachable from every lane with uniform probability (the fold is keyed by the destination register; no item is colder than 1/D by construction, the hot set is per program and per window) | shared by every lane and every engine on the board: D once per machine, never per engine | a machine holds D or recomputes (section 13: recomputation loses at every point; a partial store of fraction f serves f of the reads uniformly, or up to 0.58 to 0.72 at f = 0.5 on the window layer, 0.50 with the layer off) | closed-form (the item distribution is the census's; the SRAM price per GiB is claimed) | +| Capacity, the live state | 2,112 bits per hash in flight; the chain forbids reducing it (61 of 64 registers necessary; the connected-state lane: free for a chip, only the width counts) | lanes in flight x 2,112 bits: 1,172 lanes on the GDDR7 board (310 KB), 21,000 on the SRAM die (5.5 MB) | an SRAM macro per 8 lanes, 3.5 pJ per access (2.0 to 7.0): the one term this file's placed rows measure | physical (the macro energy band; the rest of the core measured placed) | +| Bandwidth, random reads | 128 activates per hash: the device's activate rate, not its pin rate, binds (21.3 G per second on 16 GDDR7 devices, 82 percent reached by the 5090; 10.7 G on an HBM3 stack, unmeasured, the JEDEC floor 2.3 G; the SRAM die's 1,060 G never reached before power binds) | N x 128 activates: the sustained rate is activates per second over 128, shared across every engine on the board | the memory's activate ceiling per dollar of devices: a chip cannot buy more activates per device than the card has (section 11) | the GDDR7 ceiling measured on the card (82 percent); the HBM3 ceiling physical (the AWS F2 hour); the SRAM die's a model | +| Bandwidth, bytes | 32-byte sectors at W = 1 (4 KB per hash, 38 percent of the GDDR7 pins at the activate ceiling); 2 sectors at W = 16 (dead on the cards) | linear in N | never the bound at W = 1 to 8 | closed-form | +| Bandwidth, the state to the data | 2,112 bits per read if the computation moves to the item; 80 bits per read if the item moves to the lane | 26x on every medium (section 11) | data-local execution cannot pay | closed-form (the bit counts) with the per-bit energies claimed | +| Energy, the memory | 2.0 nJ per GDDR7 read (1.5 to 2.6), 1.2 on HBM3, 0.25 on the SRAM die at W = 1: 0.256 / 0.154 / 0.032 microjoules per hash | linear in N plus the static and controller terms (35 W on the GDDR7 board) | the device's activate energy (chip-model-v3 5.3, modelled from HBM2's breakdown and the vendors' per-bit figures) | physical (claimed breakdowns; the card's marginal measured at 8.7 nJ per read) | +| Energy, the shadow | 102,612 lane-ops x 6.55 pJ (placed, N5) = 0.67 microjoules; 0.48 at N3; the 32-lane core about 0.58 | linear in N; the clock, the window and the units measured per op; the leakage per lane | the placed rows (sections 3 to 5); the SRAM term's band | physical (measured placed; the SRAM term modelled) | +| Energy, the machine | the power train (PSU 92 percent, VRM 90), cooling (3 percent), the host (0.85 W per machine) | fixed per machine, amortised over its rate | section 6's rows | approximate | +| Amortisation, the set-up | the dataset build 0.7 J per GiB per window per machine; the host USD 15 and 0.85 W per machine; the era's registers | shared by every engine of the machine and every hash of the window: 1.4e-12 J per hash, under 1 percent of capex | nothing to amortise further: the set-up is already a window term | closed-form (the build measured on a card, the host approximate) | +| Amortisation, the silicon | the core die USD 0.11 to 0.55 per MH/s, the memory USD 320 to 1,000 per board, the package, the board | spread over the life (0.5 to 3 years): 0.085 USD per TH at 3 years on the GDDR7 machine, 0.22 to 0.27 on the cards | capex per sustained MH/s is the larger half of the chip's edge (section 8) | the core measured placed, the memory and board claimed or approximate | +| Selective participation | the per-epoch ratio spreads 9 percent (5th to 95th percentile 1.45x to 1.58x same-node) | a specialist mining the best x of epochs earns x of the revenue at +2 to +5 percent of ratio | nothing to gain | closed-form on the band (the draws uniform within it, approximate) | + +The reading: capacity is a ticket (D once per machine, in DRAM at USD 10 per GiB or SRAM at USD 250), bandwidth is +the activate ceiling per dollar of devices and is the card's own, energy is the memory's activate energy plus the +shadow at the placed core's pJ per op, and amortisation is already complete at one machine (the set-up is a window +term, the silicon a life term). The bounds that are closed-form: the capacity and state terms, the bit counts of +data-local execution, the bytes, the set-up amortisation, selective participation. The bounds that rest on physical +design: the SRAM macro's access energy (the one modelled term in the placed rows), the HBM3 activate ceiling, the +SRAM die's wire term and the on-package hop, the device activate energies (claimed breakdowns), and the board's +power train and cooling (approximate). Nothing in the model rewards a chip for anything but the memory's own +activate energy and the shadow's pJ per op, which is where sections 6 and 13 put the honest bracket. + +## 17. Review B's F05: the reg64 address mixer's incremental form, priced at the placed level (20:0x BST; the clock 23:30) + +The finding: the connected-state candidate's address (the fold over all 63 live registers before every load) has an +exact incremental form through a prefix-XOR tree, so a chip never reads and folds 63 registers per load; a design +that assumes the literal fold overstates the chip's cost, and a one-register perturbation test says nothing about a +minimum circuit. The shipped class (v4, v5, v6) folds ONE source register per load (this core's load op), so the +finding touches the connected-state candidate (killed as a class at 17:25 BST on other grounds) and the bound it +sets for any future class that couples the address to the whole window. Three designs for that coupling on this +core, priced with the placed per-op figures (6.55 pJ per lane-op at N5 on the class v4 draw; the SRAM macro 3.5 pJ +per 256-bit access, 2.0 to 7.0, shared by 8 lanes; the 102,612-op hash with 128 loads): + +| Design | Extra state per lane | Extra work | Extra lane-ops per hash | Extra energy per hash at N5 | Share of the chip's shadow energy (0.672 microjoules) | +|---|---|---|---|---|---| +| The literal fold: read and fold 63 registers at each load | none | 63 reads of the window (SIMD, one macro access per 8 lanes each) and 63 rotate-xor ops per load | 128 x 63 = 8,064 (plus 8,064 macro accesses per 8 lanes: 3.5 pJ x 8,064 / 8 = 3.5 nJ) | 8,064 x 6.55 pJ + 3.5 nJ = 56 nJ (48 to 72) | +8.4 percent | +| The prefix-XOR tree (the reviewer's form, floor lane 3's Fenwick reading): 65 words of prefix state, seven read-modify-writes per register write, eleven ops per load | 260 bytes in a second gated macro (one per 8 lanes, the same shape as the window) | 7 x 2 macro accesses and 7 xor-rotate ops per instruction that writes the window; 11 ops per load | on the base program's 512 writes and 128 loads: 4,992 ops and 7,168 accesses per 8 lanes; on every instruction of the hash (the shadow block writes the same window): 718,000 ops and 1.44 M accesses | base program only: 33 nJ of ops + 3.1 nJ of accesses = 36 nJ; every instruction: 4.7 microjoules of ops + 0.63 of accesses (7x the whole shadow) | +5.4 percent if the shadow block's writes are exempt; +800 percent if they are not | +| The running total (this lane's form: the fold is linear over GF(2), so a write to register j changes the fold by a fixed rotation of old xor new, and the old value is already read in phase 0 of this core's slot) | one 32-bit register per lane (flops, written every instruction) | two rotates and two xors per instruction, merged into the write phase | 102,612 (one op's worth of datapath per instruction, no extra macro access) | about 1.0 pJ per instruction (an xor-rotate pair on operands already latched; the add row's datapath term is 1.7 pJ, approximate): 0.10 microjoules | +15 percent, paid on every instruction; +0.8 percent if only the base program's writes count | + +Reading. (1) Which form the adversary picks depends on how many instructions write the window between loads: at +the shipped shape (one load per 800 instructions once the shadow block is in) the LITERAL fold is the cheapest +(+8.4 percent of the shadow, 56 nJ), because any incremental form pays per write and the shadow writes 800 times +per load; the running total wins only if the shadow block's registers are exempt from the fold (then +0.8 +percent), and the Fenwick tree never wins on this core (its seven read-modify-writes per instruction are macro +accesses, the one term this core pays dearly for). Floor lane 3's 30 nJ for the tree counts the base program's +writes only; the row above shows both counts. (2) The bound the review asks for: the cheapest adversary form on +the placed core costs at most 56 nJ per hash (the literal fold; 48 to 72 across the SRAM band) and at least 5 nJ +(the running total with the shadow exempt), so the complete-machine bracket for a class carrying the whole-window +fold moves from 1.5x (1.3 to 1.7) same-node to 1.42x to 1.49x (the chip's machine energy 1.528 to 1.53 + 0.056 x +1.21 = 1.60 microjoules at the literal fold; 1.535 at the running total), and 1.8x a node ahead to 1.7x to 1.8x: +the coupling buys the honest side at most 0.08x on this core, which is inside the SRAM term's band and agrees +with the connected-state lane's KILL (1.10x against its 1.25x gate) and floor lane 3's 2.6 percent on the GDDR7 +board. (3) No row here assumes a 63-read cost that the adversary can avoid: the literal fold is priced as 63 SIMD +macro reads shared by 8 lanes (3.5 nJ per hash of accesses, not 63 window reads per lane), and the incremental +forms are priced per write. The shipped class is untouched: its fold reads one register. (4) The GPU side of the same two forms (the fleet +lane, 20:4x BST, the hash lane's hl-v6-all fold form against hl-v6-all-prefix, the same program id and vectors, +stock clocks, 250 batches, fingerprints equal; evidence on build-1 under /srv/artefacts/tas/54900078/ and +/srv/artefacts/tas/si1xc4yhpakk1v/): the 5090 reads 70.6 MH/s at 437.8 W (6.20 nJ per hash) on the literal fold +and 70.2 at 500.0 W (7.13 nJ) on the prefix form, 100 against 248 registers per thread; the 4090 31.3 MH/s at +238.1 W (7.60 nJ) against 31.3 at 231.7 W (7.41 nJ), 93 against 154 registers. The rate is unmoved on both cards +(both are bound at the dataset reads) and the prefix form costs the 5090 14 percent more board power for the same +hashes; so on the card as on this core the cheapest form at the shipped shape is the literal fold, and the +review's incremental form is a design the adversary can take and does not want. (5) The bound restated for the +connected-state class's OWN shape (the hash lane's closed form, 20:5x BST: `address_source(s) = r[s] ^ ror(P_s, 1) +^ (S ^ P_s ^ a[s])`, a[k] = rotl(r[k], (63 - k) mod 32), S the xor of every a[k], P_s the prefix xor below s; +32 loads per 64-instruction iteration, 256 loads and 512 register writes per hash in the base program): there the +literal fold is 256 x 63 = 16,128 lane-ops and 16,128 SIMD macro reads per hash, 113 nJ at N5 (97 to 145), and the +prefix form is one running-total update per write (an xor-rotate pair, about 1 pJ) plus six Fenwick read-modify- +writes per write (twelve macro accesses per 8 lanes, 5.3 pJ) and six prefix reads with three xors per load: 512 x +12.3 pJ + 256 x 5.6 pJ = 7.7 nJ (5 to 15). So on that class the review is right by 14x: the chip pays about 8 nJ +per hash for the whole-window coupling, 1.2 percent of its shadow energy, and the complete-machine bracket moves +from 1.5x to 1.49x same-node (not to 1.42x, which was the literal fold's cost); the card meanwhile keeps the fold +at 6.20 nJ per hash on the 5090 and would pay 7.13 on the prefix form. The two shapes together: the chip's cost of +the coupling is 8 nJ (connected-state shape, prefix form) to 56 nJ (shipped shape, literal form), 0.02x to 0.08x +of the bracket, and no design in the record charges the chip a 63-read cost it can avoid. diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md new file mode 100644 index 000000000..b938f30c3 --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md @@ -0,0 +1,10 @@ +# The chain-seed draw on the frozen object: the freeze's (c''') read (8 October 2026, 21:5x to 22:3x UK) + +The coordinator's blocking read: the research pack hl-v6-all (4de7b836cc40a4ea) was drawn with the genesis epoch seed over the node1 state stream, a pair the node's class v5 pairing check refuses; on the chain's own seed the engine draws another program. The node lane read the live devnet-4 node's program-id line verbatim at 21:41:51 UK: epoch seed af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 (the block hash), era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 (the era seed stays the genesis hex), day 20730 (day hex 69676e65756d2d6461792ffa50000000000000), the node1 state (block 159357, root 1c583d35..., file sha abb58003...), class mx8+sh256x27+state+reg64c+fold+rw, generator 6, attempt 0: program **2a1d6caab4c24564**. The harness on the frozen tree 1a938abe4 (class-v6-census-all4 bdbe85bfb, binary f4e93766d5a3dc46 on build-4) reproduces that id from those inputs on the class-string path; the second column is the draw with the block hash as the era too (442a1691b3e3507f, era label 93a14ac6), which an earlier line named and the node lane's read ruled out; it is kept as the research comparison. Both rows on build-4 under the lease pool at 21:5x UK, the sitestats and census TSVs beside this file. + +| Draw | Program (class) | The pair | (A) the whole rule with the (c''') floor on the program; per site over 2^20 evaluations | (B) the attempts census, 256 chain-shaped seeds under the pair's era and state | +|---|---|---|---|---| +| **the engine's draw (the freeze's read)** | 2a1d6caab4c24564 (mx8-erad810f22d+sh256x27+state+reg64c+fold+rw) | seed af89be5d..., era 0:edc4fa84..., day 20730, node1 state | ACCEPTED; min site ratio 0.99988, under 0.98: 0, under 0.995: 0; largest bucket +6.25 sigma; worst free bit -3.06 sigma; sites over 6 sigma 0 | 256 of 256, 0 exhausted at 256, r 0.129, mean attempt 0.15, max 2, (c''') refused 0 of 294; parts a' 23 b 7 a 4 reg64 3 c 1 | +| the research comparison | 442a1691b3e3507f (mx8-era93a14ac6+sh256x27+state+reg64c+fold+rw) | seed af89be5d..., era 0:af89be5d..., day 20730, node1 state | ACCEPTED; min site ratio 0.99992, under 0.98: 0, under 0.995: 0; largest bucket +5.25 sigma; worst free bit 2.91 sigma; sites over 6 sigma 0 | 256 of 256, 0 exhausted at 256, r 0.129, mean attempt 0.15, max 2, (c''') refused 0 of 294; parts a' 23 b 7 a 4 reg64 3 c 1 | + +Verdict: the engine's draw 2a1d6caab4c24564 PASSES the sub-version 3 rule with the (c''') floor (every site clear of 0.98 and 0.995 at 0.99988, the largest 256-item bucket +6.25 sigma on one site, which the rule does not bound and the record's clean full-window sites read to +5.5, the worst free index bit 3.06 sigma, no site over 6 sigma) and the attempts census (256 of 256 chain-shaped seeds accepted inside two attempts, 0 exhausted, 0 (c''') refusals: the same 294 candidates and parts as the research pack's, since the census draws its own seeds under the pair's era and state). The research comparison reads the same on every line but the bucket (+5.25). The freeze's object on the chain's own seed is sound under the rule; the research pack's rows (census-packs.md section 7) are the same class on the genesis seed. diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/census.tsv b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/census.tsv new file mode 100644 index 000000000..d6b25709f --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/census.tsv @@ -0,0 +1,259 @@ +# census class mx8+sh256x27+state+reg64c+fold+rw eras [0] seeds 256 era-widths 4 state /srv/builds/v6-census/packs/node1-state.igsd1 erahex af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 weights base bittest off bin f4e93766d5a3dc46 start 2026-10-08T20:50:59Z host igneum-build-4 threads 16 +cand era seed candidates accepted attempt bit_z bit_site bit_bit reasons +census 0 8 1 1 0 nan - - +census 0 5 1 1 0 3.3 3 21 +census 0 4 1 1 0 3.4 5 23 +census 0 10 1 1 0 nan - - +census 0 12 1 1 0 3.2 1 23 +census 0 9 1 1 0 3.3 10 22 +census 0 7 1 1 0 2.8 12 25 +census 0 3 1 1 0 2.8 0 24 +census 0 0 1 1 0 nan - - +census 0 14 1 1 0 nan - - +census 0 11 1 1 0 2.6 5 22 +census 0 2 1 1 0 2.9 13 1 +census 0 13 1 1 0 3.1 0 20 +census 0 15 1 1 0 3.3 5 21 +census 0 6 1 1 0 nan - - +census 0 1 1 1 0 nan - - +census 0 20 1 1 0 nan - - +census 0 17 1 1 0 2.7 1 26 +census 0 25 2 1 1 nan - - a=1; +census 0 23 1 1 0 nan - - +census 0 18 1 1 0 3.8 12 7 +census 0 24 1 1 0 2.8 14 19 +census 0 19 1 1 0 3.0 10 17 +census 0 27 1 1 0 nan - - +census 0 16 1 1 0 nan - - +census 0 28 1 1 0 nan - - +census 0 22 1 1 0 nan - - +census 0 29 1 1 0 3.1 9 18 +census 0 26 1 1 0 3.3 1 7 +census 0 30 1 1 0 2.6 3 7 +census 0 21 2 1 1 3.0 4 26 reg64=1; +census 0 31 2 1 1 nan - - b=1; +census 0 37 1 1 0 3.4 8 10 +census 0 34 1 1 0 nan - - +census 0 32 1 1 0 nan - - +census 0 35 1 1 0 3.3 15 16 +census 0 36 2 1 1 2.9 14 6 b=1; +census 0 38 1 1 0 3.1 7 13 +census 0 33 1 1 0 3.3 0 6 +census 0 39 1 1 0 nan - - +census 0 43 1 1 0 nan - - +census 0 41 1 1 0 nan - - +census 0 45 1 1 0 nan - - +census 0 42 2 1 1 nan - - a'=1; +census 0 46 1 1 0 nan - - +census 0 44 2 1 1 3.0 1 1 a'=1; +census 0 47 1 1 0 nan - - +census 0 40 1 1 0 2.6 13 22 +census 0 52 1 1 0 nan - - +census 0 50 1 1 0 nan - - +census 0 49 1 1 0 2.8 6 1 +census 0 48 1 1 0 2.9 5 2 +census 0 55 1 1 0 3.4 8 9 +census 0 53 2 1 1 3.4 11 21 b=1; +census 0 54 1 1 0 3.4 3 2 +census 0 56 2 1 1 nan - - a'=1; +census 0 51 2 1 1 3.5 15 3 reg64=1; +census 0 60 1 1 0 nan - - +census 0 58 1 1 0 nan - - +census 0 57 1 1 0 nan - - +census 0 61 1 1 0 nan - - +census 0 59 1 1 0 3.0 3 16 +census 0 62 1 1 0 nan - - +census 0 64 1 1 0 2.9 12 26 +census 0 63 1 1 0 3.5 0 19 +census 0 66 1 1 0 3.0 15 8 +census 0 67 2 1 1 4.0 1 2 a=1; +census 0 68 1 1 0 3.0 11 7 +census 0 69 1 1 0 nan - - +census 0 70 1 1 0 3.3 6 6 +census 0 72 1 1 0 3.2 11 5 +census 0 76 1 1 0 nan - - +census 0 74 1 1 0 2.9 8 21 +census 0 71 2 1 1 nan - - a=1; +census 0 75 1 1 0 nan - - +census 0 65 1 1 0 nan - - +census 0 77 1 1 0 3.2 6 14 +census 0 78 1 1 0 3.5 3 25 +census 0 73 1 1 0 nan - - +census 0 80 2 1 1 nan - - a'=1; +census 0 81 1 1 0 nan - - +census 0 79 1 1 0 3.4 13 24 +census 0 82 1 1 0 3.8 8 0 +census 0 83 1 1 0 3.3 3 24 +census 0 84 1 1 0 nan - - +census 0 85 1 1 0 3.4 4 25 +census 0 86 1 1 0 nan - - +census 0 88 1 1 0 nan - - +census 0 87 2 1 1 nan - - a'=1; +census 0 91 1 1 0 2.7 1 23 +census 0 89 1 1 0 nan - - +census 0 92 1 1 0 3.2 3 10 +census 0 90 2 1 1 3.1 7 8 b=1; +census 0 94 1 1 0 3.5 1 15 +census 0 93 1 1 0 nan - - +census 0 95 2 1 1 2.9 4 7 a'=1; +census 0 97 1 1 0 3.2 6 10 +census 0 96 1 1 0 3.6 1 26 +census 0 99 1 1 0 3.3 1 23 +census 0 101 1 1 0 nan - - +census 0 103 1 1 0 nan - - +census 0 104 1 1 0 nan - - +census 0 102 1 1 0 2.9 3 14 +census 0 98 1 1 0 nan - - +census 0 100 1 1 0 3.9 10 2 +census 0 105 1 1 0 nan - - +census 0 106 1 1 0 nan - - +census 0 107 1 1 0 3.0 15 10 +census 0 108 1 1 0 2.8 9 25 +census 0 109 1 1 0 nan - - +census 0 113 1 1 0 nan - - +census 0 112 1 1 0 nan - - +census 0 111 1 1 0 3.3 13 8 +census 0 110 1 1 0 3.2 9 11 +census 0 114 1 1 0 nan - - +census 0 115 2 1 1 nan - - b=1; +census 0 116 1 1 0 3.4 12 10 +census 0 118 1 1 0 3.0 4 20 +census 0 117 1 1 0 nan - - +census 0 120 1 1 0 3.0 11 0 +census 0 119 1 1 0 nan - - +census 0 121 1 1 0 3.0 3 5 +census 0 122 1 1 0 2.8 0 12 +census 0 126 1 1 0 3.0 0 19 +census 0 127 2 1 1 nan - - a=1; +census 0 128 1 1 0 3.4 5 6 +census 0 129 2 1 1 2.9 11 22 a'=1; +census 0 124 1 1 0 nan - - +census 0 130 1 1 0 nan - - +census 0 131 1 1 0 nan - - +census 0 132 1 1 0 nan - - +census 0 133 1 1 0 nan - - +census 0 123 1 1 0 3.4 13 21 +census 0 134 1 1 0 3.3 3 12 +census 0 125 2 1 1 3.3 14 6 b=1; +census 0 135 1 1 0 nan - - +census 0 136 1 1 0 nan - - +census 0 137 1 1 0 nan - - +census 0 138 1 1 0 3.0 5 13 +census 0 140 2 1 1 nan - - a'=1; +census 0 143 1 1 0 nan - - +census 0 141 1 1 0 3.3 9 23 +census 0 139 1 1 0 nan - - +census 0 142 2 1 1 2.8 10 22 a'=1; +census 0 144 1 1 0 nan - - +census 0 145 1 1 0 3.4 2 23 +census 0 147 1 1 0 3.2 2 16 +census 0 146 1 1 0 3.4 1 5 +census 0 151 1 1 0 2.5 2 6 +census 0 150 1 1 0 3.9 14 11 +census 0 148 1 1 0 nan - - +census 0 152 1 1 0 2.7 9 4 +census 0 153 1 1 0 3.0 13 13 +census 0 154 2 1 1 nan - - a'=1; +census 0 155 1 1 0 nan - - +census 0 157 1 1 0 nan - - +census 0 158 1 1 0 nan - - +census 0 159 1 1 0 3.8 15 23 +census 0 156 1 1 0 3.4 1 25 +census 0 149 1 1 0 nan - - +census 0 160 1 1 0 nan - - +census 0 162 1 1 0 2.5 13 15 +census 0 163 2 1 1 3.4 1 20 a'=1; +census 0 166 1 1 0 nan - - +census 0 165 1 1 0 nan - - +census 0 164 1 1 0 nan - - +census 0 167 3 1 2 nan - - a'=2; +census 0 168 1 1 0 2.6 7 10 +census 0 170 1 1 0 3.3 14 2 +census 0 173 3 1 2 2.7 9 6 a'=2; +census 0 171 1 1 0 3.4 3 1 +census 0 172 2 1 1 3.5 3 1 a'=1; +census 0 161 1 1 0 nan - - +census 0 174 1 1 0 nan - - +census 0 175 1 1 0 nan - - +census 0 176 1 1 0 nan - - +census 0 169 2 1 1 nan - - a'=1; +census 0 177 1 1 0 nan - - +census 0 180 1 1 0 nan - - +census 0 178 1 1 0 nan - - +census 0 179 1 1 0 nan - - +census 0 182 1 1 0 3.1 14 3 +census 0 183 1 1 0 nan - - +census 0 181 1 1 0 3.4 15 23 +census 0 184 2 1 1 3.5 12 10 a'=1; +census 0 186 2 1 1 2.8 4 24 a'=1; +census 0 187 1 1 0 nan - - +census 0 185 1 1 0 nan - - +census 0 189 1 1 0 2.8 14 12 +census 0 190 2 1 1 nan - - a'=1; +census 0 192 1 1 0 nan - - +census 0 193 1 1 0 2.8 4 4 +census 0 195 1 1 0 nan - - +census 0 194 1 1 0 nan - - +census 0 196 1 1 0 3.3 14 19 +census 0 191 1 1 0 nan - - +census 0 188 1 1 0 3.5 15 15 +census 0 197 1 1 0 2.8 7 0 +census 0 198 1 1 0 3.0 12 9 +census 0 200 1 1 0 2.8 11 1 +census 0 199 1 1 0 nan - - +census 0 202 1 1 0 2.6 8 0 +census 0 201 1 1 0 3.2 3 25 +census 0 203 1 1 0 nan - - +census 0 204 1 1 0 nan - - +census 0 205 1 1 0 2.6 5 0 +census 0 207 1 1 0 nan - - +census 0 206 2 1 1 3.2 12 25 a'=1; +census 0 208 1 1 0 2.5 8 3 +census 0 209 1 1 0 3.2 5 17 +census 0 210 1 1 0 2.8 9 18 +census 0 211 1 1 0 nan - - +census 0 212 1 1 0 nan - - +census 0 213 1 1 0 3.1 9 6 +census 0 215 1 1 0 nan - - +census 0 216 1 1 0 nan - - +census 0 218 2 1 1 3.3 8 1 a'=1; +census 0 219 1 1 0 nan - - +census 0 220 1 1 0 nan - - +census 0 217 1 1 0 3.4 5 11 +census 0 221 1 1 0 nan - - +census 0 222 1 1 0 nan - - +census 0 214 1 1 0 3.3 5 21 +census 0 223 1 1 0 nan - - +census 0 225 1 1 0 2.8 0 15 +census 0 224 1 1 0 3.3 3 4 +census 0 226 1 1 0 3.1 7 16 +census 0 228 1 1 0 nan - - +census 0 229 1 1 0 nan - - +census 0 227 1 1 0 3.5 12 25 +census 0 234 1 1 0 nan - - +census 0 232 1 1 0 nan - - +census 0 235 1 1 0 nan - - +census 0 237 1 1 0 nan - - +census 0 236 1 1 0 3.1 0 18 +census 0 238 1 1 0 3.2 15 3 +census 0 239 1 1 0 nan - - +census 0 230 1 1 0 3.5 4 0 +census 0 240 2 1 1 nan - - b=1; +census 0 233 2 1 1 2.9 11 20 c=1; +census 0 241 1 1 0 3.2 7 17 +census 0 243 1 1 0 3.1 10 18 +census 0 242 1 1 0 nan - - +census 0 231 1 1 0 nan - - +census 0 245 1 1 0 nan - - +census 0 247 1 1 0 2.8 1 4 +census 0 246 2 1 1 2.8 10 23 a'=1; +census 0 244 2 1 1 nan - - reg64=1; +census 0 248 1 1 0 2.7 11 8 +census 0 249 1 1 0 3.4 15 15 +census 0 251 1 1 0 nan - - +census 0 250 1 1 0 3.4 15 24 +census 0 252 1 1 0 3.2 7 18 +census 0 253 1 1 0 3.4 6 10 +census 0 254 1 1 0 3.7 10 20 +census 0 255 1 1 0 3.1 8 20 +# end 2026-10-08T20:52:19Z rows=257 diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/run.txt b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/run.txt new file mode 100644 index 000000000..036bd1dda --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/run.txt @@ -0,0 +1 @@ +# pack cs-era-block class mx8+sh256x27+state+reg64c+fold+rw epoch af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 day 69676e65756d2d6461792ffa50000000000000 era af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 state /srv/builds/v6-census/packs/node1-state.igsd1 day-index 20730 era-widths 4 bin f4e93766d5a3dc46 f8 host igneum-build-4 start 2026-10-08T20:50:55Z diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/show.txt b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/show.txt new file mode 100644 index 000000000..237f07aa7 --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/show.txt @@ -0,0 +1,67 @@ +seed "igneum-epoch/af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3" generator v6 class mx8-era93a14ac6+sh256x27+state+reg64c+fold+rw attempt 0 program id 442a1691b3e3507f seed words 9c8caa3d 83537296 f21169a4 12d4d157 66e0ce33 cc049080 8579c352 4c6e4ac9 +op mix load=16 add=10 shfl=8 rotl=5 rotr=5 xor=5 mad=4 mul=4 sub=4 mulhi=3 loads/hash 128 bytes/hash 512 +era 93a14ac6 (igneum-era/0/af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3): width 4 B, stride mul 0x5ea34e0b rot 12, interleave [10, 11, 13, 14], windows (site:shrink:offset) 1:0:0 15:1:0 27:2:1 28:0:0 30:1:1 32:1:0 33:2:3 42:0:0 48:1:0 52:0:0 55:2:2 56:0:0 58:1:1 59:0:0 60:1:0 62:1:0 + 0: mad dst=7 src=3 src2=3 imm=0xd095f540 imm2=0xd3789b38 rot=19 bit=4 mask=4 + 1: load dst=1 src=7 src2=5 imm=0x390bbbd7 imm2=0x1b44071a rot=5 bit=13 mask=16 + 2: rotl dst=0 src=6 src2=7 imm=0xcd1e3e94 imm2=0xf0479df0 rot=29 bit=10 mask=2 + 3: shfl dst=5 src=6 src2=4 imm=0x78c099f8 imm2=0xc6d6c6bc rot=25 bit=21 mask=1 + 4: mulhi dst=5 src=3 src2=1 imm=0x2e8aa8d1 imm2=0x446c336a rot=23 bit=31 mask=16 + 5: rotl dst=7 src=1 src2=0 imm=0x46701a4a imm2=0xc2255717 rot=27 bit=20 mask=8 + 6: mad dst=4 src=2 src2=0 imm=0x487da55c imm2=0xf4675ef7 rot=26 bit=1 mask=8 + 7: rotl dst=2 src=6 src2=4 imm=0x74fdbac4 imm2=0x30e49db4 rot=11 bit=9 mask=16 + 8: mul dst=6 src=0 src2=4 imm=0x69e895ee imm2=0x66ebcedd rot=24 bit=11 mask=16 + 9: shfl dst=6 src=1 src2=7 imm=0x1510cbd0 imm2=0x607acada rot=4 bit=3 mask=2 +10: add dst=0 src=2 src2=2 imm=0x33a68b0c imm2=0xffb7f024 rot=27 bit=1 mask=4 +11: xor dst=0 src=2 src2=4 imm=0x61b96f54 imm2=0x7d5468b0 rot=30 bit=28 mask=8 +12: sub dst=7 src=4 src2=1 imm=0x39217118 imm2=0x248e3f9b rot=29 bit=7 mask=16 +13: shfl dst=1 src=4 src2=2 imm=0x6c12c43b imm2=0x6b60595d rot=20 bit=23 mask=8 +14: xor dst=1 src=0 src2=0 imm=0x030181c6 imm2=0x52fbbc27 rot=1 bit=28 mask=4 +15: load dst=5 src=0 src2=2 imm=0x5b20e3f6 imm2=0xa84ab3b3 rot=24 bit=31 mask=8 +16: xor dst=5 src=4 src2=4 imm=0x6fc104e8 imm2=0x1a522a5c rot=27 bit=8 mask=8 +17: shfl dst=6 src=7 src2=6 imm=0x5f5b071a imm2=0x39dc91da rot=16 bit=6 mask=16 +18: rotr dst=2 src=7 src2=0 imm=0x07b3a28c imm2=0x33193f0c rot=18 bit=3 mask=1 +19: add dst=4 src=1 src2=5 imm=0x0229d185 imm2=0x51cb8f70 rot=29 bit=26 mask=1 +20: add dst=4 src=7 src2=1 imm=0xc39836f7 imm2=0x0c001b55 rot=8 bit=7 mask=16 +21: add dst=0 src=3 src2=4 imm=0xb7d06b34 imm2=0x1ae7a0ac rot=9 bit=3 mask=4 +22: mad dst=2 src=6 src2=7 imm=0x0978477e imm2=0x2fec3e13 rot=21 bit=3 mask=16 +23: add dst=3 src=5 src2=7 imm=0x95cba5dd imm2=0x22934c58 rot=8 bit=19 mask=2 +24: mulhi dst=5 src=3 src2=0 imm=0x14b79a1b imm2=0xccae3d33 rot=5 bit=15 mask=16 +25: xor dst=0 src=3 src2=7 imm=0x22f74d7f imm2=0x782f1722 rot=18 bit=25 mask=4 +26: mul dst=6 src=3 src2=6 imm=0xf774717f imm2=0x3a1a2c3a rot=28 bit=25 mask=16 +27: load dst=3 src=7 src2=2 imm=0xf0d88d7d imm2=0x0fc8051c rot=14 bit=1 mask=16 +28: load dst=3 src=0 src2=5 imm=0xac8eb588 imm2=0x57844c72 rot=12 bit=8 mask=2 +29: rotr dst=6 src=7 src2=1 imm=0x89b07c78 imm2=0x90c747d7 rot=13 bit=30 mask=1 +30: load dst=1 src=4 src2=7 imm=0xdd34b81d imm2=0x96e5cb94 rot=26 bit=16 mask=1 +31: add dst=1 src=2 src2=3 imm=0x2fa2e27a imm2=0xbf8507da rot=27 bit=5 mask=1 +32: load dst=2 src=1 src2=1 imm=0x4df1d479 imm2=0xea698909 rot=29 bit=12 mask=4 +33: load dst=3 src=2 src2=1 imm=0xaa35122f imm2=0x01516545 rot=12 bit=18 mask=1 +34: mul dst=3 src=5 src2=7 imm=0x6a941ac2 imm2=0xb56c91d9 rot=24 bit=16 mask=1 +35: rotl dst=1 src=6 src2=7 imm=0xe8aa4cfe imm2=0x0d359401 rot=2 bit=3 mask=2 +36: shfl dst=1 src=5 src2=1 imm=0xd090168f imm2=0x3ea71d89 rot=9 bit=3 mask=4 +37: sub dst=0 src=4 src2=1 imm=0xdbda427b imm2=0xd9607488 rot=5 bit=12 mask=2 +38: rotr dst=4 src=2 src2=7 imm=0xe3e3804c imm2=0xccdc9668 rot=27 bit=13 mask=16 +39: mulhi dst=4 src=1 src2=2 imm=0x5d14fe55 imm2=0xb6db1d85 rot=17 bit=18 mask=4 +40: rotr dst=0 src=1 src2=4 imm=0xc77a2d1f imm2=0x5a85c407 rot=10 bit=31 mask=1 +41: add dst=2 src=3 src2=1 imm=0xfe28f51d imm2=0xf439f8e7 rot=5 bit=8 mask=2 +42: load dst=1 src=2 src2=5 imm=0xe1b6fb46 imm2=0x23bb6ba4 rot=29 bit=22 mask=1 +43: xor dst=7 src=5 src2=6 imm=0x34988c9d imm2=0xf8c6c4a8 rot=2 bit=21 mask=8 +44: shfl dst=6 src=2 src2=2 imm=0x14f4d589 imm2=0x868d3c75 rot=29 bit=31 mask=8 +45: mul dst=1 src=4 src2=1 imm=0x081dddbd imm2=0xc8e4de44 rot=23 bit=11 mask=16 +46: rotl dst=0 src=6 src2=2 imm=0xaec2cb92 imm2=0x03157ee4 rot=14 bit=5 mask=16 +47: add dst=1 src=3 src2=7 imm=0xf1719bbd imm2=0x14bb2234 rot=24 bit=7 mask=16 +48: load dst=1 src=6 src2=6 imm=0x30e39813 imm2=0x9ce47150 rot=22 bit=10 mask=1 +49: sub dst=5 src=1 src2=7 imm=0xaabdf6d2 imm2=0x0688a461 rot=13 bit=28 mask=2 +50: add dst=2 src=3 src2=6 imm=0xb129b2b4 imm2=0x4611fe29 rot=3 bit=14 mask=16 +51: sub dst=0 src=2 src2=1 imm=0xfe651d02 imm2=0x7c1929a9 rot=22 bit=31 mask=4 +52: load dst=4 src=0 src2=4 imm=0xf906070a imm2=0xf301cff4 rot=5 bit=25 mask=1 +53: mad dst=3 src=1 src2=4 imm=0xab213c09 imm2=0xf6d6f3fa rot=16 bit=28 mask=1 +54: shfl dst=4 src=1 src2=7 imm=0xf6dafbae imm2=0xdbfc32c7 rot=12 bit=1 mask=16 +55: load dst=6 src=5 src2=5 imm=0x881eaf9c imm2=0x7c50f5c8 rot=25 bit=22 mask=16 +56: load dst=2 src=4 src2=1 imm=0x899bf6e0 imm2=0xbde5b6ee rot=24 bit=10 mask=8 +57: shfl dst=5 src=7 src2=6 imm=0xea9c50d2 imm2=0xd2a8c99b rot=12 bit=28 mask=1 +58: load dst=1 src=5 src2=3 imm=0xad4912ca imm2=0x546d00b2 rot=7 bit=1 mask=1 +59: load dst=2 src=7 src2=1 imm=0x37cea58f imm2=0x13e31ff0 rot=21 bit=21 mask=16 +60: load dst=2 src=1 src2=2 imm=0x33f9a95e imm2=0xda1c8a2e rot=22 bit=28 mask=8 +61: add dst=3 src=2 src2=2 imm=0x0a051d32 imm2=0xe9ed866d rot=30 bit=1 mask=4 +62: load dst=0 src=2 src2=2 imm=0xab1dd54b imm2=0xc9fcaae2 rot=9 bit=2 mask=1 +63: rotr dst=5 src=0 src2=5 imm=0x1f0279bd imm2=0x223e7b9c rot=11 bit=3 mask=16 diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/sitestats.tsv b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/sitestats.tsv new file mode 100644 index 000000000..fae6264ea --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-block/sitestats.tsv @@ -0,0 +1,20 @@ +program id 442a1691b3e3507f class mx8-era93a14ac6+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 +rule: ACCEPTED, distinct 128.000 per hash, saturated 0, bias max 66 +site instr win off width distinct ratio under_c2 under_c3 bucket_ratio bucket_z bucket_id bit_z bit top_count +0 1 0 0 1 1046493 0.99997 0 0 2.250 5.00 43706 -1.72 14 3 +1 15 1 0 1 1044395 0.99992 0 0 1.688 3.89 10447 2.09 18 3 +2 27 2 1 1 1040460 1.00007 0 0 1.531 4.25 21546 2.38 5 3 +3 28 0 0 1 1046585 1.00005 0 0 2.062 4.25 11544 -2.58 22 3 +4 30 1 1 1 1044506 1.00002 0 0 1.844 4.77 41807 2.26 20 3 +5 32 1 0 1 1044487 1.00001 0 0 1.844 4.77 26116 1.91 0 3 +6 33 2 3 1 1040412 1.00003 0 0 1.500 4.00 49321 -1.51 23 3 +7 42 0 0 1 1046488 0.99996 0 0 2.125 4.50 9835 -2.25 0 3 +8 48 1 0 1 1044552 1.00007 0 0 1.812 4.60 17972 -1.87 6 3 +9 52 0 0 1 1046470 0.99994 0 0 2.188 4.75 49022 1.54 17 3 +10 55 2 2 1 1040461 1.00007 0 0 1.500 4.00 35424 1.72 24 3 +11 56 0 0 1 1046571 1.00004 0 0 2.312 5.25 12278 -1.84 2 3 +12 58 1 1 1 1044543 1.00006 0 0 1.750 4.24 33127 -2.12 16 3 +13 59 0 0 1 1046537 1.00001 0 0 2.125 4.50 1374 2.91 3 3 +14 60 1 0 1 1044566 1.00008 0 0 1.812 4.60 5226 -2.44 19 3 +15 62 1 0 1 1044430 0.99995 0 0 1.906 5.13 2829 -1.92 6 3 +summary: sites 16, min ratio 0.99992, under 0.98: 0, under 0.995: 0, bucket z max 5.25, bit z max 2.91, sites over 6 sigma 0, 3.9 s diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/census.tsv b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/census.tsv new file mode 100644 index 000000000..964403369 --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/census.tsv @@ -0,0 +1,259 @@ +# census class mx8+sh256x27+state+reg64c+fold+rw eras [0] seeds 256 era-widths 4 state /srv/builds/v6-census/packs/node1-state.igsd1 erahex edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 weights base bittest off bin f4e93766d5a3dc46 start 2026-10-08T20:50:55Z host igneum-build-4 threads 16 +cand era seed candidates accepted attempt bit_z bit_site bit_bit reasons +census 0 4 1 1 0 2.9 15 4 +census 0 6 1 1 0 nan - - +census 0 14 1 1 0 3.5 12 21 +census 0 5 1 1 0 nan - - +census 0 10 1 1 0 3.0 0 2 +census 0 9 1 1 0 2.8 6 25 +census 0 0 1 1 0 nan - - +census 0 20 1 1 0 3.2 10 7 +census 0 3 1 1 0 2.8 14 3 +census 0 2 1 1 0 3.5 3 15 +census 0 7 1 1 0 3.4 1 23 +census 0 18 1 1 0 nan - - +census 0 15 1 1 0 nan - - +census 0 1 1 1 0 nan - - +census 0 12 1 1 0 3.2 9 13 +census 0 21 2 1 1 3.5 0 18 reg64=1; +census 0 8 1 1 0 2.8 9 12 +census 0 13 1 1 0 2.8 12 13 +census 0 19 1 1 0 nan - - +census 0 11 1 1 0 nan - - +census 0 16 1 1 0 nan - - +census 0 22 1 1 0 3.1 6 11 +census 0 30 1 1 0 nan - - +census 0 17 1 1 0 nan - - +census 0 23 1 1 0 nan - - +census 0 26 1 1 0 3.2 7 9 +census 0 32 1 1 0 4.4 10 21 +census 0 29 1 1 0 nan - - +census 0 34 1 1 0 3.0 12 1 +census 0 27 1 1 0 3.0 9 8 +census 0 25 2 1 1 nan - - a=1; +census 0 24 1 1 0 3.7 13 12 +census 0 33 1 1 0 nan - - +census 0 36 2 1 1 3.2 14 3 b=1; +census 0 35 1 1 0 4.2 12 12 +census 0 31 2 1 1 3.2 1 5 b=1; +census 0 39 1 1 0 nan - - +census 0 38 1 1 0 nan - - +census 0 42 2 1 1 nan - - a'=1; +census 0 37 1 1 0 3.1 13 8 +census 0 28 1 1 0 nan - - +census 0 41 1 1 0 nan - - +census 0 43 1 1 0 nan - - +census 0 44 2 1 1 nan - - a'=1; +census 0 40 1 1 0 2.8 9 25 +census 0 50 1 1 0 3.3 9 9 +census 0 53 2 1 1 nan - - b=1; +census 0 45 1 1 0 nan - - +census 0 49 1 1 0 nan - - +census 0 46 1 1 0 4.4 2 3 +census 0 48 1 1 0 nan - - +census 0 51 2 1 1 nan - - reg64=1; +census 0 57 1 1 0 3.5 6 24 +census 0 47 1 1 0 3.1 4 16 +census 0 58 1 1 0 3.0 8 17 +census 0 59 1 1 0 nan - - +census 0 62 1 1 0 3.2 9 19 +census 0 55 1 1 0 nan - - +census 0 52 1 1 0 nan - - +census 0 60 1 1 0 nan - - +census 0 61 1 1 0 3.3 3 11 +census 0 56 2 1 1 2.8 2 9 a'=1; +census 0 54 1 1 0 3.5 3 13 +census 0 66 1 1 0 3.4 6 11 +census 0 64 1 1 0 3.6 9 8 +census 0 65 1 1 0 nan - - +census 0 70 1 1 0 nan - - +census 0 67 2 1 1 nan - - a=1; +census 0 63 1 1 0 nan - - +census 0 78 1 1 0 nan - - +census 0 79 1 1 0 nan - - +census 0 76 1 1 0 3.2 2 23 +census 0 81 1 1 0 nan - - +census 0 80 2 1 1 nan - - a'=1; +census 0 68 1 1 0 nan - - +census 0 69 1 1 0 3.2 14 25 +census 0 71 2 1 1 2.8 7 17 a=1; +census 0 72 1 1 0 nan - - +census 0 74 1 1 0 3.0 4 6 +census 0 82 1 1 0 nan - - +census 0 73 1 1 0 nan - - +census 0 86 1 1 0 3.0 7 19 +census 0 75 1 1 0 2.9 4 16 +census 0 77 1 1 0 nan - - +census 0 88 1 1 0 nan - - +census 0 85 1 1 0 3.1 14 24 +census 0 83 1 1 0 nan - - +census 0 92 1 1 0 nan - - +census 0 89 1 1 0 nan - - +census 0 87 2 1 1 nan - - a'=1; +census 0 84 1 1 0 nan - - +census 0 90 2 1 1 nan - - b=1; +census 0 94 1 1 0 nan - - +census 0 93 1 1 0 3.0 7 20 +census 0 91 1 1 0 3.2 13 8 +census 0 95 2 1 1 3.0 13 12 a'=1; +census 0 97 1 1 0 nan - - +census 0 96 1 1 0 3.1 8 7 +census 0 101 1 1 0 nan - - +census 0 98 1 1 0 nan - - +census 0 100 1 1 0 nan - - +census 0 99 1 1 0 3.1 2 23 +census 0 106 1 1 0 nan - - +census 0 102 1 1 0 3.5 0 13 +census 0 105 1 1 0 nan - - +census 0 103 1 1 0 nan - - +census 0 107 1 1 0 nan - - +census 0 104 1 1 0 nan - - +census 0 108 1 1 0 nan - - +census 0 114 1 1 0 2.9 7 8 +census 0 112 1 1 0 3.3 5 4 +census 0 109 1 1 0 nan - - +census 0 120 1 1 0 nan - - +census 0 113 1 1 0 nan - - +census 0 111 1 1 0 3.3 3 27 +census 0 116 1 1 0 3.1 1 5 +census 0 119 1 1 0 3.1 3 18 +census 0 110 1 1 0 3.4 7 15 +census 0 115 2 1 1 nan - - b=1; +census 0 117 1 1 0 nan - - +census 0 124 1 1 0 3.6 0 15 +census 0 118 1 1 0 nan - - +census 0 121 1 1 0 nan - - +census 0 126 1 1 0 4.3 8 3 +census 0 129 2 1 1 3.2 6 6 a'=1; +census 0 123 1 1 0 nan - - +census 0 122 1 1 0 nan - - +census 0 125 2 1 1 3.3 1 6 b=1; +census 0 127 2 1 1 nan - - a=1; +census 0 128 1 1 0 nan - - +census 0 134 1 1 0 3.7 11 4 +census 0 135 1 1 0 3.0 5 15 +census 0 131 1 1 0 3.3 5 21 +census 0 130 1 1 0 3.2 11 8 +census 0 138 1 1 0 2.7 12 19 +census 0 133 1 1 0 2.8 10 0 +census 0 132 1 1 0 3.4 15 1 +census 0 136 1 1 0 nan - - +census 0 140 2 1 1 nan - - a'=1; +census 0 137 1 1 0 nan - - +census 0 143 1 1 0 nan - - +census 0 139 1 1 0 3.4 11 3 +census 0 146 1 1 0 3.4 15 22 +census 0 142 2 1 1 4.0 6 0 a'=1; +census 0 141 1 1 0 nan - - +census 0 150 1 1 0 nan - - +census 0 149 1 1 0 nan - - +census 0 144 1 1 0 3.7 3 22 +census 0 147 1 1 0 nan - - +census 0 148 1 1 0 3.7 10 0 +census 0 145 1 1 0 2.7 14 24 +census 0 152 1 1 0 3.1 11 25 +census 0 155 1 1 0 nan - - +census 0 151 1 1 0 nan - - +census 0 157 1 1 0 3.5 1 16 +census 0 162 1 1 0 3.1 2 16 +census 0 154 2 1 1 3.3 12 17 a'=1; +census 0 156 1 1 0 nan - - +census 0 160 1 1 0 2.5 1 17 +census 0 153 1 1 0 nan - - +census 0 163 2 1 1 3.7 0 19 a'=1; +census 0 161 1 1 0 nan - - +census 0 166 1 1 0 nan - - +census 0 158 1 1 0 3.1 13 1 +census 0 159 1 1 0 nan - - +census 0 169 2 1 1 nan - - a'=1; +census 0 171 1 1 0 nan - - +census 0 170 1 1 0 nan - - +census 0 168 1 1 0 3.6 6 25 +census 0 176 1 1 0 nan - - +census 0 177 1 1 0 3.1 14 0 +census 0 165 1 1 0 3.0 11 5 +census 0 164 1 1 0 3.8 7 25 +census 0 174 1 1 0 nan - - +census 0 173 3 1 2 nan - - a'=2; +census 0 167 3 1 2 3.4 2 14 a'=2; +census 0 180 1 1 0 3.5 3 19 +census 0 178 1 1 0 4.0 14 14 +census 0 172 2 1 1 3.0 15 16 a'=1; +census 0 184 2 1 1 3.0 2 25 a'=1; +census 0 175 1 1 0 2.9 1 24 +census 0 181 1 1 0 3.1 1 14 +census 0 185 1 1 0 nan - - +census 0 186 2 1 1 nan - - a'=1; +census 0 182 1 1 0 nan - - +census 0 179 1 1 0 3.1 10 14 +census 0 190 2 1 1 3.3 14 13 a'=1; +census 0 183 1 1 0 nan - - +census 0 187 1 1 0 3.6 4 14 +census 0 191 1 1 0 nan - - +census 0 193 1 1 0 3.5 4 23 +census 0 189 1 1 0 nan - - +census 0 188 1 1 0 3.2 0 12 +census 0 192 1 1 0 4.1 3 23 +census 0 194 1 1 0 3.7 2 6 +census 0 198 1 1 0 nan - - +census 0 196 1 1 0 3.0 3 21 +census 0 199 1 1 0 2.9 14 0 +census 0 201 1 1 0 nan - - +census 0 195 1 1 0 2.9 2 10 +census 0 200 1 1 0 3.1 5 21 +census 0 197 1 1 0 nan - - +census 0 205 1 1 0 3.1 7 7 +census 0 206 2 1 1 nan - - a'=1; +census 0 204 1 1 0 3.8 8 24 +census 0 202 1 1 0 nan - - +census 0 207 1 1 0 nan - - +census 0 203 1 1 0 nan - - +census 0 210 1 1 0 3.3 1 20 +census 0 208 1 1 0 nan - - +census 0 211 1 1 0 nan - - +census 0 212 1 1 0 nan - - +census 0 214 1 1 0 3.7 7 24 +census 0 209 1 1 0 nan - - +census 0 215 1 1 0 3.0 12 7 +census 0 220 1 1 0 nan - - +census 0 217 1 1 0 nan - - +census 0 225 1 1 0 3.2 14 23 +census 0 213 1 1 0 2.8 13 3 +census 0 224 1 1 0 3.0 12 11 +census 0 221 1 1 0 nan - - +census 0 216 1 1 0 3.5 7 4 +census 0 223 1 1 0 nan - - +census 0 222 1 1 0 3.0 14 10 +census 0 227 1 1 0 3.4 14 24 +census 0 219 1 1 0 3.0 9 22 +census 0 228 1 1 0 3.0 8 9 +census 0 229 1 1 0 3.0 5 17 +census 0 218 2 1 1 2.9 0 7 a'=1; +census 0 226 1 1 0 3.6 12 11 +census 0 230 1 1 0 nan - - +census 0 232 1 1 0 3.4 4 15 +census 0 236 1 1 0 nan - - +census 0 231 1 1 0 2.9 12 13 +census 0 235 1 1 0 3.3 8 16 +census 0 238 1 1 0 nan - - +census 0 234 1 1 0 nan - - +census 0 237 1 1 0 3.1 7 12 +census 0 239 1 1 0 3.4 6 18 +census 0 242 1 1 0 nan - - +census 0 240 2 1 1 3.4 11 17 b=1; +census 0 241 1 1 0 nan - - +census 0 233 2 1 1 3.2 7 11 c=1; +census 0 249 1 1 0 nan - - +census 0 245 1 1 0 3.0 13 2 +census 0 243 1 1 0 3.4 5 5 +census 0 251 1 1 0 3.0 11 0 +census 0 246 2 1 1 nan - - a'=1; +census 0 252 1 1 0 3.0 0 24 +census 0 244 2 1 1 3.0 3 8 reg64=1; +census 0 250 1 1 0 3.9 14 21 +census 0 247 1 1 0 nan - - +census 0 248 1 1 0 3.8 0 16 +census 0 255 1 1 0 2.6 6 14 +census 0 254 1 1 0 nan - - +census 0 253 1 1 0 nan - - +# end 2026-10-08T20:53:02Z rows=257 diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/run.txt b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/run.txt new file mode 100644 index 000000000..a06bbe8e2 --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/run.txt @@ -0,0 +1 @@ +# pack cs-era-genesis class mx8+sh256x27+state+reg64c+fold+rw epoch af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 day 69676e65756d2d6461792ffa50000000000000 era edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 state /srv/builds/v6-census/packs/node1-state.igsd1 day-index 20730 era-widths 4 bin f4e93766d5a3dc46 f8 host igneum-build-4 start 2026-10-08T20:50:53Z diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/show.txt b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/show.txt new file mode 100644 index 000000000..290d24b8e --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/show.txt @@ -0,0 +1,67 @@ +seed "igneum-epoch/af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3" generator v6 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 program id 2a1d6caab4c24564 seed words 9c8caa3d 83537296 f21169a4 12d4d157 66e0ce33 cc049080 8579c352 4c6e4ac9 +op mix load=16 add=10 shfl=8 rotl=5 rotr=5 xor=5 mad=4 mul=4 sub=4 mulhi=3 loads/hash 128 bytes/hash 512 +era d810f22d (igneum-era/0/edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07): width 4 B, stride mul 0x9ad30d99 rot 29, interleave [0, 2, 12, 13], windows (site:shrink:offset) 1:0:0 15:1:0 27:2:1 28:0:0 30:1:1 32:1:0 33:2:3 42:0:0 48:1:0 52:0:0 55:2:2 56:0:0 58:1:1 59:0:0 60:1:0 62:1:0 + 0: mad dst=7 src=3 src2=3 imm=0xd095f540 imm2=0xd3789b38 rot=19 bit=4 mask=4 + 1: load dst=1 src=7 src2=5 imm=0x390bbbd7 imm2=0x1b44071a rot=5 bit=13 mask=16 + 2: rotl dst=0 src=6 src2=7 imm=0xcd1e3e94 imm2=0xf0479df0 rot=29 bit=10 mask=2 + 3: shfl dst=5 src=6 src2=4 imm=0x78c099f8 imm2=0xc6d6c6bc rot=25 bit=21 mask=1 + 4: mulhi dst=5 src=3 src2=1 imm=0x2e8aa8d1 imm2=0x446c336a rot=23 bit=31 mask=16 + 5: rotl dst=7 src=1 src2=0 imm=0x46701a4a imm2=0xc2255717 rot=27 bit=20 mask=8 + 6: mad dst=4 src=2 src2=0 imm=0x487da55c imm2=0xf4675ef7 rot=26 bit=1 mask=8 + 7: rotl dst=2 src=6 src2=4 imm=0x74fdbac4 imm2=0x30e49db4 rot=11 bit=9 mask=16 + 8: mul dst=6 src=0 src2=4 imm=0x69e895ee imm2=0x66ebcedd rot=24 bit=11 mask=16 + 9: shfl dst=6 src=1 src2=7 imm=0x1510cbd0 imm2=0x607acada rot=4 bit=3 mask=2 +10: add dst=0 src=2 src2=2 imm=0x33a68b0c imm2=0xffb7f024 rot=27 bit=1 mask=4 +11: xor dst=0 src=2 src2=4 imm=0x61b96f54 imm2=0x7d5468b0 rot=30 bit=28 mask=8 +12: sub dst=7 src=4 src2=1 imm=0x39217118 imm2=0x248e3f9b rot=29 bit=7 mask=16 +13: shfl dst=1 src=4 src2=2 imm=0x6c12c43b imm2=0x6b60595d rot=20 bit=23 mask=8 +14: xor dst=1 src=0 src2=0 imm=0x030181c6 imm2=0x52fbbc27 rot=1 bit=28 mask=4 +15: load dst=5 src=0 src2=2 imm=0x5b20e3f6 imm2=0xa84ab3b3 rot=24 bit=31 mask=8 +16: xor dst=5 src=4 src2=4 imm=0x6fc104e8 imm2=0x1a522a5c rot=27 bit=8 mask=8 +17: shfl dst=6 src=7 src2=6 imm=0x5f5b071a imm2=0x39dc91da rot=16 bit=6 mask=16 +18: rotr dst=2 src=7 src2=0 imm=0x07b3a28c imm2=0x33193f0c rot=18 bit=3 mask=1 +19: add dst=4 src=1 src2=5 imm=0x0229d185 imm2=0x51cb8f70 rot=29 bit=26 mask=1 +20: add dst=4 src=7 src2=1 imm=0xc39836f7 imm2=0x0c001b55 rot=8 bit=7 mask=16 +21: add dst=0 src=3 src2=4 imm=0xb7d06b34 imm2=0x1ae7a0ac rot=9 bit=3 mask=4 +22: mad dst=2 src=6 src2=7 imm=0x0978477e imm2=0x2fec3e13 rot=21 bit=3 mask=16 +23: add dst=3 src=5 src2=7 imm=0x95cba5dd imm2=0x22934c58 rot=8 bit=19 mask=2 +24: mulhi dst=5 src=3 src2=0 imm=0x14b79a1b imm2=0xccae3d33 rot=5 bit=15 mask=16 +25: xor dst=0 src=3 src2=7 imm=0x22f74d7f imm2=0x782f1722 rot=18 bit=25 mask=4 +26: mul dst=6 src=3 src2=6 imm=0xf774717f imm2=0x3a1a2c3a rot=28 bit=25 mask=16 +27: load dst=3 src=7 src2=2 imm=0xf0d88d7d imm2=0x0fc8051c rot=14 bit=1 mask=16 +28: load dst=3 src=0 src2=5 imm=0xac8eb588 imm2=0x57844c72 rot=12 bit=8 mask=2 +29: rotr dst=6 src=7 src2=1 imm=0x89b07c78 imm2=0x90c747d7 rot=13 bit=30 mask=1 +30: load dst=1 src=4 src2=7 imm=0xdd34b81d imm2=0x96e5cb94 rot=26 bit=16 mask=1 +31: add dst=1 src=2 src2=3 imm=0x2fa2e27a imm2=0xbf8507da rot=27 bit=5 mask=1 +32: load dst=2 src=1 src2=1 imm=0x4df1d479 imm2=0xea698909 rot=29 bit=12 mask=4 +33: load dst=3 src=2 src2=1 imm=0xaa35122f imm2=0x01516545 rot=12 bit=18 mask=1 +34: mul dst=3 src=5 src2=7 imm=0x6a941ac2 imm2=0xb56c91d9 rot=24 bit=16 mask=1 +35: rotl dst=1 src=6 src2=7 imm=0xe8aa4cfe imm2=0x0d359401 rot=2 bit=3 mask=2 +36: shfl dst=1 src=5 src2=1 imm=0xd090168f imm2=0x3ea71d89 rot=9 bit=3 mask=4 +37: sub dst=0 src=4 src2=1 imm=0xdbda427b imm2=0xd9607488 rot=5 bit=12 mask=2 +38: rotr dst=4 src=2 src2=7 imm=0xe3e3804c imm2=0xccdc9668 rot=27 bit=13 mask=16 +39: mulhi dst=4 src=1 src2=2 imm=0x5d14fe55 imm2=0xb6db1d85 rot=17 bit=18 mask=4 +40: rotr dst=0 src=1 src2=4 imm=0xc77a2d1f imm2=0x5a85c407 rot=10 bit=31 mask=1 +41: add dst=2 src=3 src2=1 imm=0xfe28f51d imm2=0xf439f8e7 rot=5 bit=8 mask=2 +42: load dst=1 src=2 src2=5 imm=0xe1b6fb46 imm2=0x23bb6ba4 rot=29 bit=22 mask=1 +43: xor dst=7 src=5 src2=6 imm=0x34988c9d imm2=0xf8c6c4a8 rot=2 bit=21 mask=8 +44: shfl dst=6 src=2 src2=2 imm=0x14f4d589 imm2=0x868d3c75 rot=29 bit=31 mask=8 +45: mul dst=1 src=4 src2=1 imm=0x081dddbd imm2=0xc8e4de44 rot=23 bit=11 mask=16 +46: rotl dst=0 src=6 src2=2 imm=0xaec2cb92 imm2=0x03157ee4 rot=14 bit=5 mask=16 +47: add dst=1 src=3 src2=7 imm=0xf1719bbd imm2=0x14bb2234 rot=24 bit=7 mask=16 +48: load dst=1 src=6 src2=6 imm=0x30e39813 imm2=0x9ce47150 rot=22 bit=10 mask=1 +49: sub dst=5 src=1 src2=7 imm=0xaabdf6d2 imm2=0x0688a461 rot=13 bit=28 mask=2 +50: add dst=2 src=3 src2=6 imm=0xb129b2b4 imm2=0x4611fe29 rot=3 bit=14 mask=16 +51: sub dst=0 src=2 src2=1 imm=0xfe651d02 imm2=0x7c1929a9 rot=22 bit=31 mask=4 +52: load dst=4 src=0 src2=4 imm=0xf906070a imm2=0xf301cff4 rot=5 bit=25 mask=1 +53: mad dst=3 src=1 src2=4 imm=0xab213c09 imm2=0xf6d6f3fa rot=16 bit=28 mask=1 +54: shfl dst=4 src=1 src2=7 imm=0xf6dafbae imm2=0xdbfc32c7 rot=12 bit=1 mask=16 +55: load dst=6 src=5 src2=5 imm=0x881eaf9c imm2=0x7c50f5c8 rot=25 bit=22 mask=16 +56: load dst=2 src=4 src2=1 imm=0x899bf6e0 imm2=0xbde5b6ee rot=24 bit=10 mask=8 +57: shfl dst=5 src=7 src2=6 imm=0xea9c50d2 imm2=0xd2a8c99b rot=12 bit=28 mask=1 +58: load dst=1 src=5 src2=3 imm=0xad4912ca imm2=0x546d00b2 rot=7 bit=1 mask=1 +59: load dst=2 src=7 src2=1 imm=0x37cea58f imm2=0x13e31ff0 rot=21 bit=21 mask=16 +60: load dst=2 src=1 src2=2 imm=0x33f9a95e imm2=0xda1c8a2e rot=22 bit=28 mask=8 +61: add dst=3 src=2 src2=2 imm=0x0a051d32 imm2=0xe9ed866d rot=30 bit=1 mask=4 +62: load dst=0 src=2 src2=2 imm=0xab1dd54b imm2=0xc9fcaae2 rot=9 bit=2 mask=1 +63: rotr dst=5 src=0 src2=5 imm=0x1f0279bd imm2=0x223e7b9c rot=11 bit=3 mask=16 diff --git a/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/sitestats.tsv b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/sitestats.tsv new file mode 100644 index 000000000..2da8d9bf2 --- /dev/null +++ b/docs/analysis/class-v6/rows/chainseed-census-1a938abe4/cs-era-genesis/sitestats.tsv @@ -0,0 +1,20 @@ +program id 2a1d6caab4c24564 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 +rule: ACCEPTED, distinct 128.000 per hash, saturated 0, bias max 60 +site instr win off width distinct ratio under_c2 under_c3 bucket_ratio bucket_z bucket_id bit_z bit top_count +0 1 0 0 1 1046503 0.99998 0 0 2.188 4.75 60156 -1.87 26 2 +1 15 1 0 1 1044355 0.99988 0 0 1.750 4.24 14357 2.42 22 3 +2 27 2 1 1 1040572 1.00018 0 0 1.562 4.50 24199 -2.24 16 4 +3 28 0 0 1 1046539 1.00001 0 0 2.312 5.25 10753 -3.06 1 3 +4 30 1 1 1 1044536 1.00005 0 0 1.781 4.42 58838 -1.54 24 3 +5 32 1 0 1 1044401 0.99992 0 0 1.906 5.13 1461 1.62 16 3 +6 33 2 3 1 1040390 1.00001 0 0 1.547 4.38 50857 -2.50 7 4 +7 42 0 0 1 1046557 1.00003 0 0 2.250 5.00 35595 -2.44 23 3 +8 48 1 0 1 1044478 1.00000 0 0 1.781 4.42 14934 2.31 19 3 +9 52 0 0 1 1046564 1.00003 0 0 2.500 6.00 57814 -3.00 20 3 +10 55 2 2 1 1040481 1.00009 0 0 1.531 4.25 45966 -2.63 2 3 +11 56 0 0 1 1046558 1.00003 0 0 2.438 5.75 65197 2.34 2 3 +12 58 1 1 1 1044602 1.00012 0 0 1.781 4.42 44729 2.46 24 3 +13 59 0 0 1 1046533 1.00000 0 0 2.562 6.25 4623 -1.77 1 3 +14 60 1 0 1 1044508 1.00003 0 0 1.906 5.13 9415 -2.48 25 3 +15 62 1 0 1 1044593 1.00011 0 0 1.875 4.95 300 2.97 9 3 +summary: sites 16, min ratio 0.99988, under 0.98: 0, under 0.995: 0, bucket z max 6.25, bit z max -3.06, sites over 6 sigma 0, 2.2 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4.md b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4.md new file mode 100644 index 000000000..154e6b1a2 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4.md @@ -0,0 +1,132 @@ +# The live-dataset census on the frozen object (Igneum 2.0 Phase 1 item (j)), 8 October 2026, 21:4x to 22:10 UK + +The frozen tree: class-v6 1a938abe4 (the draw and the acceptance of b24dfc162; nothing on it moves). The object: hl-v6-all, program 4de7b836cc40a4ea, generator 6, class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw (the fold, the rw1 table, the 64-register full-chain window), the Devnet 3 genesis epoch hex edc4fa84... as the epoch and era seed, day 20730, the node1 state (block 159357, 93 leaves, root 1c583d35...). The harness: branch class-v6-census-all4 at b819c23a4 (the census commands on the 1a938abe4 crate; the binary all4-b819c23a, sha256 6448ade354bc665a... on build-5 and build-6, byte-identical). Boxes: build-5 (igneum-build-5, 32 cores) and build-6 (igneum-build-6, 32 cores), the lease pool at class v5, nice 19, every run under a pid file through the night driver (`tools/attack/v6-census/night-run.sh`: a job without its end marker is restarted up to three times and every restart is logged; the logs are beside the rows). Nothing ran on the Mac; nothing here touches a served page or the spec. + +**What "live" means here.** The acceptance's dynamic test, the attempts census and the earlier trace reads run on the closed-form stand-in. These rows run the kernel path's own interpreter (`verify::interpret_warp_core` under a tracing probe) on the chain's dataset: the memory-hard dataset the epoch derives from the day key with the mixer and the state leaves of the node1 stream (`Epoch::chain_dataset_day` with `--state`), so every address after the first load depends on live dataset bytes; and on the header-bound init words (`bind::block_init_words` over a prehash per header with the header's index as the high nonce word), four headers per box, the object split four headers per box (eight in all), 2^18 nonces per header on the object and 2^16 on each of sixteen chain-shaped seeds p18 to p33 under the frozen class. + +## 1. The census rows (the same statistics as the closed-form census, over the live dataset) + +Per run: per (iteration, site) cell and per site the address histogram over every read (A03's form: the most read address and its share), the distinct word indices against the window model `N - N^2 / 2W` at the site's window (the (c'') form), the one-count of every address bit inside the site's window above the alignment (the value-level read, 6 sigma), and over the program the top 0.1 percent of items' share of all reads against a flat control and a windowed control (each site's reads drawn uniformly over its own window, the same counts) at the same N (the F8 form's two nulls; the gate 1.2x over the window model). + +| Run (box) | Program | Headers; nonces per header | Reads | Worst address at any site, worst cell (count, share) | Min site distinct ratio (floors 0.98, 0.995) | Worst index bit inside its window (sigma; band 6) | Top 0.1 percent item share; against the controls (gate 1.2x) | Ideal cache 1 GiB / 256 MiB / 64 MiB (top K by count; sampling-inflated above the window model) | +|---|---|---|---|---|---|---|---|---| +| object-h0 (build-5) | 4de7b836cc40a4ea | 4 from 0; 262,144 nonces each | 268,435,456 | site 8: 0x07579830 x6 (1.0e-06); cell: 0x0ab39b50 x4 (4.0e-06) | 1.00007 | -3.51 (site 7, bit 1) | 0.002138; 1.0998x flat; **0.9989x** window model | 1.0000 / 0.3540 / 0.1035 | +| seed-p18 (build-5) | 0b686c80e25cb4d3 | 4 from 0; 65,536 nonces each | 67,108,864 | site 0: 0x04b26299 x4 (2.0e-06); cell: 0x000e4f1d x3 (1.1e-05) | 0.99991 | 3.09 (site 24, bit 16) | 0.003391; 1.1032x flat; **1.0006x** window model | 1.0000 / 0.4404 / 0.1414 | +| seed-p19 (build-5) | bf8510cd00c0c70f | 4 from 0; 65,536 nonces each | 67,108,864 | site 0: 0x0813e726 x4 (2.0e-06); cell: 0x06f0d11f x3 (1.1e-05) | 0.99986 | -3.81 (site 29, bit 7) | 0.003433; 1.1159x flat; **0.9996x** window model | 1.0000 / 0.4418 / 0.1426 | +| seed-p20 (build-5) | 24133bd7265e958f | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x09d4fb1a x4 (2.0e-06); cell: 0x0ae65aa6 x3 (1.1e-05) | 0.99994 | -3.55 (site 30, bit 0) | 0.003434; 1.1175x flat; **1.0003x** window model | 1.0000 / 0.4443 / 0.1429 | +| seed-p21 (build-5) | ed647abf60a5bd32 | 4 from 0; 65,536 nonces each | 67,108,864 | site 0: 0x04e14ec7 x4 (2.0e-06); cell: 0x03973640 x3 (1.1e-05) | 0.99990 | 3.90 (site 11, bit 9) | 0.003920; 1.2759x flat; **1.0008x** window model | 1.0000 / 0.4774 / 0.1605 | +| seed-p22 (build-5) | f8e8969443448ecb | 4 from 0; 65,536 nonces each | 67,108,864 | site 6: 0x06a054ca x5 (2.0e-06); cell: 0x0342068e x3 (1.1e-05) | 0.99994 | 3.31 (site 13, bit 19) | 0.003237; 1.0540x flat; **0.9997x** window model | 1.0000 / 0.4271 / 0.1370 | +| seed-p23 (build-5) | 160649503341aaab | 4 from 0; 65,536 nonces each | 67,108,864 | site 1: 0x0e3c2793 x4 (2.0e-06); cell: 0x051243d9 x3 (1.1e-05) | 0.99994 | -3.44 (site 25, bit 1) | 0.003338; 1.0854x flat; **0.9990x** window model | 1.0000 / 0.4315 / 0.1391 | +| seed-p24 (build-5) | 62aa0bfc93f13028 | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x08bdfbf3 x4 (2.0e-06); cell: 0x0bd48627 x3 (1.1e-05) | 0.99991 | 3.46 (site 4, bit 15) | 0.003156; 1.0264x flat; **0.9988x** window model | 1.0000 / 0.4212 / 0.1338 | +| seed-p25 (build-5) | 3f1af0bbaaef74fa | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x0fb1f63d x4 (2.0e-06); cell: 0x0f8343d0 x3 (1.1e-05) | 0.99993 | 3.27 (site 2, bit 5) | 0.003436; 1.1192x flat; **1.0014x** window model | 1.0000 / 0.4418 / 0.1426 | +| object-h4 (build-6) | 4de7b836cc40a4ea | 4 from 0; 262,144 nonces each | 268,435,456 | site 21: 0x0436441b x6 (1.0e-06); cell: 0x0f45e0db x4 (4.0e-06) | 1.00010 | -3.06 (site 9, bit 1) | 0.002140; 1.1005x flat; **0.9995x** window model | 1.0000 / 0.3540 / 0.1035 | +| seed-p26 (build-6) | 2b406490ba8d3c91 | 4 from 0; 65,536 nonces each | 67,108,864 | site 3: 0x03f3960e x4 (2.0e-06); cell: 0x0f26b8e6 x3 (1.1e-05) | 0.99992 | 3.61 (site 28, bit 20) | 0.003129; 1.0183x flat; **1.0003x** window model | 1.0000 / 0.4196 / 0.1328 | +| seed-p27 (build-6) | c38b57d654ad08d4 | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x031a0ba8 x4 (2.0e-06); cell: 0x01c78316 x3 (1.1e-05) | 0.99995 | -2.90 (site 8, bit 16) | 0.003348; 1.0873x flat; **1.0010x** window model | 1.0000 / 0.4343 / 0.1396 | +| seed-p28 (build-6) | 96e4f7fdccef6fd1 | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x030525f1 x4 (2.0e-06); cell: 0x03149070 x3 (1.1e-05) | 0.99993 | -3.99 (site 25, bit 11) | 0.003499; 1.1396x flat; **1.0005x** window model | 1.0000 / 0.4400 / 0.1434 | +| seed-p29 (build-6) | 3f922ac24b46d2c2 | 4 from 0; 65,536 nonces each | 67,108,864 | site 7: 0x0e92f974 x4 (2.0e-06); cell: 0x0ef15836 x3 (1.1e-05) | 0.99997 | 3.00 (site 25, bit 18) | 0.003169; 1.0326x flat; **1.0004x** window model | 1.0000 / 0.4241 / 0.1350 | +| seed-p30 (build-6) | edd13a08477407cf | 4 from 0; 65,536 nonces each | 67,108,864 | site 0: 0x0e3a012d x4 (2.0e-06); cell: 0x0e92237a x3 (1.1e-05) | 0.99991 | 2.59 (site 4, bit 26) | 0.003348; 1.0910x flat; **0.9981x** window model | 1.0000 / 0.4343 / 0.1395 | +| seed-p31 (build-6) | e1409749e795c382 | 4 from 0; 65,536 nonces each | 67,108,864 | site 0: 0x0d3d1622 x4 (2.0e-06); cell: 0x0f8c1753 x3 (1.1e-05) | 0.99988 | -3.23 (site 7, bit 21) | 0.003432; 1.1164x flat; **0.9992x** window model | 1.0000 / 0.4417 / 0.1425 | +| seed-p32 (build-6) | 0717ad9158d5937f | 4 from 0; 65,536 nonces each | 67,108,864 | site 4: 0x0cd645f0 x4 (2.0e-06); cell: 0x08695fc3 x3 (1.1e-05) | 0.99993 | 3.40 (site 6, bit 2) | 0.003378; 1.1000x flat; **1.0004x** window model | 1.0000 / 0.4390 / 0.1410 | +| seed-p33 (build-6) | 9857a41ce42f4677 | 4 from 0; 65,536 nonces each | 67,108,864 | site 2: 0x0f425fde x4 (2.0e-06); cell: 0x03846806 x3 (1.1e-05) | 0.99994 | -3.95 (site 5, bit 5) | 0.003416; 1.1112x flat; **0.9996x** window model | 1.0000 / 0.4358 / 0.1410 | + +Reading: on the frozen object over 2^21 hashes and eight headers (two boxes), the top 0.1 percent of items hold 0.2138 and 0.2140 percent of reads against the windowed control's 0.2141 (0.9989x and 0.9995x; the flat control 1.10x, the era windows' layer 8 by design); every site's distinct ratio 1.0001 (uniform inside its window); the worst index bit inside any window under 4 sigma; the worst address at any site 6 to 7 reads of 134 million (5e-8) and the worst cell 4 of 4 million, the Poisson maxima of a uniform stream; every one of the 16,777,216 items touched. The sixteen chain-shaped seeds under the frozen class read the same: window-model ratios 0.998 to 1.001x, flat 1.03 to 1.28x (p21's 1.28x is its window draw), min site ratio 0.99986 to 0.99997, worst bit 2.6 to 4.0 sigma, worst address 4 to 5 reads of 2 million. Nothing a cache can key on beyond the era windows, which the GPU's L2 sees as well; the cache columns (top K items by sample count) sit above the window model by the sampling noise of ranking items by count, as in the A03 census (census-packs.md section 6), and the honest cache figures are the window model's (the object's 256 MiB share 0.354 measured at 2^20 hashes per box against 0.359 from its window draw). + +## 2. F06's live half: the window's liveness on live data + +The rule (`accept::check_window_liveness`, the chain's) flips each of the 64 registers by two probe words at the start of iteration 0 on the closed form at one base nonce and requires the first load's address and the hash to change in every lane. Here the same flips run on the live dataset under the header-bound init words, over four headers and 16 warps per box on the object (4,096 probes per register per box) and two headers and 8 warps on a chain seed, with every load of every iteration traced, so the least-changed load of the first iteration is read as well as the first. + +| Run (box) | Program | Headers; warps | Registers x probes | First-load address changed (fraction of lanes, least live register) | Hash changed | Least-changed first-iteration load | Verdict | +|---|---|---|---|---|---|---|---| +| liveness-object-h0 (build-5) | 4de7b836cc40a4ea | 4 from 0; 16 warps | 64 x 4096 | 1.000000 | 1.000000 | 1.000000 at (register 0, load 0) | **LIVE** | +| liveness-p18 (build-5) | 0b686c80e25cb4d3 | 2 from 0; 8 warps | 64 x 1024 | 1.000000 | 1.000000 | 1.000000 at (register 0, load 0) | **LIVE** | +| liveness-object-h4 (build-6) | 4de7b836cc40a4ea | 4 from 0; 16 warps | 64 x 4096 | 1.000000 | 1.000000 | 1.000000 at (register 0, load 0) | **LIVE** | +| liveness-p26 (build-6) | 2b406490ba8d3c91 | 2 from 0; 8 warps | 64 x 1024 | 1.000000 | 1.000000 | 1.000000 at (register 0, load 0) | **LIVE** | + +Reading: every one of the 64 registers moves every lane's first address and every lane's hash under every probe on live data (1.000000 at the least live register over 4,096 probes on each box), and every first-iteration load's address moves in every lane under every flip (the least-changed cell 1.000000). The construction's claim ("every one of the 64 registers is read by the address of each of the 32 loads") holds as measured on the live dataset, not only by construction. + +## 3. The runs, the faults, the commands + +Every job and every restart, with the UK clock, from the drivers' logs (the one fault of the night: my job-list writer ran in a shell that does not split an unquoted list, so the eight seed jobs per box collapsed into one line that the harness refused with exit 2 three times on each box; the lists were rewritten with explicit splitting and the sixteen seed rows ran through the same driver at 22:01; nothing in the harness or the crate moved): + +``` +# night driver start 21:56 UK host igneum-build-5 jobs 5 +start 1 canary-p18 21:56 UK +end 1 canary-p18 rc 0 21:56 UK +start 1 object-h0 21:56 UK +end 1 object-h0 rc 0 21:59 UK +start 1 liveness-object-h0 21:59 UK +end 1 liveness-object-h0 rc 0 21:59 UK +start 1 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 1 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +restart 2 seed-p18 19 20 21 22 23 24 25 21:59 UK +start 2 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 2 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +restart 3 seed-p18 19 20 21 22 23 24 25 21:59 UK +start 3 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 3 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +start 1 liveness-p18 21:59 UK +end 1 liveness-p18 rc 0 21:59 UK +# night driver end 21:59 UK +# night driver start 22:01 UK host igneum-build-5 jobs 8 +start 1 seed-p18 22:01 UK +end 1 seed-p18 rc 0 22:01 UK +start 1 seed-p19 22:01 UK +end 1 seed-p19 rc 0 22:02 UK +start 1 seed-p20 22:02 UK +end 1 seed-p20 rc 0 22:03 UK +start 1 seed-p21 22:03 UK +end 1 seed-p21 rc 0 22:03 UK +start 1 seed-p22 22:03 UK +end 1 seed-p22 rc 0 22:04 UK +start 1 seed-p23 22:04 UK +end 1 seed-p23 rc 0 22:05 UK +start 1 seed-p24 22:05 UK +end 1 seed-p24 rc 0 22:05 UK +start 1 seed-p25 22:05 UK +end 1 seed-p25 rc 0 22:06 UK +# night driver end 22:06 UK +# night driver start 21:56 UK host igneum-build-6 jobs 1 +start 1 canary-p18 21:56 UK +end 1 canary-p18 rc 0 21:56 UK +# night driver end 21:56 UK +# night driver start 21:56 UK host igneum-build-6 jobs 5 +start 1 object-h4 21:56 UK +end 1 object-h4 rc 0 22:00 UK +start 1 liveness-object-h4 22:00 UK +end 1 liveness-object-h4 rc 0 22:00 UK +start 1 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 1 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +restart 2 seed-p26 27 28 29 30 31 32 33 22:00 UK +start 2 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 2 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +restart 3 seed-p26 27 28 29 30 31 32 33 22:00 UK +start 3 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 3 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +start 1 liveness-p26 22:00 UK +end 1 liveness-p26 rc 0 22:00 UK +# night driver end 22:00 UK +# night driver start 22:01 UK host igneum-build-6 jobs 8 +start 1 seed-p26 22:01 UK +end 1 seed-p26 rc 0 22:02 UK +start 1 seed-p27 22:02 UK +end 1 seed-p27 rc 0 22:02 UK +start 1 seed-p28 22:02 UK +end 1 seed-p28 rc 0 22:03 UK +start 1 seed-p29 22:03 UK +end 1 seed-p29 rc 0 22:04 UK +start 1 seed-p30 22:04 UK +end 1 seed-p30 rc 0 22:05 UK +start 1 seed-p31 22:05 UK +end 1 seed-p31 rc 0 22:06 UK +start 1 seed-p32 22:06 UK +end 1 seed-p32 rc 0 22:07 UK +start 1 seed-p33 22:07 UK +end 1 seed-p33 rc 0 22:08 UK +# night driver end 22:08 UK +``` + +The commands (the lists `night-jobs-.tsv` and `night-seeds-.tsv` beside the rows carry every one verbatim): the object, `addrsite --count 4 --header-from <0|4> --warps 8192 --threads 32 --epoch-hex --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0: --state node1-state.igsd1`; a seed, the same with `--seed igneum-attack-f8/program/ --warps 2048`; the liveness, `liveness --count 4 --header-from <0|4> --warps 16 --threads 32` with the same object arguments. Every run under `lease pool 32 --min 4 --nice 19 --class v5 --owner class-v6-census` through `night-run.sh`, pid files under `/srv/builds/v6-census/pids/` on each box. + +## 4. Against the one acceptance rule, and what is owed + +On the live dataset the frozen object reads as the closed-form census read it: uniform inside every era window to the Poisson floor, no address bit biased inside its window, the window live on every register and every load. Nothing here moves the adversary's edge: the hot half of the dataset is the era windows' (layer 8), seen by a GPU's L2 and a chip's SRAM alike. Owed: the same rows at 2^24 nonces per header (the 64 x 2^24 live point every class owes; 50 to 100 core-hours per object); a per-site LRU trace for a cache figure free of the top-K ranking's sampling inflation. diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-object-h0.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-object-h0.tsv new file mode 100644 index 000000000..176a2c8ba --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-object-h0.tsv @@ -0,0 +1,67 @@ +# liveness: program 4de7b836cc40a4ea class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw registers 64 day bytes:69676e65756d2d6461792ffa50000000000000 dataset 2^28 words (memory-hard) headers 4 warps 16 threads 32 probe words 2 +reg probes first_load_changed hash_changed least_changed_load least_changed_frac +0 4096 1.000000 1.000000 0 1.000000 +1 4096 1.000000 1.000000 0 1.000000 +2 4096 1.000000 1.000000 0 1.000000 +3 4096 1.000000 1.000000 0 1.000000 +4 4096 1.000000 1.000000 0 1.000000 +5 4096 1.000000 1.000000 0 1.000000 +6 4096 1.000000 1.000000 0 1.000000 +7 4096 1.000000 1.000000 0 1.000000 +8 4096 1.000000 1.000000 0 1.000000 +9 4096 1.000000 1.000000 0 1.000000 +10 4096 1.000000 1.000000 0 1.000000 +11 4096 1.000000 1.000000 0 1.000000 +12 4096 1.000000 1.000000 0 1.000000 +13 4096 1.000000 1.000000 0 1.000000 +14 4096 1.000000 1.000000 0 1.000000 +15 4096 1.000000 1.000000 0 1.000000 +16 4096 1.000000 1.000000 0 1.000000 +17 4096 1.000000 1.000000 0 1.000000 +18 4096 1.000000 1.000000 0 1.000000 +19 4096 1.000000 1.000000 0 1.000000 +20 4096 1.000000 1.000000 0 1.000000 +21 4096 1.000000 1.000000 0 1.000000 +22 4096 1.000000 1.000000 0 1.000000 +23 4096 1.000000 1.000000 0 1.000000 +24 4096 1.000000 1.000000 0 1.000000 +25 4096 1.000000 1.000000 0 1.000000 +26 4096 1.000000 1.000000 0 1.000000 +27 4096 1.000000 1.000000 0 1.000000 +28 4096 1.000000 1.000000 0 1.000000 +29 4096 1.000000 1.000000 0 1.000000 +30 4096 1.000000 1.000000 0 1.000000 +31 4096 1.000000 1.000000 0 1.000000 +32 4096 1.000000 1.000000 0 1.000000 +33 4096 1.000000 1.000000 0 1.000000 +34 4096 1.000000 1.000000 0 1.000000 +35 4096 1.000000 1.000000 0 1.000000 +36 4096 1.000000 1.000000 0 1.000000 +37 4096 1.000000 1.000000 0 1.000000 +38 4096 1.000000 1.000000 0 1.000000 +39 4096 1.000000 1.000000 0 1.000000 +40 4096 1.000000 1.000000 0 1.000000 +41 4096 1.000000 1.000000 0 1.000000 +42 4096 1.000000 1.000000 0 1.000000 +43 4096 1.000000 1.000000 0 1.000000 +44 4096 1.000000 1.000000 0 1.000000 +45 4096 1.000000 1.000000 0 1.000000 +46 4096 1.000000 1.000000 0 1.000000 +47 4096 1.000000 1.000000 0 1.000000 +48 4096 1.000000 1.000000 0 1.000000 +49 4096 1.000000 1.000000 0 1.000000 +50 4096 1.000000 1.000000 0 1.000000 +51 4096 1.000000 1.000000 0 1.000000 +52 4096 1.000000 1.000000 0 1.000000 +53 4096 1.000000 1.000000 0 1.000000 +54 4096 1.000000 1.000000 0 1.000000 +55 4096 1.000000 1.000000 0 1.000000 +56 4096 1.000000 1.000000 0 1.000000 +57 4096 1.000000 1.000000 0 1.000000 +58 4096 1.000000 1.000000 0 1.000000 +59 4096 1.000000 1.000000 0 1.000000 +60 4096 1.000000 1.000000 0 1.000000 +61 4096 1.000000 1.000000 0 1.000000 +62 4096 1.000000 1.000000 0 1.000000 +63 4096 1.000000 1.000000 0 1.000000 +# verdict: 64 registers over 4096 probes each; first-load address changed in 1.000000 of lanes at the least live register, the hash in 1.000000; the least changed (register, first-iteration load) is (0, 0) at 1.000000; LIVE on live data (every register moves every lane's first address and hash); 6.6 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-p18.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-p18.tsv new file mode 100644 index 000000000..c9d329ba9 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/liveness-p18.tsv @@ -0,0 +1,67 @@ +# liveness: program 0b686c80e25cb4d3 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw registers 64 day 2026-10-03 dataset 2^28 words (memory-hard) headers 2 warps 8 threads 32 probe words 2 +reg probes first_load_changed hash_changed least_changed_load least_changed_frac +0 1024 1.000000 1.000000 0 1.000000 +1 1024 1.000000 1.000000 0 1.000000 +2 1024 1.000000 1.000000 0 1.000000 +3 1024 1.000000 1.000000 0 1.000000 +4 1024 1.000000 1.000000 0 1.000000 +5 1024 1.000000 1.000000 0 1.000000 +6 1024 1.000000 1.000000 0 1.000000 +7 1024 1.000000 1.000000 0 1.000000 +8 1024 1.000000 1.000000 0 1.000000 +9 1024 1.000000 1.000000 0 1.000000 +10 1024 1.000000 1.000000 0 1.000000 +11 1024 1.000000 1.000000 0 1.000000 +12 1024 1.000000 1.000000 0 1.000000 +13 1024 1.000000 1.000000 0 1.000000 +14 1024 1.000000 1.000000 0 1.000000 +15 1024 1.000000 1.000000 0 1.000000 +16 1024 1.000000 1.000000 0 1.000000 +17 1024 1.000000 1.000000 0 1.000000 +18 1024 1.000000 1.000000 0 1.000000 +19 1024 1.000000 1.000000 0 1.000000 +20 1024 1.000000 1.000000 0 1.000000 +21 1024 1.000000 1.000000 0 1.000000 +22 1024 1.000000 1.000000 0 1.000000 +23 1024 1.000000 1.000000 0 1.000000 +24 1024 1.000000 1.000000 0 1.000000 +25 1024 1.000000 1.000000 0 1.000000 +26 1024 1.000000 1.000000 0 1.000000 +27 1024 1.000000 1.000000 0 1.000000 +28 1024 1.000000 1.000000 0 1.000000 +29 1024 1.000000 1.000000 0 1.000000 +30 1024 1.000000 1.000000 0 1.000000 +31 1024 1.000000 1.000000 0 1.000000 +32 1024 1.000000 1.000000 0 1.000000 +33 1024 1.000000 1.000000 0 1.000000 +34 1024 1.000000 1.000000 0 1.000000 +35 1024 1.000000 1.000000 0 1.000000 +36 1024 1.000000 1.000000 0 1.000000 +37 1024 1.000000 1.000000 0 1.000000 +38 1024 1.000000 1.000000 0 1.000000 +39 1024 1.000000 1.000000 0 1.000000 +40 1024 1.000000 1.000000 0 1.000000 +41 1024 1.000000 1.000000 0 1.000000 +42 1024 1.000000 1.000000 0 1.000000 +43 1024 1.000000 1.000000 0 1.000000 +44 1024 1.000000 1.000000 0 1.000000 +45 1024 1.000000 1.000000 0 1.000000 +46 1024 1.000000 1.000000 0 1.000000 +47 1024 1.000000 1.000000 0 1.000000 +48 1024 1.000000 1.000000 0 1.000000 +49 1024 1.000000 1.000000 0 1.000000 +50 1024 1.000000 1.000000 0 1.000000 +51 1024 1.000000 1.000000 0 1.000000 +52 1024 1.000000 1.000000 0 1.000000 +53 1024 1.000000 1.000000 0 1.000000 +54 1024 1.000000 1.000000 0 1.000000 +55 1024 1.000000 1.000000 0 1.000000 +56 1024 1.000000 1.000000 0 1.000000 +57 1024 1.000000 1.000000 0 1.000000 +58 1024 1.000000 1.000000 0 1.000000 +59 1024 1.000000 1.000000 0 1.000000 +60 1024 1.000000 1.000000 0 1.000000 +61 1024 1.000000 1.000000 0 1.000000 +62 1024 1.000000 1.000000 0 1.000000 +63 1024 1.000000 1.000000 0 1.000000 +# verdict: 64 registers over 1024 probes each; first-load address changed in 1.000000 of lanes at the least live register, the hash in 1.000000; the least changed (register, first-iteration load) is (0, 0) at 1.000000; LIVE on live data (every register moves every lane's first address and hash); 2.0 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-jobs-5.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-jobs-5.tsv new file mode 100644 index 000000000..121b8dac5 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-jobs-5.tsv @@ -0,0 +1,5 @@ +canary-p18 # F8 form 16 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 1 --warps 256 --threads 16 --seed igneum-attack-f8/program/18 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +object-h0 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --header-from 0 --warps 8192 --threads 32 --epoch-hex edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +liveness-object-h0 # verdict 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow liveness --count 4 --header-from 0 --warps 16 --threads 32 --epoch-hex edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p18 19 20 21 22 23 24 25 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/18 19 20 21 22 23 24 25 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +liveness-p18 # verdict 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow liveness --count 2 --warps 8 --threads 32 --seed igneum-attack-f8/program/18 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-seeds-5.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-seeds-5.tsv new file mode 100644 index 000000000..02d8cb8c9 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/night-seeds-5.tsv @@ -0,0 +1,8 @@ +seed-p18 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/18 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p19 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/19 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p20 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/20 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p21 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/21 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p22 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/22 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p23 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/23 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p24 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/24 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p25 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/25 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/object-h0.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/object-h0.tsv new file mode 100644 index 000000000..72a0e9067 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/object-h0.tsv @@ -0,0 +1,42 @@ +# addrsite: program 4de7b836cc40a4ea class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day bytes:69676e65756d2d6461792ffa50000000000000 dataset 2^28 words (memory-hard) headers 4 warps 8192 nonces/header 262144 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 7 1048576 1044572 0x0f281e20 3 0.000003 +0 1 7 1048576 1044538 0x0e8e8ead 3 0.000003 +# worst cell: iteration 0 site 28 address 0x0ab39b50 in 4 reads, share 0.000004 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 7 1 8388608 8388608 8132047 0x0cdad1e9 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00069 2.67 23 +1 7 1 8388608 8388608 8131951 0x0de9a70a 5 0.000001 1.0000 0.8677 0.3536 1.0000 0.5000 0.1250 1.00068 2.09 24 +2 8 1 8388608 8388608 8131945 0x09d3dc61 5 0.000001 1.0000 0.8680 0.3538 1.0000 0.5000 0.1250 1.00067 -2.55 23 +3 8 1 8388608 8388608 8132094 0x0fcde01e 4 0.000000 1.0000 0.8679 0.3538 1.0000 0.5000 0.1250 1.00069 2.49 25 +4 9 0 16777216 8388608 8258704 0x0ec34d5e 4 0.000000 1.0000 0.7130 0.2827 1.0000 0.2500 0.0625 1.00014 2.10 23 +5 9 0 16777216 8388608 8258085 0x0d7c7231 4 0.000000 1.0000 0.7131 0.2827 1.0000 0.2500 0.0625 1.00007 2.35 27 +6 10 1 8388608 8388608 8131678 0x09d64ddc 5 0.000001 1.0000 0.8678 0.3536 1.0000 0.5000 0.1250 1.00064 -1.97 11 +7 10 1 8388608 8388608 8131492 0x0fc03997 5 0.000001 1.0000 0.8680 0.3537 1.0000 0.5000 0.1250 1.00062 -3.51 1 +8 11 2 4194304 8388608 7886321 0x07579830 6 0.000001 1.0000 1.0000 0.4840 1.0000 1.0000 0.2500 1.00280 -2.78 24 +9 11 2 4194304 8388608 7884408 0x07f9a1d2 6 0.000001 1.0000 1.0000 0.4842 1.0000 1.0000 0.2500 1.00255 -2.38 21 +10 13 1 8388608 8388608 8131831 0x028ad7af 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00066 -2.29 2 +11 13 1 8388608 8388608 8131126 0x01eca4cf 5 0.000001 1.0000 0.8680 0.3537 1.0000 0.5000 0.1250 1.00057 -2.14 17 +12 29 0 16777216 8388608 8258636 0x020fff43 4 0.000000 1.0000 0.7133 0.2827 1.0000 0.2500 0.0625 1.00013 2.45 13 +13 29 0 16777216 8388608 8258639 0x0684affd 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00013 -2.24 20 +14 30 1 8388608 8388608 8131030 0x0156b5af 4 0.000000 1.0000 0.8678 0.3535 1.0000 0.5000 0.1250 1.00056 2.47 24 +15 30 1 8388608 8388608 8132231 0x05d7450b 4 0.000000 1.0000 0.8679 0.3536 1.0000 0.5000 0.1250 1.00071 2.75 26 +16 31 1 8388608 8388608 8131162 0x016f2f20 5 0.000001 1.0000 0.8680 0.3538 1.0000 0.5000 0.1250 1.00058 -1.51 12 +17 31 1 8388608 8388608 8131757 0x054cc4b7 5 0.000001 1.0000 0.8681 0.3538 1.0000 0.5000 0.1250 1.00065 2.20 18 +18 44 1 8388608 8388608 8131834 0x05606f45 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00066 -1.64 7 +19 44 1 8388608 8388608 8131163 0x02332e6c 5 0.000001 1.0000 0.8676 0.3535 1.0000 0.5000 0.1250 1.00058 2.39 8 +20 46 1 8388608 8388608 8132339 0x0282d27f 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00072 -2.20 12 +21 46 1 8388608 8388608 8131591 0x04dd4e3a 4 0.000000 1.0000 0.8678 0.3535 1.0000 0.5000 0.1250 1.00063 1.57 9 +22 47 2 4194304 8388608 7885706 0x0322c452 6 0.000001 1.0000 1.0000 0.4839 1.0000 1.0000 0.2500 1.00272 2.18 17 +23 47 2 4194304 8388608 7885403 0x025ac4be 6 0.000001 1.0000 1.0000 0.4841 1.0000 1.0000 0.2500 1.00268 2.00 21 +24 52 0 16777216 8388608 8258667 0x019ac84e 4 0.000000 1.0000 0.7132 0.2827 1.0000 0.2500 0.0625 1.00014 -2.28 14 +25 52 0 16777216 8388608 8259291 0x00a62c92 4 0.000000 1.0000 0.7130 0.2827 1.0000 0.2500 0.0625 1.00021 1.64 16 +26 56 0 16777216 8388608 8258968 0x09e1fab5 4 0.000000 1.0000 0.7132 0.2827 1.0000 0.2500 0.0625 1.00017 2.02 5 +27 56 0 16777216 8388608 8258927 0x0a3d57dc 4 0.000000 1.0000 0.7131 0.2827 1.0000 0.2500 0.0625 1.00017 -2.36 11 +28 58 1 8388608 8388608 8132535 0x0fac6ffa 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00075 2.80 0 +29 58 1 8388608 8388608 8131321 0x08555300 4 0.000000 1.0000 0.8680 0.3537 1.0000 0.5000 0.1250 1.00060 1.61 16 +30 63 0 16777216 8388608 8259105 0x0892bf3d 4 0.000000 1.0000 0.7132 0.2827 1.0000 0.2500 0.0625 1.00019 2.28 26 +31 63 0 16777216 8388608 8258645 0x03d6fb84 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00013 1.74 27 +# F8 form over the live stream: top 0.1 percent of items hold 0.002138 of reads; flat control 0.001944 (ratio 1.0998x), windowed control 0.002141 (ratio 0.9989x; the gate 1.2x); min site distinct ratio 1.00007 (floors 0.98 and 0.995); worst index bit inside its window -3.51 sigma at site 7 bit 1 (the band 6) +# program: reads 268435456, distinct items 16777198, worst site 8 address 0x07579830 in 6 reads (share 0.000001); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.3540, 64 MiB 0.1035; the per-site ideal caches summed: 1.0000, 0.8360, 0.3478; 159.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/restarts.log b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/restarts.log new file mode 100644 index 000000000..f556f07f7 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/restarts.log @@ -0,0 +1,36 @@ +# night driver start 21:56 UK host igneum-build-5 jobs 5 +start 1 canary-p18 21:56 UK +end 1 canary-p18 rc 0 21:56 UK +start 1 object-h0 21:56 UK +end 1 object-h0 rc 0 21:59 UK +start 1 liveness-object-h0 21:59 UK +end 1 liveness-object-h0 rc 0 21:59 UK +start 1 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 1 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +restart 2 seed-p18 19 20 21 22 23 24 25 21:59 UK +start 2 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 2 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +restart 3 seed-p18 19 20 21 22 23 24 25 21:59 UK +start 3 seed-p18 19 20 21 22 23 24 25 21:59 UK +end 3 seed-p18 19 20 21 22 23 24 25 rc 2 21:59 UK +start 1 liveness-p18 21:59 UK +end 1 liveness-p18 rc 0 21:59 UK +# night driver end 21:59 UK +# night driver start 22:01 UK host igneum-build-5 jobs 8 +start 1 seed-p18 22:01 UK +end 1 seed-p18 rc 0 22:01 UK +start 1 seed-p19 22:01 UK +end 1 seed-p19 rc 0 22:02 UK +start 1 seed-p20 22:02 UK +end 1 seed-p20 rc 0 22:03 UK +start 1 seed-p21 22:03 UK +end 1 seed-p21 rc 0 22:03 UK +start 1 seed-p22 22:03 UK +end 1 seed-p22 rc 0 22:04 UK +start 1 seed-p23 22:04 UK +end 1 seed-p23 rc 0 22:05 UK +start 1 seed-p24 22:05 UK +end 1 seed-p24 rc 0 22:05 UK +start 1 seed-p25 22:05 UK +end 1 seed-p25 rc 0 22:06 UK +# night driver end 22:06 UK diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p18.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p18.tsv new file mode 100644 index 000000000..183e9429c --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p18.tsv @@ -0,0 +1,42 @@ +# addrsite: program 0b686c80e25cb4d3 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 261876 0x000e4f1d 3 0.000011 +0 1 3 262144 261871 0x029461b8 2 0.000008 +# worst cell: iteration 0 site 0 address 0x000e4f1d in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 1 8388608 2097152 2080929 0x04b26299 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00008 -2.60 22 +1 3 1 8388608 2097152 2080879 0x05b4d045 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00005 -2.51 18 +2 6 0 16777216 2097152 2089195 0x0e4e082d 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00011 -1.82 22 +3 6 0 16777216 2097152 2089046 0x01dc5cc3 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00004 -1.95 9 +4 11 1 8388608 2097152 2080698 0x0b201331 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99997 -1.88 21 +5 11 1 8388608 2097152 2080934 0x0fde6798 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00008 -2.87 7 +6 18 2 4194304 2097152 2064883 0x00482c0a 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00024 1.85 17 +7 18 2 4194304 2097152 2064474 0x02002d3b 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00004 2.09 17 +8 27 2 4194304 2097152 2064914 0x066b8f5f 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00026 -2.61 3 +9 27 2 4194304 2097152 2064236 0x04666edb 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 0.99993 3.08 19 +10 34 2 4194304 2097152 2064642 0x000d13e3 3 0.000001 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00012 2.44 14 +11 34 2 4194304 2097152 2064513 0x0214c14a 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00006 -1.94 17 +12 37 1 8388608 2097152 2080803 0x060b2662 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00002 -2.47 19 +13 37 1 8388608 2097152 2080758 0x0331a9a9 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00000 -2.26 13 +14 40 2 4194304 2097152 2064723 0x0d1e0fd4 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00016 -2.98 6 +15 40 2 4194304 2097152 2064774 0x0ec5a875 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00019 -1.61 22 +16 41 2 4194304 2097152 2064682 0x03ec6eec 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00014 -2.38 9 +17 41 2 4194304 2097152 2064788 0x01da8b47 3 0.000001 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00020 2.55 20 +18 42 2 4194304 2097152 2064547 0x08cfd70a 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00008 1.76 9 +19 42 2 4194304 2097152 2064774 0x0b615202 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00019 1.98 6 +20 48 2 4194304 2097152 2064698 0x0cf47975 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00015 -2.57 10 +21 48 2 4194304 2097152 2064685 0x0cf6fe62 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00015 2.09 2 +22 50 0 16777216 2097152 2088969 0x00d21e2c 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00000 -2.30 23 +23 50 0 16777216 2097152 2088913 0x0ee7ed6f 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 -1.63 21 +24 55 2 4194304 2097152 2064704 0x0cc94d09 3 0.000001 1.0000 1.0000 0.7135 1.0000 1.0000 0.2500 1.00016 3.09 16 +25 55 2 4194304 2097152 2064810 0x0e04588b 3 0.000001 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00021 1.79 23 +26 57 1 8388608 2097152 2080683 0x071707d2 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99996 2.26 18 +27 57 1 8388608 2097152 2080580 0x04f60cb6 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 0.99991 -2.78 16 +28 60 1 8388608 2097152 2081125 0x0a64769a 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00017 -2.33 11 +29 60 1 8388608 2097152 2080624 0x0eada28b 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99993 -1.99 14 +30 62 0 16777216 2097152 2088835 0x0d3cb88c 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99994 1.61 15 +31 62 0 16777216 2097152 2088964 0x01baa343 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00000 -1.98 12 +# F8 form over the live stream: top 0.1 percent of items hold 0.003391 of reads; flat control 0.003074 (ratio 1.1032x), windowed control 0.003389 (ratio 1.0006x; the gate 1.2x); min site distinct ratio 0.99991 (floors 0.98 and 0.995); worst index bit inside its window 3.09 sigma at site 24 bit 16 (the band 6) +# program: reads 67108864, distinct items 16288897, worst site 0 address 0x04b26299 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4404, 64 MiB 0.1414; the per-site ideal caches summed: 1.0000, 1.0000, 0.6538; 37.2 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p19.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p19.tsv new file mode 100644 index 000000000..1761c9040 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p19.tsv @@ -0,0 +1,42 @@ +# addrsite: program bf8510cd00c0c70f class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 261655 0x0b1aa513 2 0.000008 +0 1 3 262144 261636 0x0a0aa4c2 2 0.000008 +# worst cell: iteration 0 site 2 address 0x06f0d11f in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 2 4194304 2097152 2064567 0x0813e726 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00009 1.97 3 +1 3 2 4194304 2097152 2064660 0x0bdd3cc7 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00013 -2.26 1 +2 5 2 4194304 2097152 2064744 0x06f31d4f 4 0.000002 1.0000 1.0000 0.7137 1.0000 1.0000 0.2500 1.00017 1.90 4 +3 5 2 4194304 2097152 2064476 0x04f74c73 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00004 -2.49 18 +4 8 0 16777216 2097152 2089084 0x0da80068 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00006 -2.56 15 +5 8 0 16777216 2097152 2088888 0x03c298f6 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99997 -1.86 27 +6 15 1 8388608 2097152 2080922 0x0cef3dd9 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00007 3.41 7 +7 15 1 8388608 2097152 2080961 0x0e2d839d 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00009 -1.93 17 +8 16 2 4194304 2097152 2064720 0x0ed37606 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00016 -2.29 3 +9 16 2 4194304 2097152 2064829 0x0ce21642 3 0.000001 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00022 -2.40 25 +10 18 0 16777216 2097152 2088870 0x05d987d8 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99996 2.03 11 +11 18 0 16777216 2097152 2088983 0x029a3121 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00001 2.05 10 +12 20 0 16777216 2097152 2088932 0x0dadfb46 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99999 2.63 14 +13 20 0 16777216 2097152 2089010 0x04a10d8d 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00002 2.62 17 +14 24 0 16777216 2097152 2088971 0x0b3f9d83 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00001 -2.54 21 +15 24 0 16777216 2097152 2088658 0x0a5d1395 3 0.000001 1.0000 1.0000 0.5604 1.0000 0.2500 0.0625 0.99986 2.46 20 +16 28 1 8388608 2097152 2080835 0x0da33a05 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00003 2.25 17 +17 28 1 8388608 2097152 2080764 0x0cab0080 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00000 2.18 20 +18 29 1 8388608 2097152 2080979 0x056d2902 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00010 -1.88 9 +19 29 1 8388608 2097152 2080906 0x02f221f1 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00007 2.67 3 +20 35 1 8388608 2097152 2080716 0x0a2c3876 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99998 -2.34 22 +21 35 1 8388608 2097152 2080861 0x0ab58865 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00004 3.51 1 +22 41 1 8388608 2097152 2081104 0x0d4373fb 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00016 -2.57 5 +23 41 1 8388608 2097152 2080795 0x0e0c41fb 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00001 -1.83 6 +24 52 2 4194304 2097152 2064791 0x0b08686d 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00020 2.41 17 +25 52 2 4194304 2097152 2064688 0x0a04c3d9 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00015 -2.02 0 +26 54 2 4194304 2097152 2064789 0x03fcf023 4 0.000002 1.0000 1.0000 0.7126 1.0000 1.0000 0.2500 1.00020 -3.04 17 +27 54 2 4194304 2097152 2064622 0x03abef8c 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00012 -2.57 4 +28 55 0 16777216 2097152 2088972 0x017e612a 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00001 1.96 10 +29 55 0 16777216 2097152 2089045 0x02c2382b 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00004 -3.81 7 +30 62 0 16777216 2097152 2088837 0x07a76cac 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99994 1.85 7 +31 62 0 16777216 2097152 2089047 0x0b01583f 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00004 -1.68 20 +# F8 form over the live stream: top 0.1 percent of items hold 0.003433 of reads; flat control 0.003076 (ratio 1.1159x), windowed control 0.003434 (ratio 0.9996x; the gate 1.2x); min site distinct ratio 0.99986 (floors 0.98 and 0.995); worst index bit inside its window -3.81 sigma at site 29 bit 7 (the band 6) +# program: reads 67108864, distinct items 16295371, worst site 0 address 0x0813e726 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4418, 64 MiB 0.1426; the per-site ideal caches summed: 1.0000, 1.0000, 0.6251; 37.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p20.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p20.tsv new file mode 100644 index 000000000..c80acded6 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p20.tsv @@ -0,0 +1,42 @@ +# addrsite: program 24133bd7265e958f class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 7 262144 261885 0x0343ee61 2 0.000008 +0 1 7 262144 261881 0x00f22a5f 2 0.000008 +# worst cell: iteration 0 site 2 address 0x0ae65aa6 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 7 1 8388608 2097152 2080652 0x07d93627 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 0.99994 2.09 15 +1 7 1 8388608 2097152 2080868 0x0686b399 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00005 1.62 1 +2 12 2 4194304 2097152 2064729 0x09d4fb1a 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00017 2.72 22 +3 12 2 4194304 2097152 2064685 0x091bcddd 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00015 -2.57 4 +4 16 0 16777216 2097152 2088927 0x091db95c 3 0.000001 1.0000 1.0000 0.5596 1.0000 0.2500 0.0625 0.99998 2.37 24 +5 16 0 16777216 2097152 2089036 0x089bc5e3 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00004 -2.18 3 +6 21 2 4194304 2097152 2064914 0x09526974 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00026 -1.99 5 +7 21 2 4194304 2097152 2065025 0x08d25517 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00031 2.32 15 +8 23 1 8388608 2097152 2080988 0x0e5dde91 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00011 -1.78 23 +9 23 1 8388608 2097152 2081037 0x0bdf5845 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00013 2.36 3 +10 26 1 8388608 2097152 2080754 0x003b1a48 4 0.000002 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 0.99999 2.56 8 +11 26 1 8388608 2097152 2080983 0x06b45091 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00010 -1.90 25 +12 31 0 16777216 2097152 2088910 0x0aa4ae37 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99998 -2.29 24 +13 31 0 16777216 2097152 2088934 0x081c8307 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99999 2.01 16 +14 37 0 16777216 2097152 2089016 0x0d26ec54 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00003 -2.15 12 +15 37 0 16777216 2097152 2088952 0x06846339 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00000 -2.47 7 +16 42 2 4194304 2097152 2064723 0x0fdf72bf 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00016 2.56 19 +17 42 2 4194304 2097152 2064835 0x0eac09aa 3 0.000001 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00022 -2.12 10 +18 50 2 4194304 2097152 2065072 0x01c5480c 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00033 2.89 21 +19 50 2 4194304 2097152 2064560 0x02d4382d 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00009 2.32 7 +20 52 1 8388608 2097152 2080693 0x0465e729 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99996 2.31 17 +21 52 1 8388608 2097152 2080994 0x0326cf51 4 0.000002 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 1.00011 2.95 6 +22 55 1 8388608 2097152 2080816 0x00faef0c 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00002 3.53 8 +23 55 1 8388608 2097152 2080759 0x02721691 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00000 -2.40 26 +24 56 1 8388608 2097152 2080758 0x035ae275 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00000 2.13 5 +25 56 1 8388608 2097152 2080689 0x05953052 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99996 2.28 21 +26 57 2 4194304 2097152 2064382 0x09a2e80e 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00000 1.70 20 +27 57 2 4194304 2097152 2064898 0x086ecbc9 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00025 1.86 9 +28 59 2 4194304 2097152 2064762 0x02cf86d2 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00018 -1.49 22 +29 59 2 4194304 2097152 2064911 0x008d0c7b 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00026 2.31 20 +30 61 0 16777216 2097152 2088933 0x0e8cac4a 4 0.000002 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99999 -3.55 0 +31 61 0 16777216 2097152 2089107 0x0278742c 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00007 1.93 26 +# F8 form over the live stream: top 0.1 percent of items hold 0.003434 of reads; flat control 0.003073 (ratio 1.1175x), windowed control 0.003433 (ratio 1.0003x; the gate 1.2x); min site distinct ratio 0.99994 (floors 0.98 and 0.995); worst index bit inside its window -3.55 sigma at site 30 bit 0 (the band 6) +# program: reads 67108864, distinct items 16241632, worst site 2 address 0x09d4fb1a in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4443, 64 MiB 0.1429; the per-site ideal caches summed: 1.0000, 1.0000, 0.6381; 37.2 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p21.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p21.tsv new file mode 100644 index 000000000..593a137d8 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p21.tsv @@ -0,0 +1,42 @@ +# addrsite: program ed647abf60a5bd32 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 2 262144 261872 0x05f8d1aa 2 0.000008 +0 1 2 262144 261875 0x03973640 3 0.000011 +# worst cell: iteration 0 site 1 address 0x03973640 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 2 1 8388608 2097152 2080802 0x04e14ec7 4 0.000002 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00002 -2.58 25 +1 2 1 8388608 2097152 2080971 0x04211450 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00010 -2.65 21 +2 3 1 8388608 2097152 2080923 0x023d7abf 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00007 2.18 5 +3 3 1 8388608 2097152 2080683 0x04a06101 4 0.000002 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 0.99996 3.13 20 +4 7 0 16777216 2097152 2089101 0x052b5c58 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00007 2.28 12 +5 7 0 16777216 2097152 2088894 0x0ea8f6e0 4 0.000002 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99997 -1.63 2 +6 9 2 4194304 2097152 2064761 0x01cfdee9 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00018 -1.55 24 +7 9 2 4194304 2097152 2064803 0x032825af 3 0.000001 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00020 -1.84 8 +8 10 0 16777216 2097152 2088925 0x08f54043 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 2.69 21 +9 10 0 16777216 2097152 2088838 0x0ee50520 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99994 3.05 2 +10 27 0 16777216 2097152 2088759 0x0bd61849 3 0.000001 1.0000 1.0000 0.5596 1.0000 0.2500 0.0625 0.99990 -2.66 22 +11 27 0 16777216 2097152 2088929 0x0e72d133 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99999 3.90 9 +12 31 2 4194304 2097152 2064623 0x01d8e0aa 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00012 -2.24 12 +13 31 2 4194304 2097152 2064847 0x0027fdfb 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00022 -2.39 22 +14 33 0 16777216 2097152 2088973 0x04d07c60 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00001 -2.74 13 +15 33 0 16777216 2097152 2088959 0x002b5d5d 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00000 2.46 19 +16 36 1 8388608 2097152 2080712 0x05de5e64 4 0.000002 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 0.99997 1.81 3 +17 36 1 8388608 2097152 2080944 0x06b26a12 4 0.000002 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00008 2.26 21 +18 38 2 4194304 2097152 2064895 0x0a4b211d 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00025 -2.38 6 +19 38 2 4194304 2097152 2064767 0x0b1e9590 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00019 -2.15 25 +20 43 2 4194304 2097152 2064538 0x00002183 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00007 2.47 15 +21 43 2 4194304 2097152 2064785 0x00f2fa9c 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00019 1.40 24 +22 45 0 16777216 2097152 2088974 0x0232deed 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00001 -2.78 10 +23 45 0 16777216 2097152 2088823 0x082dfbc8 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99993 -2.57 12 +24 46 1 8388608 2097152 2080831 0x05307add 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00003 2.35 26 +25 46 1 8388608 2097152 2080972 0x02c7003f 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00010 -2.73 13 +26 49 2 4194304 2097152 2064869 0x0ce514d8 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00023 3.14 1 +27 49 2 4194304 2097152 2064825 0x0d1a398d 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00021 -1.92 18 +28 51 1 8388608 2097152 2081035 0x036f523c 4 0.000002 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00013 -2.44 22 +29 51 1 8388608 2097152 2080904 0x007d72c3 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00007 -2.38 17 +30 58 2 4194304 2097152 2064698 0x0fb2a665 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00015 -2.02 18 +31 58 2 4194304 2097152 2064756 0x0d9fb4df 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00018 2.81 4 +# F8 form over the live stream: top 0.1 percent of items hold 0.003920 of reads; flat control 0.003072 (ratio 1.2759x), windowed control 0.003916 (ratio 1.0008x; the gate 1.2x); min site distinct ratio 0.99990 (floors 0.98 and 0.995); worst index bit inside its window 3.90 sigma at site 11 bit 9 (the band 6) +# program: reads 67108864, distinct items 16068557, worst site 0 address 0x04e14ec7 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4774, 64 MiB 0.1605; the per-site ideal caches summed: 1.0000, 1.0000, 0.6346; 38.1 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p22.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p22.tsv new file mode 100644 index 000000000..7ae5ecba7 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p22.tsv @@ -0,0 +1,42 @@ +# addrsite: program f8e8969443448ecb class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 10 262144 261667 0x0342068e 3 0.000011 +0 1 10 262144 261665 0x037fe51f 2 0.000008 +# worst cell: iteration 0 site 0 address 0x0342068e in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 10 2 4194304 2097152 2064542 0x015c50c8 4 0.000002 1.0000 1.0000 0.7135 1.0000 1.0000 0.2500 1.00008 1.73 11 +1 10 2 4194304 2097152 2064770 0x020b2e49 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00019 1.63 7 +2 16 0 16777216 2097152 2089059 0x06fd1db0 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00005 2.34 17 +3 16 0 16777216 2097152 2088990 0x07e58ba5 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00001 -2.10 10 +4 17 0 16777216 2097152 2088994 0x0fd5d743 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00002 -1.94 25 +5 17 0 16777216 2097152 2089076 0x00f95406 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00006 -1.74 10 +6 21 2 4194304 2097152 2064659 0x06a054ca 5 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00013 -1.93 6 +7 21 2 4194304 2097152 2064885 0x05a7e0c2 3 0.000001 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00024 2.54 1 +8 23 1 8388608 2097152 2080870 0x0b827be5 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00005 2.19 17 +9 23 1 8388608 2097152 2080956 0x0c78df5f 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00009 -2.98 8 +10 28 0 16777216 2097152 2088984 0x0cb359c8 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00001 -2.26 18 +11 28 0 16777216 2097152 2088903 0x0638beab 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 1.54 2 +12 29 0 16777216 2097152 2088841 0x01838b36 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99994 -2.28 4 +13 29 0 16777216 2097152 2088956 0x0e442134 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00000 3.31 19 +14 33 1 8388608 2097152 2080793 0x001b8dc0 4 0.000002 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00001 -2.16 11 +15 33 1 8388608 2097152 2081029 0x04edfa10 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00013 2.26 24 +16 34 0 16777216 2097152 2089107 0x0dd04c77 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00007 2.56 13 +17 34 0 16777216 2097152 2088893 0x0ae5097a 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99997 -2.69 19 +18 35 0 16777216 2097152 2089009 0x0bb3b40d 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00002 -2.43 23 +19 35 0 16777216 2097152 2088933 0x070a0621 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99999 -2.19 24 +20 37 0 16777216 2097152 2089027 0x03099106 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00003 2.22 7 +21 37 0 16777216 2097152 2088999 0x08d383ff 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00002 -1.53 13 +22 40 1 8388608 2097152 2081031 0x0e4fb3b6 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00013 2.33 15 +23 40 1 8388608 2097152 2080995 0x0d096fc6 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00011 -1.96 24 +24 41 1 8388608 2097152 2080943 0x02b4d894 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00008 -2.94 22 +25 41 1 8388608 2097152 2080678 0x054cd53d 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99996 -2.78 8 +26 54 2 4194304 2097152 2064942 0x07779f4e 4 0.000002 1.0000 1.0000 0.7125 1.0000 1.0000 0.2500 1.00027 1.74 11 +27 54 2 4194304 2097152 2064927 0x076d6cc7 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00026 -1.95 22 +28 61 0 16777216 2097152 2089030 0x0bed0704 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00003 -1.96 8 +29 61 0 16777216 2097152 2088963 0x0192583c 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00000 2.10 26 +30 62 2 4194304 2097152 2064643 0x0cad5999 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00013 2.80 22 +31 62 2 4194304 2097152 2064563 0x0c00d56f 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00009 2.03 6 +# F8 form over the live stream: top 0.1 percent of items hold 0.003237 of reads; flat control 0.003071 (ratio 1.0540x), windowed control 0.003238 (ratio 0.9997x; the gate 1.2x); min site distinct ratio 0.99994 (floors 0.98 and 0.995); worst index bit inside its window 3.31 sigma at site 13 bit 19 (the band 6) +# program: reads 67108864, distinct items 16386023, worst site 6 address 0x06a054ca in 5 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4271, 64 MiB 0.1370; the per-site ideal caches summed: 1.0000, 1.0000, 0.6120; 37.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p23.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p23.tsv new file mode 100644 index 000000000..edac89cfc --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p23.tsv @@ -0,0 +1,42 @@ +# addrsite: program 160649503341aaab class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 1 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 1 262144 261626 0x0c36e229 2 0.000008 +0 1 1 262144 261575 0x0c4df63a 2 0.000008 +# worst cell: iteration 0 site 5 address 0x051243d9 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 1 2 4194304 2097152 2064620 0x0f20f08a 3 0.000001 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00011 -1.75 0 +1 1 2 4194304 2097152 2064664 0x0e3c2793 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00014 -2.22 24 +2 8 1 8388608 2097152 2080742 0x05aa1636 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99999 2.43 4 +3 8 1 8388608 2097152 2080803 0x0174c4bf 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00002 2.23 5 +4 9 0 16777216 2097152 2089015 0x07bfc86f 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00003 2.56 3 +5 9 0 16777216 2097152 2089059 0x027b30bc 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 2.13 11 +6 13 1 8388608 2097152 2080752 0x08a9e70c 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99999 -1.82 22 +7 13 1 8388608 2097152 2080802 0x0d6c89d5 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00002 2.45 0 +8 22 0 16777216 2097152 2089102 0x07323aba 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00007 -2.58 8 +9 22 0 16777216 2097152 2089143 0x0a707102 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00009 -2.02 24 +10 26 2 4194304 2097152 2064711 0x0f35989a 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00016 -2.87 25 +11 26 2 4194304 2097152 2064898 0x0e10140d 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00025 -2.79 1 +12 33 0 16777216 2097152 2088937 0x0cc52d13 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99999 -1.77 0 +13 33 0 16777216 2097152 2089065 0x0451d2fd 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 -2.38 13 +14 34 1 8388608 2097152 2080864 0x0a1af540 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00005 -2.69 2 +15 34 1 8388608 2097152 2080867 0x0a3d0ae9 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00005 2.95 21 +16 35 0 16777216 2097152 2088945 0x025f3be0 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99999 -1.83 23 +17 35 0 16777216 2097152 2089147 0x0c8f9740 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00009 -2.67 14 +18 44 1 8388608 2097152 2080826 0x02e56123 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00003 1.72 22 +19 44 1 8388608 2097152 2080916 0x01310f61 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00007 -2.93 11 +20 46 0 16777216 2097152 2089144 0x03bd5597 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00009 2.14 12 +21 46 0 16777216 2097152 2088957 0x09024473 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00000 2.32 5 +22 50 0 16777216 2097152 2088845 0x0445d9d5 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99994 2.80 23 +23 50 0 16777216 2097152 2089093 0x04df6ce7 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00006 2.74 17 +24 54 0 16777216 2097152 2088933 0x0a07a102 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99999 -2.02 2 +25 54 0 16777216 2097152 2089030 0x0c1379f3 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00003 -3.44 1 +26 55 0 16777216 2097152 2088878 0x085501a8 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99996 -3.12 25 +27 55 0 16777216 2097152 2088948 0x0bbd318e 4 0.000002 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99999 -2.15 15 +28 60 2 4194304 2097152 2064493 0x08396e6d 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00005 -2.12 20 +29 60 2 4194304 2097152 2064724 0x0868b1b5 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00016 -2.12 0 +30 63 0 16777216 2097152 2089012 0x0678c249 3 0.000001 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00002 -1.83 13 +31 63 0 16777216 2097152 2089134 0x02233538 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00008 2.22 15 +# F8 form over the live stream: top 0.1 percent of items hold 0.003338 of reads; flat control 0.003075 (ratio 1.0854x), windowed control 0.003341 (ratio 0.9990x; the gate 1.2x); min site distinct ratio 0.99994 (floors 0.98 and 0.995); worst index bit inside its window -3.44 sigma at site 25 bit 1 (the band 6) +# program: reads 67108864, distinct items 16370394, worst site 1 address 0x0e3c2793 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4315, 64 MiB 0.1391; the per-site ideal caches summed: 1.0000, 1.0000, 0.6025; 37.7 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p24.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p24.tsv new file mode 100644 index 000000000..a14fb6cad --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p24.tsv @@ -0,0 +1,42 @@ +# addrsite: program 62aa0bfc93f13028 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 2 262144 262018 0x0e42540a 2 0.000008 +0 1 2 262144 262009 0x0e87042e 2 0.000008 +# worst cell: iteration 0 site 3 address 0x0bd48627 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 2 0 16777216 2097152 2089004 0x0cd23206 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 -3.31 11 +1 2 0 16777216 2097152 2089074 0x01eacf3c 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00005 -3.36 10 +2 14 2 4194304 2097152 2064697 0x08bdfbf3 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00015 -2.16 3 +3 14 2 4194304 2097152 2064991 0x0adf7230 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00029 -2.24 2 +4 15 1 8388608 2097152 2080753 0x0b5b8ced 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99999 3.46 15 +5 15 1 8388608 2097152 2080866 0x0eb45afa 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00005 -3.01 9 +6 16 0 16777216 2097152 2088985 0x09e312bd 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00001 -2.32 21 +7 16 0 16777216 2097152 2089013 0x0e41d3af 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00003 -3.46 23 +8 21 0 16777216 2097152 2089074 0x0233b8e7 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00005 3.40 15 +9 21 0 16777216 2097152 2088934 0x04dda3e6 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99999 -2.18 24 +10 26 2 4194304 2097152 2064727 0x00d5209f 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00017 2.10 15 +11 26 2 4194304 2097152 2064833 0x0282a4be 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00022 -1.77 15 +12 30 0 16777216 2097152 2088776 0x0486d4e0 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99991 -3.05 1 +13 30 0 16777216 2097152 2089051 0x05d602a3 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00004 2.14 17 +14 32 2 4194304 2097152 2064617 0x06a3fec8 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00011 -2.67 2 +15 32 2 4194304 2097152 2064708 0x05c925e7 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00016 3.15 21 +16 36 1 8388608 2097152 2080776 0x08c73031 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00000 1.81 2 +17 36 1 8388608 2097152 2080754 0x0de40a50 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99999 1.74 26 +18 39 2 4194304 2097152 2064597 0x000af8f5 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00010 2.75 18 +19 39 2 4194304 2097152 2064470 0x005eaed8 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00004 -2.00 19 +20 44 1 8388608 2097152 2080775 0x007f50dc 3 0.000001 1.0000 1.0000 0.6157 1.0000 0.5000 0.1250 1.00000 -1.98 0 +21 44 1 8388608 2097152 2080944 0x070ee707 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00008 2.92 4 +22 45 1 8388608 2097152 2080867 0x062f7ddd 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00005 -2.07 18 +23 45 1 8388608 2097152 2081022 0x075a2ba5 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00012 1.94 18 +24 50 0 16777216 2097152 2089068 0x0fee120f 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00005 2.18 17 +25 50 0 16777216 2097152 2088928 0x0a8c8847 4 0.000002 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 1.97 2 +26 60 1 8388608 2097152 2080743 0x0e047ef5 4 0.000002 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 0.99999 -2.67 15 +27 60 1 8388608 2097152 2080946 0x08edd8b2 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00009 2.95 9 +28 61 0 16777216 2097152 2088889 0x0a37d852 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 -1.90 17 +29 61 0 16777216 2097152 2088952 0x0961c7e8 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00000 1.94 11 +30 63 1 8388608 2097152 2081084 0x0e81d734 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00015 -2.27 16 +31 63 1 8388608 2097152 2080785 0x0e871b55 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00001 2.09 7 +# F8 form over the live stream: top 0.1 percent of items hold 0.003156 of reads; flat control 0.003075 (ratio 1.0264x), windowed control 0.003160 (ratio 0.9988x; the gate 1.2x); min site distinct ratio 0.99991 (floors 0.98 and 0.995); worst index bit inside its window 3.46 sigma at site 4 bit 15 (the band 6) +# program: reads 67108864, distinct items 16429212, worst site 2 address 0x08bdfbf3 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4212, 64 MiB 0.1338; the per-site ideal caches summed: 1.0000, 1.0000, 0.6190; 37.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p25.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p25.tsv new file mode 100644 index 000000000..e4dd3f622 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-5/seed-p25.tsv @@ -0,0 +1,42 @@ +# addrsite: program 3f1af0bbaaef74fa class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 262002 0x07f134b1 2 0.000008 +0 1 3 262144 262012 0x0a8848bb 2 0.000008 +# worst cell: iteration 0 site 2 address 0x0f8343d0 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 0 16777216 2097152 2088996 0x0cbb59da 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 2.18 1 +1 3 0 16777216 2097152 2089183 0x0a718089 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00011 2.08 11 +2 5 1 8388608 2097152 2080847 0x0fb1f63d 4 0.000002 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00004 3.27 5 +3 5 1 8388608 2097152 2080897 0x0d06ab75 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00006 -2.05 24 +4 13 2 4194304 2097152 2064814 0x05e5885b 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00021 -2.58 4 +5 13 2 4194304 2097152 2064602 0x047ac946 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00011 -1.81 5 +6 15 2 4194304 2097152 2064413 0x0b1385e8 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00001 -2.35 15 +7 15 2 4194304 2097152 2064991 0x0a8c2bdc 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00029 1.95 5 +8 16 2 4194304 2097152 2064808 0x0e3d532a 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00021 -2.07 6 +9 16 2 4194304 2097152 2064803 0x0f1eb20a 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00020 -2.16 20 +10 24 0 16777216 2097152 2088991 0x0550bb50 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00001 -3.16 1 +11 24 0 16777216 2097152 2088858 0x0d44845f 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99995 -2.00 20 +12 33 2 4194304 2097152 2064743 0x0fcb1fc5 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00017 2.21 4 +13 33 2 4194304 2097152 2064971 0x0d9a081b 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00028 -2.21 19 +14 37 1 8388608 2097152 2080823 0x08014036 4 0.000002 1.0000 1.0000 0.6158 1.0000 0.5000 0.1250 1.00003 2.52 4 +15 37 1 8388608 2097152 2080830 0x0c1b3d35 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00003 1.48 5 +16 44 2 4194304 2097152 2064369 0x0f89e882 4 0.000002 1.0000 1.0000 0.7135 1.0000 1.0000 0.2500 0.99999 -2.00 7 +17 44 2 4194304 2097152 2064584 0x0d4704d5 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00010 2.59 18 +18 45 2 4194304 2097152 2064707 0x0a38b699 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00016 2.00 7 +19 45 2 4194304 2097152 2064395 0x088409e8 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00001 2.25 3 +20 51 2 4194304 2097152 2064454 0x00cb2b66 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00003 2.08 23 +21 51 2 4194304 2097152 2064670 0x0034b787 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00014 2.21 2 +22 53 1 8388608 2097152 2080753 0x0696b0ab 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99999 -2.50 9 +23 53 1 8388608 2097152 2080886 0x005b4fa2 4 0.000002 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00006 1.75 7 +24 57 0 16777216 2097152 2088898 0x0bb45708 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99997 2.93 25 +25 57 0 16777216 2097152 2089068 0x0e8a9b07 3 0.000001 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00005 1.83 2 +26 59 0 16777216 2097152 2088887 0x022c48f7 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99997 3.26 1 +27 59 0 16777216 2097152 2088972 0x07d98200 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00001 2.05 16 +28 61 0 16777216 2097152 2088836 0x053563a9 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99994 -2.43 12 +29 61 0 16777216 2097152 2088824 0x0e2d271f 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99993 -2.10 19 +30 62 0 16777216 2097152 2088923 0x033cc4ac 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 -2.29 15 +31 62 0 16777216 2097152 2088953 0x04cd2576 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00000 -1.60 6 +# F8 form over the live stream: top 0.1 percent of items hold 0.003436 of reads; flat control 0.003070 (ratio 1.1192x), windowed control 0.003432 (ratio 1.0014x; the gate 1.2x); min site distinct ratio 0.99993 (floors 0.98 and 0.995); worst index bit inside its window 3.27 sigma at site 2 bit 5 (the band 6) +# program: reads 67108864, distinct items 16295799, worst site 2 address 0x0fb1f63d in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4418, 64 MiB 0.1426; the per-site ideal caches summed: 1.0000, 1.0000, 0.6373; 37.1 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-object-h4.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-object-h4.tsv new file mode 100644 index 000000000..6e8b39441 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-object-h4.tsv @@ -0,0 +1,67 @@ +# liveness: program 4de7b836cc40a4ea class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw registers 64 day bytes:69676e65756d2d6461792ffa50000000000000 dataset 2^28 words (memory-hard) headers 4 warps 16 threads 32 probe words 2 +reg probes first_load_changed hash_changed least_changed_load least_changed_frac +0 4096 1.000000 1.000000 0 1.000000 +1 4096 1.000000 1.000000 0 1.000000 +2 4096 1.000000 1.000000 0 1.000000 +3 4096 1.000000 1.000000 0 1.000000 +4 4096 1.000000 1.000000 0 1.000000 +5 4096 1.000000 1.000000 0 1.000000 +6 4096 1.000000 1.000000 0 1.000000 +7 4096 1.000000 1.000000 0 1.000000 +8 4096 1.000000 1.000000 0 1.000000 +9 4096 1.000000 1.000000 0 1.000000 +10 4096 1.000000 1.000000 0 1.000000 +11 4096 1.000000 1.000000 0 1.000000 +12 4096 1.000000 1.000000 0 1.000000 +13 4096 1.000000 1.000000 0 1.000000 +14 4096 1.000000 1.000000 0 1.000000 +15 4096 1.000000 1.000000 0 1.000000 +16 4096 1.000000 1.000000 0 1.000000 +17 4096 1.000000 1.000000 0 1.000000 +18 4096 1.000000 1.000000 0 1.000000 +19 4096 1.000000 1.000000 0 1.000000 +20 4096 1.000000 1.000000 0 1.000000 +21 4096 1.000000 1.000000 0 1.000000 +22 4096 1.000000 1.000000 0 1.000000 +23 4096 1.000000 1.000000 0 1.000000 +24 4096 1.000000 1.000000 0 1.000000 +25 4096 1.000000 1.000000 0 1.000000 +26 4096 1.000000 1.000000 0 1.000000 +27 4096 1.000000 1.000000 0 1.000000 +28 4096 1.000000 1.000000 0 1.000000 +29 4096 1.000000 1.000000 0 1.000000 +30 4096 1.000000 1.000000 0 1.000000 +31 4096 1.000000 1.000000 0 1.000000 +32 4096 1.000000 1.000000 0 1.000000 +33 4096 1.000000 1.000000 0 1.000000 +34 4096 1.000000 1.000000 0 1.000000 +35 4096 1.000000 1.000000 0 1.000000 +36 4096 1.000000 1.000000 0 1.000000 +37 4096 1.000000 1.000000 0 1.000000 +38 4096 1.000000 1.000000 0 1.000000 +39 4096 1.000000 1.000000 0 1.000000 +40 4096 1.000000 1.000000 0 1.000000 +41 4096 1.000000 1.000000 0 1.000000 +42 4096 1.000000 1.000000 0 1.000000 +43 4096 1.000000 1.000000 0 1.000000 +44 4096 1.000000 1.000000 0 1.000000 +45 4096 1.000000 1.000000 0 1.000000 +46 4096 1.000000 1.000000 0 1.000000 +47 4096 1.000000 1.000000 0 1.000000 +48 4096 1.000000 1.000000 0 1.000000 +49 4096 1.000000 1.000000 0 1.000000 +50 4096 1.000000 1.000000 0 1.000000 +51 4096 1.000000 1.000000 0 1.000000 +52 4096 1.000000 1.000000 0 1.000000 +53 4096 1.000000 1.000000 0 1.000000 +54 4096 1.000000 1.000000 0 1.000000 +55 4096 1.000000 1.000000 0 1.000000 +56 4096 1.000000 1.000000 0 1.000000 +57 4096 1.000000 1.000000 0 1.000000 +58 4096 1.000000 1.000000 0 1.000000 +59 4096 1.000000 1.000000 0 1.000000 +60 4096 1.000000 1.000000 0 1.000000 +61 4096 1.000000 1.000000 0 1.000000 +62 4096 1.000000 1.000000 0 1.000000 +63 4096 1.000000 1.000000 0 1.000000 +# verdict: 64 registers over 4096 probes each; first-load address changed in 1.000000 of lanes at the least live register, the hash in 1.000000; the least changed (register, first-iteration load) is (0, 0) at 1.000000; LIVE on live data (every register moves every lane's first address and hash); 18.3 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-p26.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-p26.tsv new file mode 100644 index 000000000..df184e588 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/liveness-p26.tsv @@ -0,0 +1,67 @@ +# liveness: program 2b406490ba8d3c91 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw registers 64 day 2026-10-03 dataset 2^28 words (memory-hard) headers 2 warps 8 threads 32 probe words 2 +reg probes first_load_changed hash_changed least_changed_load least_changed_frac +0 1024 1.000000 1.000000 0 1.000000 +1 1024 1.000000 1.000000 0 1.000000 +2 1024 1.000000 1.000000 0 1.000000 +3 1024 1.000000 1.000000 0 1.000000 +4 1024 1.000000 1.000000 0 1.000000 +5 1024 1.000000 1.000000 0 1.000000 +6 1024 1.000000 1.000000 0 1.000000 +7 1024 1.000000 1.000000 0 1.000000 +8 1024 1.000000 1.000000 0 1.000000 +9 1024 1.000000 1.000000 0 1.000000 +10 1024 1.000000 1.000000 0 1.000000 +11 1024 1.000000 1.000000 0 1.000000 +12 1024 1.000000 1.000000 0 1.000000 +13 1024 1.000000 1.000000 0 1.000000 +14 1024 1.000000 1.000000 0 1.000000 +15 1024 1.000000 1.000000 0 1.000000 +16 1024 1.000000 1.000000 0 1.000000 +17 1024 1.000000 1.000000 0 1.000000 +18 1024 1.000000 1.000000 0 1.000000 +19 1024 1.000000 1.000000 0 1.000000 +20 1024 1.000000 1.000000 0 1.000000 +21 1024 1.000000 1.000000 0 1.000000 +22 1024 1.000000 1.000000 0 1.000000 +23 1024 1.000000 1.000000 0 1.000000 +24 1024 1.000000 1.000000 0 1.000000 +25 1024 1.000000 1.000000 0 1.000000 +26 1024 1.000000 1.000000 0 1.000000 +27 1024 1.000000 1.000000 0 1.000000 +28 1024 1.000000 1.000000 0 1.000000 +29 1024 1.000000 1.000000 0 1.000000 +30 1024 1.000000 1.000000 0 1.000000 +31 1024 1.000000 1.000000 0 1.000000 +32 1024 1.000000 1.000000 0 1.000000 +33 1024 1.000000 1.000000 0 1.000000 +34 1024 1.000000 1.000000 0 1.000000 +35 1024 1.000000 1.000000 0 1.000000 +36 1024 1.000000 1.000000 0 1.000000 +37 1024 1.000000 1.000000 0 1.000000 +38 1024 1.000000 1.000000 0 1.000000 +39 1024 1.000000 1.000000 0 1.000000 +40 1024 1.000000 1.000000 0 1.000000 +41 1024 1.000000 1.000000 0 1.000000 +42 1024 1.000000 1.000000 0 1.000000 +43 1024 1.000000 1.000000 0 1.000000 +44 1024 1.000000 1.000000 0 1.000000 +45 1024 1.000000 1.000000 0 1.000000 +46 1024 1.000000 1.000000 0 1.000000 +47 1024 1.000000 1.000000 0 1.000000 +48 1024 1.000000 1.000000 0 1.000000 +49 1024 1.000000 1.000000 0 1.000000 +50 1024 1.000000 1.000000 0 1.000000 +51 1024 1.000000 1.000000 0 1.000000 +52 1024 1.000000 1.000000 0 1.000000 +53 1024 1.000000 1.000000 0 1.000000 +54 1024 1.000000 1.000000 0 1.000000 +55 1024 1.000000 1.000000 0 1.000000 +56 1024 1.000000 1.000000 0 1.000000 +57 1024 1.000000 1.000000 0 1.000000 +58 1024 1.000000 1.000000 0 1.000000 +59 1024 1.000000 1.000000 0 1.000000 +60 1024 1.000000 1.000000 0 1.000000 +61 1024 1.000000 1.000000 0 1.000000 +62 1024 1.000000 1.000000 0 1.000000 +63 1024 1.000000 1.000000 0 1.000000 +# verdict: 64 registers over 1024 probes each; first-load address changed in 1.000000 of lanes at the least live register, the hash in 1.000000; the least changed (register, first-iteration load) is (0, 0) at 1.000000; LIVE on live data (every register moves every lane's first address and hash); 4.7 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-jobs-6.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-jobs-6.tsv new file mode 100644 index 000000000..fda777164 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-jobs-6.tsv @@ -0,0 +1,5 @@ +canary-p18 # F8 form 16 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 1 --warps 256 --threads 16 --seed igneum-attack-f8/program/18 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +object-h4 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --header-from 4 --warps 8192 --threads 32 --epoch-hex edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +liveness-object-h4 # verdict 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow liveness --count 4 --header-from 4 --warps 16 --threads 32 --epoch-hex edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p26 27 28 29 30 31 32 33 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/26 27 28 29 30 31 32 33 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +liveness-p26 # verdict 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow liveness --count 2 --warps 8 --threads 32 --seed igneum-attack-f8/program/26 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-seeds-6.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-seeds-6.tsv new file mode 100644 index 000000000..6ea5f6a7c --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/night-seeds-6.tsv @@ -0,0 +1,8 @@ +seed-p26 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/26 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p27 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/27 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p28 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/28 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p29 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/29 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p30 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/30 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p31 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/31 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p32 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/32 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 +seed-p33 # F8 form 32 env IGNEUM_FAMILY_GATE=1 /srv/builds/v6-census/bin/all4-b819c23a/igneum-pow addrsite --count 4 --warps 2048 --threads 32 --seed igneum-attack-f8/program/33 --day-hex 69676e65756d2d6461792ffa50000000000000 --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --state /srv/builds/v6-census/packs/node1-state.igsd1 diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/object-h4.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/object-h4.tsv new file mode 100644 index 000000000..93772a7d5 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/object-h4.tsv @@ -0,0 +1,42 @@ +# addrsite: program 4de7b836cc40a4ea class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day bytes:69676e65756d2d6461792ffa50000000000000 dataset 2^28 words (memory-hard) headers 4 warps 8192 nonces/header 262144 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 7 1048576 1044536 0x0e05c4a9 3 0.000003 +0 1 7 1048576 1044607 0x08697f24 3 0.000003 +# worst cell: iteration 0 site 28 address 0x0f45e0db in 4 reads, share 0.000004 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 7 1 8388608 8388608 8131224 0x08f95f48 4 0.000000 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00059 -2.28 12 +1 7 1 8388608 8388608 8132204 0x0a60bde7 4 0.000000 1.0000 0.8678 0.3536 1.0000 0.5000 0.1250 1.00071 -2.24 21 +2 8 1 8388608 8388608 8132174 0x0d9d2d01 5 0.000001 1.0000 0.8680 0.3536 1.0000 0.5000 0.1250 1.00070 -2.48 13 +3 8 1 8388608 8388608 8131438 0x0899c671 5 0.000001 1.0000 0.8678 0.3536 1.0000 0.5000 0.1250 1.00061 -2.83 6 +4 9 0 16777216 8388608 8258753 0x08a8b28d 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00015 1.88 14 +5 9 0 16777216 8388608 8259388 0x03d1dc2b 4 0.000000 1.0000 0.7131 0.2827 1.0000 0.2500 0.0625 1.00022 2.64 25 +6 10 1 8388608 8388608 8132147 0x0ee46b12 5 0.000001 1.0000 0.8679 0.3536 1.0000 0.5000 0.1250 1.00070 1.88 15 +7 10 1 8388608 8388608 8132252 0x087b47fa 4 0.000000 1.0000 0.8679 0.3536 1.0000 0.5000 0.1250 1.00071 2.82 7 +8 11 2 4194304 8388608 7885782 0x07578642 5 0.000001 1.0000 1.0000 0.4839 1.0000 1.0000 0.2500 1.00273 -2.39 1 +9 11 2 4194304 8388608 7884591 0x048afc00 5 0.000001 1.0000 1.0000 0.4841 1.0000 1.0000 0.2500 1.00258 -3.06 1 +10 13 1 8388608 8388608 8131079 0x02be2d07 4 0.000000 1.0000 0.8681 0.3537 1.0000 0.5000 0.1250 1.00057 -2.24 7 +11 13 1 8388608 8388608 8131565 0x04d6955b 4 0.000000 1.0000 0.8680 0.3538 1.0000 0.5000 0.1250 1.00063 -1.87 17 +12 29 0 16777216 8388608 8259329 0x08f9a4bf 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00022 1.99 25 +13 29 0 16777216 8388608 8258841 0x0a5492cf 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00016 -2.54 14 +14 30 1 8388608 8388608 8131950 0x02134f18 5 0.000001 1.0000 0.8677 0.3535 1.0000 0.5000 0.1250 1.00068 -2.31 16 +15 30 1 8388608 8388608 8132719 0x04eec855 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00077 -2.37 24 +16 31 1 8388608 8388608 8131259 0x055f81c2 4 0.000000 1.0000 0.8680 0.3537 1.0000 0.5000 0.1250 1.00059 2.65 23 +17 31 1 8388608 8388608 8132146 0x00887025 5 0.000001 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00070 -2.40 24 +18 44 1 8388608 8388608 8132643 0x06da0c02 4 0.000000 1.0000 0.8679 0.3537 1.0000 0.5000 0.1250 1.00076 -2.11 11 +19 44 1 8388608 8388608 8131442 0x033fda08 4 0.000000 1.0000 0.8678 0.3537 1.0000 0.5000 0.1250 1.00061 -2.04 20 +20 46 1 8388608 8388608 8132391 0x00647e1d 5 0.000001 1.0000 0.8680 0.3538 1.0000 0.5000 0.1250 1.00073 2.73 24 +21 46 1 8388608 8388608 8131479 0x0436441b 6 0.000001 1.0000 0.8678 0.3536 1.0000 0.5000 0.1250 1.00062 2.56 17 +22 47 2 4194304 8388608 7885914 0x0173a911 5 0.000001 1.0000 1.0000 0.4842 1.0000 1.0000 0.2500 1.00275 -1.67 11 +23 47 2 4194304 8388608 7885359 0x01fa7113 5 0.000001 1.0000 1.0000 0.4839 1.0000 1.0000 0.2500 1.00268 -1.60 2 +24 52 0 16777216 8388608 8258931 0x08292ca1 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00017 2.73 11 +25 52 0 16777216 8388608 8258747 0x064542dc 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00015 -2.33 0 +26 56 0 16777216 8388608 8259124 0x084f5e4c 4 0.000000 1.0000 0.7131 0.2827 1.0000 0.2500 0.0625 1.00019 -1.40 5 +27 56 0 16777216 8388608 8259571 0x0eefc792 4 0.000000 1.0000 0.7130 0.2826 1.0000 0.2500 0.0625 1.00025 2.08 6 +28 58 1 8388608 8388608 8131558 0x0d472d62 4 0.000000 1.0000 0.8676 0.3535 1.0000 0.5000 0.1250 1.00063 -1.62 17 +29 58 1 8388608 8388608 8132744 0x0ac6b454 5 0.000001 1.0000 0.8680 0.3536 1.0000 0.5000 0.1250 1.00077 -1.80 23 +30 63 0 16777216 8388608 8258365 0x077876fc 4 0.000000 1.0000 0.7130 0.2827 1.0000 0.2500 0.0625 1.00010 2.87 25 +31 63 0 16777216 8388608 8258808 0x011e117e 4 0.000000 1.0000 0.7130 0.2827 1.0000 0.2500 0.0625 1.00015 2.46 27 +# F8 form over the live stream: top 0.1 percent of items hold 0.002140 of reads; flat control 0.001944 (ratio 1.1005x), windowed control 0.002141 (ratio 0.9995x; the gate 1.2x); min site distinct ratio 1.00010 (floors 0.98 and 0.995); worst index bit inside its window -3.06 sigma at site 9 bit 1 (the band 6) +# program: reads 268435456, distinct items 16777198, worst site 21 address 0x0436441b in 6 reads (share 0.000001); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.3540, 64 MiB 0.1035; the per-site ideal caches summed: 1.0000, 0.8360, 0.3478; 213.8 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/restarts.log b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/restarts.log new file mode 100644 index 000000000..b383748b2 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/restarts.log @@ -0,0 +1,38 @@ +# night driver start 21:56 UK host igneum-build-6 jobs 1 +start 1 canary-p18 21:56 UK +end 1 canary-p18 rc 0 21:56 UK +# night driver end 21:56 UK +# night driver start 21:56 UK host igneum-build-6 jobs 5 +start 1 object-h4 21:56 UK +end 1 object-h4 rc 0 22:00 UK +start 1 liveness-object-h4 22:00 UK +end 1 liveness-object-h4 rc 0 22:00 UK +start 1 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 1 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +restart 2 seed-p26 27 28 29 30 31 32 33 22:00 UK +start 2 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 2 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +restart 3 seed-p26 27 28 29 30 31 32 33 22:00 UK +start 3 seed-p26 27 28 29 30 31 32 33 22:00 UK +end 3 seed-p26 27 28 29 30 31 32 33 rc 2 22:00 UK +start 1 liveness-p26 22:00 UK +end 1 liveness-p26 rc 0 22:00 UK +# night driver end 22:00 UK +# night driver start 22:01 UK host igneum-build-6 jobs 8 +start 1 seed-p26 22:01 UK +end 1 seed-p26 rc 0 22:02 UK +start 1 seed-p27 22:02 UK +end 1 seed-p27 rc 0 22:02 UK +start 1 seed-p28 22:02 UK +end 1 seed-p28 rc 0 22:03 UK +start 1 seed-p29 22:03 UK +end 1 seed-p29 rc 0 22:04 UK +start 1 seed-p30 22:04 UK +end 1 seed-p30 rc 0 22:05 UK +start 1 seed-p31 22:05 UK +end 1 seed-p31 rc 0 22:06 UK +start 1 seed-p32 22:06 UK +end 1 seed-p32 rc 0 22:07 UK +start 1 seed-p33 22:07 UK +end 1 seed-p33 rc 0 22:08 UK +# night driver end 22:08 UK diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p26.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p26.tsv new file mode 100644 index 000000000..a5f8d7872 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p26.tsv @@ -0,0 +1,42 @@ +# addrsite: program 2b406490ba8d3c91 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 261881 0x0796afa2 2 0.000008 +0 1 3 262144 261869 0x01cee15a 2 0.000008 +# worst cell: iteration 0 site 6 address 0x0f26b8e6 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 1 8388608 2097152 2080650 0x0741db04 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 0.99994 2.85 24 +1 3 1 8388608 2097152 2080597 0x029d5b9c 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99992 1.78 12 +2 7 2 4194304 2097152 2064742 0x0121006a 3 0.000001 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00017 -2.28 24 +3 7 2 4194304 2097152 2064903 0x03f3960e 4 0.000002 1.0000 1.0000 0.7125 1.0000 1.0000 0.2500 1.00025 -1.90 12 +4 10 0 16777216 2097152 2089002 0x002c876d 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00002 -2.20 5 +5 10 0 16777216 2097152 2088876 0x07df131c 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99996 1.78 11 +6 17 1 8388608 2097152 2080848 0x0884b4b7 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00004 -2.05 7 +7 17 1 8388608 2097152 2081059 0x0d8689c5 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00014 -2.04 4 +8 18 1 8388608 2097152 2080725 0x0977d37e 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 0.99998 2.78 23 +9 18 1 8388608 2097152 2080924 0x0b418382 4 0.000002 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00007 2.18 12 +10 19 1 8388608 2097152 2080842 0x08d357f6 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00004 -1.92 4 +11 19 1 8388608 2097152 2080982 0x0df9e9cd 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00010 1.58 0 +12 20 1 8388608 2097152 2081066 0x025615ff 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00014 -2.18 12 +13 20 1 8388608 2097152 2080599 0x01ff4b28 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99992 -1.92 1 +14 23 2 4194304 2097152 2064627 0x0a245421 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00012 3.51 14 +15 23 2 4194304 2097152 2064463 0x0a5c53c6 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00004 -2.44 2 +16 26 1 8388608 2097152 2080876 0x058fa156 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00005 2.43 7 +17 26 1 8388608 2097152 2080706 0x04338f74 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99997 2.00 12 +18 27 0 16777216 2097152 2089001 0x095e38fe 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00002 2.48 12 +19 27 0 16777216 2097152 2088914 0x06fa25cf 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 -2.19 27 +20 28 1 8388608 2097152 2080721 0x029a3077 3 0.000001 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 0.99998 -2.11 26 +21 28 1 8388608 2097152 2081033 0x001ea1b6 4 0.000002 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00013 2.67 15 +22 36 2 4194304 2097152 2064724 0x0cfd1910 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00016 -1.69 7 +23 36 2 4194304 2097152 2064729 0x0e8d39a5 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00017 2.12 18 +24 39 1 8388608 2097152 2080666 0x07f5b296 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99995 -1.47 3 +25 39 1 8388608 2097152 2080855 0x03721473 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00004 2.67 18 +26 40 2 4194304 2097152 2064757 0x0d652b7d 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00018 2.01 5 +27 40 2 4194304 2097152 2064796 0x0e2a2c8c 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00020 1.88 7 +28 52 0 16777216 2097152 2089053 0x02e3b79a 4 0.000002 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00004 3.61 20 +29 52 0 16777216 2097152 2089018 0x00cf2ad8 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00003 1.53 23 +30 56 2 4194304 2097152 2064646 0x06d6a083 4 0.000002 1.0000 1.0000 0.7125 1.0000 1.0000 0.2500 1.00013 1.94 8 +31 56 2 4194304 2097152 2064990 0x05536f11 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00029 2.82 23 +# F8 form over the live stream: top 0.1 percent of items hold 0.003129 of reads; flat control 0.003073 (ratio 1.0183x), windowed control 0.003129 (ratio 1.0003x; the gate 1.2x); min site distinct ratio 0.99992 (floors 0.98 and 0.995); worst index bit inside its window 3.61 sigma at site 28 bit 20 (the band 6) +# program: reads 67108864, distinct items 16434319, worst site 3 address 0x03f3960e in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4196, 64 MiB 0.1328; the per-site ideal caches summed: 1.0000, 1.0000, 0.6354; 50.6 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p27.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p27.tsv new file mode 100644 index 000000000..df09b9754 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p27.tsv @@ -0,0 +1,42 @@ +# addrsite: program c38b57d654ad08d4 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 261997 0x07d1eebf 2 0.000008 +0 1 3 262144 262019 0x0e939f6a 2 0.000008 +# worst cell: iteration 0 site 2 address 0x01c78316 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 0 16777216 2097152 2089066 0x038a399f 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00005 2.10 6 +1 3 0 16777216 2097152 2089052 0x00223010 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00004 -2.32 1 +2 5 1 8388608 2097152 2080951 0x031a0ba8 4 0.000002 1.0000 1.0000 0.6148 1.0000 0.5000 0.1250 1.00009 -2.01 1 +3 5 1 8388608 2097152 2080827 0x01cef2a6 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00003 1.85 25 +4 6 0 16777216 2097152 2088908 0x06f84932 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99998 -1.71 12 +5 6 0 16777216 2097152 2089038 0x0a9f3c2e 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00004 1.74 16 +6 8 2 4194304 2097152 2064774 0x06a7b797 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00019 2.13 23 +7 8 2 4194304 2097152 2065283 0x0540406b 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00044 -2.06 24 +8 18 0 16777216 2097152 2088890 0x0bf8b2ea 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 -2.90 16 +9 18 0 16777216 2097152 2088889 0x0ef39ae7 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99997 -1.77 20 +10 20 0 16777216 2097152 2088949 0x092b13a6 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99999 2.27 3 +11 20 0 16777216 2097152 2089093 0x062cbd71 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00006 -1.74 26 +12 39 1 8388608 2097152 2080772 0x045ba978 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00000 -2.34 14 +13 39 1 8388608 2097152 2080878 0x00133859 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00005 2.22 9 +14 45 1 8388608 2097152 2081020 0x0f39bd80 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00012 -2.29 2 +15 45 1 8388608 2097152 2080852 0x09dc13e3 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00004 2.11 0 +16 47 1 8388608 2097152 2080863 0x09e38573 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00005 -1.93 13 +17 47 1 8388608 2097152 2080695 0x0ccd34c5 3 0.000001 1.0000 1.0000 0.6157 1.0000 0.5000 0.1250 0.99996 2.01 20 +18 48 0 16777216 2097152 2088968 0x0ec9cce7 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00000 2.79 23 +19 48 0 16777216 2097152 2089007 0x07a0a4f2 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00002 1.83 7 +20 50 1 8388608 2097152 2080975 0x05fd559e 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00010 -2.56 19 +21 50 1 8388608 2097152 2080734 0x0286bedb 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 0.99998 2.80 1 +22 51 0 16777216 2097152 2089049 0x0121e88c 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00004 -2.09 9 +23 51 0 16777216 2097152 2088846 0x0732038a 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99995 2.45 19 +24 53 0 16777216 2097152 2088905 0x0b3dfd67 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99997 -1.75 9 +25 53 0 16777216 2097152 2088998 0x0872ca75 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00002 -2.30 5 +26 54 1 8388608 2097152 2080735 0x00baa42d 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 0.99998 -2.13 6 +27 54 1 8388608 2097152 2080896 0x0566331d 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00006 2.38 25 +28 59 2 4194304 2097152 2064408 0x0e2a3d91 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00001 2.85 13 +29 59 2 4194304 2097152 2064617 0x0f88d3d4 3 0.000001 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00011 2.61 7 +30 63 1 8388608 2097152 2080907 0x03195a58 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00007 2.18 5 +31 63 1 8388608 2097152 2080916 0x030e7e56 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00007 -2.03 6 +# F8 form over the live stream: top 0.1 percent of items hold 0.003348 of reads; flat control 0.003079 (ratio 1.0873x), windowed control 0.003344 (ratio 1.0010x; the gate 1.2x); min site distinct ratio 0.99995 (floors 0.98 and 0.995); worst index bit inside its window -2.90 sigma at site 8 bit 16 (the band 6) +# program: reads 67108864, distinct items 16328481, worst site 2 address 0x031a0ba8 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4343, 64 MiB 0.1396; the per-site ideal caches summed: 1.0000, 1.0000, 0.6033; 50.8 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p28.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p28.tsv new file mode 100644 index 000000000..7dc94cebe --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p28.tsv @@ -0,0 +1,42 @@ +# addrsite: program 96e4f7fdccef6fd1 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 4 262144 262014 0x0fef6e9b 2 0.000008 +0 1 4 262144 262012 0x0c0fc40d 2 0.000008 +# worst cell: iteration 0 site 7 address 0x03149070 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 4 0 16777216 2097152 2088962 0x0f297121 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00000 -2.85 15 +1 4 0 16777216 2097152 2088985 0x0ed393d0 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00001 -3.21 1 +2 8 1 8388608 2097152 2080764 0x030525f1 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00000 3.54 3 +3 8 1 8388608 2097152 2080858 0x067bb746 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00004 -2.62 18 +4 9 2 4194304 2097152 2064518 0x0dd0a987 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00006 -2.41 18 +5 9 2 4194304 2097152 2064686 0x0ec38ef5 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00015 -2.48 7 +6 11 2 4194304 2097152 2064652 0x003f4555 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00013 -2.27 0 +7 11 2 4194304 2097152 2064759 0x03c88d86 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00018 2.18 5 +8 12 0 16777216 2097152 2088812 0x0b0da342 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99993 1.96 10 +9 12 0 16777216 2097152 2089058 0x068f7410 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 -2.50 13 +10 23 0 16777216 2097152 2088888 0x0089f2ab 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99997 1.50 15 +11 23 0 16777216 2097152 2088888 0x06daaad0 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99997 -1.89 0 +12 24 1 8388608 2097152 2080872 0x043fe3db 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00005 -1.85 15 +13 24 1 8388608 2097152 2080950 0x01ffb71c 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00009 -3.46 6 +14 26 1 8388608 2097152 2080924 0x0ceac1e0 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00007 1.83 4 +15 26 1 8388608 2097152 2080753 0x0f54ef61 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99999 -1.66 23 +16 27 2 4194304 2097152 2064761 0x06ea3773 4 0.000002 1.0000 1.0000 0.7126 1.0000 1.0000 0.2500 1.00018 -1.84 3 +17 27 2 4194304 2097152 2064907 0x04b668aa 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00025 -1.92 5 +18 30 1 8388608 2097152 2080959 0x02a62f63 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00009 -2.76 20 +19 30 1 8388608 2097152 2080936 0x03b294e3 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00008 2.59 12 +20 37 0 16777216 2097152 2089043 0x07e38f1d 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00004 -3.09 0 +21 37 0 16777216 2097152 2088987 0x07cc45d0 3 0.000001 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00001 2.34 1 +22 39 2 4194304 2097152 2064545 0x00823b70 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00008 2.16 5 +23 39 2 4194304 2097152 2064803 0x00354b28 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00020 2.46 22 +24 44 0 16777216 2097152 2089015 0x0f9cd92e 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00003 2.14 16 +25 44 0 16777216 2097152 2088808 0x0237ee9c 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99993 -3.99 11 +26 52 2 4194304 2097152 2065077 0x0b35596e 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00034 2.05 4 +27 52 2 4194304 2097152 2064762 0x09ecc32b 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00018 2.29 10 +28 53 1 8388608 2097152 2080801 0x0b3620c0 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00002 2.45 9 +29 53 1 8388608 2097152 2080894 0x0a454d53 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00006 -1.99 14 +30 63 2 4194304 2097152 2064520 0x034a2155 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00007 -2.38 25 +31 63 2 4194304 2097152 2064832 0x02c50431 4 0.000002 1.0000 1.0000 0.7126 1.0000 1.0000 0.2500 1.00022 1.66 14 +# F8 form over the live stream: top 0.1 percent of items hold 0.003499 of reads; flat control 0.003071 (ratio 1.1396x), windowed control 0.003498 (ratio 1.0005x; the gate 1.2x); min site distinct ratio 0.99993 (floors 0.98 and 0.995); worst index bit inside its window -3.99 sigma at site 25 bit 11 (the band 6) +# program: reads 67108864, distinct items 16340448, worst site 2 address 0x030525f1 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4400, 64 MiB 0.1434; the per-site ideal caches summed: 1.0000, 1.0000, 0.6346; 50.1 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p29.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p29.tsv new file mode 100644 index 000000000..4242f99a1 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p29.tsv @@ -0,0 +1,42 @@ +# addrsite: program 3f922ac24b46d2c2 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 1 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 3 262144 261878 0x0c2ec6c7 2 0.000008 +0 1 3 262144 261865 0x0ef15836 3 0.000011 +# worst cell: iteration 0 site 1 address 0x0ef15836 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 3 1 8388608 2097152 2080901 0x0b8c7476 3 0.000001 1.0000 1.0000 0.6148 1.0000 0.5000 0.1250 1.00006 2.12 3 +1 3 1 8388608 2097152 2080842 0x0e0e9857 3 0.000001 1.0000 1.0000 0.6156 1.0000 0.5000 0.1250 1.00004 -2.70 13 +2 6 0 16777216 2097152 2088910 0x0ccf2db5 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99998 2.21 22 +3 6 0 16777216 2097152 2088975 0x067df852 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00001 2.42 23 +4 9 0 16777216 2097152 2088942 0x0b41129a 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99999 1.71 0 +5 9 0 16777216 2097152 2088972 0x07e0c715 3 0.000001 1.0000 1.0000 0.5603 1.0000 0.2500 0.0625 1.00001 -2.30 24 +6 11 0 16777216 2097152 2088998 0x0b5b69b9 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00002 2.44 17 +7 11 0 16777216 2097152 2088921 0x0e92f974 4 0.000002 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99998 1.98 14 +8 12 0 16777216 2097152 2088931 0x0d9e4e72 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99999 -1.66 5 +9 12 0 16777216 2097152 2088899 0x043a0980 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 -1.73 13 +10 19 1 8388608 2097152 2081053 0x0d78029b 4 0.000002 1.0000 1.0000 0.6148 1.0000 0.5000 0.1250 1.00014 1.94 1 +11 19 1 8388608 2097152 2080725 0x09ff33fa 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99998 1.97 8 +12 21 1 8388608 2097152 2080850 0x085bed84 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00004 2.29 20 +13 21 1 8388608 2097152 2080735 0x0cfb8ada 4 0.000002 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 0.99998 -1.89 25 +14 28 0 16777216 2097152 2089104 0x010e3e04 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00007 2.81 26 +15 28 0 16777216 2097152 2089028 0x0ff2d25e 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00003 2.24 16 +16 34 2 4194304 2097152 2064689 0x0226eb19 3 0.000001 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00015 2.50 12 +17 34 2 4194304 2097152 2064744 0x02f7f431 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00017 -2.07 3 +18 37 2 4194304 2097152 2064562 0x04069af3 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00009 -2.93 23 +19 37 2 4194304 2097152 2064860 0x077eea20 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00023 -2.24 19 +20 50 2 4194304 2097152 2064569 0x0b2e4e25 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00009 2.76 6 +21 50 2 4194304 2097152 2064719 0x0a183716 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00016 -2.06 23 +22 53 2 4194304 2097152 2064699 0x0739628d 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00015 -1.62 21 +23 53 2 4194304 2097152 2064379 0x068d23d5 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00000 -1.92 15 +24 55 0 16777216 2097152 2089025 0x04daf1b2 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00003 -1.69 2 +25 55 0 16777216 2097152 2089136 0x0f760a24 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00008 3.00 18 +26 57 1 8388608 2097152 2081024 0x01e33a42 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00012 1.65 10 +27 57 1 8388608 2097152 2080955 0x033c7675 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00009 2.57 4 +28 59 2 4194304 2097152 2064717 0x0ec174b6 3 0.000001 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00016 2.24 2 +29 59 2 4194304 2097152 2064609 0x0e2fdb21 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00011 2.69 12 +30 62 1 8388608 2097152 2080947 0x0ae4acab 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00009 1.96 10 +31 62 1 8388608 2097152 2080771 0x0d5adff3 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00000 -1.68 7 +# F8 form over the live stream: top 0.1 percent of items hold 0.003169 of reads; flat control 0.003069 (ratio 1.0326x), windowed control 0.003168 (ratio 1.0004x; the gate 1.2x); min site distinct ratio 0.99997 (floors 0.98 and 0.995); worst index bit inside its window 3.00 sigma at site 25 bit 18 (the band 6) +# program: reads 67108864, distinct items 16398093, worst site 7 address 0x0e92f974 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4241, 64 MiB 0.1350; the per-site ideal caches summed: 1.0000, 1.0000, 0.6251; 50.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p30.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p30.tsv new file mode 100644 index 000000000..df7d7f252 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p30.tsv @@ -0,0 +1,42 @@ +# addrsite: program edd13a08477407cf class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 2 262144 261596 0x0e92237a 3 0.000011 +0 1 2 262144 261624 0x0e452649 3 0.000011 +# worst cell: iteration 0 site 0 address 0x0e92237a in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 2 2 4194304 2097152 2064660 0x0e3a012d 4 0.000002 1.0000 1.0000 0.7135 1.0000 1.0000 0.2500 1.00013 -2.13 19 +1 2 2 4194304 2097152 2064792 0x0efd0e64 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00020 -1.88 10 +2 3 0 16777216 2097152 2089026 0x089fe2f1 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00003 -2.04 19 +3 3 0 16777216 2097152 2088866 0x0f538658 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99996 2.06 2 +4 5 1 8388608 2097152 2081083 0x0113a588 4 0.000002 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00015 2.59 26 +5 5 1 8388608 2097152 2080739 0x00b80889 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 0.99999 -1.31 1 +6 7 2 4194304 2097152 2064766 0x06e15152 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00019 -1.63 1 +7 7 2 4194304 2097152 2064743 0x075b8ab1 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00017 1.80 0 +8 10 2 4194304 2097152 2064536 0x0aa9d2e5 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00007 -1.82 14 +9 10 2 4194304 2097152 2064775 0x0a458569 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00019 -2.15 3 +10 12 2 4194304 2097152 2064772 0x047b5d50 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00019 1.72 6 +11 12 2 4194304 2097152 2064471 0x072c3ae9 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00004 -2.31 18 +12 14 0 16777216 2097152 2089071 0x07f185e5 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 2.53 14 +13 14 0 16777216 2097152 2089027 0x0551ac9e 4 0.000002 1.0000 1.0000 0.5604 1.0000 0.2500 0.0625 1.00003 1.99 3 +14 35 1 8388608 2097152 2081160 0x071cdd6f 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00019 -1.66 12 +15 35 1 8388608 2097152 2080869 0x028dc39f 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00005 -2.47 4 +16 41 0 16777216 2097152 2088900 0x070d37d0 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99997 2.48 12 +17 41 0 16777216 2097152 2089041 0x05e5c1d2 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00004 2.13 24 +18 42 0 16777216 2097152 2089192 0x0f074fdc 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00011 1.85 11 +19 42 0 16777216 2097152 2089007 0x05de0df0 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 -2.08 25 +20 49 2 4194304 2097152 2064790 0x08b805dd 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00020 1.78 15 +21 49 2 4194304 2097152 2064415 0x08429932 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00002 -2.19 18 +22 50 0 16777216 2097152 2088881 0x03d794a9 4 0.000002 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99996 1.81 2 +23 50 0 16777216 2097152 2088771 0x0906f3bb 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99991 2.30 16 +24 54 2 4194304 2097152 2064447 0x01174ec0 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00003 -2.38 19 +25 54 2 4194304 2097152 2064637 0x00f5480b 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00012 1.97 15 +26 56 0 16777216 2097152 2088993 0x0248a45d 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00002 2.31 22 +27 56 0 16777216 2097152 2089061 0x0e415537 4 0.000002 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 2.14 18 +28 58 1 8388608 2097152 2080959 0x03cc4951 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00009 -1.96 24 +29 58 1 8388608 2097152 2080841 0x0780a964 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00004 -2.22 19 +30 62 0 16777216 2097152 2089002 0x034a75de 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 -2.32 5 +31 62 0 16777216 2097152 2089002 0x0f5d6282 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 -2.03 6 +# F8 form over the live stream: top 0.1 percent of items hold 0.003348 of reads; flat control 0.003069 (ratio 1.0910x), windowed control 0.003355 (ratio 0.9981x; the gate 1.2x); min site distinct ratio 0.99991 (floors 0.98 and 0.995); worst index bit inside its window 2.59 sigma at site 4 bit 26 (the band 6) +# program: reads 67108864, distinct items 16327902, worst site 0 address 0x0e3a012d in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4343, 64 MiB 0.1395; the per-site ideal caches summed: 1.0000, 1.0000, 0.6278; 50.7 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p31.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p31.tsv new file mode 100644 index 000000000..ac1d3bba3 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p31.tsv @@ -0,0 +1,42 @@ +# addrsite: program e1409749e795c382 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 1 262144 261603 0x0f8c1753 3 0.000011 +0 1 1 262144 261651 0x0d5543d7 3 0.000011 +# worst cell: iteration 0 site 0 address 0x0f8c1753 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 1 2 4194304 2097152 2064417 0x0d3d1622 4 0.000002 1.0000 1.0000 0.7128 1.0000 1.0000 0.2500 1.00002 3.14 14 +1 1 2 4194304 2097152 2064840 0x0fa5865f 4 0.000002 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00022 -2.46 6 +2 3 1 8388608 2097152 2080966 0x03d01c00 4 0.000002 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00010 -2.56 14 +3 3 1 8388608 2097152 2080827 0x01743ea9 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00003 2.27 10 +4 4 1 8388608 2097152 2080757 0x07072358 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 0.99999 -1.68 10 +5 4 1 8388608 2097152 2080892 0x02f59100 4 0.000002 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00006 -2.12 23 +6 7 1 8388608 2097152 2080928 0x039d6050 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00008 -3.16 18 +7 7 1 8388608 2097152 2080806 0x04c9f0c0 4 0.000002 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00002 -3.23 21 +8 11 1 8388608 2097152 2080660 0x0f16f53b 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99995 2.46 21 +9 11 1 8388608 2097152 2080780 0x0db21bbc 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00001 3.16 20 +10 12 0 16777216 2097152 2088897 0x066eced5 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 -2.05 11 +11 12 0 16777216 2097152 2088940 0x0a429328 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 0.99999 -2.17 25 +12 13 0 16777216 2097152 2088856 0x083b252d 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99995 -3.06 8 +13 13 0 16777216 2097152 2088909 0x00cf618b 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 0.99998 2.43 25 +14 21 0 16777216 2097152 2089005 0x0987e15e 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00002 -2.48 1 +15 21 0 16777216 2097152 2089048 0x0521f8d9 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00004 2.42 26 +16 28 0 16777216 2097152 2089052 0x076ce703 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00004 -1.85 0 +17 28 0 16777216 2097152 2088783 0x0294ce2e 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99992 2.21 23 +18 41 1 8388608 2097152 2080761 0x0aa1f1bb 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00000 -2.71 6 +19 41 1 8388608 2097152 2080520 0x0e3e5fbc 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99988 -2.07 17 +20 43 2 4194304 2097152 2064966 0x0aff5e6c 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00028 -3.05 3 +21 43 2 4194304 2097152 2064713 0x0947d9e2 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00016 -2.94 10 +22 47 0 16777216 2097152 2088775 0x09c797b7 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99991 -2.99 11 +23 47 0 16777216 2097152 2088930 0x0cd8eb21 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99999 2.00 17 +24 54 1 8388608 2097152 2080730 0x0a57503c 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99998 3.06 0 +25 54 1 8388608 2097152 2080989 0x0c0438a7 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00011 -1.78 23 +26 56 2 4194304 2097152 2064734 0x0939f6e7 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00017 -1.76 5 +27 56 2 4194304 2097152 2064767 0x089d01aa 4 0.000002 1.0000 1.0000 0.7135 1.0000 1.0000 0.2500 1.00019 1.85 15 +28 61 1 8388608 2097152 2081039 0x09fd07dd 3 0.000001 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00013 -2.61 14 +29 61 1 8388608 2097152 2080997 0x0d5cf9e2 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00011 2.21 5 +30 62 0 16777216 2097152 2089098 0x06ff173a 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00007 2.65 14 +31 62 0 16777216 2097152 2088898 0x0b984754 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99997 -2.51 25 +# F8 form over the live stream: top 0.1 percent of items hold 0.003432 of reads; flat control 0.003075 (ratio 1.1164x), windowed control 0.003435 (ratio 0.9992x; the gate 1.2x); min site distinct ratio 0.99988 (floors 0.98 and 0.995); worst index bit inside its window -3.23 sigma at site 7 bit 21 (the band 6) +# program: reads 67108864, distinct items 16295937, worst site 0 address 0x0d3d1622 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4417, 64 MiB 0.1425; the per-site ideal caches summed: 1.0000, 1.0000, 0.6128; 50.5 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p32.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p32.tsv new file mode 100644 index 000000000..1d4a3ff9a --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p32.tsv @@ -0,0 +1,42 @@ +# addrsite: program 0717ad9158d5937f class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 2 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 2 262144 261895 0x08695fc3 3 0.000011 +0 1 2 262144 261887 0x0955348b 2 0.000008 +# worst cell: iteration 0 site 0 address 0x08695fc3 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 2 1 8388608 2097152 2081067 0x0d4f9faf 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 1.00014 -2.72 25 +1 2 1 8388608 2097152 2081036 0x0ed453f1 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00013 -1.92 3 +2 14 1 8388608 2097152 2080837 0x03443ba9 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00003 1.81 6 +3 14 1 8388608 2097152 2080665 0x01575a10 3 0.000001 1.0000 1.0000 0.6154 1.0000 0.5000 0.1250 0.99995 -2.30 14 +4 20 2 4194304 2097152 2064959 0x0cd645f0 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00028 -2.07 5 +5 20 2 4194304 2097152 2064678 0x0c6a1d56 4 0.000002 1.0000 1.0000 0.7132 1.0000 1.0000 0.2500 1.00014 -2.29 13 +6 29 0 16777216 2097152 2088928 0x03b55570 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99998 3.40 2 +7 29 0 16777216 2097152 2089054 0x06afe3b6 3 0.000001 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00004 -3.05 16 +8 31 1 8388608 2097152 2081166 0x0a04bf02 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00019 -2.47 20 +9 31 1 8388608 2097152 2080744 0x0e56cd9d 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 0.99999 -1.94 15 +10 32 2 4194304 2097152 2064477 0x0e061843 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00005 2.82 18 +11 32 2 4194304 2097152 2064673 0x0df8ef99 4 0.000002 1.0000 1.0000 0.7133 1.0000 1.0000 0.2500 1.00014 -2.17 8 +12 33 0 16777216 2097152 2089016 0x0f28266b 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00003 -2.04 26 +13 33 0 16777216 2097152 2089185 0x07578dbd 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00011 -2.69 5 +14 39 1 8388608 2097152 2080978 0x0211cb12 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00010 -2.03 6 +15 39 1 8388608 2097152 2081059 0x061d30a0 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00014 2.14 16 +16 42 2 4194304 2097152 2064856 0x0746f9ef 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00023 -2.12 0 +17 42 2 4194304 2097152 2064582 0x07aac484 3 0.000001 1.0000 1.0000 0.7134 1.0000 1.0000 0.2500 1.00010 -1.97 10 +18 43 1 8388608 2097152 2080783 0x0d8fccc6 4 0.000002 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00001 -2.22 4 +19 43 1 8388608 2097152 2080755 0x0b1fc588 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99999 -2.48 14 +20 44 0 16777216 2097152 2089111 0x03453f54 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00007 1.76 5 +21 44 0 16777216 2097152 2089070 0x0751e392 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00005 -1.92 18 +22 47 1 8388608 2097152 2080841 0x0313f4d1 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00004 1.46 3 +23 47 1 8388608 2097152 2080811 0x0561317b 4 0.000002 1.0000 1.0000 0.6149 1.0000 0.5000 0.1250 1.00002 3.14 1 +24 48 2 4194304 2097152 2064886 0x050e620b 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00024 2.87 1 +25 48 2 4194304 2097152 2064825 0x0704c911 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00021 1.89 6 +26 49 0 16777216 2097152 2089046 0x04c89672 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00004 1.73 8 +27 49 0 16777216 2097152 2088824 0x031c13c0 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99993 2.76 7 +28 51 0 16777216 2097152 2089054 0x06747e52 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00004 2.00 7 +29 51 0 16777216 2097152 2089115 0x018b83fc 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00007 2.42 5 +30 52 0 16777216 2097152 2088883 0x07e795d6 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99996 -2.45 9 +31 52 0 16777216 2097152 2089172 0x0e17768c 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00010 2.22 2 +# F8 form over the live stream: top 0.1 percent of items hold 0.003378 of reads; flat control 0.003071 (ratio 1.1000x), windowed control 0.003377 (ratio 1.0004x; the gate 1.2x); min site distinct ratio 0.99993 (floors 0.98 and 0.995); worst index bit inside its window 3.40 sigma at site 6 bit 2 (the band 6) +# program: reads 67108864, distinct items 16303463, worst site 4 address 0x0cd645f0 in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4390, 64 MiB 0.1410; the per-site ideal caches summed: 1.0000, 1.0000, 0.6190; 50.7 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p33.tsv b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p33.tsv new file mode 100644 index 000000000..e1743422d --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/build-6/seed-p33.tsv @@ -0,0 +1,42 @@ +# addrsite: program 9857a41ce42f4677 class mx8-erad810f22d+sh256x27+state+reg64c+fold+rw attempt 0 generator v6 day 2026-10-03 dataset 2^28 words (memory-hard) headers 4 warps 2048 nonces/header 65536 threads 32 +# per (iteration, site) cell: the most read address and its share (A03's form); cells over 0.1 percent listed +it site instr reads distinct top_addr top_count top_share +0 0 4 262144 261854 0x03886725 2 0.000008 +0 1 4 262144 261876 0x06d3ba58 2 0.000008 +# worst cell: iteration 0 site 14 address 0x03846806 in 3 reads, share 0.000011 +# per site, pooled over the 8 iterations (hit rates: an ideal cache of the site's top K items, K = bytes / 64; exp = min(1, K / window items)) +site instr win window_items reads distinct top_addr top_count top_share hit_1GiB hit_256MiB hit_64MiB exp_1GiB exp_256MiB exp_64MiB distinct_ratio bit_z_max bit +0 4 1 8388608 2097152 2080828 0x034e20ad 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 1.00003 2.61 5 +1 4 1 8388608 2097152 2080697 0x0082ff20 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 0.99997 2.86 26 +2 6 2 4194304 2097152 2064740 0x0f425fde 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00017 2.45 3 +3 6 2 4194304 2097152 2064712 0x0d43bd52 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00016 -1.82 5 +4 7 1 8388608 2097152 2080884 0x099e7c18 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00006 2.38 20 +5 7 1 8388608 2097152 2080853 0x0e58403c 3 0.000001 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 1.00004 -3.95 5 +6 8 0 16777216 2097152 2088995 0x012d4547 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00002 2.05 6 +7 8 0 16777216 2097152 2089049 0x08a3d7fc 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 1.00004 1.96 24 +8 10 0 16777216 2097152 2088976 0x0ba1a02e 3 0.000001 1.0000 1.0000 0.5597 1.0000 0.2500 0.0625 1.00001 -2.65 6 +9 10 0 16777216 2097152 2088946 0x060bcdb9 3 0.000001 1.0000 1.0000 0.5603 1.0000 0.2500 0.0625 0.99999 -2.50 17 +10 13 0 16777216 2097152 2088889 0x05e3d58e 4 0.000002 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99997 1.28 5 +11 13 0 16777216 2097152 2089025 0x0b78defd 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00003 -1.84 26 +12 14 1 8388608 2097152 2080873 0x04877c20 3 0.000001 1.0000 1.0000 0.6150 1.0000 0.5000 0.1250 1.00005 1.45 24 +13 14 1 8388608 2097152 2081038 0x003a2c13 3 0.000001 1.0000 1.0000 0.6151 1.0000 0.5000 0.1250 1.00013 2.52 0 +14 21 2 4194304 2097152 2064428 0x01e0e6f5 4 0.000002 1.0000 1.0000 0.7130 1.0000 1.0000 0.2500 1.00002 -2.45 7 +15 21 2 4194304 2097152 2064800 0x028d9855 4 0.000002 1.0000 1.0000 0.7127 1.0000 1.0000 0.2500 1.00020 1.68 5 +16 26 2 4194304 2097152 2064895 0x036bf80b 4 0.000002 1.0000 1.0000 0.7129 1.0000 1.0000 0.2500 1.00025 1.95 19 +17 26 2 4194304 2097152 2064720 0x01d12723 4 0.000002 1.0000 1.0000 0.7131 1.0000 1.0000 0.2500 1.00016 1.82 10 +18 30 0 16777216 2097152 2088921 0x08a5d6a0 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99998 -2.74 5 +19 30 0 16777216 2097152 2088982 0x02d7209d 3 0.000001 1.0000 1.0000 0.5596 1.0000 0.2500 0.0625 1.00001 2.31 19 +20 41 1 8388608 2097152 2080644 0x04f6d097 4 0.000002 1.0000 1.0000 0.6155 1.0000 0.5000 0.1250 0.99994 2.59 14 +21 41 1 8388608 2097152 2080991 0x03743b6f 4 0.000002 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00011 -2.05 6 +22 42 0 16777216 2097152 2088965 0x0a107c86 3 0.000001 1.0000 1.0000 0.5602 1.0000 0.2500 0.0625 1.00000 1.89 21 +23 42 0 16777216 2097152 2088980 0x0bed59ae 3 0.000001 1.0000 1.0000 0.5598 1.0000 0.2500 0.0625 1.00001 2.68 23 +24 43 0 16777216 2097152 2088957 0x043578b0 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 1.00000 2.73 12 +25 43 0 16777216 2097152 2088906 0x0cc002e5 3 0.000001 1.0000 1.0000 0.5600 1.0000 0.2500 0.0625 0.99997 1.78 9 +26 48 1 8388608 2097152 2080828 0x0b9e1d33 3 0.000001 1.0000 1.0000 0.6152 1.0000 0.5000 0.1250 1.00003 -1.88 12 +27 48 1 8388608 2097152 2080665 0x08abccb4 3 0.000001 1.0000 1.0000 0.6153 1.0000 0.5000 0.1250 0.99995 1.96 25 +28 49 0 16777216 2097152 2088834 0x0761a1b4 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 0.99994 2.50 1 +29 49 0 16777216 2097152 2088962 0x0c8f7caa 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00000 -1.91 18 +30 62 0 16777216 2097152 2088884 0x0d7a8fad 3 0.000001 1.0000 1.0000 0.5601 1.0000 0.2500 0.0625 0.99996 -2.31 0 +31 62 0 16777216 2097152 2089107 0x0fc73850 3 0.000001 1.0000 1.0000 0.5599 1.0000 0.2500 0.0625 1.00007 2.92 16 +# F8 form over the live stream: top 0.1 percent of items hold 0.003416 of reads; flat control 0.003074 (ratio 1.1112x), windowed control 0.003417 (ratio 0.9996x; the gate 1.2x); min site distinct ratio 0.99994 (floors 0.98 and 0.995); worst index bit inside its window -3.95 sigma at site 5 bit 5 (the band 6) +# program: reads 67108864, distinct items 16348197, worst site 2 address 0x0f425fde in 4 reads (share 0.000002); one cache over the program's reads: 1 GiB 1.0000, 256 MiB 0.4358, 64 MiB 0.1410; the per-site ideal caches summed: 1.0000, 1.0000, 0.6059; 50.8 s diff --git a/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/rows.md b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/rows.md new file mode 100644 index 000000000..8b1378917 --- /dev/null +++ b/docs/analysis/class-v6/rows/live-dataset-census-1a938abe4/rows.md @@ -0,0 +1 @@ + diff --git a/docs/analysis/class-v6/rows/pairing-20261008.md b/docs/analysis/class-v6/rows/pairing-20261008.md new file mode 100644 index 000000000..4b0da0cac --- /dev/null +++ b/docs/analysis/class-v6/rows/pairing-20261008.md @@ -0,0 +1,44 @@ +# The pairing class and the chain-paired packs (8 October 2026, 20:4x to 21:1x UTC) + +The frozen research pack `hl-v6-all` (id `0x4de7b836cc40a4ea`, generator 6, the class-v6 tree 1a938abe4) was exported with the +genesis epoch seed `edc4fa84…fb07` over node1's state stream captured after block `af89be5d…66b3` (number 159357, root +`1c583d35…1526`, 93 records, file sha256 `abb58003…0098`). `IgneumEngine::epoch_for` refuses that pair by the class v5 rule +(the stream's block must be the epoch's seed block), so the node and pool readers cannot re-check the object as packed. The +pairing was the W = 8 lane's research recipe of 14:00 (the CLI had no seed-block check), not a tool fault. + +## The pairing holds on the chain's own pair + +| Reader | Inputs | Id | +|---|---|---| +| the node engine, `igneum-miner program-id` on the placed (c) pair (node lane, 20:46:55 UTC) | epoch `af89be5d…`, era `edc4fa84…`, day 20730, the state above, class v6 | `2a1d6caab4c24564`, attempt 0 | +| the freeze CLI at 1a938abe4, `export … --era 0:edc4fa84…` (build-5, 20:48 UTC) | the same | `0x2a1d6caab4c24564`, attempt 0, generator 6, loads 256 | + +A read with the era set to the block hash as well (`--era 0:af89be5d…`) draws `442a1691b3e3507f` (era label 93a14ac6): a +different input, void for the pairing. The ruling (hash lane, 21:00 UTC): D1 freezes the generator tree 1a938abe4; F0 names +the chain-seed draw `2a1d6caab4c24564` on the pair above; the research pack stays labelled at its pairing. + +## The chain-paired packs (build-1 `/srv/artefacts/packs/`, read back 21:1x UTC) + +| Pack | Class | Id | Attempt | Loads | tgz sha256 | +|---|---|---|---|---|---| +| hl-v6-all-cs | mx8+sh256x27+state+reg64c+fold+rw | `0x2a1d6caab4c24564` | 0 | 256 | `a4742bfefdc632a1f3977c9dfb8f66417c2f132436dcd9ad72c32a608638d6ca` | +| hl-v6-all-nowin-cs | the same +nowin | `0x4e1897e6ee262228` | 0 | 256 | `6ef02eeea5d078f5215b09145239e27a83c8a41e6bccb11bd638d3170b0538bb` | +| hl-v6-foldrw-cs | mx8+sh256x27+state+fold+rw | `0xb53d00f2bf629076` | 0 | 128 | `4f2abd36aee600d97d230b5b09f10680f228448007c6c7062fca737bf6351748` | +| hl-v5-nowin-cs | mx8+sh256x27+state+nowin | `0xa02b1a9dee6b8587` | 1 | 128 | `e2eb2840879d264a8d3562751f983ce57d821087ae6d52796eccf3ef48484b8e` | +| hl-v6-all-prefix-cs | as hl-v6-all-cs, the F05 prefix text | `0x2a1d6caab4c24564` | 0 | 256 | `a9e01f13d6f26f133504c6d62e73b86ee460b53d8798218100b2f250e0ac8ca5` | + +All five: epoch seed `af89be5d…`, era `edc4fa84…`, day 20730, the state above, exported at 1a938abe4 on build-5. + +## The P01 reference of the signing object + +`igneum-pow hash-bound --prehash 00…01 --nonce 0 --count 1000000` on hl-v6-all-cs's inputs (build-5, 20:55 to 21:02 UTC): +1,000,000 lines `nonce hash16`, first `0 2394c9f10f9447a2`, last `999999 cdaadae412c7d9c1`, sha256 +`b77c61d874aed238394fd0e556113192acf21e0762871b1044796f3fbaea338a`, at build-1 `/srv/artefacts/packs/p01-vectors/hl-v6-all-cs.txt` +(+ .sha256). The OpenCL read on PC 1's RX 7600 is the job `run-ca3-pc1-p01-opencl-7600-20261008` (behind the knee rows; the +pack by `fetch-ca3-p01cs-pack-20261008`); equal digests are 1,000,000 of 1,000,000. The Metal read is the morning's. + +## The tool fix + +class-v6 `ce6e6902f45f40e727726cf3e0dbf0e1c924658a` (suite 151 passed, 0 failed, 8 ignored on build-7): `StateStream::check_pairing` +runs first on every `--state` command; a refused pair exits 2 and writes nothing; a string seed never pairs; `--unpaired-state` +records a research pairing on purpose. Known-failed test `igneum-pow/tests/pairing.rs`. The generator is untouched. diff --git a/docs/analysis/class-v6/same-work/same-work-20261008-01/job-context.json b/docs/analysis/class-v6/same-work/same-work-20261008-01/job-context.json new file mode 100644 index 000000000..03ac7c918 --- /dev/null +++ b/docs/analysis/class-v6/same-work/same-work-20261008-01/job-context.json @@ -0,0 +1,75 @@ +{ + "format": "igneum-same-work-job-context-1", + "spec": "docs/plans/igneum-2.0-same-work-test.md (F03, Review B); the driver tools/ci/p01-vectors.py --job-context --phase 1|2|3", + "class": "v6", + "generator": 6, + "load_class": "mx8+sh256x27+state+reg64c+fold+rw", + "era": "0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "era_seed_bytes": "edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "era_widths": 4, + "generator_tree": "class-v6 1a938abe4 (igneum-pow built on build-4 at /srv/builds/igneum-wt-same-work-v6/igneum-pow, binary sha256 0d3f3fca713b10a3...)", + "state_stream": { + "path": "build-4:/srv/builds/v6-census/packs/node1-state.igsd1", + "chain_block": 159357, + "block_hash": "af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3", + "root": "1c583d352bb9c75a06dadb8d82d42836ebe8afa82d0b413be87bf921741f1526", + "records": 93, + "leaves": 93 + }, + "day": { + "D": { + "index": 20730, + "bytes": "69676e65756d2d6461792ffa50000000000000" + }, + "D1": { + "index": 20731, + "bytes": "69676e65756d2d6461792ffb50000000000000" + } + }, + "day_rule": "day bytes = 'igneum-day/' || day_le64 (igneum_pow::bind::day_bytes); D is the frozen pack's day index 20730, D+1 the next index 20731: the dataset-day rotation (infra/fast-time/override-60x.json, pow_day_ms 1440000) changes the day bytes and the dataset only; the program id is the same on both days", + "prehash": "0000000000000000000000000000000000000000000000000000000000000001", + "range_log2": 20, + "phases": { + "1": [ + 0, + 1048576 + ], + "2": [ + 1048576, + 2097152 + ], + "3": [ + 2097152, + 3145728 + ] + }, + "boundary_nonce": 1572864, + "boundary_rule": "the midpoint of phase 2 (2^20 + 2^19 = 1572864, 32-aligned for the workers): under the 60x clock the day switches every 1,440,000 ms and phase 2 is the engine's window across one switch; every reader switches program and dataset at this nonce; the boundary block is the last 2^12 nonces of day D [1568768, 1572864) and the first 2^12 of day D+1 [1572864, 1576960)", + "manifest": "c30ab32c", + "manifest_note": "packaging/release-manifest.json on release-2.0.1 c30ab32c (the F03 R01 record, node 7cfa422a); the pool kit is release-2.0.2 f3e99e9c whose manifest file carries the same 2.0.1 text; the kit's node enum ends at V5, so a class=v6 job line is unnameable by it (the pool lane's read-back, 22:0x UK)", + "references": { + "D": "references/ref-D.txt", + "D1": "references/ref-D1.txt" + }, + "reference_recipe": "igneum-pow hash-bound --epoch-hex --day-hex --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --era-widths 4 --state node1-state.igsd1 --prehash 00..01 --nonce --count on build-4 with the class-v6 1a938abe4 binary; ref-D covers [0, 1572864), ref-D1 covers [1572864, 3145728)", + "readers": { + "cpu_reference": "the reference files themselves (igneum-pow hash-bound, build-4)", + "cuda": "the kit worker igneum-worker-cuda gen 6 (sha256 804a6f7f...) --serve on packs.D, driven by the driver (prepare of packs.D1 before phase 2)", + "opencl": "igneum-worker-opencl --serve, PC 1 RX 7600, the morning (08:30 UK)", + "metal": "the mini's worker, the morning (08:30 UK)", + "node": "igneum-miner --recheck-vectors on a branch off class-v6-node-review e8773ff5 (IgneumEngine::epoch_for then hash_bound per nonce)", + "pool": "igneum-pool recheck --job-context (the member-side share verifier); on the 2.0.2 kit BLOCKED by its V5 pins, the D1 pairing against class-v6-node-review e8773ff5 a separate labelled row" + }, + "evidence_shape": "the driver's JSON: agree, disagree, missing, the first ten disagreements, answered, segments (program id and day bytes per segment), boundary (phase 2: nonce, ids and day bytes either side, the hashes and references either side, switched), prepare_line, manifest_sha, verdict", + "job_line": "job ffffffffffffffff class=v6 era=edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "run_id": "same-work-20261008-01", + "object": "the frozen class v6 object: pack hl-v6-all (tgz sha256 9131431015e102f4b2f545e1e56e7e2271b0e805568682200113f749709858b1, re-exported byte for byte from class-v6 1a938abe4 on build-4 at 21:44 UK), program id 0x4de7b836cc40a4ea, generator 6, epoch seed edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 (the genesis seeds) over the node1 state stream", + "object_id": "0x4de7b836cc40a4ea", + "epoch_seed_bytes": "edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "packs": { + "D": "packs/hl-v6-all", + "D1": "packs/hl-v6-all-d20731" + }, + "pairing_note": "the node engine refuses this pair: IgneumEngine::epoch_for's class v5 check wants the state stream's block (af89be5d...) to equal the epoch seed (edc4fa84...), so the node and pool readers cannot run it (the node lane's program-id read-back, 21:5x UK); this context is the CUDA and CPU row only and is never counted as same-work (the coordinator's ruling, 22:0x UK); the same-work run is same-work-20261008-02", + "written": "2026-10-08 22:1x UK by the same-work hand (worktree same-work-harness)" +} \ No newline at end of file diff --git a/docs/analysis/class-v6/same-work/same-work-20261008-02/job-context.json b/docs/analysis/class-v6/same-work/same-work-20261008-02/job-context.json new file mode 100644 index 000000000..3d07deb62 --- /dev/null +++ b/docs/analysis/class-v6/same-work/same-work-20261008-02/job-context.json @@ -0,0 +1,75 @@ +{ + "format": "igneum-same-work-job-context-1", + "spec": "docs/plans/igneum-2.0-same-work-test.md (F03, Review B); the driver tools/ci/p01-vectors.py --job-context --phase 1|2|3", + "class": "v6", + "generator": 6, + "load_class": "mx8+sh256x27+state+reg64c+fold+rw", + "era": "0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "era_seed_bytes": "edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "era_widths": 4, + "generator_tree": "class-v6 1a938abe4 (igneum-pow built on build-4 at /srv/builds/igneum-wt-same-work-v6/igneum-pow, binary sha256 0d3f3fca713b10a3...)", + "state_stream": { + "path": "build-4:/srv/builds/v6-census/packs/node1-state.igsd1", + "chain_block": 159357, + "block_hash": "af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3", + "root": "1c583d352bb9c75a06dadb8d82d42836ebe8afa82d0b413be87bf921741f1526", + "records": 93, + "leaves": 93 + }, + "day": { + "D": { + "index": 20730, + "bytes": "69676e65756d2d6461792ffa50000000000000" + }, + "D1": { + "index": 20731, + "bytes": "69676e65756d2d6461792ffb50000000000000" + } + }, + "day_rule": "day bytes = 'igneum-day/' || day_le64 (igneum_pow::bind::day_bytes); D is the frozen pack's day index 20730, D+1 the next index 20731: the dataset-day rotation (infra/fast-time/override-60x.json, pow_day_ms 1440000) changes the day bytes and the dataset only; the program id is the same on both days", + "prehash": "0000000000000000000000000000000000000000000000000000000000000001", + "range_log2": 20, + "phases": { + "1": [ + 0, + 1048576 + ], + "2": [ + 1048576, + 2097152 + ], + "3": [ + 2097152, + 3145728 + ] + }, + "boundary_nonce": 1572864, + "boundary_rule": "the midpoint of phase 2 (2^20 + 2^19 = 1572864, 32-aligned for the workers): under the 60x clock the day switches every 1,440,000 ms and phase 2 is the engine's window across one switch; every reader switches program and dataset at this nonce; the boundary block is the last 2^12 nonces of day D [1568768, 1572864) and the first 2^12 of day D+1 [1572864, 1576960)", + "manifest": "c30ab32c", + "manifest_note": "packaging/release-manifest.json on release-2.0.1 c30ab32c (the F03 R01 record, node 7cfa422a); the pool kit is release-2.0.2 f3e99e9c whose manifest file carries the same 2.0.1 text; the kit's node enum ends at V5, so a class=v6 job line is unnameable by it (the pool lane's read-back, 22:0x UK)", + "references": { + "D": "references/ref-D.txt", + "D1": "references/ref-D1.txt" + }, + "reference_recipe": "igneum-pow hash-bound --epoch-hex --day-hex --class mx8+sh256x27+state+reg64c+fold+rw --era 0:edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 --era-widths 4 --state node1-state.igsd1 --prehash 00..01 --nonce --count on build-4 with the class-v6 1a938abe4 binary; ref-D covers [0, 1572864), ref-D1 covers [1572864, 3145728)", + "readers": { + "cpu_reference": "the reference files themselves (igneum-pow hash-bound, build-4)", + "cuda": "the kit worker igneum-worker-cuda gen 6 (sha256 804a6f7f...) --serve on packs.D, driven by the driver (prepare of packs.D1 before phase 2)", + "opencl": "igneum-worker-opencl --serve, PC 1 RX 7600, the morning (08:30 UK)", + "metal": "the mini's worker, the morning (08:30 UK)", + "node": "igneum-miner --recheck-vectors on a branch off class-v6-node-review e8773ff5 (IgneumEngine::epoch_for then hash_bound per nonce)", + "pool": "igneum-pool recheck --job-context (the member-side share verifier); on the 2.0.2 kit BLOCKED by its V5 pins, the D1 pairing against class-v6-node-review e8773ff5 a separate labelled row" + }, + "evidence_shape": "the driver's JSON: agree, disagree, missing, the first ten disagreements, answered, segments (program id and day bytes per segment), boundary (phase 2: nonce, ids and day bytes either side, the hashes and references either side, switched), prepare_line, manifest_sha, verdict", + "job_line": "job ffffffffffffffff class=v6 era=edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07", + "run_id": "same-work-20261008-02", + "object": "the chain-seed class v6 object: epoch seed af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 (the node1 state stream's own block hash, the pair the engine accepts) with the genesis era seed, class v6 generator 6, program id 0x2a1d6caab4c24564 (the id the node lane drew on class-v6-node-review; the export with era 0:af89be5d... draws 0x442a1691b3e3507f and is not it), packs exported from class-v6 1a938abe4 on build-4 at 21:48 UK", + "object_id": "0x2a1d6caab4c24564", + "epoch_seed_bytes": "af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3", + "packs": { + "D": "packs/chain-seed-d20730", + "D1": "packs/chain-seed-d20731" + }, + "pairing_note": "every reader runs this context (the coordinator's ruling, 22:0x UK: the same-work test's meaning is six readers on one context); the frozen-object context 01 is the CUDA and CPU-only row", + "written": "2026-10-08 22:1x UK by the same-work hand (worktree same-work-harness)" +} \ No newline at end of file diff --git a/docs/analysis/class-v6/same-work/same-work-20261008-03/job-context.json b/docs/analysis/class-v6/same-work/same-work-20261008-03/job-context.json new file mode 100644 index 000000000..1e24488e0 --- /dev/null +++ b/docs/analysis/class-v6/same-work/same-work-20261008-03/job-context.json @@ -0,0 +1,78 @@ +{ + "format": "igneum-same-work-job-context-1", + "spec": "docs/plans/igneum-2.0-same-work-test.md (F03, Review B); the driver tools/ci/p01-vectors.py --job-context --phase 1|2|3", + "class": "v5", + "generator": 5, + "load_class": "mx8-era+sh256x27+state (class v5, --program-class v5)", + "era": "0:7c36b83374a673e990213be462509dcb08bcfc85144306aa9517cf3ad66faf6e", + "era_seed_bytes": "7c36b83374a673e990213be462509dcb08bcfc85144306aa9517cf3ad66faf6e", + "era_widths": 4, + "generator_tree": "release-2.0.1 c30ab32c (igneum-pow at the class v5 freeze 1c420786, fingerprint cbc5bd0a), built on build-4 at /srv/builds/igneum-wt-same-work-v5/igneum-pow", + "state_stream": { + "path": "state-epoch2.igsd1 (beside this file; from build-1's seed EVM RPC 127.0.0.1:27810 igneum_getPowStateLeaves for the seed block; the hand 26870 answered \"no published state stream\" for it at 22:18 UK)", + "chain_block": 3423, + "block_hash": "3c3fab434f7fd894ce6db0b09f298c3865726253e4fc68fd77acd163ccea8221", + "root": "0xf798d1d89ee4de62...", + "records": 224, + "bytes": 21132, + "sha256": "f36e6bbab71dc8b049fff052d0895bc4dd1e3f245779e82968fcf5b42535dee1" + }, + "day": { + "D": { + "index": 20734, + "bytes": "69676e65756d2d6461792ffe50000000000000" + }, + "D1": { + "index": 20735, + "bytes": "69676e65756d2d6461792fff50000000000000" + } + }, + "day_rule": "day bytes = 'igneum-day/' || day_le64 (igneum_pow::bind::day_bytes); D is the frozen pack's day index 20730, D+1 the next index 20731: the dataset-day rotation (infra/fast-time/override-60x.json, pow_day_ms 1440000) changes the day bytes and the dataset only; the program id is the same on both days", + "prehash": "0000000000000000000000000000000000000000000000000000000000000001", + "range_log2": 20, + "phases": { + "1": [ + 0, + 1048576 + ], + "2": [ + 1048576, + 2097152 + ], + "3": [ + 2097152, + 3145728 + ] + }, + "boundary_nonce": 1572864, + "boundary_rule": "the midpoint of phase 2 (2^20 + 2^19 = 1572864, 32-aligned for the workers): under the 60x clock the day switches every 1,440,000 ms and phase 2 is the engine's window across one switch; every reader switches program and dataset at this nonce; the boundary block is the last 2^12 nonces of day D [1568768, 1572864) and the first 2^12 of day D+1 [1572864, 1576960)", + "manifest": "c30ab32c", + "manifest_note": "packaging/release-manifest.json on release-2.0.1 c30ab32c (the F03 R01 record, node 7cfa422a); the pool kit is release-2.0.2 f3e99e9c whose manifest file carries the same 2.0.1 text; the kit's node enum ends at V5, so a class=v6 job line is unnameable by it (the pool lane's read-back, 22:0x UK)", + "references": { + "D": "references/ref-D.txt", + "D1": "references/ref-D1.txt" + }, + "reference_recipe": "igneum-pow hash-bound --epoch-hex 3c3fab434f7fd894ce6db0b09f298c3865726253e4fc68fd77acd163ccea8221 --day-hex --program-class v5 --era-hex 7c36b83374a673e990213be462509dcb08bcfc85144306aa9517cf3ad66faf6e --state state-epoch2.igsd1 --prehash 00..01 --nonce --count on build-4 with release-2.0.1's binary 7ba781db...; ref-D covers [0, 1572864), ref-D1 [1572864, 3145728)", + "readers": { + "cpu_reference": "the reference files themselves (igneum-pow hash-bound, build-4)", + "cuda": "the kit worker igneum-worker-cuda 9bfcf728 (generation 5) --serve on packs.D, driven by the driver (prepare of packs.D1 before phase 2)", + "opencl": "igneum-worker-opencl --serve, PC 1 RX 7600, the morning (08:30 UK)", + "metal": "the mini's worker, the morning (08:30 UK)", + "node": "igneum-miner --recheck-vectors on the release line's engine (class v5 by construction); until the subcommand is on a release-line branch the row reads from same-work-node cc23f9bd labelled as such", + "pool": "igneum-pool recheck on the 2.0.2 kit as pinned (class v5 is nameable by its node)" + }, + "evidence_shape": "the driver's JSON: agree, disagree, missing, the first ten disagreements, answered, segments (program id and day bytes per segment), boundary (phase 2: nonce, ids and day bytes either side, the hashes and references either side, switched), prepare_line, manifest_sha, verdict", + "job_line": "job ffffffffffffffff class=v5 era=7c36b83374a673e990213be462509dcb08bcfc85144306aa9517cf3ad66faf6e", + "run_id": "same-work-20261008-03", + "object": "the live chain half: igneum-devnet-4 class v5 object at epoch 2, program id 0x81fbfa3aa413173f, epoch seed 3c3fab434f7fd894ce6db0b09f298c3865726253e4fc68fd77acd163ccea8221 (the epoch-2 seed block, chain block 3423, common to every tonight's chain: the split came after it), day 20734, era 0 seed 7c36b83374a673e990213be462509dcb08bcfc85144306aa9517cf3ad66faf6e (class v5 reads no era: the id is the same under era zero, both read), generator 5, on release-2.0.1's igneum-pow (class v5 freeze 1c420786; binary sha256 7ba781db08525637... built on build-4 from c30ab32c)", + "object_id": "0x81fbfa3aa413173f", + "epoch_seed_bytes": "3c3fab434f7fd894ce6db0b09f298c3865726253e4fc68fd77acd163ccea8221", + "packs": { + "D": "packs/v5-epoch2-d20734", + "D1": "packs/v5-epoch2-d20735" + }, + "pairing_note": "the coordinator's third row (22:1x UK): the same-work test's live-chain half; the node and pool readers run it on their release-line engines; CPU and CUDA cells by 06:00 UK, node and pool NOT RUN with a 08:30 UK clock if the hours run out", + "written": "2026-10-08 22:2x UK by the same-work hand (worktree same-work-harness)", + "genesis_day_index": 20734, + "witness": "igneum-miner program-id --epoch-hex --era-hex --day 20734 --class v5 --state state-epoch2.igsd1 reads \"class v5 attempt 0 id 81fbfa3aa413173f\" under era 7c36b833... and under era 00..00 alike (the miner at same-work-node cc23f9bd on build-2, the class v5 engine path; the 2.0.1 pair's miner ef0f2ed8 on build-1 has no program-id subcommand); the placed (c) pair's read on the seed's stream gave the same id (the node lane, 22:33 UK); build-1's seed is a dead fork since 21:34 UK (the devnet-4 split at the epoch-3 cut) and epoch 2's object is unaffected" +} \ No newline at end of file diff --git a/docs/analysis/pool/pool-pair-2026-10-08.md b/docs/analysis/pool/pool-pair-2026-10-08.md new file mode 100644 index 000000000..e79c28d8b --- /dev/null +++ b/docs/analysis/pool/pool-pair-2026-10-08.md @@ -0,0 +1,54 @@ +# The devnet-4 pool pair, 8 October 2026 (UX-05, UX-04 evidence; the night's record) + +Pool seat, 8 October 2026, 20:0x to 21:4x UK. Binaries: the node /srv/artefacts/200-12424341/node-lane/igneumd on +build-2 (successor-2.0.1's gate build), the pool daemon from pool-2.0 (8106ba27 then e063fdcd; igneum-pow fingerprint +cbc5bd0aa10585c8, the freeze 1c420786), two CPU members from the fork at 2b1a247a (the same fingerprint; a test +binary, never shipped). Two Vast hosts rented for the pair (i7-5820K, Xeon E5-2609 v3, Haswell) died with Illegal +instruction at the class v5 catch-up on every node build and were destroyed; the pair ran on build-2 under lease +pool class measure and was brought down by pid file at 21:3x UK (0 leases, 0 processes left). + +## UX-05 Keep voting keys with the miner through pooling: PASS in the crate + +| Test (pool crate, build-2) | Known-pass | Known-fail | Result | +|---|---|---|---| +| `verify::tests::a_share_under_another_key_is_refused_before_the_hash` | the member's key on job and share: ok | another key on the share, and a job naming another key: `vote_key`, hash 0, under a tenth of an evaluation | ok (51 of 51 at e063fdcd, 52 of 52 at 986252e7) | +| `sidechain::tests::a_share_whose_keys_disagree_is_refused_before_its_pow` | make_share | the claim swapped, the header's key swapped, a foreign reveal | ok | +| `the same nonce on another template hashes differently` | | a nonce moved to another template: `wrong_hash` | ok | +| the TLS binding (replay refused), the admission bounds, the intents (review B) | | | ok | +| `an_unsynced_node_hands_the_pool_no_state_and_no_job` (986252e7) | a synced node: leaves served, jobs issued | synced false: no leaves, no job | red against 8106ba27 on build-6, green with the guard | + +The live pair reached: authorise with the members' own keys (the pool log names each key beside its payout address), +class v5 seeds issued (epoch 1a87e870..., day 20734, era 7c36b833...), jobs issued with `vote_key_hash` the +member's, shares sent. Every share read `wrong_hash`. + +## The wrong_hash cause, from the retained logs (not a generator skew) + +The node, the pool and the member carry the same igneum-pow (fingerprint cbc5bd0aa10585c8, the freeze; pool-2.0's +tree 93c36844 byte-identical to 1c420786, read back by the pool lane from the mirror and from the binaries). The pool +and the members hashed the identical epoch seed, day, class and era. Build-2's node never reached synced on devnet-4 +(its log loops on "class v5 execution catch-up" against peers that close the connection; `synced=false` on every +read), so the class v5 state leaves the pool and the members fetched by `igneum_getPowStateLeaves` for the epoch's +seed block were the still-settling catch-up state, not the node's state at template time; a class v5 lane hash over +unsettled leaves does not match the node's. The class kept: a class v5 pool needs its node fully synced before it +verifies shares, because the dataset is keyed on settled execution state. The guard by construction is pool-2.0 +986252e7 (the provider refuses leaves while `igneum_getExecStatus` reads unsynced, blocked or reexecuting; the feed +issues no job; the STATUS line says so). + +## Two 2.0 gaps closed by the pair (both on pool-2.0, in the 2.0.2 take) + +1. The pool daemon had no class v5 day-state source and issued no job on a class v5 chain (8ff7a0f4: + `state_provider.rs`, `--exec-rpc` defaulting to `--evm-rpc`). +2. The daemon read amounts at 8 decimals and refused every 18-decimal template as a high-word amount (8106ba27: the + base unit installed from the node's network before any amount is read). + +## UX-04 Pay small operators without hidden custody + +PPLNS distribution, the payout key round trip and the signed transfer decode: PASS in the crate. The live payout path +(a member earns, is paid at the minimum, reconnects, a redirection attempt) is NOT RUN: it needs the pair on a +fully-synced devnet-4 node with the 2.0.2 kit, tomorrow. + +## Consequences per tier + +A home miner on a pool: the key stays theirs on every job and share and a pool naming another key is refused before +the hash; a pool operator: the daemon refuses to issue jobs until its node is synced, so an unsynced start costs idle +minutes, never a wrong_hash storm; the network: no change to consensus from any of this. diff --git a/docs/design/key-succession-schedule.md b/docs/design/key-succession-schedule.md new file mode 100644 index 000000000..6af1647f3 --- /dev/null +++ b/docs/design/key-succession-schedule.md @@ -0,0 +1,35 @@ +# Key succession on the live object: the H and W proposal (Phase 1 item d, 8 to 9 October 2026) + +For the founder's word in the 08:00 UK read-back. The mechanism is docs/design/key-succession.md (`proving_key_succession_daa` H, `proving_key_succession_window_daa` W, `proving_next_shard_program_id` and `proving_next_aggregator_id` the next pair; both pairs verify for H <= d < H + W, only the next from H + W). Nothing here activates anything: the pin tool is on master, the real pin and the object's fields move on the founder's word. + +## 1. The proposal + +| Field | Proposed | Why | +|---|---|---| +| W, the window | one epoch of the live object: 3,600 DAA (`POW_EPOCH_BLOCKS`, consensus/core/src/igneum.rs; one hour at one block per second) | the coordinator's word (W one epoch). A prover on the old host keeps earning for the whole epoch it started in; the verdict cache's epoch key (`a_verdict_cached_in_the_window_is_not_valid_after_it`) and the fast-time runs below show both pairs verifying across a window and the right refusal on each side of it. The object's default of 86,400 (one day) is the mainnet clock; on the devnet a day of two pairs is a day of two hosts to keep, with no gain the runs could show. | +| H, the height | the first epoch boundary (a multiple of 3,600 DAA) at least one epoch after the end of a clean 24-hour run of the live chain on the 2.0.2 line: no finality pause, no reorg over depth 3, every fleet node on the cut; named as a DAA score in the object, never a clock | the coordinator's word (H after the chain's clean run). An epoch boundary so the window is one whole epoch of one seed; a full epoch of notice so every prover host has moved before the window opens (the fleet's hosts move with the kit, the app's with its update). | +| The next pair | pin C: shard 0x51cd8cba314a32b60fac393949a4571714da6d6656717d286011601b2a163fe7, aggregator 0x05b395ec238f67406084f8a449d400f64c87dc62151daebf66695864727ded8a (branch p22-stage-2-pin, b5b82c958; manifest source_commit c45db4420, guest input format 3; deterministic across three builds) | docs/analysis/v6-10-guest-repin-2026-10-08.md | +| The prior pair | the served pair 0x2b1a81cb… / 0x474678f3… (devnet-4's pinned pair) | the 2.0.1 kits embed it; the 17:58 UK pair 0x282dcfce… never activated and is skipped | + +Consequences, stated: for a home prover on the app, the old host earns through the hour of the window and the app's update carries the new pair before it; for a fleet box, the kit's host moves at the cut, before H; for a pool, the pool's verifier accepts both pairs in the window and only the next after (the pool lane's rows). A record under the old pair carried after H + W pays nothing (the after-window row below); a record under the new pair carried before H pays nothing (the below-H row). + +## 2. The evidence (fast time, three local nodes, the live pair as prior and the 17:58 pair as next, one real proof under each) + +Every run on the verdict-cache fix node 3f672661 (review B F01/F02), build-8, 8 October 2026. The harness is infra/fast-time/proving-enforcement.mjs in succession mode; a chain at about one DAA per second with 60-DAA epochs; the attacker A carries what its pool holds, H1 and H2 refuse with the verifier in consensus. Every record carried in every run was refused on the right ground and nothing was ever paid; the runs differ only in how many of the six records the harness managed to get carried (its attacker's one-record-per-carrier shape, fixed over the evening). + +| Run (UK) | H, W | Below H | In the window | After H + W | Paid | Verdict | +|---|---|---|---|---|---|---| +| 20:29 to 20:38 (vcache-2) | 240, 120 | next pair refused on its pair | prior pair accepted on its pair, refused on its statement | prior pair refused on its pair | none | the three carried records right; one record per phase carried (harness) | +| 20:42 to 20:55 (vcache-3) | 240, 120 | both refused on their statements: the second record's carrier landed after H (window too short for two records) | prior pair refused on its pair (its carrier past H + W) | prior pair refused on its pair | none | every refusal right for the carrier's DAA; the harness's clocks wrong | +| 20:56 to 21:14 (vcache-4) | 360, 300 | next pair on its pair, prior pair on its statement | both on their statements, none on a pair | prior pair on its pair; the next-pair record went unread (the attacker did not rejoin in 150 s) | none | five of six right | +| 21:15 to 21:33 (vcache-5) | 360, 300 | with the attacker's miner paused for the rejoin, A never rejoined (300 s, twice) | | | none | a harness fault, reverted | +| 21:34 to 22:04 (vcache-7) | 360, 300 | next pair on its pair, prior pair on its statement | both on their statements, none on a pair | prior pair on its pair, next pair on its statement | none | PASS: all six right; registry batch enforced-proving-20261008-02 | + +What the rows establish for the live schedule: the pair accepted is decided by the carrier's DAA against H and H + W, not by when the record was made (vcache-3's second records, forged below H and carried after it, were judged at their carriers); both pairs verify inside the window and a verified proof is answered from its facts at each carrier, never from a stale refusal (the F01 shape of the 19:49 run is gone on the fix node); a window of two harness epochs held every record the attacker managed to carry inside it. None of this measures a live epoch: the harness's epoch is 60 DAA, the live object's 3,600, so W of one live epoch is 60 times the harness's smallest passing window relative to the record's lifetime (RECORD_WINDOW_CHAIN_BLOCKS), which is the margin the proposal rests on. + +## 3. What the founder's word moves + +1. The object's four fields on the 2.0.2 line's override and digest (the node lane's digest move, the start check accepting both pairs: the 291ee6ae check refuses an elf/ whose top pair is not the object's, so the pin and the fields move in one cut). +2. proving/igneum-prove/elf/ on master to pin C with the served pair as prior (p22-stage-2-pin), site/release-manifest.json's proof_guests and succession blocks (the steward's signed manifest with the sha256s 0ce9e351… / 3ef25e3f… elf and 0dbb6605… / 074eb906… vk). +3. The fleet's prover kit on the new host before H; the app's host in its next update before H. +4. The fast-time succession case rerun on the cut's node with pin C as next (the harness takes `--next-ids` and a `--next-proof` under pin C: one compressed proof of a devnet-4 block under the new host, about 100 s on a box CPU). diff --git a/docs/evidence.md b/docs/evidence.md index c314d7089..09bcf7fad 100644 --- a/docs/evidence.md +++ b/docs/evidence.md @@ -38,7 +38,7 @@ Every row carries its release evidence packet at the end of its Result cell: par | 3 | The 64-register window per lane costs a GPU under 1 percent of rate at stock, and at most 5 percent per load with the liveness chain | The litepaper (class v6); `docs/plans/igneum-2.0.md` D1 (the placed 64-register rows) | TEAM-REPORTED; tested by the team | `docs/analysis/class-v6/connected-state.md` section 4; `docs/design/class-v6-rotating-family.md` section 10.0e | The class v5 nvcc harness and the kit worker, both packs on the same card minutes apart, 250 batches of 2^24, nvidia-smi at 1 Hz, vectors PASS on every row (`connected-state.md` section 4); the per-load rows of the full chain against the base (`class-v6-rotating-family.md` 10.0e) | 8 October 2026, rented RTX 5090 (575 W cap) and RTX 4090 (450 W cap) at stock: energy per hash +0.6 percent on the RTX 5090 and -0.9 percent on the RTX 4090, inside the run-to-run noise; under 1 percent of rate; 80 to 87 registers per thread, no spill (all measured). Per load: RTX 5090 16.7 nJ base, 17.6 nJ full chain; RTX 4090 26.0 nJ, 27.0 nJ (measured). The lock row on the project's own rigs is owed Case: GPU-03 | none yet. Packet: parameters a rented RTX 5090 and RTX 4090 at stock, the liveness chain, class v4; procedure the hash lane's harness rows in connected-state.md section 4; raw result energy per hash +0.6 percent and -0.9 percent, at most 5 percent per load; reproduction none yet; review scope none; unresolved two cards, one day, no AMD or Apple row | | 4 | Reorganising the same work around live state (the connected-state variant, experiment D2(a)) does not reduce a specialised chip's edge: KILL as a class | `docs/plans/igneum-2.0.md` D2(a); this page | TEAM-REPORTED; tested by the team (a published failure) | `docs/analysis/class-v6/connected-state.md` (the verdict, section 6) | The census, liveness and GPU rows in `connected-state.md` sections 2 to 4; the chip side priced on the drawn program by synthesis (a model, never a lower bound) | 8 October 2026, verdict 17:25 UK: the window is necessary (63 of 64 registers live at every address, measured) but only its width reaches the chip, +1.2 pJ per lane-op at N5 (synthesised); the window moves the chip's edge 1.10x node for node against a 1.25x gate (modelled); the GPU side +0.6 percent energy per hash on the RTX 5090, -0.9 percent on the RTX 4090 at stock (measured). Rearranging the dependency graph of the same operations moves neither side Case: POW-04 | none yet. Packet: parameters the connected-state generator variant behind a flag, the census TSVs; procedure connected-state.md; raw result +1.2 pJ per lane-op at N5 on the chip side, the GPU side unmoved; reproduction none yet; review scope none; unresolved the chip side is modelled, not measured | | 5 | "A GPU-secured network for Ethereum-compatible applications and verifiable computation." served on every page | Every page | PROPOSED; designed (served) | `docs/plans/igneum-2.0.md` (the objective: the positioning line) | `node tools/ci/ledger-text-check.mjs`: the sentence pinned (R0) on the home page, the litepaper and this page | 8 October 2026: on this page; the home page and the litepaper carry it as their 2.0 text lands (designed) Case: GOV-08 | none yet. Packet: parameters none (a served sentence); procedure the ledger-text check pins it on every page; raw result the check's count; reproduction not applicable; review scope the three external reviews the founder accepted; unresolved none | -| 6 | The chip claim as served: "Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes." Under it the three statements, separate: energy ("Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). For the board on commodity DRAM the two independent chip models agree after placement: 1.5x to 2.1x as a complete machine and 2.0x to 2.9x for the board alone on the GPU's own node; a node ahead 1.8x to 2.4x and 2.45x to 3.3x (placed and routed on ASAP7, both lanes, the node scaling claimed, the machine terms modelled; the 2.9x end is the resizer-downsized floor of the placed 32-lane comparator, not a point, until the placed core32 lands). The standard's P04 target reads FAIL at both ends, served as such. The standard's P04 target as approved: R_E at most 1.5 on the same node and one node ahead; today's placed bracket reads against it as a FAIL to work against." Per machine on the same node and a node ahead: the DRAM board 1.5x to 1.6x and 1.8x, the hybrid 1.9x to 2.1x and 2.4x to 2.6x, the die 2.3x and 3.1x; across the adversary's lane-count choice the same-node bracket is 1.5x to 2.1x and a node ahead 1.8x to 2.6x; 3x to 6x per dollar of hardware at list price. MODELLED: the GPU side measured, the chip's core placed and routed, the rest of the machine modelled, no chip measured, hardware cost approximate within 2x), economic and response capability, rotation an optional improvement. Class v5 derives the dataset from chain state; whether that excludes a specialised design is under evaluation (Deliverable 3), since a design that tracks state is not excluded by staleness. The dataset policy (decided 8 October 2026, 20:05 UK: the genesis size is 4 GiB, the lane's recommendation taken; 2 GiB and 5.5 GiB the costed alternatives beside it; later steps at 5 percent): "The dataset’s size is a one-off hardware ticket on specialised designs and a running energy tax on commodity cards: at 4 to 5.5 GiB a locked Blackwell card pays 12 to 14 percent more energy per hash than at 1 GiB (an 8 GB AMD card under 3 percent of rate), while the board on commodity DRAM pays nothing and the SRAM designs pay a hardware cost that does not change their outcome. So the dataset starts at 4 GiB, the largest size that keeps every entry card and a 12 GB card’s mining and proving together, decided at genesis, and every later step is scored at 5 percent against it and taken only when the chain’s own state outgrows the dataset, not on a calendar." (decided; the energy-against-size curve on the litepaper: 1, 2, 4 and 5.5 GiB at stock and at the lock measured on an RTX 5090 against its own 1 GiB control, +0.7 and +4.3 percent at stock, +11.7 and +13.4 at the lock for 4 and 5.5 GiB, the 2 GiB knee cell a paired read in flight; the exclusions by memory; the SRAM tickets modelled). A failure, reported as found: "ECO-05, the standard's coexistence sweep, was run on a register frozen before any result against a sourced revenue reference of USD 31.65 million a year of miner revenue (Ethereum Classic's trailing year at its current era 6 reward) and FAILS the envelope as the chain stands. Of sixteen revenue and tariff worlds (a quarter, one, four and ten times the reference; electricity at 3, 10, 25 and 40 cents per kilowatt-hour) only one sustains new entry across two vendors, ten times the reference at 3 cents (about USD 316 million a year), because on this hash the measured AMD and Intel cards cost four to six times a Blackwell card per joule and never earn a new entrant's purchase back at list price below that world; in that one world no specialised design sits inside the envelope against the whole cohort (the board on commodity DRAM is within the envelope only against the best Blackwell card, the die and the hybrid against no card of today's), and the quarter-reference worlds at 25 and 40 cents are collapse worlds with no rational profitable operator. What moves the result is the specialist's hardware cost per unit of work, the honest cards' own efficiency on this hash, above all the AMD and Intel cards' energy, and the dataset's size floor; not a smaller network, a higher token price or any chip's death. Reported as found; the register, the full result cube and the model are published for independent reproduction." (Labels: the register frozen at 18:37 UK on 8 October 2026, the reference corrected by a second public read and the run repeated with the verdict unchanged, the cube MODELLED on measured card rows, two cohort rows BLOCKED, the RX 7600's knee and the Arc's watts, their measurement running tonight; the registry row ECO-05 on /acceptance; the results file docs/analysis/class-v6/eco-05-results.md.) The energy ratio is not the pass criterion: the coexistence model ([docs/analysis/class-v6/coexistence-model.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/analysis/class-v6/coexistence-model.md)) is, and its first run's result is served with its conditions: A specialised supplier may earn a normal return; ordinary GPUs remain sufficiently close in total cost, widely obtainable and useful outside mining that new operators can still compete. On today's modelled rows that holds for the chip anyone can build, a stored-dataset board on commodity DRAM, at a productive life of one to three years: its cost per accepted unit of work sits within the range of the best GPU owner and entrant, it passes six of the seven conditions (a third of the network in boards now costs less than a year's revenue at the final hardware price), and a fleet of it holds a minority of the network with GPU entrants still setting the price. For the SRAM-store die the outcome turns on its hardware cost per unit of work, not its energy advantage: at the reconciled machine cost, set by the power train and the shadow core rather than the die, it fails the cost, hardware, fleet and margin conditions at every point of the band, a modest fleet holds about two fifths of a growing network and three fifths of a flat one on arrival and takes every flat or shrinking network within five years, and the only coexistence-shaped outcome is private supply in a growing network; what holds it is the investment decision, since its economics are project economics. A third design, a DRAM board with the hottest half of the dataset in on-board SRAM, sits between the two: it coexists only in a growing network at cheap GPU electricity and fails the cost conditions in a flat or shrinking one, and the dataset's size floor is a real lever on it where it was none on the SRAM die. What holds the die is the investment decision, not the hash; every chip figure here is modelled, not measured, and the chip's hardware cost per unit of work is approximate within 2x. | The litepaper (the chip model) | MODELLED; designed (the bracket modelled; the GPU side tested by the team) | `docs/design/class-v6-rotating-family.md` section 10 (10.0h to 10.0n, 8 October 2026); `docs/plans/igneum-2.0.md` D3 and D4 | the scoring rule in the close (the minimum over workloads of the maximum over free adversarial designs of the GPU's joules per hash over the adversary's, under the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility); the placed rows are D3's | the GPU side measured: the RTX 5080 at its 1,100 MHz lock 2.06 microjoules per hash and the RTX 5090 at its 1,300 MHz lock 2.33 (8 October 2026, the project's own rigs and rented pods); the chip side synthesised and claimed, its placed gated row pending Case: ADV-01 | none yet. Packet: parameters the placed full 18-family core on ASAP7, claimed node scaling, the GDDR7 board, the RTX 5090 at its 1,300 MHz lock on class v4; procedure class-v6-rotating-family.md section 10 and coexistence-model.md; raw result the energies and verdicts as served; reproduction none yet; review scope three external reviews of the close, findings taken; unresolved no chip measured, hardware cost approximate within 2x, the k lane's 32-lane placed row pending | +| 6 | The chip claim as served: "Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes." Under it the three statements, separate: energy ("Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). For the board on commodity DRAM the two independent chip models agree after placement: 1.5x to 2.1x as a complete machine and 2.0x to 2.9x for the board alone on the GPU's own node; a node ahead 1.8x to 2.4x and 2.45x to 3.3x (placed and routed on ASAP7, both lanes, the node scaling claimed, the machine terms modelled; the 2.9x end is the resizer-downsized floor of the placed 32-lane comparator, not a point, until the placed core32 lands). The standard's P04 target reads FAIL at both ends, served as such. The standard's P04 target as approved: R_E at most 1.5 on the same node and one node ahead; today's placed bracket reads against it as a FAIL to work against." Per machine on the same node and a node ahead: the DRAM board 1.5x to 1.6x and 1.8x, the hybrid 1.9x to 2.1x and 2.4x to 2.6x, the die 2.3x and 3.1x; across the adversary's lane-count choice the same-node bracket is 1.5x to 2.1x and a node ahead 1.8x to 2.6x; 3x to 6x per dollar of hardware at list price. MODELLED: the GPU side measured, the chip's core placed and routed, the rest of the machine modelled, no chip measured, hardware cost approximate within 2x), economic and response capability, rotation an optional improvement. Class v5 derives the dataset from chain state; whether that excludes a specialised design is under evaluation (Deliverable 3), since a design that tracks state is not excluded by staleness. The dataset policy (decided 8 October 2026, 20:05 UK: the genesis size is 4 GiB, the lane's recommendation taken; 2 GiB and 5.5 GiB the costed alternatives beside it; later steps at 5 percent): "The dataset’s size is a one-off hardware ticket on specialised designs and a running energy tax on commodity cards: at 4 to 5.5 GiB a locked Blackwell card pays 12 to 14 percent more energy per hash than at 1 GiB (an 8 GB AMD card under 3 percent of rate), while the board on commodity DRAM pays nothing and the SRAM designs pay a hardware cost that does not change their outcome. So the dataset starts at 4 GiB, the largest size that keeps every entry card and a 12 GB card’s mining and proving together, decided at genesis, and every later step is scored at 5 percent against it and taken only when the chain’s own state outgrows the dataset, not on a calendar." (decided; the energy-against-size curve on the litepaper: 1, 2, 4 and 5.5 GiB at stock and at the lock measured on an RTX 5090 against its own 1 GiB control, +0.7 and +4.3 percent at stock, +11.7 and +13.4 at the lock for 4 and 5.5 GiB, the 2 GiB knee cell a paired read in flight; the exclusions by memory; the SRAM tickets modelled). A failure, reported as found: "ECO-05, the standard's coexistence sweep, was run on a register frozen before any result against a sourced revenue reference of USD 31.65 million a year of miner revenue (Ethereum Classic's trailing year at its current era 6 reward) and FAILS the envelope as the chain stands. Of sixteen revenue and tariff worlds (a quarter, one, four and ten times the reference; electricity at 3, 10, 25 and 40 cents per kilowatt-hour) one sustains new entry across two vendors on the measured cards, ten times the reference at 3 cents (about USD 316 million a year), and a second, ten times the reference at 10 cents, on the RX 7600's modelled efficiency point, which the metered row due in the morning keeps at or below 5.4 microjoules per hash and takes away above about 5.6; the cause is that on this hash the measured AMD and Intel cards cost four to six times a Blackwell card per joule and never earn a new entrant's purchase back at list price below those worlds; the verdict is FAIL either way; in those worlds no specialised design sits inside the envelope against the whole cohort (the board on commodity DRAM is within the envelope only against the best Blackwell card, the die and the hybrid against no card of today's), and the quarter-reference worlds at 25 and 40 cents are collapse worlds with no rational profitable operator. What moves the result is the specialist's hardware cost per unit of work, the honest cards' own efficiency on this hash, above all the AMD and Intel cards' energy, and the dataset's size floor; not a smaller network, a higher token price or any chip's death. Reported as found; the register, the full result cube and the model are published for independent reproduction." (Labels: the register frozen at 18:37 UK on 8 October 2026, the reference corrected by a second public read and the run repeated with the verdict unchanged, the cube MODELLED on measured card rows, two cohort rows BLOCKED, the RX 7600's knee and the Arc's watts, their measurement running tonight; the registry row ECO-05 on /acceptance; the results file docs/analysis/class-v6/eco-05-results.md.) The energy ratio is not the pass criterion: the coexistence model ([docs/analysis/class-v6/coexistence-model.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/analysis/class-v6/coexistence-model.md)) is, and its first run's result is served with its conditions: A specialised supplier may earn a normal return; ordinary GPUs remain sufficiently close in total cost, widely obtainable and useful outside mining that new operators can still compete. On today's modelled rows that holds for the chip anyone can build, a stored-dataset board on commodity DRAM, at a productive life of one to three years: its cost per accepted unit of work sits within the range of the best GPU owner and entrant, it passes six of the seven conditions (a third of the network in boards now costs less than a year's revenue at the final hardware price), and a fleet of it holds a minority of the network with GPU entrants still setting the price. For the SRAM-store die the outcome turns on its hardware cost per unit of work, not its energy advantage: at the reconciled machine cost, set by the power train and the shadow core rather than the die, it fails the cost, hardware, fleet and margin conditions at every point of the band, a modest fleet holds about two fifths of a growing network and three fifths of a flat one on arrival and takes every flat or shrinking network within five years, and the only coexistence-shaped outcome is private supply in a growing network; what holds it is the investment decision, since its economics are project economics. A third design, a DRAM board with the hottest half of the dataset in on-board SRAM, sits between the two: it coexists only in a growing network at cheap GPU electricity and fails the cost conditions in a flat or shrinking one, and the dataset's size floor is a real lever on it where it was none on the SRAM die. What holds the die is the investment decision, not the hash; every chip figure here is modelled, not measured, and the chip's hardware cost per unit of work is approximate within 2x. | The litepaper (the chip model) | MODELLED; designed (the bracket modelled; the GPU side tested by the team) | `docs/design/class-v6-rotating-family.md` section 10 (10.0h to 10.0n, 8 October 2026); `docs/plans/igneum-2.0.md` D3 and D4 | the scoring rule in the close (the minimum over workloads of the maximum over free adversarial designs of the GPU's joules per hash over the adversary's, under the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility); the placed rows are D3's | the GPU side measured: the RTX 5080 at its 1,100 MHz lock 2.06 microjoules per hash and the RTX 5090 at its 1,300 MHz lock 2.33 (8 October 2026, the project's own rigs and rented pods); the chip side synthesised and claimed, its placed gated row pending Case: ADV-01 | none yet. Packet: parameters the placed full 18-family core on ASAP7, claimed node scaling, the GDDR7 board, the RTX 5090 at its 1,300 MHz lock on class v4; procedure class-v6-rotating-family.md section 10 and coexistence-model.md; raw result the energies and verdicts as served; reproduction none yet; review scope three external reviews of the close, findings taken; unresolved no chip measured, hardware cost approximate within 2x, the k lane's 32-lane placed row pending | | 7 | Mining and proving together on one card needs a 16 GB card at the proposed 5.5 GiB dataset (the genesis size is 4 GiB, decided 8 October 2026; at 4 GiB the miner holds less and the rule is not yet measured there): the miner holds about 6.1 GiB and a compressed shard proof peaks at about 7.5 GiB, so 8 GB and 12 GB cards time-share (the app pauses the miner for the proof). NVIDIA proves; AMD and Apple mine | The litepaper (Proving, vs RandomX); the miner page | TEAM-REPORTED; tested by the team | `docs/analysis/class-v6/coexist-rows.md` (the 5.5 GiB ds55 miner beside igneum-prove-host-0317, compressed at threshold 2^26, the served sm_86 and sm_89 floors) | the RESULT rows in that file, verbatim from the runs | rented RTX 3060 12 GB: 26.82 MH/s at 117.4 W with 6,129 MiB resident; the compressed shard 13.2 s, peak 7,525 MiB (6,129 + 7,525 = 13,654 MiB against 12,288); rented RTX 4060 8 GB: 18.84 MH/s, 6,116 MiB resident; the shard 8.2 s, peak 7,532 MiB; 8 October 2026 Case: GPU-05 | none yet. Packet: parameters the 5.5 GiB ds55 miner, igneum-prove-host-0317 compressed at threshold 2^26, sm_86 and sm_89; procedure coexist-rows.md; raw result the RESULT rows verbatim; reproduction none yet; review scope none; unresolved two cards on one day, the 6 October rows stand as 1 GiB-dataset rows | | 8 | Finality is active on the Igneum 2.0 devnet from checkpoint 241, 115 minutes after block one, with 78 percent of active weight signing | The live page's strip; the explorer; this page | TEAM-REPORTED; activated: the first lock at 19:08:25 UK on 8 October 2026 (checkpoint 241, DAA 7,247, 77.8 percent of active weight; checkpoint 242 at 19:08:48) | the node's checkpoint state through the observer (/api/live finality.active, latest_locked_index); node 4cdcc488 on release-2.0.0-node | the observer's finality fields read at the edge (supported true, active true, latest_locked_index 244 at 19:10 UK). Case: FIN-01 | 8 October 2026, 19:08 UK: the first lock 115 minutes after the first block at 17:14; the weight window filled at DAA 7,200. Packet: parameters rule v3 from checkpoint DAA 0, the 7,200 DAA presence window, two thirds of active and of total weight; procedure the observer's checkpoint table; raw result checkpoint 241 locked at DAA 7,247 with 77.8 percent of active weight; reproduction none yet; review scope none; unresolved a pause has not yet been observed on this chain | none yet | | 9 | The reference population and the cost per accepted unit of work: The reference population is the discrete-GPU classes the network protects, from the RTX 5090 to the RX 7600 8 GB and the Arc B580, with Apple reported beside them; for each the table gives the cost per accepted unit of work for an existing owner (power, wear, fees, over accepted work) and for a new entrant (purchase at list and street price, two years of operation, resale), at three electricity prices, with every figure labelled measured or modelled. On today's rows the cheapest honest owner is a 16 GB Blackwell card at its efficiency point and the cheapest entrant the same card at list price; the specialised board on commodity DRAM costs more per accepted unit than any owner and sits between the entrant's list and street figures. | The litepaper (the chip model); /scorecard | MODELLED; designed (the card rows measured, the chip rows modelled with hardware cost approximate within 2x) | `docs/analysis/class-v6/reference-population.md` (floor lane 3 for the research lane, on master at 10aa76d7, 8 October 2026) | the table's own cells, each labelled measured or modelled; the two tests per class as the plan's D1 names them. Case: GPU-02 | 8 October 2026: the cheapest honest owner a 16 GB Blackwell card at its efficiency point, the cheapest entrant the same card at list price, the DRAM board above every owner and between the entrant's list and street figures. Packet: parameters the reference cohort (RTX 5090 to RX 7600 8 GB and Arc B580, Apple beside), three electricity prices, two years of operation; procedure the table's method section; raw result the table; reproduction none yet; review scope none; unresolved the Arc's watts and the RX 7600's knee rows are BLOCKED | none yet | diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index de8e083c6..942781d36 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -520,6 +520,79 @@ THE 21:00 COPY's THIRD REFUSAL (20:5x BST): the registry's evidence rule 2 (a fi THE SIXTY-THIRD LANDING AND THE 20:5x LINES (BST). The sixty-third landing on master at 3f2050ab. The kit on the generator-6 packs (20:49 to 20:53): CUDA pairs on the fleet's standing RTX 4090 (pod si1xc4yhpakk1v, driver 580.159, at 20:52; the zip's sha 735e1411 read back on the Mac, the worker 804a6f7f): hl-v6-all check PASS e8f4f3289c6ee1fc (31.31 MH/s, 93 registers), hl-v6-foldrw check PASS 6ce3dc344a613500 (62.45 MH/s, 32 registers), both at 2^24 nonces from base 0, equal to the Mac's Metal and Apple OpenCL reads; the all pack at four of six platforms (CPU emulation, CUDA 4090, Metal, Apple OpenCL), the partner at three; the hash lane's last re-export metadata only (kernel texts and vectors byte-identical), the readings final; the 5090 and 7600 (PC 1's held runner, about 04:40 or the founder's desk) and the Arc (PC 2 by 22:00) the morning's rows, the generator 5 record (six of six on the same object before the review) beside them; zip 3 the kit the pin names unless a fourth zip reads back by 22:30; the page row class-v5 a08647f5a. F05 with both sides (the hash lane 20:5x, the adversary lane section 17 bb8cf8c30 at 20:54): the closed prefix form an exact algebraic equivalent (the native test proving it on every source register); on a GPU it buys nothing (the card memory-bound at the dataset on both texts; the prefix's running total costing 61 registers on sm_89 and 148 on sm_120, halving the 5090's occupancy: the 5090 6.20 nJ on the fold against 7.13 on the prefix at the same rate, +14 percent; the 4090 7.60 against 7.41, a wash); on the chip the bound moves with the shape: on the connected-state class's own form (32 loads per 64-instruction iteration, 256 loads and 512 register writes per hash) the literal fold 113 nJ per hash and the prefix form 7.7 nJ (one running-total update and six Fenwick read-modify-writes per write, six prefix reads and three xors per load), the chip paying about 8 nJ, 1.2 percent of its shadow energy, the complete-machine bracket 1.5x to 1.49x same node (not 1.42x, the literal fold's cost the adversary avoids by 14x); on the shipped shape (one load per 800 instructions) the literal fold the chip's cheapest at 56 nJ (0.08x); the register's F05 line: the chip's cost of the whole-window coupling 8 nJ to 56 nJ, 0.02x to 0.08x of the same-node bracket, measured placed on the chip side and on two cards on the honest side; the verifier keeping the fold as the definition; the connected-state KILL standing on the GPU-cost budget, not this term; cases POW-02 and ADV-04. V6-10's repinned ids ahead of 23:30 (the enforced lane): shard 0x51cd8cba314a32b60fac393949a4571714da6d6656717d286011601b2a163fe7, aggregator 0x05b395ec238f67406084f8a449d400f64c87dc62151daebf66695864727ded8a, sha 7d38077df on p22-stage-2 (elf sha256 0ce9e351 and 3ef25e3f; vks 0dbb6605 and 074eb906), deterministic across three builds on build-1 (identical bytes); the manifest with source_commit c45db4420, guest_input_format 3 (the first field, both guests refusing another format before anything else) and the live pair as prior, the 17:58 pair skipped (never activated); the host suite green on build-2 (the format refusal, the fee rounding with the odd wei to the burn, duplicate and paid-before and invalid carried records paying nothing); the host's --mode id read-back, the old-mode and new-mode compressed proofs (the new from a block exported by the D4 node 930b6322 with proving_payment_activation_daa 0) by 23:30; for the 2.0.2 tree. Floor lane 3's batch line to the landing hand inside 21:10 (eco05-20261008-01b at manifest 24883757: model:eco05 FAIL, model:coexist-fixtures RUNNING). The reference-apps lane's F04 pages on master at 2caa033a2 (20:46), the light service restarted by pid at 20:47, the deploy read-back owed before any "done". THE RESEARCH LANE'S 21:00 COPY LANDED (20:55 BST, read back by the landing hand): box master 10aa76d71265629120c78cc00e1e153fca68de15 (Merge counter-asic-4-docs-3 ae5a6868; full gate 87, the evidence rules green): the documents byte-equal to the tip (the 4 GiB decision FROZEN, the three-row chip line, the F05 correction, F09's corrected (c) cells, the B580 at 11.0 MH/s), sim/economy/coexist, the map cell harness:economics-model, the research batch eco-d4-20261008-01 (nine cases RUNNING) and lane 3's batch eco05-20261008-01b (ECO-05 FAIL, ECO-01 and ECO-08 RUNNING at manifest 24883757) replayed on master's registry; thirty landings by the hand through 10aa76d7. The census lane closed (20:55): the registry cell census:class-v6 PASS on master at 2f44f642 (run census-v6-20261008-2034, manifest 9415e9c8, evidence census-packs.md); its record on master (census-w16-mix.md 018a0877; census-packs.md sections 0 to 7 with the logs: 77f0c4b4, cdbdda05, eba774af; the row 2f44f642); the harness commits for the freeze's digest: class-v6-census-fold 5b3486f0, class-v6-census-reg64 b29e690d2, class-v6-census-all 25098c1a2 and b10fe1351 (the A03 command 9893b4c9d), class-v6-census-all3 6debbac1a (the post-review crate); no lease on any box; a re-read of a new all pack fifteen minutes from its line. +THE FREEZE TREE GREEN AND THE REVIEW VERDICTS (20:5x BST, the hash lane, delivered ahead of 22:30; every verdict with its native test on the sha). The freeze tree: class-v6 9c4e4247308acf42c998c1aafddad14afd9703fa on the mirror (ls-remote agreeing), its suite on build-7 147 passed, 0 failed, 8 ignored across 13 binaries, rc 0; the one sha for the node lane's last re-cut of (c). A02 lane connectivity (row 106; POW-02, POW-03): fixed by construction, every class with a v6 flag reserving five non-load slots as shuffles over the five lane dimensions in a drawn order (tests/v6fold.rs v6_draw_connects_all_lanes_and_keeps_mad_bijective_by_construction, 64 seeds x 4 classes); the overnight census POW-03's. A03 per-site concentration (row 107; POW-03, ADV-02): the census hand's, not applicable on v5 and v6 (uniform inside every window; the v2 cause closed by (c') and (a'); cdbdda05). A04 the acceptance's execution model (row 108; POW-02, POW-04): fixed by construction since class v4 sub-version 3 (the acceptance executing the shadow block as the hash does; a zeroing shadow failing acceptance, tests/packs.rs a04_a_zeroing_shadow_fails_acceptance); tonight's two predicate faults found by lane D (a +nowin or +reg64c program, and a multi-width era, judged by the class v2 parts on the chain's path) fixed at 04442d9ca and b24dfc162 under test (every_v6_flag_keeps_the_class_v4_acceptance_shape). A05 (row 109): the attack seat's 5a, fixed by construction. A06 program identity (row 110; POW-01): fixed by construction: the id recipe carrying the era draw ("era/" bytes), the generator byte and every class flag; the pack carrying program, dataset and era identities and identity.json authenticating every kernel text by BLAKE2b-256 (a06_program_json_hashes_every_kernel_text). A07 dispatch alignment (row 111; POW-02): fixed by construction: the verifier's bound hash the lane of the aligned 32-nonce group across tails and the low-32 rollover (a07_bound_hash_is_group_aligned_across_tails_and_rollover); the launchers refusing a job whose nonce_start is not 32-aligned or whose count is not a multiple of 32. A08 bijectivity (row 112; POW-02, POW-06): fixed by construction: a v6 mad never naming its destination as its second source; the fuzz corpus POW-06's. A09 exhaustion (row 113; POW-04): not applicable: no rejection pass for lane connectivity exists; the attempts census r 0.154 at width 4, 0 exhausted in 3,000 eras (lane D's 6.11). Review B on the object: F03 ProgramClass::V6 at generator 6 (program_class_v6_is_generator_6); F05 the closed prefix form proven equal on every source register (reg64_closed_form_equals_the_reference_fold_on_every_source) and measured on the 5090 and 4090 (neutral to worse on a GPU; the chip pricing the adversary lane's), no object change; F06 the liveness rule wired behind the reg64 flag, every v6 flag keeping the full rule and the attempt cap (reg64_liveness_rule_refuses_the_subset_fold_and_passes_the_full_chain through accept::check); V6-02 the executed-load counters with the agreement assert; found and fixed by the corpus: bind::unhex's panic on a multi-byte character (POW-06); GOV-05 the line itself. + +THE SIXTY-FOURTH LANDING AND THE 21:0x LINES (BST). The sixty-fourth landing on master at 1d499ab3. A FAULT OF THE HASH LANE'S, REPORTED ONCE (21:0x): the V6-02 commit (0266c9ec0, in 9c4e42473) made Program::loads_per_hash report the executed count (256 under the window) and accept.rs sizes its per-site arrays from that function, so for every reg64 class the acceptance's verdicts moved: the re-export of hl-v6-all at 43f1b1581 drew program id 0x1626c5853aa84261, not the object's 0x4de7b836cc40a4ea; found in the lane's own read-back of the re-export at 20:57 after naming 9c4e42473 green at 20:55; the node lane held the cut at 20:58 and went back to (c) 1a21d1ec (ac86d7910, whose acceptance is the object's; six suites green, the pair and canaries placed); the fix (the acceptance and the draw reading the drawn count as before; the executed counters separate functions the emitters alone read, program.h and program.json, with the agreement assert) committed and pushing; the re-export on build-5 reading back the id before anything is named; the corrected sha with its green and the id 0x4de7b836cc40a4ea by 21:25, then the one last cut. Nothing in the verdict line changes (the tests the same, the object's pack and id standing); the four P01 references and the fleet's F05 rows were read on packs of the object's draw (6df3d430) and stand. THE CLASS: a reporting change inside a function the acceptance consumes is an object change; a green suite does not catch it when the suite compares against pinned packs of the same tree; the read-back of the exported id against the object's is the gate. V6-10's rows all read back ahead of 23:30 (docs/analysis/v6-10-guest-repin-2026-10-08.md, b5b82c958 on p22-stage-2): the deterministic rebuild (three builds, identical ELF and vk bytes; pin 7d38077df); the rebuilt host reading the pinned ids back on build-2 and build-3 (--mode id; SP1's key setup deriving the manifest's id before each prove); genuine compressed proofs under the new pair: the old fee mode (fixtures/fees-v1-shards2.json on build-3: VERIFIED, prove 111.1 s, 1,272,961 bytes, verify 0.035 s), the new fee mode (a block exported from the D4 node 930b6322 with proving_payment_activation_daa 0, fixtures/d4-block-149-payment-on.json on build-2: VERIFIED, prove 68.5 s, verify 0.079 s); the exporter replaying the D4 node's 149 segments with every state root equal; the tests green on build-2; the stated limit: block 149 carries no transactions, so the new-mode proof exercises the mode, not a moved wei (the transactions row owed with the D4 merge onto 2.0.2); one class found: the exec RPC reading provingPaymentToPool as "some transaction paid" (false on an empty block with the mode on), fixed on node branch proving-payment-flag. V6-08: the Mac a push host from here; both self-tests re-run on build-2 (box-prover: chain_health 11 cases, task_mode 5, shard_candidates, preflight_verdict 8; prover-outcomes: 8 log jobs, 4 state rows, conservation), rc 0; the node side 7d6cbd21 on v608-proving-tasks-node (igneum-exec 94 passed, its 8 among them, one failure the tip's own reannounce_slice test, the node lane's); the final sha at 02:00. Stage A of the 2.0.1 roll closed at 20:56:53: all 24 kept mining boxes on the kit ("igneumd 2.0.1", 013986fe / f922b216 read back on each, the reference stream served, the pack gate PASS), no Illegal instruction, no refusal, no error; hub-1's last 300 EVM blocks after it on 9 distinct keys (lp-4090-12's solo key stopped at 20:48 fading at 127; the fixed miners' keys 0x8db0505b 56, 0xe12b8e7e 44, 0x53fe9802 40, 0xab46e78b 16 and four small): the chain's fresh blocks the fleet's again; stage B (the 40 non-mining nodes) rolling in tens since 20:56:54, then the 23 peerless on empty datadirs, dn2-2 last, hub-1's miner on the shipper's word; no lock yet, the signing climbing; the F05 and F10 pods destroyed on their done lines (evidence read back on build-1 first). The adversary lane's 21:30 delta to the landing hand at 21:05 ("complete bb8cf8c30": the placed 32-lane comparator and band, the ticket reconciliation, the formal memory model, F05 on both shapes, the layer-8-off hybrid row, the transition matrix, the batch adversary-20261008-placed-8lane with eight cases); the placed 32-lane full core at 22:45 its own delta. +FLOOR LANE 2's SLIP, ONCE (21:0x BST): the pod's 60 GB disk filled (24 GB of gate-level VCDs from ten parallel runs); the window core's route written, its row re-run from the routed netlist (parasitics from global routing, the SPEF unwritten, plus or minus 15 percent) landing 21:40; the tile and crossbar rows relaunched and the core8r64 and core32 placements resumed from their last written stage, 22:30; core32r16 and core32all after; read back (22 GB free, the netlist present, the relaunched runs alive); the Makefile deletes VCDs after each power report. +V6-08 AT ITS 02:00 CLOCK, DELIVERED 21:0x: the igneum branch v608-proving-tasks at 7bf33fd1b (the design, box-prover.py, prover-outcomes.py, the gate line in pre-push.sh and checks.txt), the node branch v608-proving-tasks-node at 201d40d2 (off successor-2.0.1's tip ff35cf26, to the node lane's gate); read back on build-2: igneum-exec 95 passed, 0 failed (eight V6-08's, known-failed first); cargo check -p kaspad with the igneum-pow feature rc 0 (the freeze guard off for the check only, master's igneum-pow a65e4c5a not the freeze's cbc5bd0a); the two python self-tests PASS; two 2.0.2 tip faults found and fixed by the node lane (igneum-exec not compiling on a let chain in an edition-2021 crate; the re-announce ring test disagreeing with its function; db096a6e, ff35cf26); the word to land given at 21:1x. +ECO-05 BATCH 02 LANDED AHEAD OF 22:00 (21:07 UK, floor lane 3, read back on build-4 and from the mirror): the driver reading the override back on its first line (the RX 7600 at 5.4 microjoules and 15.79 MH/s, modelled; the B580 at 10.0 microjoules and 11.0 MH/s, watts estimated), 2,592 cells per cube at both proving efficiencies on P12's approved grid; 6 of 48 world-demand cells sustainable (10R at 0.03 and 0.10) against batch 01's 3, the added world on a 1.6 percent margin of the 7600's modelled entry cost; 0 of 108 cells per specialist passing all three envelope lines; RUN, FAIL, unchanged; run eco05-20261008-02 at manifest 3f2050ab written to ECO-05, ECO-01, ECO-08; box master 4c679226, all eight mirrors; master's rows at 21:07: ECO-05 FAIL, ECO-01 RUNNING, ECO-08 RUNNING; one slip once (a 20:57 attempt ran master's driver without the override hook and reproduced batch 01, discarded); batch 03 on the metered 7600 knee the morning's after the AMD-and-Intel lane's row (about 05:30). +F04 ON THE REFERENCE APPS (master 2caa033a2, 20:46 UK): the light service mapping lockKind to lock_state beside every certificate (/light/checkpoint, /balance, /receipt); /light and /receipt printing "recovery lock, not final"; the receipt file carrying lock_state, the one-file verifier printing it and refusing a receipt claiming final under a reported recovery lock; the terms block on all three pages; /oracle and its README saying recovery locks are not accepted by the Sepolia verifiers (two-thirds only, fail closed; no contract change); run ra-20261008T1915-ver recorded (VER-03/04/06/08 RUNNING with the F04 cases in coverage; VER-01/02 FAIL by design; VER-05 in its own cell FAIL on this run: the public read node reporting startedFrom snapshot where it reported genesis at 17:46, the build-server lane asked which restart, default the row FAIL with the reason). Read back: the light service on build-1 restarted by its unit's pid at 20:47, answering checkpoint 270 with no lock_state field yet (the node has none until the 2.0.2 field); the pages not yet served (the edge last-modified 19:47:18 GMT: the rolling deploy retired under the founder's word, master's pages riding the site lane's next deploy). +THE F04 PAGES LIVE (read back by the reference-apps lane at 21:1x UK): at the edge since 21:08:23 (last-modified 20:08:23 GMT on /lc/core.js, fetched past the cache): /light and /receipt carrying the Recovery lock definition and the lock-state code (lockStateOf in the served core.js), /oracle the "recovery locks are not accepted by this verifier" line; the site lane's deploy took master 2caa033a2 on its own landing; the served text unchanged until the node's 2.0.2 field pairs. +BATCH 02's MEANING (the research lane, 21:1x UK): the added world (10R at 10 cents: USD 316 M a year, 14 to 16 classes across 2 vendors) rests on a 1.6 percent margin (the 7600's modelled entry cost 1,206 against the 1,225 equilibrium), kept by a metered knee at or below 5.4 microjoules and taken away above about 5.6, so the morning's batch 03 decides one sustainable world and no verdict; the served ECO-05 sentence made exact now on the coordinator's word ("one world on the measured cards; a second on the RX 7600's modelled knee, which the metered row keeps at or below 5.4 and takes away above about 5.6; FAIL either way"), in the design's 10.0x for the amendment landing. +THE KIT LANE's TREES (21:09 UK): master 2caa033a2 (the counter-asic-4 code revert 98976b31 in) merged clean into class-v5 (025978de3, page tip 534078bb9) and class-v6-kits (43ed8d9e9), one full gate each GREEN in ci mode on box 2 (87 checks; tools/class-v5/gate-remote.sh running the gate in ci mode on box 2 after local-mode runs read environment reds only), both on both mirrors; class-v5 (the (c''') floor, the AP-F4-1 agreed form, the verified last resort, spec 1.4.7 and 1.8.6, the harness and the kits) told to land itself through the merge tool (its Mac gate the push host's text checks, no cargo; rule 24's crate gate on the box). + +THE MASTER-LANDING LOCK AND THE REGISTRY ON 12b5cf42 (21:11 UK, the steward). The lock live on build-1 (/srv/builds/_locks/master-landing, holder "pid host branch utc"; self-tested: taken and released, a stale holder reaped, a fresh holder queued to the cap, master merged into the branch under the lock stamped as the union of two gated parents; two classes found and fixed with self-tests: the reap threshold was the wait cap, now IGNEUM_LOCK_STALE 1200 s separate from IGNEUM_LOCK_CAP 1200 s; the lock's globals shadowed by locals inside lock_acquire, the first live run queuing behind an empty holder for 7 minutes, stopped by its pid file); the INT landing under it: box mirror master 12b5cf42 (merge of ci-int-suite 79f7f78c, 88 checks, pushed on try 1 at 21:11, every mirror); the F03 landing queued behind it (refused only for its own text conflicts in three append-only check lists, resolved; its gate on c0516d3a, landing about 21:20). THE REGISTRY on 12b5cf42 (written only through test-record.mjs): 18 suites, 190 cases: NOT RUN 182, FAIL 6, PASS 2, 73 in progress; GOV 8 NOT RUN; GPU 8 NOT RUN; POW 8 (FAIL 2: the two kills, NOT RUN 6); ADV 8 NOT RUN; ROT 8 NOT RUN; ECO 8 (FAIL 1: ECO-05); EVM, ZKP, CAP, INC 8 NOT RUN each; FIN 8 (PASS 2: FIN-02, FIN-07); VER 8 (FAIL 3: VER-01, VER-02 by design, VER-05 on the snapshot restart); OPS, UX, COM, LEAD 8 NOT RUN each; REV 44 NOT RUN; INT 18 NOT RUN. The served /acceptance embed the site lane's copy from before the landing (17 suites, 172 cases, no INT), the regeneration from 12b5cf42 asked of the site lane for its next landing. On master since 21:1x: the shipper's per-case batch form (UX-06), the energy lane's GPU-03 batch (NOT RUN in progress), the census lane's census:class-v6 PASS. +V6-08 LANDED (21:12 UK, read back from the mirror): box master f8b7883ee (Merge v608-proving-tasks 7bf33fd1 into master; the branch's full gate 85 checks in 377 s, the merge's light gate 7 in 52 s; rule 26 touching no moved path; no registry rows); the node side 201d40d2 on v608-proving-tasks-node with the node lane for its gate onto successor-2.0.1; nothing open on V6-08. +THE WORKERS PAGE's MINI ROW AND THE DL HOST (21:1x UK, the build-server lane): merge-workers.mjs on build-1 emitting a "mini" row ("igneum-mini, the Mac build box, M6") from /srv/workers/sources/mini.json, down after 120 s, appearing when the mini's own launchd collector pushes mini.json to build-1 (the relay lane's step; the founder's LAN unreachable from the boxes); the page 9 of 9 up at build.igneum.network. A blocker, not a slip: the Arc kit for PC 2 (the gen6 zip 735e1411) and its jobs cannot reach PC 2 tonight because the OTA feed and the kit publish through the dl host (igneum-dlsite on Vercel) and three concurrent Vercel deploys are running (the 17 GB class the founder flagged); the kit staged and the jobs signed locally, publishing on the first clean dl deploy (the dl-publish-from-build-1 migration at 21:30); the Arc row the morning's. +THE DL BLOCKER WITHDRAWN (21:14 BST, the build-server lane, read by pid): one deploy of igneum-dlsite, a single process tree (pids 68043 to 68784, cwd igneum-dlsite, about 1.5 minutes elapsed) from publish-jobs.sh add --kind update-now --title "2.0.1 is published urgent" (the OTA notice following the shipper's Windows 2.0.1 entry live at 20:56), an owner and an in-tree pid; the "three concurrent" was that tree's descendants miscounted; the 17 GB class not recurring (one deploy about 6 GB); the Arc kit's dl deploy serialized behind it, the Arc able to run tonight; the dl-publish-from-build-1 migration the durable path, its first clean deploy's time the line carried. The shipper's Windows 2.0.1 entry live at 20:56 (read in the build-server lane's line). +THE SUCCESSION CASE ON THE F01/F02 FIX NODE (3f672661; the two-record shape, floor 360, window 300; build-8, 20:56 to 21:14 UK): five of six refusals read, each on the right ground (below H the next pair refused on its pair and the prior pair on its statement; in the window both on their statements, none on a pair; after H+W the prior pair on its pair), nothing paid, no stale refusal replayed (the F01 shape gone); the sixth (the next-pair proof after the window) unread for a harness reason (the attacker's one mining thread keeping its dead chain ahead of the honest pair for over 150 s, its last carrier never read); the harness pausing the attacker's miner for the rejoin (58c4bda99), the rerun from 21:15; one slip once: the harness RESULT and the registry batch 21:30 to 21:40. The p22-stage-2 landing in flight on the box master (the stages' code and documents, elf/ unchanged at the served pair; pin C held on p22-stage-2-pin since the 2.0.1 kits embed master's elf/). +THE POOL PAIR's FINDING (21:1x UK, the pool seat, the cause CORRECTED at 21:2x): UX-05 PASS in the crate (suite 51 of 51 on build-2 at pool-2.0 e063fdcd: the vote-key known-pass and known-fail, the open pool's sidechain key check, the same-nonce-other-template wrong_hash, the TLS binding; batch pool-2.0-20261008-02); the live pair (build-2's devnet-4 node, the pool daemon, two CPU members) reaching authorise, class v5 seeds, jobs and shares, then every share read wrong_hash. The first reading (a class v5 igneum-pow version skew between pool-2.0's release-2.0.0 base and the node) was WRONG and is struck: the pool lane read back and the pool seat confirmed from the three binaries that pool-2.0 e063fdcd's igneum-pow is byte-identical to the freeze 1c420786 (tree 93c36844, fingerprint cbc5bd0aa10585c8 on the node, the pool and the member alike), with the identical epoch seed 1a87e870, day 20734, class v5, era 7c36b833. THE REAL CAUSE from the retained logs: build-2's node never reached synced on devnet-4 (looping on "class v5 execution catch-up" against peers that keep closing the connection), so the class v5 state leaves the pool and members fetched by igneum_getPowStateLeaves for the epoch's seed block were the still-settling catch-up state, not the node's state at template time; a class v5 lane hash over unsettled leaves does not match the node's. THE CLASS TO KEEP: a class v5 pool needs its node fully synced before it verifies shares, because the dataset is keyed on settled execution state. The pair brought down by pid; the live UX-05 and UX-04 rows re-run on a synced devnet-4 node with the 2.0.2 kit (pool-review-b-202 off release-2.0.2); the registry batch 03 carrying the corrected cause; two real pool fixes landed on pool-2.0 and in the 2.0.2 take (the class v5 day-state provider, the base unit from the node's network), gaps any 2.0 pool would hit. +The build-2 pool pair down by pid file (m1 lease 1483266, m2 1484824, the pool daemon 1398825, the node 993506; 0 attack-pass leases, 0 pool2 processes), read back 21:1x; nothing of the pool seat's on any box. +CLASS-V5 LANDED (21:17 UK, read back from build-1's mirror): class-v5 14febf3b5 on master at dcc59359a through the merge tool (its gate GREEN on 14febf3b5, 87 checks; rule 26 and the evidence check passed; the five mirrors the same sha): the (c''') floor and its census, the AP-F4-1 agreed form, the verified last resort, spec 1.4.7 and 1.8.6, the harness with the attempt-3 check, the class v5 kits and the page; one slip once (a page row committed on the branch while the first merge run gated it, so the stamp missed the tip and the tool stopped; the class: no commit on a branch while the merge tool gates it); class-v6-kits 8da8ed574 landing the same way from 21:18. +THE HOUSE BAN AGAIN (21:17:45 UK, the shipper, from the mini's 2.0.1 node log): the mini's node refused a relay block (f09df69b, the carried-proofs path above the fork in its kept datadir), dropped build-1's seed as "misbehaving: re-advertised the refused block", and the two public seeds answer "peer is banned": the house IP banned again as at 19:30, so neither the mini nor PC 2 (same house, no peers since 21:05) can peer (the inbound cap not the cause: build-1's seed accepted the mini at 21:17:45 before the mini dropped it); the fix: the fleet lane unbans the house IP on the seeds with the ban list read back; the mini and PC 2 restart their nodes on EMPTY datadirs (their kept branches above the fork trigger the refusal; the fleet's rule for the peerless boxes), the mini by the shipper's hand after a line to main, PC 2 by the relay agent; the rejoin class (an IBD marking a proof-wait block refused, then the N6 ban) the node lane's e9ab052f on 2.0.2; the seed topology (the fleet's nodes stop dialling the public seeds; build-7 and build-8 at 128 inbound; the RunPod seeds at 32; seeds.igneum.network from 2.0.2) the second fix; lp-4090-07 (213.192.2.71:40045, a packaged dial target) reading closed at 21:18, its restore asked. +THE ACCEPTANCE FIX HOLDS (21:2x BST, the hash lane): the re-export of hl-v6-all at class-v6 bc2deb208 reading back program id 0x4de7b836cc40a4ea (generator 6, attempt 0, loads_per_hash 256) on build-5, the acceptance the object's again; one slip once: bc2deb208's suite one red (the pinned-pack byte-identity test, a comment on program.h's define lines), fixed in the next commit; the final sha with its green by 21:40 (was 21:25), then the node lane's one cut and the reg64 packs' re-export at that sha with their tarball shas by 21:55; registry batch 2 (bench:fleet-pods with the F05 rows on the post-review object, suite:pow on the review-fix tree) on master at d8a2fa323 through the recorder's replay. +THE F03 LANDING, ONE SLIP (21:20 to 21:28 UK, the steward): refused behind the INT landing on three append-only check lists, then three evidence-rule refusals of its own batch (prose in an evidence field reading as a path; the F0 page GOV-01's evidence, so GOV-01 moving with it through the recorder) until the check read clean at 21:20; the gate on 75bc6f5e, landing under the lock on green: release-manifest-check with the provenance rule (the proving manifest's source_commit an ancestor of HEAD), build-from-manifest, the same-work spec page, p01-vectors --job-context/--phase (self-tested on a fake worker across the boundary), the map cells harness:release-manifest and harness:same-work (R2-F03-R01 to R03 off the not-run list), the batch f03-manifest-20261008-01: R2-F03-R01 PASS on release-2.0.1's final tip c30ab32c (every component building from the manifest on build-4 at 21:14, the pool included now that the release tree carries pool-review-b; the log on build-1 under /srv/artefacts/tas/f03-manifest-20261008-01); the F0 page's cut-tip row naming c30ab32c beside the shipped tip aa0e0f45. +THE AMD/INTEL REGISTRY LANDED (21:20 BST, the landing hand): box master c170cf4e0604ae98c497ec8aa57de1542fd2551e (Merge amd-intel-energy-registry-docs 92dc857d; 88 checks, the evidence rules green): the cell bench:amd-intel-energy, the batch amd-intel-energy-20261008-01 replayed (GPU-03 NOT RUN in progress), the harness page regenerated; thirty-one landings. The adversary lane's delta (bb8cf8c30): gate GREEN, master merged, then refused by the evidence rules: multi-family-adversary.md changes and master's rows ADV-01 to ADV-05, POW-03 and POW-07 name it as evidence; the lane's batch covering ADV-01, 02, 03, 04, 07, 08, POW-03, 04, so ADV-05 (the adversary lane's) and POW-07 (the steward's kill cell) must move in the same landing by their owners' batches; the sha 21:45 if the owners answer by 21:35. +The adversary delta's two rows: run_id team-2026-10-08 is the coordinator's (the approved registry's tonight-evidence records at 50ff1611f, before the recorder); the landing hand records the one-cell repeat batch for ADV-05 and POW-07 at the delta's manifest, named as the coordinator's register landing, master's current statuses kept, and lands the delta. +THE SEED TOPOLOGY READ (21:16 BST, the build-server lane): all three box seeds already at the 128 inbound cap (build-7 and build-8 igneum-dn4-seed --maxinpeers=128 on 0.0.0.0:26631, active; build-1's seed and hand the same on 26631 and 26671), the 32 cap the RunPod containers' only; the fleet's own nodes dropping the public seeds from their dial list the fleet lane's env change; the public seeds' 128 slots for home miners. LANE D's 6.12 ON THE FROZEN OBJECT'S TREE: PASS (21:2x BST; class-v6 ac86d7910, the full class string mx8+sh256x27+state+reg64c+nowin+fold+rw, the packs' draw read back equal on both ids): under the harness's predicate, width 4, 3,000 eras: r = 0.144, mean attempt 0.17, max 4, 0 exhausted, (c''') 0.46 percent of reaching candidates; under the crate's OWN predicate, width 4, 1,500 eras: r = 0.137, (a') 8.4 percent against the harness's 8.8, (c''') 0.40 percent: THE TWO PREDICATES AGREE on b24dfc162's fix (on 04442d9ca the same column read r 0.05 and (a') 0), the row the freeze asked for; width 1, 1,500 eras, r = 0.134, 0 refused by either floor; the bit-R read at 6.11's level (over 300 sigma in 3.9 percent of eras, the fold's half); attack-f8 on the mirror-valid subset, 64 of 64 seeds at 2^20: 0 hot sets, 0 over 1.2x, 1 of 64 on the bucket class; the verdict PASS on the acceptance's side of the frozen object under the full rule and under the rule the chain runs, now the same; the landing held by the evidence rule (the steward's kills-20261008 batch citing lane D's then-unlanded log post-w4-family_gate_era_census-0-3000.tsv as POW-03's and POW-07's evidence), the fix a repeat batch for the two rows named as the steward's inside lane D's landing (not a rename, which would leave a stale citation); the class for the recorder: a cell citing an unlanded file should be refused at record time; the hash lane's V6-02 slip named in 6.12 as theirs, lane D's rows binding ac86d7910 only. +THE THREE EVIDENCE CLASSES CLOSED IN ONE STEWARD LANDING (ci-evidence-added off master c170cf4e under the lock, by 21:40 UK): the kills-20261008 batch re-recorded with POW-03's and POW-07's evidence narrowed from the class-v6 directory to their own files (FAIL kept; the directory citation the steward's, firing on every class-v6 landing); rule 2 binding modified and deleted evidence files only, so a file first appearing in the tree lands free (lane D's 6.12 needing no repeat batch); the recorder refusing at --record a relative evidence path that is a directory or not in the tree, with self-tests. THE WINDOWS 2.0.1 ENTRY live at 20:56:34 BST (Setup ce6bb00c, both token folders and the public alias, read back from the dl host; the manifest urgent since 21:11:28, which the mini applied on at 21:11:42); the combined exes the build-server lane's about 21:30. THE HOME RESTARTS HELD on one fact (the shipper, by 21:35): PC 2's 2.0.1 IBD from the seed ended at block 3847 on "the proofs of 10 carried records are not held yet", and no empty-datadir node on 2.0.1 has synced past 3847 since the outage (the fleet's peerless boxes starting their fresh syncs; four that tried across the fork reading the same class); the first one past 3847 and mining the word for the mini and PC 2; a stall at 3847 means the home machines wait for the 2.0.2 node entry (the record store following the block store with the IBD skip, the top of 2.0.2) rather than churn. +A coordinator order withdrawn once (21:2x): the "PC 2 restarts on an empty datadir by 21:45 regardless" conflicted with the shipper's hold on the 3847 fact; the relay lane refused to pick by guess and asked; the hold stands (the first fleet box past 3847 on 2.0.1 or the 2.0.2 node entry is the word). +THE ADVERSARY DELTA's ROWS (21:3x, the landing hand): the repeat batch first proposed (ADV-05's owner_lane on master reading the k lane with no map cell) dropped once both owners answered: the adversary lane recording method "model" on adversary:mf-placed and adversary:d2b with ADV-05 added to adversary:mf-placed as RUNNING; the steward's kills-20261008 batch re-recorded with POW-03's and POW-07's evidence narrowed to their files (docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md among them) in its evidence-classes landing by 21:40; the delta holding for that sha (polled to 21:45), rebasing on it and landing with no repeat of anyone's rows (past 21:45 without it, the POW-07 repeat alone); the sha about 21:55. +THE 3847 PROBE (21:3x, the shipper's word to the relay lane): PC 2 restarts fresh now as the probe for the one unproven fact (whether a fresh 2.0.1 node syncs past block 3847 or stalls on the carried records), its after-line (peers, synced, the tip, the first accepted block or the stall) within four minutes; the mini restarts fresh by the shipper's hand the minute PC 2 reads past 3847 and mining; a stall means the home machines wait for the 2.0.2 node entry, the clock said once. P22 STAGES 1 AND 2 LANDED (21:22 UK): box master 24896a8f5 (merge of p22-stage-2 fca720ec, gate green, all seven mirrors): the guest code (the inputs and derivation commitments, the carried fixtures, the versioned guest input format 3, the pin tool's provenance fields merged with the node lane's succession block), docs/design/consensus-proof-stages.md with stage 2 as shipped, docs/analysis/v6-10-guest-repin-2026-10-08.md with every row, proving/igneum-prove/elf/ unchanged at the served pair (pin C held on p22-stage-2-pin b5b82c958 until main names H). +THE HOUSE UNBAN AND THE TOPOLOGY (21:18 to 21:24 BST, the fleet): the house IP unbanned on dn4-seed (39 addresses cleared, one stuck entry re-cleared at 21:19), lp-4090-01 (34) and lp-4090-02 (4) at 21:18:55, lp-4090-07 holding none; the seed guard re-running the unban on those four every five minutes until the 2.0.2 rejoin fix (no allow-list on the node's ban path); build-1's seed and hand the build-server lane's (the same ask, 21:40 default). lp-4090-07's node died at 21:03:21 in stage B's restart on "While lock file .../meta/LOCK: Resource temporarily unavailable" (the new node started while the old one still held the datadir lock; the only such death among 65 rolled boxes), restored by pid files on its kept datadir at 21:20:01; the roll script now waiting for the lock's release before each start; the panic a 2.0.2 item. The seed topology: SEED on every non-hub fleet box rewritten to the seven hubs (lp-4090-02 to -08, every port open from the Mac), the 64 rolled boxes restarting in tens on kept datadirs since 21:24, stage C and dn2-2 taking it at their roll restart; the fleet-slot counts on dn4-seed and lp-4090-01 read at 21:35, 21:50 and 22:05. hub-1's lock line held: at 21:04:59 and 21:06:01 it logged checkpoints 263 then 262 LOCKED with "signed 0 = 0.0 percent" (pre-outage checkpoints at blue score 7,784 and 7,754, taken from relayed certificates, no local tally) while its own signing read 25.86 percent; whether rule v4 counts those as locks is the node lane's; the lock the register wants (two thirds of the weight signing on the fleet's chain) not yet come. The pid-only fleet tree (every stop through a pid file, 17 devnet-2-era scripts retired) in the merge gate. +THE ARC READ (21:3x UK, the kit lane): PC 2's job ran zip 2's kit, not zip 3's (every file sha in its RESULT lines zip 2's: kernel_bound.cl b2729b52 and fd550b21, worker 90aaa1f8, against zip 3's c97e630a, d83e6f14, be169903; the fetch not replacing the dir's old extraction), against the generator 6 expected value, so the "mismatch" was the kit and script pairing, not the device; the reading standing as the generator 5 Arc read: the B580 computing 59e6708e46f1e87c on the generator 5 all pack, equal to the other six, so the generator 5 record on the window object is SEVEN of seven (CPU, CUDA 4090, RTX 5090, Metal, Apple OpenCL, RX 7600, Arc B580); the generator 6 record at four of six (the Arc re-run with zip 3 in a fresh dir asked of the build-server lane, 22:30 default the morning's; the 5090 and 7600 the morning's); the identical leaves.bin across the two packs by construction (one era state, 93 leaves); the freeze wording gaining the Arc on the generator 5 side. +PC 2 at 21:23:14 BST: the restart run found the 2.0.1 node already with 1 peer (the unban reaching it between 21:19 and 21:23; "behind", not synced) and left it alone by the shipper's guard, the datadir in place; whether that peer carries it past 3847 with the kept datadir or hits the carried-records wall read within two minutes; the shipper deciding on the empty-datadir probe. +PC 2's read at 21:23:33 to 21:23:35: peers back to 0 ("waiting for a peer on our chain"); the node on its kept datadir refusing the network's block 4c51b17a by rule, banning two peers of its own for re-advertising it, its IBD ending "parent 306271ad is invalid": the kept datadir on the old branch rejecting the fork's chain, the stall case the shipper pre-authorised; the empty-datadir restart running on PC 2 from 21:24 through the relay agent (api/quit, the devnet-4 datadir moved aside and kept, the app started, 20-second reads for 150 s, the probe's verdict verbatim about 21:29); PC 2 the fleet's probe for the 3847 question. +THE NODE LANE's 21:40 LINE. (1) The fresh-sync read: one empty-datadir 7cfa422a node on build-1 dialling the seed, the hand and both hubs, 21:20:36 to 21:23:07: IBD taking the first 3,600 blocks with one-block reorgs, then the executor stopping at tip 1,943 (DAA 3,600, the epoch-1 boundary) for 90 s with "IBD: a class v5 header chunk waits for this node's execution state (class v5 needs the execution state after the epoch's seed block 92137840)", the seed at 6,162 by then; the 90 s window inside the class v5 catch-up's own wait at an epoch boundary, so not yet the fact (it stopped before the 3,685 to 3,847 band where PC 2 and four fleet boxes stall on "not held yet"); the rerun with a five-minute window from 21:34, the result about 21:50 (past 3,847 means the fleet's boxes stalled on their syncer's record gap, not the chain; a stop at 3,847 names the record). (2) The fix's clock: the record store following the block store (the proof bytes of every carried record persisted under the block store, surviving restart and reorg, pruned with the block); IBD taking a block whose carried records nobody can supply only when it lies under a locked checkpoint (the certificate's two thirds standing for the records; the node's exec state following the network's; logged once per block), never an endless wait and never a ban; above the last lock the rule standing; on successor-2.0.1 by 22:45 with its known-failed test (a joiner against a peer whose record store lacks a served block's records syncing past it under the lock), the 2.0.2 pair with read-backs by 23:15, the shipper cutting the 2.0.2 node entry from that sha. (3) hub-1's 262 and 263 at 21:05: locks under the rule (the certificate arm, a received certificate re-tested against both tables, as 270 was), not recovery locks and not an artefact; the LOCKED line printing the node's OWN vote tally (0 on a node partitioned at those indices); backfill of pre-outage indices, so not "the first lock after the roll" (that line: the first lock at an index determined after the roll with two thirds signing on the fleet's chain, still owed). (4) lp-4090-07's LOCK panic a 2.0.2 item: the datadir lock refusal naming the holder, waiting up to 60 s, then exiting clean. +THE FLEET's PID-ONLY TREE (21:33 BST, the fleet): box-prover.py's stops through pids (the SP1 server by the pid owning its unix socket, read with ss -xlp and written to /root/fleet/pids/sp1-server.pid; the worker through its parent miner's pid); 27 files in tools/fleet carrying pkill or killall: the live ones converted to the shared helper tools/fleet/lib/pidkill.sh (kill_pidfile, kill_children by parent pid, kill_sock_owner) and fleet-stop.sh (lib/box.py's three stops, box-kill.sh, kill-node.sh, box-ember.sh, box-rig.sh, box-matrix.sh, box-floor-v5.sh, lib/standing.py, publish-2-move.py), 17 devnet-2-era scripts moved to tools/fleet/retired/ with a README (git grep over the live tree zero); sha 34d4d45e on fleet-pidkill-20261008 in the merge gate since 21:33; read back on tas-p01-3090 under the shim (pkill -0 sleep exits 97; kill_pidfile and kill_children on demo processes rc 0) and on lp-4090-02 (the eight live files zero non-comment pkill lines); the push to all 102 fleet boxes with /root/fleet. +PC 2's PROBE, ONE SLIP (21:24:18 BST): the guard-off run sent api/quit and 90 s later the window host, the engine, igneumd and a miner were still up, so the run stopped by its own rule (no kill by name, no datadir moved under a live node); the cause read on PC 2 (the engine's quitting flag, the app log's quit and node-stop lines, the processes with start times); the restart again the minute the cause names the step (the quit through the engine's own path or by pid); the verdict by 21:40. +F03's second slip (21:28 to 21:36 UK): the gate red on one check (the REV suite's generated form moving under the R2-F03 record, the generator and the recorder writing different key orders; the merge regenerating REV, the gate reading the tree), regenerated and amended as 1fd509d5; the evidence-classes landing (d7689a43) unaffected, 21:33 to 21:35. +The node lane at 21:3x: candidate (c) re-cut as e8773ff5 on the hash lane's final sha (core 184 and consensus 143 green so far on build-1, the rest, the pair and the canaries following), the freeze's last node-side condition; ff35cf26's placement and canary as the 2.0.2 node entry's sha for the shipper, then the 45e7b910 gate (V6-08 plus the finality-backed take) as the next cut; the 2.0.2 items: the proof-bytes persistence half (the archive at inclusion whether or not the pool held the bytes, served to joiners), igneum_getProofRecord, the relay and body-rule size caps against consensus-core's MAX_PROOF_BYTES, the LOCKED line's fractions, the datadir LOCK refusal, F01's two-node test, INT-15's v2 session binding, D4's merge (67912c80) after the freeze with the repinned next ids. + +THE FREEZE TREE FINAL (21:3x BST, the hash lane's closing line): class-v6 1a938abe408eacabf293e675cc30d8fafa03bc8f on the mirror, the suite on build-7 147 passed, 0 failed, 8 ignored; the five packs re-exported at it and read back on build-1 /srv/artefacts/packs/ at 21:26: hl-v6-all 0x4de7b836cc40a4ea (tgz 91314310...9858b1), hl-v6-all-nowin 0xbe1d6f48928cef4a (38ace2a8...9641b1), hl-v6-all-prefix 0x4de7b836cc40a4ea (d4b07747...cd87ce), hl-v6-foldrw 0xd7eba30115d26dd4 (02eff590...46cf8f), hl-v5-nowin 0xdace2893e7653830 (a321c79b...5e721b), all generator 6, each with identity.json; the node lane's one cut on it; the v5 lane's shas for zip 4; the word on nowin given (layer 8 stays on in the frozen object; the knee rows on PC 1 when the runner frees, the cap about 04:40); the hash lane's line closed. + +THE NIGHT RULE (main's words, the founder to bed, 21:3x UK): (1) From this line until 08:00 UK no lane takes a turn that is not a real change: a landed sha read back, a verdict, a measured row, a fault with its fix and clock. The "privately listed, what I need next" close-outs stop entirely; a lane with nothing to report ends its turn with no message. (2) Released, their clocks spent: the worker lane, the census lane, the finality lane, the Ember lane, the DEX lane, the reference-apps lane, the AMD and Intel energy lane, the V6-08 lane, the app lane once its 23:00 quit fix is pushed, the pool lane once the 23:30 binding switch is in, the comparative lane after its 02:30 first landing (its 09:00 chip model is tomorrow's). Staying: shipper, node, hash, fleet, steward, build-server, the research landing hand, adversary and floor lane 2 until their placed cores land, V6-07 until 01:00, relay until PC 1 and PC 2 read MINING-ON. (3) The coordinator sends main at most one consolidated line an hour, only if something changed; otherwise nothing until the 08:00 read-back (the freeze: which candidate, the sha, the object id, D1's status; 2.0.2: the cut sha, the entries, the fleet roll, the home machines; the chain: locks overnight, the key count, any stall; the census; the board: PASS, FAIL, BLOCKED counts; spend; faults with fixes; the morning items for the founder). (4) The freeze at 23:30 is decided under main's rule by the shipper, not held for main: candidate (c) if every suite, the pair and the canaries are green with the object id 0x4de7b836cc40a4ea read back; otherwise candidate (a) fixed; one slide to 00:30 at most; never the unfixed (a); if neither is green by 00:30 the register reads "frozen pending" with the cause and the freeze is the morning's first item. (5) 2.0.2 cuts tonight on ship-on-green by the shipper with the same authority; the home machines take it on the urgent manifest; nothing is done by hand on the chain overnight, the guards do their work, and a stall is recorded for the morning, not rescued. (6) No lane spawns a new lane overnight; a new fault is recorded with its evidence and a morning clock unless it blocks the freeze or 2.0.2. +A FAULT FOUND AT 21:28 (the build-server lane by pid; the coordinator's read at 21:29): a dl-host deploy running from the Mac with no recorded pid, `node /Users/joshm/Projects/igneum/tools/workers/push.mjs` (pid 47013, parent launchd, started 21:28:00; npm exec vercel 50070, cwd igneum-dlsite), re-hashing the 5.9 GB dl/ tree each fire: the launchd agent com.igneum.workers-push (~/Library/LaunchAgents/com.igneum.workers-push.plist), the old Mac workers publish still scheduled after the hand-over to build-1; the class the founder named; the fix: the agent unloaded by its label and its plist retired by whoever installed it (the site lane), never a kill by name; the build-server lane's one Arc deploy serialized behind it with its pid recorded. +THE LAUNCHD AGENT UNLOADED (21:30 UK, the site lane, read back): com.igneum.workers-push unloaded by its label (launchctl bootout gui/501/com.igneum.workers-push), its plist renamed .retired-20261008, launchctl list no longer showing it; its running upload (pid 47013) had ended on its own, nothing killed; nothing publishes from the Mac now but tools/site-deploy-from-mirror.sh with its pid file. Candidate (c) e8773ff5 all six suites green on the final tree (184/143/74/30/38/19), the pair building, then the canaries and the id read-back. The night rule broadcast to every lane at 21:3x with its stay or release. + +MAIN's ADDITION TO THE 08:00 READ-BACK (21:3x): the accepted-block count since the devnet-4 genesis for each of the mini, PC 1 and PC 2, the time each first mined on 2.0.1 or 2.0.2 and its current rate, from their logs through the relay and the mini's api, the first line (the founder noting they have mined almost nothing since 2.0); the launchd workers-push agent confirmed retired by main's own read. + +THE FOUNDER'S WORD at 21:33 UK: "Do not let anything die or bug out overnight. I want to wake up to serious progress. Build at maximum speed." Two amendments to the night rule (the messaging rule unchanged: real changes only, one line an hour from the coordinator, the 08:00 read-back). (1) NOTHING DIES: every long-running job runs under a watcher that restarts it by pid and records the restart; the fleet lane reads the chain every 15 minutes (blocks per minute, key count, time since the last lock, seed slot counts, the home machines' peers); infrastructure faults are fixed as they occur under the pid rule (a dead seed, a banned IP, a stalled roll, a filled disk, a dead pod); only consensus-level intervention stays forbidden (no hand-made lock, no reorg by hand), and a consensus-level stall is the first line at 08:00 with its evidence; the rented ceiling stands. (2) MAXIMUM SPEED: Phase 1 of the execution plan starts tonight with the lanes that stay; new lanes are permitted overnight for a defined Phase 1 deliverable with a morning clock, each briefed with the four rules (pkill refused; fleet binaries only from the shipper's kit, "cut" only on the build-1 read-back; nothing published from the Mac but the site lane's script; a slip once, no "done" unread), the kill guard and the canary rule. Idle builders are a fault: build-5, 6, 8 and 9 carry work all night. +PHASE 1 (owner, clock UK): (a) the 2.0.2 cut with the fresh-install canary, the fleet roll and the three home machines mining on it: shipper (cut on green, about 23:15), fleet (the roll after, 01:00), relay (both PCs MINING-ON, PC 1 at the cap 04:50), the mini the shipper's; (b) the cross-backend same-work test on the frozen object across node, CPU, CUDA, Metal, OpenCL and pool: steward with the fleet (the spec page landed; the runs from the freeze, 06:00); (c) the two-node cache-history test: node with proving (03:00); (d) key succession H and W named from tonight's real next-pair run and the pin landed on the 2.0.2 line: node with proving (the RESULT 21:40; H and W proposed in the 08:00 read-back for the founder's word, the pin tool landed tonight, the real pin on his word); (e) the native 40/40/20 finality case and the backfill case on rented boxes: node (the plan 23:00, the runs on build-7/8/9 from 00:30, rows 07:00); (f) GOV-03's node build made reproducible: build-server (the build-id try 22:00, the result 23:00, the link-order try after if needed, 04:00); (g) the two-hour declared-load hold on 2.0.2 with the outcome ledger: fleet with proving (from the cut plus one hour, rows 04:00); (h) the mine-evict-prove-rebuild rows on 8, 12 and 16 GB cards: fleet with V6-07 (first rows 01:00, the 16 GB cell on the 2.0.2 modes 05:00); (i) the comparative rows and the KAWPOW chip model: the comparative lane (first landing 02:30, the chip model 09:00); (j) the live-dataset census on the frozen object: hash (overnight on build-6, rows 07:00); (k) the D5 rehearsal plan written for the morning: node (06:00); (l) /acceptance regenerated and /prize live: site (the regeneration's edge read 22:00, /prize 23:00); (m) PC 1's knee rows at 05:30 and the layer-8 verdict ready for 08:00: hash (the grid's cap 04:50, the knee rows 05:30, the verdict 07:30). +BUILDERS ALL NIGHT: build-5 the hash lane's P01 OpenCL/Arc reference generation and the live-dataset census's second half; build-6 the live-dataset census (hash); build-7 the enforced lane's succession and stage runs, then the finality cases (node); build-8 the finality cases and GOV-03's reproducible builds (node, build-server); build-9 the 2.0.2 chain and the two-node cache test (node); build-1 and build-2 the gates; build-4 the comparative lane's rows and the same-work runs (steward). +THE EVIDENCE CLASSES LANDED (21:31 UK, read back): box master 45b87ee8 (ci-evidence-added d7689a43, 89 checks, under the lock, pushed on try 1): rule 2 binding modified and deleted evidence files only (a new file landing free), the recorder refusing a missing or directory path at record time, the kills batch citing the two experiments' own files; F03 (1fd509d5) in its gate; rule 33's canary check, guards and registry case on ci-rule33-canary by 22:00. The 2.0.2 line 45e7b910: the miner suite green (33), the rest of its gate on build-9. (c)'s pair built, placement and canaries next. + +THE 21:3x TO 21:4x LINES. THE FIRST POST-ROLL LOCK: hub-1 checkpoint 620, block 8b2d4553, blue score 10,338, DAA 18,570, at 21:34:33 BST, signed 1,029 = 80.8 percent of active (63.2 percent of total, 63.3 percent of the table frozen at lock 619), finality active; 18,576 blocks, hub-1 peers 7, 4 keys over its last 300 blocks (the fleet's fixed miners); both public seeds listening with zero fleet inbound slots at 21:35 (the hub-only SEED set on 89 of 92 fleet boxes, applying at each 2.0.2 restart); the fleet's 15-minute watch from 21:34 (blocks per minute, the key count, the time since the last tallied lock, the five dial ports, the seeds' fleet slots, the mini's node, the fleet jobs' pids, hub-1's disk; faults fixed by pid with each restart logged; consensus never touched); the pid-only tree on master at 94ef14e7 (its four gate reds fixed inside 25 minutes; the founder's name scrubbed from box-dn3.sh by the pre-public scrub). A SECOND FRESH-INSTALL CLASS (the node lane, from build-1's two fresh-sync runs at 21:20 and 21:24 to 21:29): a fresh 7cfa422a node from genesis does NOT reach the tip: IBD takes the first 3,600 blocks, the executor reaches tip 1,943 (the last chain block of epoch 0) and stops; the IBD waits on "a class v5 header chunk waits for this node's execution state (class v5 needs the execution state after the epoch's seed block 92137840)" and after 300 s ends "this node's executor did not reach the class v5 epoch's seed block within 300 s", disconnects, re-dials and repeats; no "not held yet", no ban; so PC 2's 3,847 (the proof-missing class, the hubs' lost records) is the second stop, and this one comes first for every fresh node: a node fault of 2.0.1's own, the tip lag of 417c4a57 (the follower keeping the last two chain blocks of every path for the next pass) withholding the epoch's seed block at a chunk boundary while the class v5 catch-up waits for exactly that block: a deadlock at the first epoch boundary of every fresh install (the 17:58 fresh-join read passed because the seed was still in epoch 0); the fix: the lag applies only at a live tip (a sink whose timestamp is within ten minutes of now), on a stale sink the follower takes the path whole, with a known-failed test; 6c7abacb on successor-2.0.1 with the record-store take (a9ff0a25), the fresh-sync read on build-1 against the pair as the pass line (the node reaching the seed's tip from genesis through the epoch boundaries and the 3,685 to 3,847 band under lock 270); stage C's fresh joiners stalling at 3,600 the same class. PC 2's probe verdict (21:28:11 to 21:42): the empty-datadir restart's fresh 2.0.1 node stalling where the peerless boxes do (IBD 3598 blocks at 21:33:37, then "node behind", 0 MH/s); PC 2 mines again only on the 2.0.2 node entry (through its own update path the minute it publishes); PC 2's relay agent silent since 21:27 as it ran that restart, its revive through the signed-jobs channel by pid; the relay lane's two re-arm loops under a watchdog. The shipper: the app lane released (its quit fix ab37532c in release-2.0.2 at 7cb51f73); rules 17 and 18 on master (5fc4283d); hub-1's miner rolling on the 2.0.1 kit; the three rule-33 canaries briefed (the fleet kit on lp-4090-11, Windows on PC 2, the Mac DMG on the mini) with the steward's record form and build-1:/srv/canary//; the 2.0.2 node sha = 6c7abacb + the 2.0.2 bump about 22:50 (45e7b910 if red), the cut about 23:15, the entries after their canaries about 00:00. The 2.0.2 line 45e7b910 six suites green (33/95/183/143/38/19), the pair placed on both boxes, the canary be5f4068 on both empty nodes, chain id 0x1171: green end to end; 6c7abacb's gate on build-9. LANE D's 6.11 AND 6.12 ON MASTER at 885327402 (21:39, read back; the logs, the harness diffs, the batch family-gate-20261008b at manifest ac86d7910, method native; the pairing read back at 1a938abe4, both pack ids equal); lane D released. THE CENSUS LANE's LAST LINE (21:36): the (c''') read rerun at the final sha 1a938abe4 reproducing hl-v6-all 0x4de7b836cc40a4ea and reading identical to the b24dfc162 rows (harness class-v6-census-all4 c7e41d5f2); the freeze's census rows standing. FLOOR LANE 2's PLACED 64-REGISTER WINDOW CORE (21:32, read back from the pod; D3's acceptance-rule chip side; the genesis families, the register file clock-gated, 8 lanes; placed and routed on ASAP7, 563,339 cells, parasitics from global routing, the SPEF lost to the full disk; gate-level VCD, steady state from 150 and 600 run cycles; a model, never a lower bound): 9.45 pJ per lane-op at ASAP7 plus or minus 15 percent (+52 percent over its synthesis, inside the band); 6.6 at N5, 4.8 at N3, 3.4 at N2; k at the lock 1.07 / 0.77 / 0.55; the GDDR7 board at the 5090's lock 2.0x node for node, 2.45x a node ahead, 2.9x two ahead on the board identity; the window's residual against the placed gated base (6.7) +2.75 pJ per lane-op, +0.23 of k at the lock: THE WINDOW TAKES THE BOARD FROM 2.4x TO 2.0x node for node and 2.8x to 2.45x a node ahead for at most 5 percent per load on the card, a real defence, the expected 2.5x and 2.1x to the digit; F05: the chip's energy per hash at N3 from 0.82 to 0.95 microjoules with the window, floor lane 3's prefix-tree share 2.6 to about 2.2 percent; 86e5b0fb2 on class-v6-floor-k, gating with the landing hand; the crossbar, tile, core8r64 and core32 rows at 22:30. THE ADVERSARY DELTA LANDED (21:42): box master 01ce4e451 (Merge class-v6-adversary-docs-3 ac0bc17e; 89 checks): the document whole, the two cells and the batch (nine cases, ADV-05 included), no repeat of the steward's rows; thirty-two landings; the placed 32-lane full core's slip once: 22:45 to 23:15 (the slower Xeon host's run dying at the clock-tree step, the timing repair peaking at 252 GB on a 251 GB host; the fleet host's run in its global placement's last passes at 503 GB, the CTS repair skipped). THE WORKERS PAGE READ IN A PLAYWRIGHT RENDER on build-2 at 21:34:33 and 21:37:52 (the build-server lane): ten server cards (the nine boxes with their OS lines and "igneum-mini, the Mac build box, M6" with "no report yet"), the crew row (the nine boxes, MacBook-Pro, PC 1, PC 2), no hardcoded feed map (the FEEDS check false), the root 302 to /workers.html, the home page's six icon links and the five icon files served (favicon.ico 200); committed e344886c and 4b4d91d3 on build-server; the old dl bookmark's redirect stub queued on the serialized dl deploy; build-3 rendering up because its feed answers tonight (the box reachable again). THE ENFORCED LANE's SLIP, ONCE: the succession RESULT and batch 21:40 to 22:10 (pausing the attacker's miner made it worse, A never adopting the honest tip in 300 s twice; reverted to a running miner with a 600 s rejoin, 9c93fd95b, from 21:34 on build-8; the node's behaviour right on every carried record in every run, the open item the harness reading all six); its Phase 1 defaults: (c) the cache-history fast-time case on 3f672661 (a proof refused for context at carrier n then paid under a matching statement; invalid bytes cached once and refused at every later carrier without a second verify) on build-9 by 03:00; (d) W one epoch of the live object (pow_epoch_blocks DAA), H the first epoch boundary after a clean 24-hour run of the live chain on the 2.0.2 line with no pause and no reorg over depth 3, the fast-time runs as the evidence; (g) the outcome ledger over every fleet box's prover-state.json and prover.log at cut plus three hours, rows by 04:00. The pool seat: pool-2.0 986252e7 (the binding switch) read back; batch 03 landing. The shipper lacks ids for an Ember lane and a comparative lane (none spawned through the coordinator); F11 NOT RUN, dispatched, if no Ember lane exists. +THE FINALITY NATIVE-RUNS PLAN ON MASTER (21:4x, the node lane): 9e9d2532e (gate green on a470362a, read back, five mirrors): docs/plans/finality-native-runs-2026-10-09.md, PLANNED, the runs from 00:30: section 1 the 40/40/20 case past the window (honest; the equivocator on one island; on both, the 6.5 bound with two recovery certificates and lockKind "recovery" on both, the FAIL line a recovery lock presented as final; the pause-only variant); 2 the pause-only alternative with the historical-checkpoint backfill, a node with its finality state removed, every old key returning; 3 authority succession and strip, a voter's restart, certificates in reverse order (the hub-1 263-then-262 read), the seed boundary inside a pause; 4 the Sepolia verifier on a final and on a recovery certificate; 5 V6-09 on the minimum validator with the enforced-proving lane; 6 the two-node cache-history test (F01) on build-7 by 03:00; build-8 sections 1 and 2 (rows by 05:00), build-9 sections 3 and 4 after the 2.0.2 line's gate (rows by 06:00) and section 5 (rows by 12:00), build-7 section 6; every run under the lease pool with a pid file and a watcher; the rows into sim/results_v2.md with the registry batch by 07:00; the runs' lane spawned once the 2.0.2 sha is out (about 22:35), the harness extensions (the third island, the equivocating key, the backfill joiner) its first commits. + +A FREEZE-LEVEL FACT (21:5x BST, the steward's same-work hand, read back by the node lane): the frozen pack hl-v6-all (0x4de7b836cc40a4ea) was drawn with the genesis epoch seed edc4fa84 over a node1 state stream whose block is af89be5d, and IgneumEngine::epoch_for's class v5 pairing check refuses that pair ("the provider's stream is for chain block ..., not the seed block"); on the chain's own seed af89be5d the engine draws 2a1d6caab4c24564, not the pack's; the node and pool readers cannot re-check the frozen object AS PACKED, the CPU and CUDA readers can (no pairing check); the steward's ruling for the same-work test: a second job context on the chain-seed object 2a1d6caab4c24564 run on every reader first (the same-work row), the frozen-pack context a CPU/CUDA-only row with the reason. THE COORDINATOR'S DEFAULT unless the hash lane rules otherwise with evidence by 22:30: the D1 object is the generator tree 1a938abe4 with its freeze fingerprint and the dataset policy (the chain drawing per epoch from its own seed); the id named in F0's signing block and the D1 record the chain-seed draw read back equal from the node's engine and the CPU and CUDA readers on the same (seed, state) pair; the pack's id the research reference at its own pairing; the census hand and lane D resumed for one re-read each on the chain-seed draw (by 23:00 and 23:15); the shipper's 23:30 condition the engine's draw at devnet-4's epoch 0 seed from the placed pair equal to the CPU reader's; a FAIL or a disagreement reads "frozen pending" with this cause. THE CLASS: a pack is a (generator, seed, state) triple and the state must be the seed block's; the export tool paired them without the engine's check; the research reads at the mismatched pair are reads of the generator's draw at that pair, named so. +THE PAIRING READ BACK (21:46:55 BST, the node lane, from the placed (c) pair /srv/artefacts/200-e8773ff5/node-lane/igneum-miner, sha 2ee4893d, the 1a938abe4 tree): `igneum-miner program-id --epoch-hex af89be5d --era-hex af89be5d --day 20730 --class v6 --state ` printing "program-id class v6 attempt 0 id 442a1691b3e3507f seed af89be5d era af89be5d day 20730 state 1c583d35", EQUAL to the freeze CLI's export of the same class on the same inputs at 1a938abe4 on build-5 (generator 6, attempt 0, id 0x442a1691b3e3507f, loads 256, era label 93a14ac6; the hash lane's decision (a)): the D1 object is the tree 1a938abe4 (fingerprint 5f4d6dc6199294db89042171004e6420c1e5791e716d4b39b73d375818c10b6f, the class-v6-review freeze line) with the dataset policy; the id in F0's signing block and the D1 record the chain-seed draw 442a1691b3e3507f at (seed af89be5d, era af89be5d, day 20730, state abb58003), read back equal from the node's engine and the freeze CLI on one pair; the pack's 0x4de7b836cc40a4ea the research reference at its own pairing (seed edc4fa84 over the same state, refused by the engine's class v5 rule by construction); the steward's 2a1d6caab4c24564 the engine's draw on MIXED inputs (epoch af89be5d, era edc4fa84), a third instance; the same-work test's node and pool contexts on the real pairing expecting 442a1691b3e3507f; the chain-seed pack for the census and lane D re-reads /srv/artefacts/packs/hl-v6-all-chainseed.tgz on build-1; (c)'s canary condition PASS on this read. A 2.0.2-BLOCKING FAULT (the V6-07 sub-lane, 21:5x, with evidence): master's proving host after the V6-10 commit 7604fcf5d writes every guest input with the first field format = 3 (core/src/shard.rs GUEST_INPUT_FORMAT, check_input_format in the guest) while master's pinned guests are the 5 October pair (elf/igneum-prove-program.elf last changed at 15bb6cdd4, the manifest pinned_at 2026-10-05T16:20:38Z with no input-format or source-commit field; pin C held on p22-stage-2-pin); measured: a host built from box master cef5234b5 with cuda (66662219a3630772) executing fees-v1-shards2 shard 0 to "public values are 0 bytes, expected 328" on an RTX 3060 and an RTX 4060, the served 0317 host (71bc2438) proving and verifying the same shard in 14.1 s on the same card; nothing built from master's proving crate proves against the pinned guest; the fix by default: the host writing the input format the pinned manifest names (format 3 only when the manifest's pair is pin C, the manifest carrying input_format and source_commit), a known-failed test, and a CI check (a GUEST_INPUT_FORMAT change without an elf/ and manifest change fails), the enforced lane's by 22:30, the 2.0.2 kit's prover held on it; the V6-07 rows' default path on the served 0317 host, the proving rows on master's host NOT RUN with the cause. THE 2.0.1 LEDGER BASELINE (the enforced lane's dry run on lp-4090-01 and lp-4090-02 over 10.2 hours, pulled 21:45): 160 claimed jobs, paid 2, active 32 (submitted and waiting), expired 98 (97 unpaid after a submit, 1 held past its deadline), cancelled 28 (17 shards refused, 8 segment records refused, 3 chain failures), abandoned 0, the conservation holding; paid completions 2 segments and 47 shards, 3.72 IGN, median end to end 212 s, median time to pay 232 s; missed deadlines a median 24 DAA past with a median margin of 434 DAA at the claim; 11,862 of 13,489 GPU seconds wasted, 8,700 on records accepted and never carried in time; 0.2 segments an hour per two boxes, 2.7 percent of seconds paid; the loss the carrier side (97 of 160), not the prover (3 chain failures) nor the claim margin: the cell the 2.0.2 hold must move (the record store and relay caps, V6-08's lease and backpressure); if the unpaid share does not fall from 61 percent, 2.0.2 did not fix the carrier path; a 4090 box earning 1.86 IGN in ten hours at this rate, a home card nothing it can rely on; the 47-box pull at the cut plus three hours (about 02:15), rows by 04:00 per tier and kind with this as the 2.0.1 column. THE 17 GB CLASS CLOSED BY CONSTRUCTION (21:46, the build-server lane): two jobs deploys running at once again (pids 15981 and 27252, publish-jobs.sh from other lanes, the Mac's dozens of worktree copies carrying no lock); the fix at /opt/homebrew/bin/npx, a serializer taking an exclusive lock on ~/.igneum-guard/vercel-deploy.lock for any `npx ... vercel ... deploy`, inherited by the tree, released on exit, a second deploy waiting (the holder named) and refusing with exit 75 after 15 minutes, every other npx call passing through (the Homebrew link kept as a backup), tested with two concurrent fake deploys, logged; the script side on dl-publish-off-mac d0005844 (publish-workers.sh refusing on a Mac, publish-fleet.sh refusing unless IGNEUM_MAC_DEPLOY_OK=1 with a pid-recorded process group, publish-jobs.sh with the lock and IGNEUM_DL_PUBLISH=box, docs/release/dl-publish.md naming the split: the jobs triple movable to build-1's Caddy under a dl-jobs host with no app change after one last deploy whose vercel.json 307s the feed there); the flip held on the coordinator's word: after the 2.0.2 entries are live and PC 2 reads MINING-ON, on the shipper's word with PC 2's fetch through the redirect as the canary, else the morning's first item; the old bookmark redirecting (307) since 21:44:19. +MAIN'S RULING ON THE PAIRING (21:5x): the coordinator's default is the ruling (D1 freezes the generator tree 1a938abe4 with its fingerprint and the dataset policy; the chain draws per epoch from its own seed; the id in F0 and the D1 record the chain-seed draw read back equal from the node's engine and the CPU and CUDA readers on the same (seed, state) pair; the mismatched pack's id the research reference at its pairing, labelled; the census hand and lane D rerunning on the chain-seed draw by 23:00 and 23:15; the shipper's 23:30 condition the engine's draw at devnet-4's epoch 0 seed from the placed pair; a FAIL or a disagreement "frozen pending" with this cause); the class in the record; the export tool gains the engine's pairing check before any pack is named again (the hash lane, with the freeze note); the hash lane's 22:30 window for a contrary ruling with evidence standing. GOV-03's CLASS NAMED (21:49, the build-server lane): the cross-box igneumd difference a C __DATE__/__TIME__ compiled into a C dependency (mimalloc's version banner), not Rust nondeterminism: build-1's igneumd carrying "Oct 7 2026" and "02:53:46" (its sccache serving yesterday's object), build-8's "Oct 8 2026" and "18:58:34", build-9's "20:31:38"; .text and .rodata differing only by that string's shift, .eh_frame, .data and .data.rel.ro identical, no build-id note in any (zig linking none, so --build-id=none a no-op); the earlier "identical string tables" read (strings -n 12) missing the 11-character date, corrected once; the fix SOURCE_DATE_EPOCH set to the node commit's time for every ship build (zig's clang pinning __DATE__/__TIME__ to it), forwarded to the box and part of the object hash, folded into the ship-v3-sysroot change in tools/build-remote.sh; the test the 7cfa422a seed pair built on build-8 and build-9 byte-identical, the row PASS on that read by 04:00; the miner pair already bit-identical; the 2.0.2 chains holding the served prover pair (host 71bc2438, export 263bf4ce) unless the enforced lane's format fix lands green before the cut. +THE HASH LANE's RULING (22:00): the pairing holds; the freeze CLI at 1a938abe4 on the engine's inputs (epoch seed af89be5d, era 0:edc4fa84, day 20730, the node1 state 1c583d35 at block 159357) drawing generator 6, attempt 0, id 0x2a1d6caab4c24564, equal by its read to the engine's program-id line on the placed (c) pair; the pack's pairing (the genesis string seed edc4fa84 over the state after af89be5d) a deliberate research pairing from the W = 8 lane's 14:00 recipe, not a tool fault (the CLI having no seed-block check; the engine's check the chain's rule); the D1 object agreed as the tree 1a938abe4 with its fingerprint and the dataset policy; the five packs re-exported on the chain pairing as a parallel set (hl-v6-all-cs and partners) by 22:30. A DISAGREEMENT on the signing id (22:0x): the node lane's 442a1691b3e3507f (--era-hex af89be5d) against the hash lane's 2a1d6caab4c24564 (era 0:edc4fa84), the era field the question; closed by a live read: the node lane reading the program-id line the live devnet-4 node prints (build-1's seed log or lp-4090-11's miner log, epoch 0, day 20730, the era label) by 22:15, that id F0's; the census and lane D holding ten minutes for the inputs; the export tool's pairing check still owed by main's word (a CLI without the seed-block check having produced the mismatched pack). +THE SIGNING ID CORRECTED (22:05, the hash lane): the id read back EQUAL by the node's engine and the CLI is 2a1d6caab4c24564: the node lane's engine line at 21:46:55 reading "program-id class v6 attempt 0 id 2a1d6caab4c24564 seed af89be5d era edc4fa84 day 20730 state 1c583d35" (the era the chain's era seed edc4fa84, not the block hash), the CLI at 1a938abe4 on those inputs drawing the same (build-5, 21:48); 442a1691b3e3507f the CLI's draw with the block hash as the era (the hash lane's first read at 21:45:59, the census hand's 21:48 read the same wrong era), matching no engine run; F0 and D1 naming 2a1d6caab4c24564 at seed af89be5d, era edc4fa84, day 20730, state abb58003 (root 1c583d35), the node lane's live log line by 22:15 as the confirmation; the export tool's pairing check with its known-failed test on class-v6 tonight. THE PROVER DECISION (22:0x, the enforced lane, said once to the shipper): the host-format fault's root older than the format tag (master's proving crate writing inputs the 5 October guests cannot read since the D4 flag landed on master without its pin, 34f5914d2, compounded by stages 1 and 2 and the format tag; the only host proving against the served pair one built at the pin's source 15bb6cdd4, the 0317 host); the 2.0.2 kits ship the served 0317 prover pair (host 71bc2438, export 263bf4ce); a host rewritten in forty minutes and rolled to 47 boxes the fault class the founder forbade; the layout-by-manifest host on 2.0.3 with a card-measured proof first; on master before the cut by 22:25: the manifest's provenance for the served pair (source_commit 15bb6cdd4, guest_input_format 1), the host refusing at start when its input format is not the manifest's (naming the source commit to build from, never "0 bytes"), the known-failed test, the CI check (a GUEST_INPUT_FORMAT differing from the manifest's red unless the same diff moves elf/; the kit's prover built from the manifest's source_commit, never master's tip, until pin C moves). V6-07's floor patch 8c1fb754c (sha 9098c3e5, the one the landed server db37c38b was built from). +The coordinator's 442a line withdrawn once (22:1x; it carried the node lane's mis-quoted argument); F0 names 2a1d6caab4c24564 at (epoch seed af89be5d, era 0:edc4fa84, day 20730, the node1 state at block 159357, root 1c583d35, sha abb58003), the live node's program-id line the confirmation by 22:15; the steward's same-work hand's second context on it with hl-v6-all-cs.tgz and its CPU reference by 23:00. The pool seat released (22:0x): pool-2.0 986252e7 (the daemon refusing jobs while its node reads unsynced, blocked or reexecuting), batch 03 with the corrected cause and docs/analysis/pool/pool-pair-2026-10-08.md on master at 499c5c9b (21:49; UX-05 the vote-key PASS in the crate, the live pair NOT RUN; UX-04 NOT RUN with the synced-node dependency). The whole fleet's miners on 2.0.1 (hub-1's rolled at 21:43, 102 blocks in 343 s, zero refusals; the shipper's read). +THE SIGNING ID CLOSED (the node lane's verbatim lines from the placed (c) pair, igneum-miner sha 2ee4893d, the 1a938abe4 tree, on build-1): (1) 21:41:51 BST on epoch af89be5d, era edc4fa84, day 20730, the node1 IGSD1 state (sha abb58003): "program-id class v6 attempt 0 id 2a1d6caab4c24564 seed af89be5ddbadb6f6b4aee28ac8f249713be5d4c12621e3cea7f83ceada3c66b3 era edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 day 20730 state 1c583d352bb9c75a06dadb8d82d42836ebe8afa82d0b413be87bf921741f1526"; (2) 21:46:55 with the block hash as the era: id 442a1691b3e3507f, the wrong argument for F0 (the chain's era seed is edc4fa84, the era VDF's output, not the block hash), named once; F0 AND D1 NAME 2a1d6caab4c24564 at (seed af89be5d, era edc4fa84, day 20730, state 1c583d35), the pack's 0x4de7b836cc40a4ea the research reference. (3) The live node's own line: the live chain is class v5, generator 5 (no class v6 epoch on any live chain, by construction of the freeze); build-1's seed and the fixed miner at the live epoch 2: "epoch seed 3c3fab434f7fd894ce6db0b09f298c3865726253e4fc68fd77acd163ccea8221 day 20734 (daa 8565): program and 256 MiB cache ready in 2604 ms; class v5 program id 81fbfa3aa413173f", and the (c) pair at 22:50:21 on those inputs with the live epoch-2 stream (igneum_getPowStateLeaves on 3c3fab43, 21,132 bytes) reading "program-id class v5 attempt 0 id 81fbfa3aa413173f seed 3c3fab43 era 0000...0000 day 20734" and the same id with era 3c3fab43 (class v5's id not reading the era, which enters from class v3's era rungs under the ladder, never active on devnet-4): the live node's id reproduced exactly by the placed (c) pair; the pairing witness for class v6 is line (1); for devnet-4's epoch 0 instance of the v6 object the (c) pair drew attempt 1 id a3764f0fc4c3d9f3 (era = genesis) and 1c54a42911b93e1e (era = zero) on the genesis stream at 21:48:17, the hash lane naming which era devnet-4's epoch 0 carries if the register wants that row. (The node lane's "22:50:21" stamp is its box's, two hours ahead of the Mac's; the Mac read 21:5x.) +F03 LANDED (21:52 UK, read back): box master ee3e0245 (ci-f03-manifest 69b51369, 89 checks, under the lock, try 1): release-manifest-check with the provenance rule, build-from-manifest, the same-work spec page, p01-vectors --job-context/--phase, the cells harness:release-manifest and harness:same-work, GOV-01 moved with the F0 page, the generators keeping evidence_records on regeneration; one fault read back: R2-F03-R01 reading NOT RUN though its cell recorded PASS (the normalizer's lifted legacy "record" entry, a reason with no run, counted by the combined decision), the fix (a reason-only entry never counting, dropped when a real cell lands) with the guest-format landing by 22:10; rule 33's gate on 5fc267f9. +THE EXPORT TOOL's PAIRING CHECK (21:58 BST, read back): class-v6 ce6e6902f45f40e727726cf3e0dbf0e1c924658a (the suite on build-7 151 passed, 0 failed, 8 ignored: the freeze's 147 plus 4): StateStream::check_pairing first on every --state command (export, bench, hash, hash-bound); a seed whose block is not the stream's block exits 2 with the engine's reason and writes nothing; a string seed never pairs; --unpaired-state recording a research pairing on purpose and printing it; the known-failed test (tests/pairing.rs) exporting the hl-v6-all shape and reading the refusal, then the same with --unpaired-state and the chain's own pairing; the generator untouched (state.rs, main.rs and the test only), the frozen object still 1a938abe4's draw; the five chain-paired packs exported at 1a938abe4 on build-5 (hl-v6-all-cs 0x2a1d6caab4c24564; the four partners' ids and shas about 22:15). +RULE 33 LANDED (22:01 UK, read back): box master d2e1c192 (ci-rule33-canary 8687874e, 91 checks, under the lock, try 1): tools/ci/canary-check.sh (the record tools/ci/canary/.json, one file per sha with an artefacts list fleet/windows/mac/hive, each block its own non-AVX-512 box and eight read-back lines; --artefact ; --form), the guards in packaging/ota/publish-manifest.sh (--release-sha, refused without a PASS block for each platform published; loopback test writes and --verify-only not gated) and publish-public.sh (the sha from the manifest's "release: " note; hive its own block), deploy-win.sh covered through them; the registry: INT-07 BLOCKED on cell canary:fresh-install (no 2.0.x sha with a record; the shipper's 2.0.2 canary the first), POW-03 and POW-07 citing their own files (the merge replaying modified batches too); the guest-format check (a format bump without elf/ red at the merge; a manifest field off the source red only without provenance) and the recorder's lifted-record fix queued behind it. +THE CHAIN-PAIRED PACKS READ BACK (22:03 BST, build-1 /srv/artefacts/packs/, sha256sum -c OK): hl-v6-all-cs 0x2a1d6caab4c24564 attempt 0 loads 256, tgz a4742bfefdc632a1f3977c9dfb8f66417c2f132436dcd9ad72c32a608638d6ca; hl-v6-all-nowin-cs 0x4e1897e6ee262228 attempt 0, 6ef02eeea5d078f5215b09145239e27a83c8a41e6bccb11bd638d3170b0538bb; hl-v6-foldrw-cs 0xb53d00f2bf629076 attempt 0 loads 128, 4f2abd36aee600d97d230b5b09f10680f228448007c6c7062fca737bf6351748; hl-v5-nowin-cs 0xa02b1a9dee6b8587 attempt 1 loads 128, e2eb2840879d264a8d3562751f983ce57d821087ae6d52796eccf3ef48484b8e; hl-v6-all-prefix-cs 0x2a1d6caab4c24564 (the F05 prefix text), a9e01f13d6f26f133504c6d62e73b86ee460b53d8798218100b2f250e0ac8ca5; all at 1a938abe4 on the pair epoch af89be5d, era edc4fa84, day 20730, state abb58003, generator 6, each with identity.json. The P01 CPU reference of the signing object: /srv/artefacts/packs/p01-vectors/hl-v6-all-cs.txt, 1,000,000 lines, sha256 b77c61d874aed238394fd0e556113192acf21e0762871b1044796f3fbaea338a (first line "0 2394c9f10f9447a2", last "999999 cdaadae412c7d9c1"), build-5 21:55 to 22:02; the OpenCL read on PC 1's RX 7600 queued behind the knee rows; the Metal read the morning's; the row docs/analysis/class-v6/rows/pairing-20261008.md with batch hash-lane-20261008-batch3 landing next. +UX-01's WRITE-BACK ON MASTER (21:43 UK, read back by the relay lane): dc94dda9 (the batch ux-01-20261008-win-2.0.0.json replayed; manifest aa354ed5; method team-reported; the cell pc:install-update covering UX-01 as team-run evidence with the P10 study NOT RUN, UX-07's install classes and OPS-03's update path; the evidence docs/plans/evidence/UX-01-20261008.md with PC 2's 2.0.0 and 2.0.1 read-back lines and the two network classes); four earlier attempts refused by rule 26 while other lanes landed docs: the shape that lands is a branch carrying only the batch, the cell and the evidence, never the registry or the generated page (the class for every lane's write-back). +GOV-03 PASS (22:05 BST, the build-server lane, read back on the boxes): the 7cfa422a seed pair built on build-8 and on build-9 byte-identical (igneumd 6502b3c7d58a16dfa5adaef30ffc696714f1a09f117648c62b4973fe129a8075, igneum-miner b4748308e0887982c7f2ce3f06bc64802aa6ea9780adb61413fcbb8934f69e37), the C banner reading the commit's author time ("Oct 8 2026" "18:44:40"), the fingerprint cbc5bd0aa10585c8 in both; the exact cause under the date: SOURCE_DATE_EPOCH exported but sccache's server compiling C in its own environment so clang never saw it; the fix defining __DATE__/__TIME__ on the compiler command line (both caches keying on it), ship-v3-sysroot 5c494c08; one class left: a non-ship native build through sccache still baking the wall clock, only the --ship path pinned. THE V3 KIT (a correction first: the 2,018 zmm lines were blake3 1.8.3's AVX-512 assembly, cpuid-dispatched, not glibc; under zig glibc is dynamic): the certified build --ship seed/linux at target-cpu x86-64-v3 with blake3's pure feature (no AVX-512 code linked), -mpclmul for rocksdb's crc32c, an ISA gate on the box failing the run on any AVX-512 line; read back zmm 0, ymm 371,416, runs ("igneumd 2.0.1"), GLIBC_2.34 floor; the hive/rig class defaulting to x86-64 (v1) on purpose (common HiveOS rig CPUs without AVX2; a v3 igneum-miner dying with SIGILL), zero zmm there too; the branch pushed not merged, the shipper deciding if the 2.0.2 cut takes it (green before the cut); the cost blake3 pure dropping the AVX-512 hash path on AVX-512 seeds, hashing only; the 2.0.2 dual-chain script staged (app202/run-202.sh, asserting the served prover pair, a kit-isa line per binary); two gaps for the shipper: the DMG and the Setup exes outside the chain (the Mac lock, the PC job), the lab hive's archive renamed to the brief's name with its inner directory igneum-lab/. +THE SUCCESSION CASE PASSES (22:04 UK, the enforced lane; build-8, 21:34 to 22:04, the F01/F02 fix node 3f672661, floor 360, window 300, two real proofs per phase): below H the next pair refused on its pair and the prior on its statement; in the window both on their statements, none on a pair; after H+W the prior on its pair and the next on its statement; nothing paid; no stale refusal replayed; the batch enforced-proving-20261008-02 (harness:proving-enforcement, seven cases, manifest 3f672661) in the gate with the harness and docs/design/key-succession-schedule.md, THE H AND W PROPOSAL for the 08:00 read-back: W one live epoch (3,600 DAA); H the first epoch boundary at least an epoch after a clean 24-hour run of the live chain on 2.0.2 (no pause, no reorg over depth 3, every fleet node on the cut); pin C the next pair, the served pair the prior; the evidence table carrying the five runs. Phase 1 item (d)'s evidence complete. + +A CONSENSUS-LEVEL FAULT (22:08 BST, the node lane, read from build-1): igneum-devnet-4 split into at least four chains at the class v5 epoch cuts. The matrix (eth_getBlockByHash on each node at 22:06): build-1's seed (188.40.146.49:26631, a dial target) stuck at executed tip 6,162 (daa 10,799, its epoch-3 boundary) since 21:34, holding 1a87e870 as chain block 5,760 (its epoch-3 seed); the hand (26671) holding the same 1a87e870 at 5,760 then its own epoch-4 seed 550eab88 at 7,988, tip 8,144 (daa 14,474), still mined; the light reader (26882) holding neither, its epoch seed f8dffb78 at 5,560, tip 6,919 (daa 20,496), locking checkpoints 681 to 683 at 59.7 percent of total; the fleet's chain (peers 213.173.111.10, 203.57.40.129, hub 64.119.209.250) on 756ff5bd as its epoch-3 seed, absent from all three; the seed refusing every fleet epoch-3 header ("header rejected before the PoW engine: invalid proof of work", strikes, bans), the fleet banning the seed for 600 s (N6) for re-advertising its refused tip f09df69b; the seed's, the hand's and the light reader's IBD attempts against fleet peers dying in the 300 s wait "no published state stream after 756ff5bd (the block is not on its chain)"; the seed logging voter EQUIVOCATIONS at indexes 76 to 83, 250 and 262 and holding locks 260 and 261 by certificate with zero local votes: the voters split across the chains. THE CAUSE (two node classes, both in 2.0.1 and in 6c7abacb): (1) the class v5 IBD catch-up syncing bodies once, before the first deferred chunk, so every further epoch boundary costs the 300 s state wait and an IBD restart (measured on 6c7abacb's fresh node: 1,943 for 300 s, then 2,645 to 3,843 in 20 s after the restart); (2) structural: a node whose executor captured block X as epoch N's reference validating only epoch-N headers seeded by X; another chain's epoch-N headers (seed Y) refused for want of the state after Y, their post-cut weight never counting, GHOSTDAG never moving the virtual to Y's chain, the executor never capturing Y: once two nodes differ at a cut they can never rejoin, each extending its own chain with whatever miner points at it; a lock above the fork (the seed's 260/261) making it permanent: THE D5 PARTITION HAPPENING LIVE WITHOUT A PARTITION, THE EPOCH CUT ITSELF THE PARTITION. The fresh-sync read on 6c7abacb's pair red for the wrong reason (1,943 to 3,843 across the first two cuts, then 3,844 whose carried proof no build-1 node serves in 20 s, the records lost after the hub reorg; the lock rule unable to cover it on a fresh node; the seed's "tip" a dead fork). THE NODE LANE'S DEFAULTS unless main says otherwise by 22:40: (a) fix (1) on the 2.0.2 line as one commit by 22:45 (bodies re-synced to the highest validated deferred header on every state wait, the 300 s budget reset on progress), the six suites read back; the 2.0.2 name sliding once from 22:35 to 23:30; (b) fix (2), the foreign-seed capture (on the state wait for Y, the executor executing Y's selected-parent chain from the fork point in a scratch state and publishing the stream under Y's hash, so the headers validate, the weight counts and the virtual can move), designed with the enforced and hash lanes (class v5 design section 5) and built on the 2.0.2 line tonight, suites by 02:00, the two-node cache test's shape as its gate; (c) nothing by hand on the chain (no seed restart, its datadir the fork; no lock; no reorg); (d) the 23:20 freeze line standing on its own inputs (the D1 candidates gated on the live line before the split). Devnet-4 as it stands cannot heal with 2.0.1 binaries on the fleet; a reset (a devnet-5 genesis, or a coordinated restart from one chosen chain's snapshot) main's call, the node lane recommending a reset once (b) is read back; the coordinator's default to main: the chain left as it stands overnight under the guards, the 2.0.2 roll with fix (1) proceeding, the reset the 08:00 read-back's first item with (b)'s evidence, no genesis cut without main's word; the shipper's cut held on fix (1); the canary's pass line the node reaching the FLEET's chain tip from genesis through every cut, never build-1's seed; the fleet lane reading which chain the hubs, the rented miners and the voters' majority weight extend by 22:40. +MAIN'S RULING ON THE SPLIT (22:1x UK): (a), (b), (c), (d) standing as the node lane set them; the 2.0.2 cut proceeding with fix (1) for the fleet kit (the fleet one chain, the roll keeping it one); no home-machine entry (Mac, Windows, HiveOS) publishing until its rule 33 canary proves a fresh install reaches the fleet's majority tip (within ten blocks of hub-1's) with the entry's dial targets verified by the fleet lane as nodes on that chain; the entries waiting on fix (2) if it needs it (a fresh install syncing to a dead seed's chain worse than no entry); the reset the founder's decision: the chain left overnight under the guards, the fleet rolling 2.0.2 with fix (1), the home machines waiting, the 08:00 read-back opening with the split, its cause, fix (2)'s evidence and the node lane's recommendation (a devnet-5 genesis against a coordinated restart from the majority chain's snapshot) with the cost of each; no genesis cut without his word. FOR THE REGISTER (main's words): the epoch cut acted as a partition and the network did not heal on its own: the D5 property tested live and FAILED on 2.0.1; the fix is software rolled, never hands. + A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the founder's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | diff --git a/docs/plans/evidence/UX-01-20261008.md b/docs/plans/evidence/UX-01-20261008.md new file mode 100644 index 000000000..c7340e6b2 --- /dev/null +++ b/docs/plans/evidence/UX-01-20261008.md @@ -0,0 +1,21 @@ +# UX-01 evidence, run ux-01-20261008-win-2.0.0 (8 October 2026) + +Onboard ordinary owners on native desktop apps, the team-run half: the two Windows PCs take the Igneum Miner 2.0.x Windows +entry (2.0.0 live 18:44 UK, Setup exe 793a631d, manifest aa354ed5; 2.0.1 about 20:55 UK with the coinbase-over-u64 fix) +through the app's own update path, with no click after the install and mining on every card (the founder's rule of +18:0x UK), observed through the apps' own intake uploads and the relay agents. The P10 study (30 unaffiliated +participants) is NOT RUN: not yet recruited; never a staff run. + +## Shape +- PC 1 (ae432dc7): Igneum Miner 0.3.26 since 17:26 UK, RTX 5090, RTX 5080, RX 7600; mining off under the Devnet 3 off order; the 2.0.0 installer downloaded and verified 18:58 UK, the install queued in the hash lane's order (update-now-20261008-181124). +- PC 2 (1ccfe586): RTX 5090, RTX 5060 Ti, Arc B580; mining off since the Devnet 3 off jobs (#1519 api/pause 16:38 UK, #1521 17:15 UK). +- The read-back: the engine's "update-return: app up after the update from " line at intake, then the relay run "mining on after the 2.0.1 install" (mining-on-after-200.ps1: wait for 2.0.1 or later, clear a stale install-running.flag, api/resume, start the app if silent) printing `RESULT MINING-ON ok|partial version=... network=... node=... synced=... paused=false cards= rates=...`. + +## Read-back lines (time UK, PC, the line or the fault and its class) +- 19:22:01 PC 2: `update-return: app 2.0.0 up after the update from 0.3.26 (node igneumd 2.0.0, machine 1ccfe586)`; node started 19:22:05; `[ok] mining resumed` 19:22:13 (no click: relay run #1742 cleared the pause through api/resume). +- 19:28 PC 2 (#1754): `RESULT MINING-ON partial version=2.0.0 network=devnet node=no peers synced=False paused=False cards=3` (every card waiting). Class: the devnet-4 hubs' outage (every dial target down 19:15 to 19:17, back by 19:29), not the install. +- 19:41 PC 2 (#1757): `RESULT MINING-ON partial ... node=behind peers=1 synced=False tip_age_s=1289`; IBD completed 19:29:16, the node then "behind". Class: the 2.0.0 miner refuses every template whose coinbase exceeds a u64 (the shipper, 19:5x UK), fixed in node 777214af as the 2.0.1 entry. +- PC 1: pending (0.3.26; the install runs when its queue reaches update-now, then 2.0.1 through the same path). + +## Status +- 20:36 UK: RUNNING; the 2.0.1 read-backs (relay runs #1762 PC 2, #1763 PC 1) are the next lines. diff --git a/docs/plans/finality-native-runs-2026-10-09.md b/docs/plans/finality-native-runs-2026-10-09.md new file mode 100644 index 000000000..d4b4a5c57 --- /dev/null +++ b/docs/plans/finality-native-runs-2026-10-09.md @@ -0,0 +1,48 @@ +# The native finality runs of 9 October 2026 (the node lane; Review B F04 and I03; V6-09 beside them) + +Status: PLANNED (written 8 October 2026, 21:4x UK, main's order under the night rule). The runs start from 00:30 UK on build-8 and build-9 (build-7 for the two-node cache case), under the lease pool, every process under a pid watcher that restarts it and records the restart; the rows land in `sim/results_v2.md` under "Rule v4" with their result files under `sim/finality-attacks-results/` and the registry batch (FIN-08, FIN-02's native half, ROT-05, VER-08's recovery row) through `tools/ci/test-record.mjs`, by 07:00 UK. An accelerated simulation is evidence of the rule's shape, never operating history: every row below runs on real nodes with the 60x file's windows (W = 120 DAA s at 1 block/s) and says so. + +The harness: `tools/finality-attacks/v3.mjs` (three nodes on the 60x file, six voters, one-way delay 300 ms per proxied link, the pass lines of `finality-guarantees.md` 6.7), extended for the rows that need a third island, an equivocating key, a stopped voter, a succession item and a backfilled checkpoint history; the extensions land with the rows. The node: the 2.0.2 line (successor-2.0.1 at or after 45e7b910: rule v4 with the pause fix 6872db13, the lock kind of F04, the finality-backed take of a9ff0a25) in the gate pair under `/srv/artefacts/200-/node-lane` (gate evidence; never a fleet binary). + +## 1. The 40/40/20 case past the window with equivocation (F04, the reviewer's hard FAIL line) + +Three islands by weight 40 / 40 / 20 (keys p0,p1 on n0; p2,p3 on n1; q0 on n2, shares 0.2 / 0.2 / 0.2 / 0.2 / 0.2 across five keys, the sixth key e the equivocator at 0.2 placed by the row), WARM 230 s, SPLIT 420 s (longer than the window after the last lock), HEAL 400 s, 1 block/s in all, rule v4 with the recovery on. + +| row | the equivocator e | expected under 6.2 and 6.5 | the FAIL line | +|---|---|---|---| +| 1a | absent (honest three-way) | no side locks during the split (no island holds more than half of the anchored table), every node pauses, the heal locks within two intervals, 0 conflicts | any lock during the split; any conflicting certificate | +| 1b | mines on island A only (reaching 60 of the anchored table on A) | A recovers once a full window has passed (the recovery lock at the first index past the window), B and C pause, the heal brings B and C onto A's chain, 0 conflicts | a lock on B or C; two certificates at one index | +| 1c | mines dust-valid on A AND B (the 6.5 bound: both at 60 percent) | BOTH A and B recover after the window: two recovery certificates at one index, the measured conflict the spec names; the heal strips e (3.6) and reports the pair under 3.11.4; the history through the anchored lock untouched | a recovery lock presented as final on any surface (lockKind must read "recovery" on both); the anchored history moving | +| 1d | 1c under the pause-only variant (recovery off) | no lock on any side during the split, the pause until the heal, 0 conflicts (the strictly stronger guarantee of 6.5) | any lock during the split | + +Measured per row: new locks per side during the split (index and DAA), the lock kind on `igneum_getFinalityCheckpoints` (final or recovery), conflicting certificates logged, disagreeing locked indices after the heal, the equivocator's strip at the heal (the ban line), every pre-heal lock kept, the first lock after the heal (s). + +## 2. The pause-only alternative with backfill, missing history and the old keys returning (I03) + +Rule v4, recovery off. A chain is run 230 s with six voters, then split 3/3 for 420 s (no lock on either side, the pause), then healed; during the heal window: (a) a fresh node joins from genesis and must backfill every checkpoint and certificate (the historical-checkpoint backfill; it reads the same latest lock as the three), (b) one node restarts from a datadir with its finality state removed (missing historical data: it rebuilds from the chain's carried certificates and must agree), (c) every old key returns and signs (the pause ends on two thirds, the lock within two intervals). Measured: the backfilled node's locked indices equal the others' (0 disagreement), the restarted node's, the first lock after the return, 0 conflicts. + +## 3. Authority succession and strip, restart, certificate arrival order, seed boundaries (I03) + +| row | shape | expected | +|---|---|---| +| 3a | a voter leaves (W7, the leave item carried) mid-window, the rest sign | the frozen table reduces by the leaver (frozen_floor), the next lock at two thirds of the remaining; the leaver's weight never counts | +| 3b | a key is stripped (an equivocation evidence item carried) one interval before a lock | the strip applies before the lock's test; a certificate carrying the stripped key's signature counts it as 0 | +| 3c | a voter restarts between determination and lock (kept datadir) | it votes once (no double vote), the lock forms on time, its locks equal the others' after the restart | +| 3d | two certificates for consecutive indices arrive in reverse order at a node (the fleet's 263-then-262 read on hub-1) | both lock under the rule, the LOCKED line prints the certificate's fractions (the 2.0.2 log fix), no "signed 0" artefact | +| 3e | a seed boundary (the epoch's reference block) inside a pause | the seed is drawn from the chain block below the lead whether or not it is locked (section 8); mining continues; the first lock after the pause names a block past the boundary | + +## 4. The inter-chain verifier and a recovery lock (I03) + +The Sepolia certificate verifier (dex lane's bridge, 0x874D8Be5… on igneum-devnet-4's voter table) given (i) a final certificate, (ii) a recovery certificate from row 1b: it accepts (i) as final; for (ii) it must read lockKind "recovery" and never present it as final (the bridge doc 829b839ec: recovery locks fail closed on the verifier, which reads only weight). The row records what the verifier answers for each and the receipt page's word; a recovery certificate accepted as final is the FAIL line. + +## 5. V6-09, cold compressed verification on the minimum validator (with the enforced-proving lane) + +One validator node pinned to one core (taskset), no warm relay cache (fresh datadir, the pool empty), fed by a relay peer: (a) ten cold valid shard proofs in one block's carried records (the measured 0.668 to 0.710 s a proof on one loaded core); (b) ten expensive-invalid payloads (proofs whose bytes deserialise to the largest accepted shape and fail at the last check) with the relay's pre-deserialise cap (MAX_PROOF_BYTES in consensus-core, V6-08's constant) and the in-flight bound of 8; (c) a forged record under each pair across the key and fee transitions, before, at and after activation, on an unmodified validator. Measured per row: verify seconds per proof, block-validation time against the deadline, the NotReady retries, memory before and after deserialising, the carrier paid exactly once (igneum_getProofRecords on the validator against the relay's), the forged record refused with its reason. The rows go to the test map cell `harness:v6-09-cold-verify` with the F0 fixture, by 12:00 UK 9 October. + +## 6. The two-node cache-history test (F01, with the proving lane's fix 3f672661) + +Two nodes, one with a warm verdict cache built on carriers 1..k, one cold, both fed the same blocks in a different order (the cold one sees the later carrier first): identical block-validity verdicts and identical payouts (igneum_getProofRecords and the paid map equal on both), with the known-failed shape first (the pre-fix node's cached context refusal replayed under a later carrier, the 19:49 UK reproduction). On build-7 by 03:00 UK. + +## Boxes and clocks + +build-8: sections 1 and 2 (the 40/40/20 rows 1a to 1d, then the backfill case), from 00:30, rows by 05:00. build-9: sections 3 and 4 (after the 2.0.2 line's gate ends), from 01:00, rows by 06:00; section 5 with the enforced-proving lane's fixtures, rows by 12:00. build-7: section 6, by 03:00. Every run under `lease pool N --class release` with a pid file and a watcher; a stall is recorded for the 08:00 read-back, never a hand-made lock. The rows land in sim/results_v2.md with their result files and the registry batch by 07:00 UK, the plan's status moved to MEASURED per section as each lands. diff --git a/docs/plans/igneum-2.0-f0-manifest.md b/docs/plans/igneum-2.0-f0-manifest.md index 0c8a05d3e..79e194e89 100644 --- a/docs/plans/igneum-2.0-f0-manifest.md +++ b/docs/plans/igneum-2.0-f0-manifest.md @@ -6,7 +6,7 @@ The fixture every case of the Test and Acceptance Standard (docs/plans/igneum-2. | Field | Value | Read from | Owner | |---|---|---|---| -| Miner cut tip (release-2.0.1) | aa0e0f45 (9c844503 + the pin file; 9c844503 = 2826f37e + the six-target packaged peer list; the app crate byte-identical to 2ea7b43f's throughout, so the pow and app cells read on 9c844503 cover it by content) | the shipper's line 19:5x | shipper (ae892a8b0f78fe31c) | +| Miner cut tip (release-2.0.1) | aa0e0f45 is the shipped tip (the entries stand on its binaries); release-2.0.1's final tip is c30ab32c (aa0e0f45 + the pool lane's pool/ and docs a54dffa3 + the release manifest f03-manifest-201 7437a31a merged at 800faaf7 + the hand-merged spec 09; no app, node pin or packaging change). The clean build from the manifest (R2-F03-R01) read green on c30ab32c at 21:14 UK on build-4: kaspad with igneum-pow, igneum-miner, igneum-pool, igneum-app, igneum-prove-host, and every component's own pin equals packaging/release-manifest.json. (9c844503 + the pin file; 9c844503 = 2826f37e + the six-target packaged peer list; the app crate byte-identical to 2ea7b43f's throughout, so the pow and app cells read on 9c844503 cover it by content) | the shipper's lines 19:5x and 21:0x; the steward's build 21:14 | shipper (ae892a8b0f78fe31c) | | Node sha for the roll | 7cfa422a = ef0f2ed8 (291ee6ae + the 2.0.1 version) + the miner base-unit fix, amended (777214af did not compile: a self-recursive connect, caught by the steward's read at 19:50) | the node lane's and shipper's lines 19:5x | node lane (a283f5f0d364ceef0) | | Node line read green tonight | 4cdcc488, d5981514, bee41b5e, 9fc9f42a, 5713d547, 417c4a57, 291ee6ae (ef0f2ed8 = 291ee6ae + the version bump, its own read on build-4 recorded as the literal) | the steward's matrices on build-2 and build-4 | CI steward | | Network | igneum-devnet-4, a fresh genesis; EVM chain id 4465 (0x1171), set in devnet4_params, read by the canaries as eth_chainId on every candidate tonight, pinned by the digest be5f4068; every 2.0 devnet node, pool and reference app signs with it; mainnet's and the testnet's ids unchanged from the 0.3 line | the node lane's line 19:3x | node lane | diff --git a/docs/plans/igneum-2.0-register.md b/docs/plans/igneum-2.0-register.md index 2e7b1c80e..c790d3659 100644 --- a/docs/plans/igneum-2.0-register.md +++ b/docs/plans/igneum-2.0-register.md @@ -41,7 +41,7 @@ Built 8 October 2026, 18:3x BST (the founder's order: no feature left out, no st | 35 | D4. A five-year coexistence model (p. 13) | Profit-maximising operator simulation: mine, internal prove, external prove, off; under a proving demand spike, a token price fall, a major prover leaving, a specialised entrant in either market. Pass if pricing and capacity rules restore service without an administrator. | research lane (ad6a2bd47d4a46105) | 21:00 tonight | in flight: operator-simulation.md landed 859b3daa, the four shocks run on floor lane 3 by 20:15 | docs/analysis/class-v6/operator-simulation.md | INC-03, INC-04 | | 36 | D5. A no-rescue network exercise (p. 19) | Prerequisite: proof verification enforced in consensus (verifier_in_consensus, proof_rule_active_from) live on the exercise network. | enforced-proving lane (a6e8f84588b809d62) | landed | PASSED: verifier_in_consensus live on igneum-devnet-4 from block zero (4cdcc488), the seven refusals and the fast-time crossing PASS at 17:22 | docs/spec/proving-enforcement.md | ZKP-01, ZKP-08 | | 37 | D5. A no-rescue network exercise (p. 19) | No founder-operated mining, proving, aggregation or mandatory distribution infrastructure. | node lane (a283f5f0d364ceef0) | days two and three | open: the three ex-testnet seeds held for it | | OPS-01 | -| 38 | D5. A no-rescue network exercise (p. 19) | Cross epoch boundaries, interrupt signing, partition the network, remove major operators, hostile proof submissions, independently written clients. | finality lane (aca0f5ed924a2a99b) | days two and three | in flight: the partition row landed ec9ea053d (rule v4); the rest of the scenario table owed | docs/spec/finality-guarantees.md | FIN-02, FIN-03, FIN-04, FIN-08, ROT-01 | +| 38 | D5. A no-rescue network exercise (p. 19) | Cross epoch boundaries, interrupt signing, partition the network, remove major operators, hostile proof submissions, independently written clients. | finality lane (aca0f5ed924a2a99b) | days two and three | in flight: the partition row landed ec9ea053d (rule v4); the rest of the scenario table owed; LIVE, 8 October 22:08 UK: igneum-devnet-4 split into at least four chains at the class v5 epoch cuts (a node that captured block X as epoch N's reference validates only epoch-N headers seeded by X; another chain's headers are refused and their weight never counts, so the virtual never moves and the nodes never rejoin; a lock above the fork makes it permanent): the epoch cut acted as a partition and the network did not heal on its own, the D5 property tested live and FAILED on 2.0.1; the fix is software rolled (the IBD catch-up re-syncing bodies on every state wait on the 2.0.2 line by 22:45; the foreign-seed capture built tonight with suites by 02:00), never hands; the reset the founder's decision | docs/spec/finality-guarantees.md | FIN-02, FIN-03, FIN-04, FIN-08, ROT-01 | | 39 | D5. A no-rescue network exercise (p. 19) | A withholding concentrated prover: replacement operators, usable inputs, reassignment, explicit behaviour during proof delays. | enforced-proving lane (a6e8f84588b809d62) | days two and three | open | | CAP-07, INC-08 | | 40 | Pools, software and participation (launch requirements) (p. 14) | Vote keys stay with the miner at protocol level: the member's retained voting key committed into its work, payment aggregation separate, verifiable, pool identity substitution resisted. | pool design seat (a3832b1c3b274b310) | tomorrow 18:00 | in flight: the design on master 637e508b (the header commitment, the key on job and share); the code the pool branches rebase first | docs/design/pool-vote-key-commitment.md | UX-05, FIN-05 | | 41 | Pools, software and participation (launch requirements) (p. 14) | Non-custodial payouts, practical minimum payouts, local work verification, low-bandwidth participation (P2Pool as precedent, not code). | pool design seat (a3832b1c3b274b310) | tomorrow 18:00 | open: designed in the same file | | UX-04 | diff --git a/docs/plans/igneum-2.0-same-work-test.md b/docs/plans/igneum-2.0-same-work-test.md new file mode 100644 index 000000000..6ecfdd5c8 --- /dev/null +++ b/docs/plans/igneum-2.0-same-work-test.md @@ -0,0 +1,48 @@ +# The cross-backend same-work test (F03, Review B; specified by the CI steward, 8 October 2026, 20:1x UK) + +One job context, six readers, three phases around a transition, bit-for-bit agreement. Run by the fleet lane with the freeze object; the evidence recorded against POW-01 through the batch tools. + +## The job context (one file, `job-context.json`, written once by the steward or the hash lane and copied to every reader) + +| Field | Value tonight | Source | +|---|---|---| +| object | the class v5 freeze: igneum-pow 1c420786, fingerprint cbc5bd0aa10585c8576e71e37a8ee47a045ae51754e9ddf749d0c21e6a535f88 | packaging/release-manifest.json (generator) | +| epoch seed bytes | edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 (the genesis seeds) | the hash lane's P01 line | +| day bytes | 69676e65756d2d6461792ffa50000000000000 | the hash lane's P01 line | +| class | 5; era 0: | the pack's program.json | +| prehash | 0000000000000000000000000000000000000000000000000000000000000001 | the P01 convention | +| nonce range | 0 .. 2^20 per phase (three phases, three ranges: [0, 2^20), [2^20, 2^21), [2^21, 2^22)) | this page | +| transition | the day boundary: day D for phase 1, the boundary block for phase 2 (the last 2^12 nonces of day D and the first 2^12 of day D+1 as the engine sees them under fast-time 60x), day D+1 for phase 3 | infra/fast-time/override-60x.json | + +The transition is a dataset-day rotation (the class and era unchanged, the day bytes change), the one transition every live network crosses hourly at 60x; a class rotation (v5 to v6) is the same test with `class` and the second `day bytes` changed and runs only on a research object until a v6 floor is set. + +## The six readers (every one writes `-.json` of the P01 driver's evidence shape: nonce, hash per line in the raw file; agree, disagree, missing, the first ten disagreements, the device line, the pack and program ids, the manifest sha in the JSON) + +1. **node**: `igneumd` at the manifest's node sha, the engine's own re-check (`IgneumEngine::epoch_for` then `hash_bound` per nonce) through `igneum-miner --recheck-vectors` on the node binary's CPU path (the pool.rs seam), on build-2. +2. **CPU reference**: `igneum-pow hash-bound --count 2^20 --nonce ` from the manifest's generator commit, on build-2 (the hash lane's reference files are this reader). +3. **CUDA**: the kit's `igneum-worker-cuda --serve` driven by `tools/ci/p01-vectors.py` with the job context, on a 5090, 4090 and 3090 pod. +4. **OpenCL**: `igneum-worker-opencl --serve` the same way, on the AMD pod when one exists, else PC 1's RX 7600 (the only OpenCL retail cell tonight). +5. **Metal**: the Mac's own worker, the same driver, on the mini (the morning's run; never on this Mac). +6. **pool**: `igneum-pool` at the manifest's sha with its vendored node at the manifest's node sha, the member-side re-check (`pool/src/node.rs` → `kaspa_pow::igneum::IgneumEngine`) on the same job lines, on build-2. + +## The three phases + +Phase 1 (before): every reader on range 1 under day D. Phase 2 (during): every reader on range 2 where the engine's day moves from D to D+1 inside the range at the boundary nonce the fast-time clock sets; every reader must switch program and dataset at the same nonce. Phase 3 (after): every reader on range 3 under day D+1. + +## Acceptance (the registry row POW-01, cell `harness:same-work`, PASS only when all hold) + +- every reader's hash equals the CPU reference's for every nonce of every phase (zero disagreements, zero missing); +- the program id and the day each reader reports at phase 2's boundary are the same across readers (the transition is seen at one nonce); +- the pool's accepted-share verdict for a sample of 64 nonces per phase equals the node's (the seam closes by a build: `release-manifest-check.sh` refuses a redefined EpochSeeds and an unpinned vendored node); +- the run names the manifest sha (packaging/release-manifest.json), and the evidence sits at build-1:/srv/artefacts/tas/same-work-/. + +A disagreement on any reader is a red to main within fifteen minutes (the coordinator's rule for the cross-checks). + +## What is still to build (owners, defaults) + +| Piece | Owner | Clock | Default if silent | +|---|---|---|---| +| `p01-vectors.py --job-context --phase N` (the three ranges and the boundary assertion; the driver already drives the workers) | CI steward | 21:30 | built as specified | +| the node reader (`igneum-miner --recheck-vectors`, the seam with a count) | node lane | 22:00 | the steward builds it on a branch of release-2.0.0-node under rule 24 | +| the pool reader (the member-side re-check over a job-lines file) | pool lane | 22:30 | the pool's existing recheck_pack path over the context, driven by the steward | +| the pods and the mini | fleet lane | on the artefact line | as P01 | diff --git a/docs/plans/igneum-2.0-test-harness-map.md b/docs/plans/igneum-2.0-test-harness-map.md index 572138472..4d401d387 100644 --- a/docs/plans/igneum-2.0-test-harness-map.md +++ b/docs/plans/igneum-2.0-test-harness-map.md @@ -133,8 +133,8 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover ### bench:pc1-packs -- Command: `tools/ca3-v4-amend/pc1-ca4-packs.ps1 on PC 1 (RTX 5090, the signed-jobs channel, --cards-off, the Power Helper lock at 1,300 MHz, nvidia-smi at 1 Hz, 250 x 2^24 per row, the kit's CUDA worker --bench)` -- Box class: PC 1 bench +- Command: `tools/ca3-v4-amend/pc1-ca4-packs.ps1 on the project's own rig (RTX 5090, the signed-jobs channel, --cards-off, the Power Helper lock at 1,300 MHz, nvidia-smi at 1 Hz, 250 x 2^24 per row, the kit's CUDA worker --bench)` +- Box class: the project's own rig bench - Fixtures: F0, F1 - Cases: - GPU-02 Reproduce Ember clock-lock savings: partial: the paired stock and locked rows on the same board, host and workload (the rate held, 2.37 against 3.26 microjoules per hash on the class v5 pack); the historical 34 to 41 percent claim's full configuration set is owed @@ -144,8 +144,8 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover ### bench:pc1-amd -- Command: `tools/ca3-v4-amend/pc1-amd-cardin-bench.ps1 on PC 1 (RX 7600, OpenCL, gfx1102, 30 dispatches of 2^24 per size, rate only)` -- Box class: PC 1 bench +- Command: `tools/ca3-v4-amend/pc1-amd-cardin-bench.ps1 on the project's own rig (RX 7600, OpenCL, gfx1102, 30 dispatches of 2^24 per size, rate only)` +- Box class: the project's own rig bench - Fixtures: F0, F1 - Cases: - GPU-01 Cover the declared commodity population: partial: the 8 GB AMD cell, fingerprints and rates at 1, 2, 4 and 5.5 GiB; one cell of P02's twelve @@ -243,7 +243,7 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover - Box class: harness (network run on the 2.0 devnet plus Sepolia reads) - Fixtures: none - Cases: - - VER-03 Prove successful payment rather than inclusion: partial: a payment receipt is labelled payment only when the receipt is proven against the segment statement's receipts commitment under the finality certificate, inclusion-only receipts read inclusion, a tampered receipt and a flipped status fail; run on the Devnet 3 fixtures, the 2.0 devnet re-run waits for its first paid segment whose last block carries a transaction + - VER-03 Prove successful payment rather than inclusion: partial: a payment receipt is labelled payment only when the receipt is proven against the segment statement's receipts commitment under the finality certificate, inclusion-only receipts read inclusion, a tampered receipt and a flipped status fail; run on the the earlier devnet fixtures, the 2.0 devnet re-run waits for its first paid segment whose last block carries a transaction - VER-04 Bound cross-chain oracle trust and replay: partial: the oracle's trust() names the deployer-installed table and the unchecked aggregator signature, a second hash at a stored certificate index is refused, a root claim at an unknown index is refused, another chain id is refused (tools/reference-apps/oracle/test.mjs on Sepolia); Review B F04: the Sepolia verifiers apply the two-thirds rule only, carry no lock-kind field, and an under-threshold (recovery-rule) certificate fails closed in submitCertificate, so no stored root is a recovery lock (the DEX lane's docs/bridge/light-client-bridge.md paragraph); the claimed-option review of the trust model is the reviewer's - VER-05 Reconstruct required state without founder storage: partial: the public node and the reference reader on build-1 executed the 2.0 devnet from genesis with no snapshot (unit ExecStart without --igneum-exec-snapshot), and the pages fetch headers, certificates, coinbase bodies and account proofs from the public read RPC only; the archive and availability model beyond the 2,048-block state ring is the OPS no-founder exercise - VER-06 Detect withholding, corruption and stale data: partial: the read service never serves a certificate from another network, a withheld header in the path and a corrupted proof node are detected, stale data prints its lock age beside every balance, and a client told no certificate never falls back to a trusted RPC balance; detection on the fault network F4 is not run @@ -336,24 +336,95 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover ### bench:amd-intel-energy -- Command: `the AMD-and-Intel energy lane jobs on the signed-jobs channel: run-ae-pc2-b580-energy-20261008 (PC 2, Arc B580, the class v6 kit worker --memprobe and --bench-pack on hl-v6-foldrw and hl-v6-all, Level Zero energy counter) and run-ae-pc1-7600-energy-20261008 (PC 1, RX 7600, the same with ADLX watts at stock, plimit -30, gmax -500 + plimit -30); scripts in docs/analysis/class-v6/amd-intel-energy/` -- Box class: PC 1 and PC 2 bench (OpenCL) +- Command: `the AMD-and-Intel energy lane jobs on the signed-jobs channel: run-ae-pc2-b580-energy-20261008 (PC 2, Arc B580, the class v6 kit worker --memprobe and --bench-pack on hl-v6-foldrw and hl-v6-all, Level Zero energy counter) and run-ae-pc1-7600-energy-20261008 (the project's own rig, RX 7600, the same with ADLX watts at stock, plimit -30, gmax -500 + plimit -30); scripts in docs/analysis/class-v6/amd-intel-energy/` +- Box class: the project's own rig and PC 2 bench (OpenCL) - Fixtures: F0, F1 - Cases: - GPU-03 Measure the real 64-register GPU cost: partial: the 64-register window on AMD and Intel, rate per unit of work (RX 7600 0 percent, Arc B580 -0.3 percent, kernel throughput, quiet) with the B580 fingerprints equal on both packs and the offline RDNA allocation (160 VGPRs, no spill); energy owed (the 7600 job queued, the B580 counter unsupported unelevated); team-run, not under the standard's paired protocol or a wall meter +### adversary:mf-placed + +- Command: `cd tools/chip-model/mf && make flow- power- (inside openroad/orfs:latest on a rented CPU host; never the Mac); python3 flow/collect.py results; python3 flow/board.py ; python3 flow/hash.py results power` +- Box class: rented CPU host (Vast, 48 to 72 cores) on the ORFS image +- Fixtures: F0, F1 +- Cases: + - ADV-01 Build a multi-family programmable opponent: the mf core (18 families, SRAM window and imem macros, operand isolation, 5-phase port) placed and routed on ASAP7 with SPEF and a gate-level VCD; k per family and per draw; outputs checked against the RTL simulation's checksums per tag, not yet against the POW vectors (owed) + - ADV-03 Attack with data-local and hybrid execution: the data-local, hybrid and companion-host rows of multi-family-adversary.md sections 11, 13 and 14 (bit counts closed-form; the hop and wire energies claimed) + - ADV-07 Evaluate lifetime without forced obsolescence: the lifetime table and the six-row transition matrix (sections 7 and 14) on the placed rows; the 32-lane genesis comparator placed on adv-g + - ADV-08 Independently challenge the best-cost envelope: the best-cost envelope on the complete machine (section 6) and the SRAM-die ticket reconciliation with lane B (section 15); the unaffiliated second reviewer is not this lane's + - POW-03 Test whether live state is unavoidable: partial: the live state held in an SRAM macro per 8 lanes with a time-multiplexed single port and operand isolation, the complete-system cost in section 6; the liveness trace itself is the connected-state lane's tool + - POW-04 Evaluate connected-resource restructuring: partial: the 64-register window's cost on the macro core (sections 4 and 5, agreeing with the k lane's gated-flop row within 5 percent); the restructured candidate's GPU cost is the invention lane's + - ADV-05 Validate physical and complete-board costs: partial: the SRAM macros, ports, wiring, clocking and the complete-board terms are modelled in sections 2.3, 5 and 6 with the unmodelled items carried as uncertainty; the calibration against an existing hardware block is the k lane's bare-lane row beside it, owed as a named comparison + +### adversary:d2b + +- Command: `cd tools/chip-model/mf && python3 flow/d2b.py results N5 1 && python3 flow/d2b.py results N3 1 (on a build box under lease pool or a rented host; reads results/table.csv)` +- Box class: any box (a one-minute Python model on the placed rows) +- Fixtures: F0 +- Cases: + - ADV-02 Price shared, reduced and reconstructed memory: memory sharing, partial stores at the measured window-layer hit rates (and hit 0.50 with layer 8 off), recomputation and the set-up amortisation on the complete board (section 13); the formal memory model's terms (section 16) + - ADV-04 Measure profitable selective participation: selective participation over 2,000 era draws under the layer 1 band with two reserve families live per epoch, the specialist's revenue against its ratio gain (section 13); downtime and re-entry priced as the DAA window's lag, not simulated against the difficulty rule itself (owed) + +### pc:install-update + +- Command: `signed jobs and relay runs on the project's own rig (ae432dc7) and PC 2 (1ccfe586): the installer over the running app (rule 14: installed versions, the process set, the first upload), the OTA path (update-now, the update-return read-back line), and the no-click resume after the install (relay run mining-on-after-200.ps1)` +- Box class: PC (the two Windows PCs; nothing on the Mac) +- Fixtures: F2 +- Cases: + - UX-01 Onboard ordinary owners on native desktop apps: team-run evidence only (the two PCs taking the Windows entry through the app's own update path with no click and mining on every card); the P10 study is NOT RUN until unaffiliated participants are recruited + - UX-07 Expose actionable failures and safe updates: partial: the install classes (the payload's stop step, the detached installer under a job, the installer refusing a wrong-version name, a stale install flag) and the no-click resume; the recovery-instruction and canary rows are the shipper's + - OPS-03 Separate update distribution from consensus authority: partial: the update path's read-back and the signed manifest's verify on the PC (a tampered or rolled-back payload is refused by the engine's manifest check); authority separation is the shipper's review + +### harness:release-manifest + +- Command: `bash tools/ci/release-manifest-check.sh (self-test, then the tree; the pins, the proof guests' hashes on disk, the fork freeze, the pool's vendored node, the proving manifest's source_commit provenance) and bash tools/ci/build-from-manifest.sh --box N on the release tree (kaspad with igneum-pow, igneum-miner, igneum-pool, igneum-app, igneum-prove-host from packaging/release-manifest.json with the node vendored at the manifest's sha)` +- Box class: gate +- Fixtures: F0 +- Cases: + - R2-F03-R01 Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.: full for the components the tree builds (node, miner, pool, app, prove-host from one manifest, no unpublished vendor tree); the GPU workers are the kit's cross-build and read under the shipper's kit-isa line, not this cell + +### harness:same-work + +- Command: `tools/ci/p01-vectors.py --job-context --phase 1|2|3 per reader (CUDA, OpenCL, Metal workers), igneum-miner --recheck-vectors (node), igneum-pow hash-bound (CPU reference), the pool's member-side re-check; docs/plans/igneum-2.0-same-work-test.md` +- Box class: release (the readers on their pods and boxes) +- Fixtures: F0 +- Cases: + - R2-F03-R02 Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.: partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context + - R2-F03-R03 Cross every scheduled transition with old/new client behavior documented and identical rule identities.: partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set + +### canary:fresh-install + +- Command: `the rule 33 fresh-install canary on a release tip (the founder, 8 October 2026): install from the published artefact on a non-AVX-512 box with an empty datadir, sync genesis to tip, five minutes mining with zero refusals and an accepted block, one shard claimed, proved and paid or queued, a bounded quit, every line read back; the record tools/ci/canary/.json (one file per sha, an artefacts list: fleet, windows, mac, hive) read by tools/ci/canary-check.sh [--artefact kind], which publish-manifest.sh and publish-public.sh refuse without` +- Box class: release (a non-AVX-512 box with an empty datadir) +- Fixtures: F0 +- Cases: + - INT-07 One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.: partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's + +### review:k-lane-shadow-k + +- Command: `floor lane 2's placed and routed cores on ASAP7 in tools/chip-model/rtl (the rows in docs/analysis/class-v6/floor/shadow-k.md); the register landing 50ff1611f recorded ADV-06 against it before the recorder existed` +- Box class: none +- Fixtures: none +- Cases: + - ADV-06 Separate process advantage from specialisation: partial: the placed gated cores and the adversary's forms are modelled in shadow-k.md; the independent review remains + +### kit:class-v6-fingerprints + +- Command: `KITS_BOX_SCRIPT=kits-v6-on-box.sh tools/class-v5/kits-remote.sh --box 1 (the kit zip with its emulation check), then the kit's workers on every platform: the box's CPU emulation (--check, 96 of 96 vector lanes), the fleet's CUDA 4090 (--check and --bench at 2^24, base nonce 0), the Mac's Metal (proto-metal/packbench.swift --pack) and Apple OpenCL (proto-opencl/host.c --pack --bench-pack), PC 1's RTX 5090 and RX 7600 (tools/class-v5/pc1-v6-bench.ps1), PC 2's Arc B580 (tools/class-v5/arc-v6-bench.ps1); the fingerprint of the 2^24 outputs at base nonce 0 equal on every platform for the all pack and for its known-failed partner, the two distinct` +- Box class: build box + pods + Mac + PC 1 + PC 2 +- Fixtures: F0, F2 +- Cases: + - R2-F03-R02 Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.: partial: the worker half (CPU reference, CUDA, Metal, OpenCL) on the same program packs; the node's and the pool's accepted work on the same job context are the CI steward's and the pool lane's cells; PASS only when every listed platform reads one fingerprint and the node and pool halves are green + ## Automated cases with no harness in the matrix (NOT RUN, the reason) - GOV-02 Approve thresholds before results: the approval is recorded in the registry's approval field; the automated half (thresholds frozen before any run_status) is the gate rule landing by 21:00 - GOV-04 Preserve raw and negative evidence: the evidence vault F9 (raw and negative evidence preserved) is the gate rule landing by 21:00: a PASS must carry its evidence file - GOV-08 Invalidate stale evidence and control public status: the stale-evidence rule (evidence older than the manifest sha reads NOT RUN) is the gate rule landing by 21:00 -- GPU-04 Find the memory-clock operating ladder: the memory-clock ladder has no harness tonight: PC 1 mines nothing under the Devnet 3 off order +- GPU-04 Find the memory-clock operating ladder: the memory-clock ladder has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order - GPU-06 Measure accepted work under ordinary connectivity: accepted work under ordinary connectivity needs the fault network F4 -- GPU-07 Survive sustained thermal and power operation: the sustained thermal and power soak has no harness tonight: PC 1 mines nothing under the Devnet 3 off order +- GPU-07 Survive sustained thermal and power operation: the sustained thermal and power soak has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order - POW-05 Prevent amortised cheap winning attempts: amortised cheap winning attempts are the attack lanes' grind and era harnesses (tools/attack/f7-era, f9-grind), not in the release matrix; their rows come from those lanes -- ADV-04 Measure profitable selective participation: selective participation needs the economic model F7 and a live chain window -- ADV-06 Separate process advantage from specialisation: process-advantage separation is the adversary lanes' chip study -- ADV-07 Evaluate lifetime without forced obsolescence: lifetime rows are the adversary lanes' models - ROT-03 Test miner-voted bring-forward governance: miner-voted bring-forward needs a vote harness on the fault network F4 - ROT-04 Resist seed selection and faster evaluators: seed-selection resistance is the census harness (the class v6 invention lane), not yet in the matrix - EVM-01 Match the selected EVM semantics: no EVM conformance-vector harness is mapped tonight; the exec suite does not run the reference test vectors @@ -440,7 +511,6 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover - INT-04 Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.: INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map - INT-05 The supplied finality implementation matches the approved anchor rule after >window healing.: INT-05 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map - INT-06 Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.: INT-06 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map -- INT-07 One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.: INT-07 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map - INT-08 Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.: INT-08 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map - INT-09 Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.: INT-09 (R1 integration gate): the gate's harness is the owner lane's (app lane); not yet named in the map - INT-10 Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.: INT-10 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map @@ -459,9 +529,6 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover - R2-F02-R01 Release build cannot activate test bypass.: R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map - R2-F02-R02 Missing oracle or pinned keys prevents service readiness after enforcement activation.: R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map - R2-F02-R03 Missing proof bytes retry without incorrectly marking a valid block permanently invalid.: R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map -- R2-F03-R01 Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.: R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map -- R2-F03-R02 Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.: R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map -- R2-F03-R03 Cross every scheduled transition with old/new client behavior documented and identical rule identities.: R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map - R2-F04-R01 Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.: R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map - R2-F04-R02 Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.: R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map - R2-F04-R03 Pause-only resume with historical backfill, missing historical data and all old keys returning.: R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map @@ -499,4 +566,4 @@ Rule: a case maps to a cell only where the cell's tests visibly answer it; cover ## Count -171 automated cases: 69 mapped to a cell, 152 NOT RUN with a reason. +171 automated cases: 83 mapped to a cell, 145 NOT RUN with a reason. diff --git a/docs/plans/igneum-2.0-test-registry.json b/docs/plans/igneum-2.0-test-registry.json index d73a797e7..809a0e38f 100644 --- a/docs/plans/igneum-2.0-test-registry.json +++ b/docs/plans/igneum-2.0-test-registry.json @@ -50,29 +50,30 @@ "manual_page": 18, "owner_lane": "node lane (a283f5f0d364ceef0)", "run_status": "NOT RUN", - "evidence_path": "docs/plans/igneum-2.0-f0-manifest.md; packaging/pow-freeze.txt; build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-kaspad-check.log", - "run_id": "201-7cfa422a-aa0e0f45", - "updated": "2026-10-08T19:32:50.856Z", + "evidence_path": "docs/plans/igneum-2.0-f0-manifest.md; build-4:/srv/builds/igneum-wt-f03-201/vendor/igneum-node/packaging/pow-freeze.txt; build-4:/srv/builds/igneum-wt-f03-201", + "run_id": "f03-manifest-20261008-01", + "updated": "2026-10-08T21:11:46.383Z", "evidence_record": { - "cell": "check:freeze", - "manifest_sha": "7cfa422a", - "coverage": { - "GOV-01": "partial: the linked igneum-pow tree's fingerprint must match a listed freeze or the build fails, the binary prints which; the manifest (igneum_getManifest) names the object digest; the signed F0 manifest is the node lane's row tonight" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "GOV-01", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "static", + "cell": "check:freeze", + "manifest_sha": "c30ab32c", + "run_id": "f03-manifest-20261008-01", + "evidence": "docs/plans/igneum-2.0-f0-manifest.md; build-4:/srv/builds/igneum-wt-f03-201/vendor/igneum-node/packaging/pow-freeze.txt; build-4:/srv/builds/igneum-wt-f03-201", + "in_progress": false, + "coverage": "partial: the linked igneum-pow tree's fingerprint must match a listed freeze or the build fails, the binary prints which; the manifest (igneum_getManifest) names the object digest; the signed F0 manifest is the node lane's row tonight", "release_identity": { - "commit": "7cfa422a", - "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", - "profile_hashes": "" - } + "commit": "c30ab32c", + "lockfile": "the release tree's Cargo.lock files at c30ab32c", + "binary": "cargo check only: no binary is claimed by this cell; the fleet binaries are the shipper's kit on aa0e0f45", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "none (a build fact)", + "profile_hashes": "release-manifest-check: every component's own pin equals packaging/release-manifest.json" + }, + "claim_impact": "F03's first rung: one manifest, one build, no unpublished vendor tree; the same-work rung (R02) and the transition rung (R03) stay NOT RUN until the readers run on the job context", + "reviewer": "", + "at": "2026-10-08T21:11:46.383Z" }, "in_progress_since": "2026-10-08T19:32:50.856Z", "approvals": { @@ -83,28 +84,26 @@ }, "evidence_records": { "check:freeze": { - "cell": "check:freeze", - "manifest_sha": "7cfa422a", - "coverage": { - "GOV-01": "partial: the linked igneum-pow tree's fingerprint must match a listed freeze or the build fails, the binary prints which; the manifest (igneum_getManifest) names the object digest; the signed F0 manifest is the node lane's row tonight" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "GOV-01", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "static", + "cell": "check:freeze", + "manifest_sha": "c30ab32c", + "run_id": "f03-manifest-20261008-01", + "evidence": "docs/plans/igneum-2.0-f0-manifest.md; build-4:/srv/builds/igneum-wt-f03-201/vendor/igneum-node/packaging/pow-freeze.txt; build-4:/srv/builds/igneum-wt-f03-201", + "in_progress": false, + "coverage": "partial: the linked igneum-pow tree's fingerprint must match a listed freeze or the build fails, the binary prints which; the manifest (igneum_getManifest) names the object digest; the signed F0 manifest is the node lane's row tonight", "release_identity": { - "commit": "7cfa422a", - "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", - "profile_hashes": "" + "commit": "c30ab32c", + "lockfile": "the release tree's Cargo.lock files at c30ab32c", + "binary": "cargo check only: no binary is claimed by this cell; the fleet binaries are the shipper's kit on aa0e0f45", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "none (a build fact)", + "profile_hashes": "release-manifest-check: every component's own pin equals packaging/release-manifest.json" }, - "run_id": "201-7cfa422a-aa0e0f45", - "evidence": "docs/plans/igneum-2.0-f0-manifest.md; packaging/pow-freeze.txt; build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-kaspad-check.log", - "in_progress": true + "claim_impact": "F03's first rung: one manifest, one build, no unpublished vendor tree; the same-work rung (R02) and the transition rung (R03) stay NOT RUN until the readers run on the job context", + "reviewer": "", + "at": "2026-10-08T21:11:46.383Z" } } }, @@ -950,10 +949,10 @@ "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/floor/sm-sparse.md", "run_id": "team-2026-10-08", - "updated": "2026-10-08T20:10:24.556Z", + "updated": "2026-10-08T21:00:32.846Z", "evidence_record": { - "reason": "the memory-clock ladder has no harness tonight: PC 1 mines nothing under the Devnet 3 off order", - "at": "2026-10-08T20:10:24.556Z", + "reason": "the memory-clock ladder has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order", + "at": "2026-10-08T21:00:32.846Z", "method": "static", "requirement_id": "GPU-04", "decision": "NOT RUN", @@ -1198,10 +1197,10 @@ "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/floor/sm-sparse.md", "run_id": "team-2026-10-08", - "updated": "2026-10-08T20:10:24.556Z", + "updated": "2026-10-08T21:00:32.846Z", "evidence_record": { - "reason": "the sustained thermal and power soak has no harness tonight: PC 1 mines nothing under the Devnet 3 off order", - "at": "2026-10-08T20:10:24.556Z", + "reason": "the sustained thermal and power soak has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order", + "at": "2026-10-08T21:00:32.846Z", "method": "static", "requirement_id": "GPU-07", "decision": "NOT RUN", @@ -1330,30 +1329,30 @@ "manual_page": 24, "owner_lane": "hash lane (a690540514aa453d7)", "run_status": "NOT RUN", - "evidence_path": "docs/analysis/review-2026-10-08-b/f10/emu-test.log; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all-nowin.json", - "run_id": "p01-20261008-01", - "updated": "2026-10-08T20:10:24.686Z", + "evidence_path": "docs/analysis/review-2026-10-08-b/f10/emu-test.log; build-1:/srv/artefacts/tas/same-work-20261008-01/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D1.txt", + "run_id": "same-work-20261008-01", + "updated": "2026-10-08T21:36:08.400Z", "evidence_record": { "requirement_id": "POW-01", "decision": "NOT RUN", "method": "GPU", "cell": "harness:p01-vectors", - "manifest_sha": "417c4a57", - "run_id": "p01-20261008-01", - "evidence": "build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all-nowin.json", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-01", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-01/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D1.txt", "in_progress": false, "coverage": "the million-vector campaign per backend per pack, bit-for-bit; PASS only when every supported backend reads a million vectors with zero disagreement; the malformed-input half is harness:parser-malformed", "release_identity": { - "commit": "417c4a57 (the node pin at the kit's cut); the kit packs-class-v6-20261008T162324Z.zip 098e64c3…; the worker igneum-worker-cuda 9bfcf728", + "commit": "c30ab32c; the CPU reference class-v6 1a938abe4; the CUDA reader the kit's gen 6 worker 804a6f7f", "lockfile": "", - "binary": "bin/linux/igneum-worker-cuda (the kit's)", - "network_object": "the class v5 freeze 1c420786, pack hl-v5-win e3da3669 id 0x6554474f410f36f3", - "activation": "igneum-devnet-4 object be5f4068", + "binary": "igneum-pow sha256 0d3f3fca...; igneum-worker-cuda sha256 804a6f7f...", + "network_object": "the frozen class v6 object: pack hl-v6-all (tgz sha256 9131431015e102f4..., re-exported byte for byte from class-v6 1a938abe4 on build-4 at 21:44 UK, every file's sha256 equal), id 0x4de7b836cc40a4ea, epoch seed edc4fa84... (the genesis seeds) over the node1 state stream", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", "profile_hashes": "" }, - "claim_impact": "POW-01's CUDA half on the class v5 object and all three class v6 D1 candidates: a million nonces agree bit-for-bit with the CPU reference on three CUDA generations each; OpenCL and Metal remain", + "claim_impact": "POW-01's CUDA half across a dataset-day switch on the frozen object: CUDA against the CPU reference bit for bit on three ranges with the day switch at nonce 1572864. NOT same-work evidence: the node engine refuses this seed/stream pair (IgneumEngine::epoch_for's class v5 check wants the stream's block af89be5d... to equal the epoch seed edc4fa84...), so the node and pool readers cannot read it; the coordinator's ruling 22:0x UK keeps it as the CUDA and CPU-only row", "reviewer": "", - "at": "2026-10-08T20:10:24.686Z" + "at": "2026-10-08T21:36:08.400Z" }, "in_progress_since": "2026-10-08T20:07:26.255Z", "approvals": { @@ -1393,22 +1392,22 @@ "decision": "NOT RUN", "method": "GPU", "cell": "harness:p01-vectors", - "manifest_sha": "417c4a57", - "run_id": "p01-20261008-01", - "evidence": "build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v5-win.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-foldrw.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-5090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-4090-hl-v6-all-nowin.json; build-1:/srv/artefacts/p01/p01-20261008-01/cuda-3090-hl-v6-all-nowin.json", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-01", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-01/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D1.txt", "in_progress": false, "coverage": "the million-vector campaign per backend per pack, bit-for-bit; PASS only when every supported backend reads a million vectors with zero disagreement; the malformed-input half is harness:parser-malformed", "release_identity": { - "commit": "417c4a57 (the node pin at the kit's cut); the kit packs-class-v6-20261008T162324Z.zip 098e64c3…; the worker igneum-worker-cuda 9bfcf728", + "commit": "c30ab32c; the CPU reference class-v6 1a938abe4; the CUDA reader the kit's gen 6 worker 804a6f7f", "lockfile": "", - "binary": "bin/linux/igneum-worker-cuda (the kit's)", - "network_object": "the class v5 freeze 1c420786, pack hl-v5-win e3da3669 id 0x6554474f410f36f3", - "activation": "igneum-devnet-4 object be5f4068", + "binary": "igneum-pow sha256 0d3f3fca...; igneum-worker-cuda sha256 804a6f7f...", + "network_object": "the frozen class v6 object: pack hl-v6-all (tgz sha256 9131431015e102f4..., re-exported byte for byte from class-v6 1a938abe4 on build-4 at 21:44 UK, every file's sha256 equal), id 0x4de7b836cc40a4ea, epoch seed edc4fa84... (the genesis seeds) over the node1 state stream", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", "profile_hashes": "" }, - "claim_impact": "POW-01's CUDA half on the class v5 object and all three class v6 D1 candidates: a million nonces agree bit-for-bit with the CPU reference on three CUDA generations each; OpenCL and Metal remain", + "claim_impact": "POW-01's CUDA half across a dataset-day switch on the frozen object: CUDA against the CPU reference bit for bit on three ranges with the day switch at nonce 1572864. NOT same-work evidence: the node engine refuses this seed/stream pair (IgneumEngine::epoch_for's class v5 check wants the stream's block af89be5d... to equal the epoch seed edc4fa84...), so the node and pool readers cannot read it; the coordinator's ruling 22:0x UK keeps it as the CUDA and CPU-only row", "reviewer": "", - "at": "2026-10-08T20:10:24.686Z" + "at": "2026-10-08T21:36:08.400Z" } } }, @@ -1439,9 +1438,9 @@ "manual_page": 24, "owner_lane": "hash lane (a690540514aa453d7)", "run_status": "NOT RUN", - "evidence_path": "docs/analysis/review-2026-10-08-b/f10/packfile-test.log;docs/analysis/review-2026-10-08-b/f10/geometry-check-mini.log; docs/analysis/class-v6/family-gate.md", + "evidence_path": "docs/analysis/review-2026-10-08-b/f10/packfile-test.log;docs/analysis/review-2026-10-08-b/f10/geometry-check-mini.log; docs/analysis/class-v6/family-gate.md; docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md; docs/analysis/class-v6/rows/pairing-20261008.md", "run_id": "family-gate-20261008c", - "updated": "2026-10-08T21:33:21.177Z", + "updated": "2026-10-08T21:39:56.770Z", "evidence_record": { "requirement_id": "POW-02", "decision": "NOT RUN", @@ -1462,7 +1461,7 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" }, "in_progress_since": "2026-10-08T20:07:26.255Z", "approvals": { @@ -1516,7 +1515,51 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" + }, + "census:class-v6": { + "requirement_id": "POW-02", + "decision": "PASS", + "method": "native", + "cell": "census:class-v6", + "manifest_sha": "1a938abe4", + "run_id": "census-v6-chainseed-20261008-2230", + "evidence": "docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md", + "in_progress": false, + "coverage": "partial: the fold's index statistics and the grammar bounds on 256 seeds plus the F8 set; the malformed programs are owed to harness:parser-malformed", + "release_identity": { + "commit": "1a938abe4", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:33:35.822Z" + }, + "suite:pow": { + "requirement_id": "POW-02", + "decision": "PASS", + "method": "native", + "cell": "suite:pow", + "manifest_sha": "1a938abe4", + "run_id": "hash-lane-20261008-batch3", + "evidence": "docs/analysis/class-v6/rows/pairing-20261008.md", + "in_progress": false, + "coverage": "partial: program derivation, ds55 geometry, the v6 fold, the packs and the spec read-back tests; the independent re-implementation and the index-fold census are the hash lane's harnesses", + "release_identity": { + "commit": "1a938abe4", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:34:44.641Z" } } }, @@ -1547,9 +1590,9 @@ "manual_page": 24, "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "FAIL", - "evidence_path": "docs/analysis/class-v6/connected-state.md; docs/analysis/class-v6", + "evidence_path": "docs/analysis/class-v6/connected-state.md; docs/analysis/class-v6/multi-family-adversary.md", "run_id": "kills-20261008", - "updated": "2026-10-08T20:10:24.624Z", + "updated": "2026-10-08T21:00:32.906Z", "evidence_record": { "requirement_id": "POW-03", "decision": "FAIL", @@ -1557,7 +1600,7 @@ "cell": "experiment:connected-state", "manifest_sha": "7cfa422a", "run_id": "kills-20261008", - "evidence": "docs/analysis/class-v6", + "evidence": "docs/analysis/class-v6/connected-state.md", "in_progress": false, "coverage": "the experiment ran and its claim failed: live state does not make the work unavoidable for a chip; the master's register row 18 reads FAIL, published, never PASSED", "release_identity": { @@ -1570,7 +1613,7 @@ }, "claim_impact": "the claims the two experiments carried are withdrawn: live state as an ASIC barrier (connected state), a cheaper mixed-FP32 lane", "reviewer": "", - "at": "2026-10-08T20:10:24.624Z" + "at": "2026-10-08T21:00:32.906Z" }, "approvals": { "scope_approved": null, @@ -1608,7 +1651,7 @@ "cell": "experiment:connected-state", "manifest_sha": "7cfa422a", "run_id": "kills-20261008", - "evidence": "docs/analysis/class-v6", + "evidence": "docs/analysis/class-v6/connected-state.md", "in_progress": false, "coverage": "the experiment ran and its claim failed: live state does not make the work unavoidable for a chip; the master's register row 18 reads FAIL, published, never PASSED", "release_identity": { @@ -1621,7 +1664,29 @@ }, "claim_impact": "the claims the two experiments carried are withdrawn: live state as an ASIC barrier (connected state), a cheaper mixed-FP32 lane", "reviewer": "", - "at": "2026-10-08T20:10:24.624Z" + "at": "2026-10-08T21:00:32.906Z" + }, + "adversary:mf-placed": { + "requirement_id": "POW-03", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "partial: the live state held in an SRAM macro per 8 lanes with a time-multiplexed single port and operand isolation, the complete-system cost in section 6; the liveness trace itself is the connected-state lane's tool", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -1652,27 +1717,30 @@ "manual_page": 25, "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", - "evidence_path": "docs/analysis/class-v6/connected-state.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08 18:3x UK", + "evidence_path": "docs/analysis/class-v6/connected-state.md; docs/analysis/class-v6/multi-family-adversary.md", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "what_was_run": "the same experiment, D2(a) closed", - "run_by": "adversary lane (a1a9876a88f5a72fc)", - "under_the_standard": "no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one", - "pass_or_fail_today": "not judged under the standard yet", - "method": "static", "requirement_id": "POW-04", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "partial: the 64-register window's cost on the macro core (sections 4 and 5, agreeing with the k lane's gated-flop row within 5 percent); the restructured candidate's GPU cost is the invention lane's", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -1703,6 +1771,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/connected-state.md", "in_progress": true + }, + "adversary:mf-placed": { + "requirement_id": "POW-04", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "partial: the 64-register window's cost on the macro core (sections 4 and 5, agreeing with the k lane's gated-flop row within 5 percent); the restructured candidate's GPU cost is the invention lane's", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -1897,9 +1987,9 @@ "manual_page": 26, "owner_lane": "hash lane (a690540514aa453d7)", "run_status": "FAIL", - "evidence_path": "docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md; docs/analysis/class-v6", + "evidence_path": "docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md; docs/analysis/class-v6/mixed-fp32.md; docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md", "run_id": "kills-20261008", - "updated": "2026-10-08T20:10:24.624Z", + "updated": "2026-10-08T21:00:32.906Z", "evidence_record": { "requirement_id": "POW-07", "decision": "FAIL", @@ -1907,7 +1997,7 @@ "cell": "experiment:mixed-fp32", "manifest_sha": "7cfa422a", "run_id": "kills-20261008", - "evidence": "docs/analysis/class-v6", + "evidence": "docs/analysis/class-v6/mixed-fp32.md; docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md", "in_progress": false, "coverage": "the branch ran and its claim failed: the FP32 branch costs the card more energy and widens the chip edge; the master's register row 12 reads FAIL, published; the branch is excluded and unreachable on master (the grep evidence stays)", "release_identity": { @@ -1920,7 +2010,7 @@ }, "claim_impact": "the claims the two experiments carried are withdrawn: live state as an ASIC barrier (connected state), a cheaper mixed-FP32 lane", "reviewer": "", - "at": "2026-10-08T20:10:24.624Z" + "at": "2026-10-08T21:00:32.906Z" }, "approvals": { "scope_approved": null, @@ -1962,7 +2052,7 @@ "cell": "experiment:mixed-fp32", "manifest_sha": "7cfa422a", "run_id": "kills-20261008", - "evidence": "docs/analysis/class-v6", + "evidence": "docs/analysis/class-v6/mixed-fp32.md; docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md", "in_progress": false, "coverage": "the branch ran and its claim failed: the FP32 branch costs the card more energy and widens the chip edge; the master's register row 12 reads FAIL, published; the branch is excluded and unreachable on master (the grep evidence stays)", "release_identity": { @@ -1975,7 +2065,7 @@ }, "claim_impact": "the claims the two experiments carried are withdrawn: live state as an ASIC barrier (connected state), a cheaper mixed-FP32 lane", "reviewer": "", - "at": "2026-10-08T20:10:24.624Z" + "at": "2026-10-08T21:00:32.906Z" } } }, @@ -2005,34 +2095,32 @@ "owner": "Cryptography + GPU lead", "manual_page": 26, "owner_lane": "hash lane (a690540514aa453d7)", - "run_status": "NOT RUN", - "evidence_path": "docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md", - "run_id": "hash-lane-20261008-batch2", - "updated": "2026-10-08T19:59:34.316Z", + "run_status": "PASS", + "evidence_path": "docs/analysis/class-v6/rows/pairing-20261008.md", + "run_id": "hash-lane-20261008-batch3", + "updated": "2026-10-08T21:34:44.641Z", "evidence_record": { - "cell": "suite:pow", - "manifest_sha": "b24dfc162", - "coverage": { - "POW-02": "partial: program derivation, ds55 geometry, the v6 fold, the packs and the spec read-back tests; the independent re-implementation and the index-fold census are the hash lane's harnesses", - "POW-08": "partial: the freeze list and the generator version pin; the public-claim scrub is the site gate's", - "POW-07": "the mixed FP32 branch is excluded and unreachable: no class flag reaches an FP op in igneum-pow on master (the mixedfp lane's branch is not on master); evidence the grep of the emitters on master, recorded by the hash lane" - }, - "at": "2026-10-08T19:59:34.316Z", - "method": "native", "requirement_id": "POW-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "suite:pow", + "manifest_sha": "1a938abe4", + "run_id": "hash-lane-20261008-batch3", + "evidence": "docs/analysis/class-v6/rows/pairing-20261008.md", + "in_progress": false, + "coverage": "partial: the freeze list and the generator version pin; the public-claim scrub is the site gate's", "release_identity": { - "commit": "b24dfc162", + "commit": "1a938abe4", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:34:44.641Z" }, - "in_progress_since": "2026-10-08T19:59:34.316Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -2041,30 +2129,26 @@ }, "evidence_records": { "suite:pow": { - "cell": "suite:pow", - "manifest_sha": "b24dfc162", - "coverage": { - "POW-02": "partial: program derivation, ds55 geometry, the v6 fold, the packs and the spec read-back tests; the independent re-implementation and the index-fold census are the hash lane's harnesses", - "POW-08": "partial: the freeze list and the generator version pin; the public-claim scrub is the site gate's", - "POW-07": "the mixed FP32 branch is excluded and unreachable: no class flag reaches an FP op in igneum-pow on master (the mixedfp lane's branch is not on master); evidence the grep of the emitters on master, recorded by the hash lane" - }, - "at": "2026-10-08T19:59:34.316Z", - "method": "native", "requirement_id": "POW-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "suite:pow", + "manifest_sha": "1a938abe4", + "run_id": "hash-lane-20261008-batch3", + "evidence": "docs/analysis/class-v6/rows/pairing-20261008.md", + "in_progress": false, + "coverage": "partial: the freeze list and the generator version pin; the public-claim scrub is the site gate's", "release_identity": { - "commit": "b24dfc162", + "commit": "1a938abe4", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "hash-lane-20261008-batch2", - "evidence": "docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:34:44.641Z" } } } @@ -2114,26 +2198,29 @@ "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08 18:3x UK", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "what_was_run": "the 18-family programmable core placed and routed (9.36 pJ per lane-op, k 0.64 same-node)", - "run_by": "adversary lane (a1a9876a88f5a72fc)", - "under_the_standard": "no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one", - "pass_or_fail_today": "not judged under the standard yet", - "method": "static", "requirement_id": "ADV-01", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the mf core (18 families, SRAM window and imem macros, operand isolation, 5-phase port) placed and routed on ASAP7 with SPEF and a gate-level VCD; k per family and per draw; outputs checked against the RTL simulation's checksums per tag, not yet against the POW vectors (owed)", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2164,6 +2251,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md", "in_progress": true + }, + "adversary:mf-placed": { + "requirement_id": "ADV-01", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the mf core (18 families, SRAM window and imem macros, operand isolation, 5-phase port) placed and routed on ASAP7 with SPEF and a gate-level VCD; k per family and per draw; outputs checked against the RTL simulation's checksums per tag, not yet against the POW vectors (owed)", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -2196,26 +2305,29 @@ "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08 18:3x UK", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "what_was_run": "D2(b): the stored-half hybrid, memory sharing, recomputation priced (the placed hybrid 1.93x same-node at the mean hit)", - "run_by": "adversary lane (a1a9876a88f5a72fc)", - "under_the_standard": "no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one", - "pass_or_fail_today": "not judged under the standard yet", - "method": "static", "requirement_id": "ADV-02", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:d2b", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "memory sharing, partial stores at the measured window-layer hit rates (and hit 0.50 with layer 8 off), recomputation and the set-up amortisation on the complete board (section 13); the formal memory model's terms (section 16)", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2246,6 +2358,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md", "in_progress": true + }, + "adversary:d2b": { + "requirement_id": "ADV-02", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:d2b", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "memory sharing, partial stores at the measured window-layer hit rates (and hit 0.50 with layer 8 off), recomputation and the set-up amortisation on the complete board (section 13); the formal memory model's terms (section 16)", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -2278,26 +2412,29 @@ "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08 18:3x UK", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "what_was_run": "data-local execution moves nothing (2,112 bits of live state against an 80-bit read)", - "run_by": "adversary lane (a1a9876a88f5a72fc)", - "under_the_standard": "no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one", - "pass_or_fail_today": "not judged under the standard yet", - "method": "static", "requirement_id": "ADV-03", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the data-local, hybrid and companion-host rows of multi-family-adversary.md sections 11, 13 and 14 (bit counts closed-form; the hop and wire energies claimed)", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2328,6 +2465,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md", "in_progress": true + }, + "adversary:mf-placed": { + "requirement_id": "ADV-03", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the data-local, hybrid and companion-host rows of multi-family-adversary.md sections 11, 13 and 14 (bit counts closed-form; the hop and wire energies claimed)", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -2360,24 +2519,29 @@ "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "reason": "selective participation needs the economic model F7 and a live chain window", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "ADV-04", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:d2b", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "selective participation over 2,000 era draws under the layer 1 band with two reserve families live per epoch, the specialist's revenue against its ratio gain (section 13); downtime and re-entry priced as the DAA window's lag, not simulated against the difficulty rule itself (owed)", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2408,6 +2572,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md", "in_progress": true + }, + "adversary:d2b": { + "requirement_id": "ADV-04", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:d2b", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "selective participation over 2,000 era draws under the layer 1 band with two reserve families live per epoch, the specialist's revenue against its ratio gain (section 13); downtime and re-entry priced as the DAA window's lag, not simulated against the difficulty rule itself (owed)", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -2439,27 +2625,30 @@ "manual_page": 28, "owner_lane": "k lane (a3c9601a6d4686fe1)", "run_status": "NOT RUN", - "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md; docs/analysis/class-v6/floor/shadow-k.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08 18:3x UK", + "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md; docs/analysis/class-v6/floor/shadow-k.md; docs/analysis/class-v6/floor/shadow-k.md", + "run_id": "floor-k-20261008-rows-repeat", + "updated": "2026-10-08T21:09:38.300Z", "evidence_record": { - "what_was_run": "the complete GDDR7 machine 1.5x same-node, 1.8x a node ahead at the placed energy; the honest same-node bracket 1.5x to 2.1x: FAIL against P04 at R_E 1.5, served as such", - "run_by": "k lane (a3c9601a6d4686fe1)", - "under_the_standard": "no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one", - "pass_or_fail_today": "FAIL against P04 at R_E 1.5", - "method": "static", "requirement_id": "ADV-05", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "86e5b0fb", + "run_id": "floor-k-20261008-rows-repeat", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "in_progress": true, + "coverage": "partial: the SRAM macros, ports, wiring, clocking and the complete-board terms are modelled in sections 2.3, 5 and 6 with the unmodelled items carried as uncertainty; the calibration against an existing hardware block is the k lane's bare-lane row beside it, owed as a named comparison", "release_identity": { - "commit": "", + "commit": "86e5b0fb", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:09:38.300Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2490,6 +2679,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md; docs/analysis/class-v6/floor/shadow-k.md", "in_progress": true + }, + "adversary:mf-placed": { + "requirement_id": "ADV-05", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "86e5b0fb", + "run_id": "floor-k-20261008-rows-repeat", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "in_progress": true, + "coverage": "partial: the SRAM macros, ports, wiring, clocking and the complete-board terms are modelled in sections 2.3, 5 and 6 with the unmodelled items carried as uncertainty; the calibration against an existing hardware block is the k lane's bare-lane row beside it, owed as a named comparison", + "release_identity": { + "commit": "86e5b0fb", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:09:38.300Z" } } }, @@ -2522,24 +2733,29 @@ "owner_lane": "k lane (a3c9601a6d4686fe1)", "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/floor/shadow-k.md", - "run_id": "team-2026-10-08", - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "floor-k-20261008-rows-repeat", + "updated": "2026-10-08T21:09:38.300Z", "evidence_record": { - "reason": "process-advantage separation is the adversary lanes' chip study", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "ADV-06", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "review:k-lane-shadow-k", + "manifest_sha": "86e5b0fb", + "run_id": "floor-k-20261008-rows-repeat", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "in_progress": false, + "coverage": "partial: the placed gated cores and the adversary's forms are modelled in shadow-k.md; the independent review remains", "release_identity": { - "commit": "", + "commit": "86e5b0fb", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:09:38.300Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2570,6 +2786,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/floor/shadow-k.md", "in_progress": true + }, + "review:k-lane-shadow-k": { + "requirement_id": "ADV-06", + "decision": "NOT RUN", + "method": "model", + "cell": "review:k-lane-shadow-k", + "manifest_sha": "86e5b0fb", + "run_id": "floor-k-20261008-rows-repeat", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "in_progress": false, + "coverage": "partial: the placed gated cores and the adversary's forms are modelled in shadow-k.md; the independent review remains", + "release_identity": { + "commit": "86e5b0fb", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:09:38.300Z" } } }, @@ -2601,25 +2839,30 @@ "manual_page": 29, "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", - "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md section 14", - "run_id": "team-2026-10-08", - "updated": "2026-10-08T20:10:24.556Z", + "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md section 14; docs/analysis/class-v6/multi-family-adversary.md", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "evidence_record": { - "reason": "lifetime rows are the adversary lanes' models", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "ADV-07", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the lifetime table and the six-row transition matrix (sections 7 and 14) on the placed rows; the 32-lane genesis comparator placed on adv-g", "release_identity": { - "commit": "", + "commit": "3a8874fef", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -2650,6 +2893,28 @@ "run_id": "team-2026-10-08", "evidence": "docs/analysis/class-v6/multi-family-adversary.md section 14", "in_progress": true + }, + "adversary:mf-placed": { + "requirement_id": "ADV-07", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the lifetime table and the six-row transition matrix (sections 7 and 14) on the placed rows; the 32-lane genesis comparator placed on adv-g", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" } } }, @@ -2681,15 +2946,62 @@ "manual_page": 29, "owner_lane": "adversary lane (a1a9876a88f5a72fc)", "run_status": "NOT RUN", - "evidence_path": "", - "run_id": "", - "updated": "2026-10-08 18:3x UK", + "evidence_path": "docs/analysis/class-v6/multi-family-adversary.md", + "run_id": "adversary-20261008-placed-8lane", + "updated": "2026-10-08T20:41:20.327Z", "approvals": { "scope_approved": null, "implementation_complete": null, "evidence_reproduced": null, "claim_authorised": null - } + }, + "evidence_records": { + "adversary:mf-placed": { + "requirement_id": "ADV-08", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the best-cost envelope on the complete machine (section 6) and the SRAM-die ticket reconciliation with lane B (section 15); the unaffiliated second reviewer is not this lane's", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" + } + }, + "evidence_record": { + "requirement_id": "ADV-08", + "decision": "NOT RUN", + "method": "model", + "cell": "adversary:mf-placed", + "manifest_sha": "3a8874fef", + "run_id": "adversary-20261008-placed-8lane", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "in_progress": true, + "coverage": "the best-cost envelope on the complete machine (section 6) and the SRAM-die ticket reconciliation with lane B (section 15); the unaffiliated second reviewer is not this lane's", + "release_identity": { + "commit": "3a8874fef", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:41:20.327Z" + }, + "in_progress_since": "2026-10-08T20:41:20.327Z" } ] }, @@ -3245,7 +3557,7 @@ "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/family-gate.md", "run_id": "family-gate-20261008c", - "updated": "2026-10-08T21:33:21.177Z", + "updated": "2026-10-08T21:39:56.770Z", "evidence_record": { "requirement_id": "ROT-07", "decision": "NOT RUN", @@ -3266,7 +3578,7 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" }, "in_progress_since": "2026-10-08 18:3x UK", "approvals": { @@ -3318,7 +3630,7 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" } } }, @@ -3351,7 +3663,7 @@ "run_status": "NOT RUN", "evidence_path": "docs/analysis/class-v6/family-gate.md", "run_id": "family-gate-20261008c", - "updated": "2026-10-08T21:33:21.177Z", + "updated": "2026-10-08T21:39:56.770Z", "evidence_record": { "requirement_id": "ROT-08", "decision": "NOT RUN", @@ -3372,7 +3684,7 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" }, "approvals": { "scope_approved": null, @@ -3381,26 +3693,6 @@ "claim_authorised": null }, "evidence_records": { - "record": { - "reason": "the no-new-rules counterfactual is a research harness", - "at": "2026-10-08T19:22:31.798Z", - "method": "static", - "requirement_id": "ROT-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", - "release_identity": { - "commit": "", - "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", - "profile_hashes": "" - }, - "run_id": "", - "evidence": "", - "in_progress": false - }, "harness:family-gate": { "requirement_id": "ROT-08", "decision": "NOT RUN", @@ -3421,7 +3713,7 @@ }, "claim_impact": "", "reviewer": "", - "at": "2026-10-08T21:33:21.177Z" + "at": "2026-10-08T21:39:56.770Z" } } } @@ -4891,39 +5183,33 @@ "owner": "Execution lead + independent implementer", "manual_page": 38, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", - "run_status": "NOT RUN", - "evidence_path": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "run_id": "enforced-proving-20261008-01", - "updated": "2026-10-08T19:03:30.171Z", + "run_status": "PASS", + "evidence_path": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "EVM-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "dependency": "the first pin into elf/prior/ (the node lane, key-succession-pin, tonight by 21:00) and the devnet-4 succession height (main, by 22:00 under the floor rule)", - "in_progress_since": "2026-10-08T19:03:30.171Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -4932,34 +5218,26 @@ }, "evidence_records": { "harness:proving-enforcement": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "EVM-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "enforced-proving-20261008-01", - "evidence": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } } @@ -5010,32 +5288,30 @@ "manual_page": 39, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log", - "run_id": "201-7cfa422a-aa0e0f45", - "updated": "2026-10-08T19:32:50.856Z", + "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log; docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "suite:exec", - "manifest_sha": "7cfa422a", - "coverage": { - "ZKP-01": "partial: a real proof verifies, a wrong statement and garbage are refused (nativeverify)", - "ZKP-03": "partial: a snapshot under another digest refused, the epoch streams bound to the digest", - "OPS-04": "partial: snapshot install, replay and genesis recapture after a crash", - "EVM-02": "partial: the replay tests on the day stream; the signature and chain-id binding vectors are an EVM harness still to map" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "ZKP-01", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", "release_identity": { - "commit": "7cfa422a", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "in_progress_since": "2026-10-08T19:32:50.856Z", "approvals": { @@ -5071,6 +5347,28 @@ "run_id": "201-7cfa422a-aa0e0f45", "evidence": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log", "in_progress": true + }, + "harness:proving-enforcement": { + "requirement_id": "ZKP-01", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", + "release_identity": { + "commit": "3f672661", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } }, @@ -5102,39 +5400,33 @@ "owner": "Proving + protocol leads; independent cryptography review", "manual_page": 39, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", - "run_status": "NOT RUN", - "evidence_path": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "run_id": "enforced-proving-20261008-01", - "updated": "2026-10-08T19:03:30.171Z", + "run_status": "PASS", + "evidence_path": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-02", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "dependency": "the mixed-pair crossing needs the node lane's first pin into elf/prior/ (key-succession-pin, tonight by 21:00) and the next-pair proof (build-2:/home/build/enforced-fixtures/next-pair-block-56-shard-0-compressed.bin)", - "in_progress_since": "2026-10-08T19:03:30.171Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -5143,34 +5435,26 @@ }, "evidence_records": { "harness:proving-enforcement": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-02", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "enforced-proving-20261008-01", - "evidence": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } }, @@ -5203,32 +5487,30 @@ "manual_page": 39, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log", - "run_id": "201-7cfa422a-aa0e0f45", - "updated": "2026-10-08T19:32:50.856Z", + "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log; docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "suite:exec", - "manifest_sha": "7cfa422a", - "coverage": { - "ZKP-01": "partial: a real proof verifies, a wrong statement and garbage are refused (nativeverify)", - "ZKP-03": "partial: a snapshot under another digest refused, the epoch streams bound to the digest", - "OPS-04": "partial: snapshot install, replay and genesis recapture after a crash", - "EVM-02": "partial: the replay tests on the day stream; the signature and chain-id binding vectors are an EVM harness still to map" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "ZKP-03", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", "release_identity": { - "commit": "7cfa422a", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "in_progress_since": "2026-10-08T19:32:50.856Z", "approvals": { @@ -5264,6 +5546,28 @@ "run_id": "201-7cfa422a-aa0e0f45", "evidence": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-exec.log", "in_progress": true + }, + "harness:proving-enforcement": { + "requirement_id": "ZKP-03", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", + "release_identity": { + "commit": "3f672661", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } }, @@ -5295,39 +5599,33 @@ "owner": "Proving + protocol leads; independent cryptography review", "manual_page": 40, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", - "run_status": "NOT RUN", - "evidence_path": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "run_id": "enforced-proving-20261008-01", - "updated": "2026-10-08T19:03:30.171Z", + "run_status": "PASS", + "evidence_path": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-04", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "dependency": "the proof side of the derivation (P22 stages 1 to 3) changes both guests' public values and so both program ids, so it ships only through a key succession (docs/design/key-succession.md, key-succession-node 291ee6ae); stage 1 (the inputs commitment carried by shard 0 and the aggregator, vetoed natively) is on branch p22-stage-1 under test since 18:46 UK; the clocks (stage 1 09:00, stage 2 14:00, stage 3's design 18:00 UK on 9 October 2026) stand because the succession's first height is asked of main by 22:00 under the floor rule; without a named height the stages are built and tested on their branch and wait for the succession that carries them", - "in_progress_since": "2026-10-08T19:03:30.171Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -5336,34 +5634,26 @@ }, "evidence_records": { "harness:proving-enforcement": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-04", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "enforced-proving-20261008-01", - "evidence": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } }, @@ -5395,38 +5685,32 @@ "owner": "Proving + protocol leads; independent cryptography review", "manual_page": 40, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", - "run_status": "NOT RUN", - "evidence_path": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "run_id": "enforced-proving-20261008-01", - "updated": "2026-10-08T19:03:30.171Z", + "run_status": "PASS", + "evidence_path": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-05", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, - "in_progress_since": "2026-10-08T19:03:30.171Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -5435,34 +5719,26 @@ }, "evidence_records": { "harness:proving-enforcement": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-05", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "enforced-proving-20261008-01", - "evidence": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } }, @@ -5622,39 +5898,33 @@ "owner": "Proving + protocol leads; independent cryptography review", "manual_page": 41, "owner_lane": "enforced-proving lane (a6e8f84588b809d62)", - "run_status": "NOT RUN", - "evidence_path": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "run_id": "enforced-proving-20261008-01", - "updated": "2026-10-08T19:03:30.171Z", + "run_status": "PASS", + "evidence_path": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "run_id": "enforced-proving-20261008-02", + "updated": "2026-10-08T21:37:02.905Z", "evidence_record": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" }, "dependency": "the proof side of the derivation (P22 stages 1 to 3) changes both guests' public values and so both program ids, so it ships only through a key succession (docs/design/key-succession.md, key-succession-node 291ee6ae); stage 1 (the inputs commitment carried by shard 0 and the aggregator, vetoed natively) is on branch p22-stage-1 under test since 18:46 UK; the clocks (stage 1 09:00, stage 2 14:00, stage 3's design 18:00 UK on 9 October 2026) stand because the succession's first height is asked of main by 22:00 under the floor rule; without a named height the stages are built and tested on their branch and wait for the succession that carries them", - "in_progress_since": "2026-10-08T19:03:30.171Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -5663,34 +5933,26 @@ }, "evidence_records": { "harness:proving-enforcement": { - "cell": "harness:proving-enforcement", - "manifest_sha": "417c4a57", - "coverage": { - "ZKP-01": "partial: the seven refusals as named tests (no proof never inserted; a wrong proof and another program id invalidate the block; the honest record paid once) and the fast-time crossing with a modified producer; the genuine-proof positive control through ordinary network paths is the testnet's live read, not run here", - "ZKP-02": "partial: the pinned-id refusal on a real proof, the daemon's start refusal, key succession (the epochs, the accepted ids, a verdict counting only where its pair is accepted, the seven refusals on both sides of the height, the start refusal under a succession, the real-proof refusal of a pair the epoch does not accept) and the fast-time crossing of a scheduled succession with a real proof under each pair; the downgrade through an old node path is not run", - "ZKP-03": "partial: the chain binding (a record signed for another network), the replay, a wrong block, a wrong shard, a stale record outside the window; the fork and replayed-sync steps are not run", - "ZKP-04": "partial: an altered payout address (after signing and re-signed), a statement over altered rewards or payouts vetoed natively, the inputs commitment of P22 stage 1 (shard 0 and the aggregator carry the commitment the node recomputes) and the derivation commitment of stage 2 (the payouts derived in the guest from the carried records); the rewards' proved derivation is P22 stage 3, PENDING", - "ZKP-05": "partial: a duplicate of a paid record pays nothing and the honest record pays once; the race, reorder and crash-recover steps are not run", - "ZKP-08": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", - "EVM-08": "partial: the controlled verifier upgrade as a key succession (both pairs embedded, the window, the start refusal) and its fast-time crossing; the mixed-client crossing on the live network and the failed-distribution step are not run" - }, - "at": "2026-10-08T19:03:30.171Z", - "method": "SP1", "requirement_id": "ZKP-08", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "native", + "cell": "harness:proving-enforcement", + "manifest_sha": "3f672661", + "run_id": "enforced-proving-20261008-02", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json", + "in_progress": false, + "coverage": "partial: the body rule and the payment rule read one floor, a producer with its body rule off still pays nothing on honest nodes (the fast-time crossing); the replacement-prover and authority steps are not run; the proof side of the derivation is P22 stage 3, PENDING", "release_identity": { - "commit": "417c4a57", + "commit": "3f672661", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "enforced-proving-20261008-01", - "evidence": "build-2:/home/build/enforced-fixtures/floor-240-expect-refuse.json", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:37:02.905Z" } } } @@ -8730,29 +8992,30 @@ "manual_page": 54, "owner_lane": "shipper (ae892a8b0f78fe31c)", "run_status": "NOT RUN", - "evidence_path": "site/release-manifest.json at the landing sha", - "run_id": "site-manifest-20261008-01", - "updated": "2026-10-08T20:07:45.894Z", + "evidence_path": "site/release-manifest.json at the landing sha; docs/plans/evidence/UX-01-20261008.md", + "run_id": "ux-01-20261008-win-2.0.0", + "updated": "2026-10-08T20:42:25.701Z", "evidence_record": { - "cell": "site:manifest", - "manifest_sha": "3f1a3f332", - "coverage": { - "OPS-03": "partial: the manifest's versions and network blocks regenerate from their sources; the separation itself is the node suites' (suite:exec, suite:p2p-flows)" - }, - "at": "2026-10-08T20:07:45.894Z", - "method": "static", "requirement_id": "OPS-03", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "partial: the update path's read-back and the signed manifest's verify on the PC (a tampered or rolled-back payload is refused by the engine's manifest check); authority separation is the shipper's review", "release_identity": { - "commit": "3f1a3f332", + "commit": "aa354ed5", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" }, "approvals": { "scope_approved": null, @@ -8784,8 +9047,31 @@ "run_id": "site-manifest-20261008-01", "evidence": "site/release-manifest.json at the landing sha", "in_progress": false + }, + "pc:install-update": { + "requirement_id": "OPS-03", + "decision": "NOT RUN", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "partial: the update path's read-back and the signed manifest's verify on the PC (a tampered or rolled-back payload is refused by the engine's manifest check); authority separation is the shipper's review", + "release_identity": { + "commit": "aa354ed5", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" } - } + }, + "in_progress_since": "2026-10-08T20:42:25.701Z" }, { "id": "OPS-04", @@ -9242,15 +9528,62 @@ "manual_page": 57, "owner_lane": "update-return lane (a22d765a2e0355a9f)", "run_status": "NOT RUN", - "evidence_path": "", - "run_id": "", - "updated": "2026-10-08 18:3x UK", + "evidence_path": "docs/plans/evidence/UX-01-20261008.md", + "run_id": "ux-01-20261008-win-2.0.0", + "updated": "2026-10-08T20:42:25.701Z", "approvals": { "scope_approved": null, "implementation_complete": null, "evidence_reproduced": null, "claim_authorised": null - } + }, + "evidence_records": { + "pc:install-update": { + "requirement_id": "UX-01", + "decision": "NOT RUN", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "team-run evidence only (the two PCs taking the Windows entry through the app's own update path with no click and mining on every card); the P10 study is NOT RUN until unaffiliated participants are recruited", + "release_identity": { + "commit": "aa354ed5", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" + } + }, + "evidence_record": { + "requirement_id": "UX-01", + "decision": "NOT RUN", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "team-run evidence only (the two PCs taking the Windows entry through the app's own update path with no click and mining on every card); the P10 study is NOT RUN until unaffiliated participants are recruited", + "release_identity": { + "commit": "aa354ed5", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" + }, + "in_progress_since": "2026-10-08T20:42:25.701Z" }, { "id": "UX-02", @@ -9461,30 +9794,30 @@ "manual_page": 58, "owner_lane": "pool design seat (a3832b1c3b274b310)", "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log", - "run_id": "pool-review-b-20261008-01", - "updated": "2026-10-08T19:58:33.370Z", + "evidence_path": "docs/analysis/pool/pool-pair-2026-10-08.md", + "run_id": "pool-2.0-20261008-03", + "updated": "2026-10-08T20:48:42.741Z", "evidence_record": { - "cell": "suite:pool", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-05": "partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network", - "UX-04": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets)" - }, - "at": "2026-10-08T19:58:33.370Z", - "method": "native", "requirement_id": "UX-04", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "native", + "cell": "suite:pool", + "manifest_sha": "986252e73", + "run_id": "pool-2.0-20261008-03", + "evidence": "docs/analysis/pool/pool-pair-2026-10-08.md", + "in_progress": true, + "coverage": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets); the devnet-4 pair's class (8 October 2026 21:24 UK): state_provider::tests::an_unsynced_node_hands_the_pool_no_state_and_no_job (no job on a node whose igneum_getExecStatus reads synced false, blocked or re-executing; known-failed first against the 8ff7a0f4 provider; pool-synced-guard-202 f3e99e9c on release-2.0.2, 986252e7 on pool-2.0, 52 of 52 on build-6)", "release_identity": { - "commit": "7cfa422a", + "commit": "986252e73", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:48:42.741Z" }, "in_progress_since": "2026-10-08T19:58:33.370Z", "approvals": { @@ -9495,29 +9828,26 @@ }, "evidence_records": { "suite:pool": { - "cell": "suite:pool", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-05": "partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network", - "UX-04": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets)" - }, - "at": "2026-10-08T19:58:33.370Z", - "method": "native", "requirement_id": "UX-04", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "native", + "cell": "suite:pool", + "manifest_sha": "986252e73", + "run_id": "pool-2.0-20261008-03", + "evidence": "docs/analysis/pool/pool-pair-2026-10-08.md", + "in_progress": true, + "coverage": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets); the devnet-4 pair's class (8 October 2026 21:24 UK): state_provider::tests::an_unsynced_node_hands_the_pool_no_state_and_no_job (no job on a node whose igneum_getExecStatus reads synced false, blocked or re-executing; known-failed first against the 8ff7a0f4 provider; pool-synced-guard-202 f3e99e9c on release-2.0.2, 986252e7 on pool-2.0, 52 of 52 on build-6)", "release_identity": { - "commit": "7cfa422a", + "commit": "986252e73", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "pool-review-b-20261008-01", - "evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:48:42.741Z" } } }, @@ -9548,12 +9878,12 @@ "manual_page": 58, "owner_lane": "pool design seat (a3832b1c3b274b310)", "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log", - "run_id": "pool-review-b-20261008-01", - "updated": "2026-10-08T20:10:24.556Z", + "evidence_path": "docs/analysis/pool/pool-pair-2026-10-08.md", + "run_id": "pool-2.0-20261008-03", + "updated": "2026-10-08T20:48:42.741Z", "evidence_record": { "reason": "voting keys through pooling is the pool lane's row", - "at": "2026-10-08T20:10:24.556Z", + "at": "2026-10-08T20:48:42.741Z", "method": "static", "requirement_id": "UX-05", "decision": "NOT RUN", @@ -9577,29 +9907,26 @@ }, "evidence_records": { "suite:pool": { - "cell": "suite:pool", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-05": "partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network", - "UX-04": "partial: PPLNS distribution tests (fee first, never overpays, late joiner), the payout key file round trip, the signed transfer decode; the live payout path on the devnet-4 pair is the UX-04 batch's evidence; review B F12 and INT-03/INT-04 (8 October 2026): payout::intent_tests (a restart from the pre-broadcast snapshot, a lost send response, a crash on either side of the broadcast, a stuck transaction replaced under the same intent, a reorged receipt and a finality pause, a failed transaction, a ledger that cannot be written: never a duplicate or a lost obligation, finalised only under the chain's final lock) and state::ledger_tests (an unreadable ledger is refused or restored, never emptied); F13/INT-16: frame, admission and pool::share_tests (the frame bound while reading, the bounded outgoing queue, one membership per session, the nonce and in-flight bounds, the share and connection budgets)" - }, - "at": "2026-10-08T19:58:33.370Z", - "method": "native", "requirement_id": "UX-05", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "native", + "cell": "suite:pool", + "manifest_sha": "986252e73", + "run_id": "pool-2.0-20261008-03", + "evidence": "docs/analysis/pool/pool-pair-2026-10-08.md", + "in_progress": true, + "coverage": "partial: the vote-key commitment on the wire (verify::tests::a_share_under_another_key_is_refused_before_the_hash: known-pass the member's key, known-fail another key on the share and a job naming another key, refused with code vote_key before the hash), the open pool's sidechain::check_key (the claimed key, the header's key and the reveal are one key), the same-nonce-other-template wrong_hash test, the TLS binding test; the malicious-pool run and the leave-and-retain run on the devnet-4 pair are the UX-05 batch's other evidence; review B INT-15 (8 October 2026): server::authorise_tests::a_replayed_proof_of_possession_is_not_an_authorisation (a public PoP replayed into another session, payout, pool or chain, or under another key, refused; only the challenge-bound binding v2 admits on a public network) and the_binding_policy_follows_the_network", "release_identity": { - "commit": "7cfa422a", + "commit": "986252e73", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "pool-review-b-20261008-01", - "evidence": "build-1:/srv/artefacts/tas/pool-review-b-20261008-01/pool-suite-build-6.log", - "in_progress": true + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:48:42.741Z" } } }, @@ -9629,34 +9956,32 @@ "owner": "Desktop product + pool leads; independent usability study", "manual_page": 58, "owner_lane": "shipper (ae892a8b0f78fe31c)", - "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-miner.log", - "run_id": "201-7cfa422a-aa0e0f45", - "updated": "2026-10-08T19:32:50.856Z", + "run_status": "FAIL", + "evidence_path": "docs/release/evidence/ux-shipper-2026-10-08.md", + "run_id": "incident-u64-coinbase-2026-10-08", + "updated": "2026-10-08T21:21:37.484Z", "evidence_record": { - "cell": "suite:miner", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-06": "partial: the miner's own template selection tests", - "UX-04": "partial: payout label and share accounting tests; custody is the pool lane's row", - "POW-01": "partial: the pack re-check seam against the pack's 96 vectors (recheck_pack); the million-vector campaign is harness:p01-vectors" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "UX-06", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "FAIL", + "method": "team-reported", + "cell": "suite:miner", + "manifest_sha": "4cdcc488", + "run_id": "incident-u64-coinbase-2026-10-08", + "evidence": "docs/release/evidence/ux-shipper-2026-10-08.md", + "in_progress": false, + "coverage": "partial: the miner's own template selection tests", "release_identity": { - "commit": "7cfa422a", + "commit": "4cdcc488", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "no miner could take the work templates the network gave it above 18.4 IGN of merged subsidy", + "reviewer": "", + "at": "2026-10-08T21:21:37.484Z" }, - "in_progress_since": "2026-10-08T19:32:50.856Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -9665,30 +9990,26 @@ }, "evidence_records": { "suite:miner": { - "cell": "suite:miner", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-06": "partial: the miner's own template selection tests", - "UX-04": "partial: payout label and share accounting tests; custody is the pool lane's row", - "POW-01": "partial: the pack re-check seam against the pack's 96 vectors (recheck_pack); the million-vector campaign is harness:p01-vectors" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "UX-06", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "FAIL", + "method": "team-reported", + "cell": "suite:miner", + "manifest_sha": "4cdcc488", + "run_id": "incident-u64-coinbase-2026-10-08", + "evidence": "docs/release/evidence/ux-shipper-2026-10-08.md", + "in_progress": false, + "coverage": "partial: the miner's own template selection tests", "release_identity": { - "commit": "7cfa422a", + "commit": "4cdcc488", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" }, - "run_id": "201-7cfa422a-aa0e0f45", - "evidence": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/node-7cfa422a/box4-miner.log", - "in_progress": true + "claim_impact": "no miner could take the work templates the network gave it above 18.4 IGN of merged subsidy", + "reviewer": "", + "at": "2026-10-08T21:21:37.484Z" } } }, @@ -9719,32 +10040,30 @@ "manual_page": 59, "owner_lane": "shipper (ae892a8b0f78fe31c)", "run_status": "NOT RUN", - "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/miner-9c844503/box2-app.log", - "run_id": "201-7cfa422a-aa0e0f45", - "updated": "2026-10-08T19:32:50.856Z", + "evidence_path": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/miner-9c844503/box2-app.log; docs/plans/evidence/UX-01-20261008.md", + "run_id": "ux-01-20261008-win-2.0.0", + "updated": "2026-10-08T20:42:25.701Z", "evidence_record": { - "cell": "suite:app", - "manifest_sha": "7cfa422a", - "coverage": { - "UX-02": "partial: the engine state machine's pause, stop and knob tests; the operator study is UX-01's", - "UX-03": "partial: the card and earnings rendering tests; the net-earnings model against real bills is COM/ECO evidence", - "UX-07": "partial: the refused-update and manifest tests; the update-return lane's install classes are its own rows", - "VER-08": "partial: the app's own state-word tests; the wallet and light client rows are VER-01 to VER-03" - }, - "at": "2026-10-08T19:32:50.856Z", - "method": "native", "requirement_id": "UX-07", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "partial: the install classes (the payload's stop step, the detached installer under a job, the installer refusing a wrong-version name, a stale install flag) and the no-click resume; the recovery-instruction and canary rows are the shipper's", "release_identity": { - "commit": "7cfa422a", + "commit": "aa354ed5", "lockfile": "", "binary": "", "network_object": "", "activation": "", "profile_hashes": "" - } + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" }, "in_progress_since": "2026-10-08T19:32:50.856Z", "approvals": { @@ -9780,6 +10099,28 @@ "run_id": "201-7cfa422a-aa0e0f45", "evidence": "build-1:/srv/artefacts/tas/201-7cfa422a-aa0e0f45/miner-9c844503/box2-app.log", "in_progress": true + }, + "pc:install-update": { + "requirement_id": "UX-07", + "decision": "NOT RUN", + "method": "team-reported", + "cell": "pc:install-update", + "manifest_sha": "aa354ed5", + "run_id": "ux-01-20261008-win-2.0.0", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "in_progress": true, + "coverage": "partial: the install classes (the payload's stop step, the detached installer under a job, the installer refusing a wrong-version name, a stale install flag) and the no-click resume; the recovery-instruction and canary rows are the shipper's", + "release_identity": { + "commit": "aa354ed5", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T20:42:25.701Z" } } }, @@ -11145,6 +11486,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F01-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11201,6 +11562,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F01-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11257,6 +11638,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F01-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11313,6 +11714,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F01 (P0, the external review): the regression's harness is the owner lane's (proving lane, node lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F01-R04", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11369,6 +11790,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F02-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11425,6 +11866,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F02-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11481,6 +11942,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F02-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11512,29 +11993,60 @@ "finding_title": "The bundle contains a v6 candidate, not a demonstrated integrated v6 release", "finding_priority": "P0 - freeze/integration blocker", "owner_lane": "CI steward, hash lane (ProgramClass::V6 on freeze), pool lane", - "run_status": "NOT RUN", + "run_status": "PASS", "base_test_ids": [ "GOV-01", "GOV-03", "POW-01", "ROT-02" ], - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "f03-manifest-20261008-01", + "evidence_path": "build-1:/srv/artefacts/tas/f03-manifest-20261008-01/build-from-manifest-c30ab32c-build4.log; build-4:/srv/builds/igneum-wt-f03-201; tools/ci/build-from-manifest.sh; tools/ci/release-manifest-check.sh", + "updated": "2026-10-08T21:11:46.383Z", "evidence_record": { - "reason": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "R2-F03-R01", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "PASS", + "method": "static", + "cell": "harness:release-manifest", + "manifest_sha": "c30ab32c", + "run_id": "f03-manifest-20261008-01", + "evidence": "build-1:/srv/artefacts/tas/f03-manifest-20261008-01/build-from-manifest-c30ab32c-build4.log; build-4:/srv/builds/igneum-wt-f03-201; tools/ci/build-from-manifest.sh; tools/ci/release-manifest-check.sh", + "in_progress": false, + "coverage": "full for the components the tree builds (node, miner, pool, app, prove-host from one manifest, no unpublished vendor tree); the GPU workers are the kit's cross-build and read under the shipper's kit-isa line, not this cell", "release_identity": { - "commit": "", - "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", - "profile_hashes": "" + "commit": "c30ab32c", + "lockfile": "the release tree's Cargo.lock files at c30ab32c", + "binary": "cargo check only: no binary is claimed by this cell; the fleet binaries are the shipper's kit on aa0e0f45", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "none (a build fact)", + "profile_hashes": "release-manifest-check: every component's own pin equals packaging/release-manifest.json" + }, + "claim_impact": "F03's first rung: one manifest, one build, no unpublished vendor tree; the same-work rung (R02) and the transition rung (R03) stay NOT RUN until the readers run on the job context", + "reviewer": "", + "at": "2026-10-08T21:11:46.383Z" + }, + "evidence_records": { + "harness:release-manifest": { + "requirement_id": "R2-F03-R01", + "decision": "PASS", + "method": "static", + "cell": "harness:release-manifest", + "manifest_sha": "c30ab32c", + "run_id": "f03-manifest-20261008-01", + "evidence": "build-1:/srv/artefacts/tas/f03-manifest-20261008-01/build-from-manifest-c30ab32c-build4.log; build-4:/srv/builds/igneum-wt-f03-201; tools/ci/build-from-manifest.sh; tools/ci/release-manifest-check.sh", + "in_progress": false, + "coverage": "full for the components the tree builds (node, miner, pool, app, prove-host from one manifest, no unpublished vendor tree); the GPU workers are the kit's cross-build and read under the shipper's kit-isa line, not this cell", + "release_identity": { + "commit": "c30ab32c", + "lockfile": "the release tree's Cargo.lock files at c30ab32c", + "binary": "cargo check only: no binary is claimed by this cell; the fleet binaries are the shipper's kit on aa0e0f45", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "none (a build fact)", + "profile_hashes": "release-manifest-check: every component's own pin equals packaging/release-manifest.json" + }, + "claim_impact": "F03's first rung: one manifest, one build, no unpublished vendor tree; the same-work rung (R02) and the transition rung (R03) stay NOT RUN until the readers run on the job context", + "reviewer": "", + "at": "2026-10-08T21:11:46.383Z" } }, "approvals": { @@ -11575,24 +12087,78 @@ "POW-01", "ROT-02" ], - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "same-work-20261008-03", + "evidence_path": "docs/design/class-v5-stored-state.md; build-1:/srv/artefacts/packs/packs-class-v6-20261008T202808Z.zip; build-1:/srv/builds/_log/v5-class/kits-20261008T202808Z/emu-check.log; build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-03/state-epoch2.igsd1", + "updated": "2026-10-08T21:36:08.520Z", "evidence_record": { - "reason": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "R2-F03-R02", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "GPU", + "cell": "harness:same-work", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-03", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-03/state-epoch2.igsd1", + "in_progress": false, + "coverage": "partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context", "release_identity": { - "commit": "", + "commit": "c30ab32c (release-2.0.1; the class v5 freeze 1c420786, fingerprint cbc5bd0a); the CUDA reader the kit's gen 5 worker 9bfcf728", "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", + "binary": "igneum-pow sha256 7ba781db... (release-2.0.1 c30ab32c, built on build-4); igneum-worker-cuda gen 5 sha256 9bfcf728...", + "network_object": "igneum-devnet-4's class v5 object at epoch 2: id 0x81fbfa3aa413173f, epoch seed 3c3fab43... (the epoch-2 seed block, chain block 3423, common to every chain tonight: the split came after it), day 20734, era 0 seed 7c36b833... (class v5 reads no era; the id is the same under era zero), state stream state-epoch2.igsd1 (sha256 f36e6bba..., 21,132 bytes, 224 records, root 0xf798d1d8...) pulled at 22:18 UK from build-1's seed EVM RPC 27810", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", "profile_hashes": "" + }, + "claim_impact": "the same-work test's live-chain half (the coordinator's third row, 22:1x UK): the readers on the chain's own class v5 object at epoch 2 across the day switch 20734 to 20735; the node and pool readers run it on their release-line engines, the row those two can PASS without the class v6 branch", + "reviewer": "", + "at": "2026-10-08T21:36:08.520Z" + }, + "evidence_records": { + "kit:class-v6-fingerprints": { + "requirement_id": "R2-F03-R02", + "decision": "NOT RUN", + "method": "GPU", + "cell": "kit:class-v6-fingerprints", + "manifest_sha": "ef0f2ed8", + "run_id": "kit-class-v6-20261008-01", + "evidence": "docs/design/class-v5-stored-state.md; build-1:/srv/artefacts/packs/packs-class-v6-20261008T202808Z.zip; build-1:/srv/builds/_log/v5-class/kits-20261008T202808Z/emu-check.log", + "in_progress": true, + "coverage": "partial: the worker half (CPU reference, CUDA, Metal, OpenCL) on the same program packs; the node's and the pool's accepted work on the same job context are the CI steward's and the pool lane's cells; PASS only when every listed platform reads one fingerprint and the node and pool halves are green", + "release_identity": { + "commit": "ef0f2ed8", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "", + "reviewer": "", + "at": "2026-10-08T21:18:18.084Z" + }, + "harness:same-work": { + "requirement_id": "R2-F03-R02", + "decision": "NOT RUN", + "method": "GPU", + "cell": "harness:same-work", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-03", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-03/state-epoch2.igsd1", + "in_progress": false, + "coverage": "partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context", + "release_identity": { + "commit": "c30ab32c (release-2.0.1; the class v5 freeze 1c420786, fingerprint cbc5bd0a); the CUDA reader the kit's gen 5 worker 9bfcf728", + "lockfile": "", + "binary": "igneum-pow sha256 7ba781db... (release-2.0.1 c30ab32c, built on build-4); igneum-worker-cuda gen 5 sha256 9bfcf728...", + "network_object": "igneum-devnet-4's class v5 object at epoch 2: id 0x81fbfa3aa413173f, epoch seed 3c3fab43... (the epoch-2 seed block, chain block 3423, common to every chain tonight: the split came after it), day 20734, era 0 seed 7c36b833... (class v5 reads no era; the id is the same under era zero), state stream state-epoch2.igsd1 (sha256 f36e6bba..., 21,132 bytes, 224 records, root 0xf798d1d8...) pulled at 22:18 UK from build-1's seed EVM RPC 27810", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", + "profile_hashes": "" + }, + "claim_impact": "the same-work test's live-chain half (the coordinator's third row, 22:1x UK): the readers on the chain's own class v5 object at epoch 2 across the day switch 20734 to 20735; the node and pool readers run it on their release-line engines, the row those two can PASS without the class v6 branch", + "reviewer": "", + "at": "2026-10-08T21:36:08.520Z" } }, + "in_progress_since": "2026-10-08T21:18:18.084Z", "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11631,22 +12197,53 @@ "POW-01", "ROT-02" ], - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "same-work-20261008-03", + "evidence_path": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json", + "updated": "2026-10-08T21:36:08.520Z", "evidence_record": { - "reason": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "R2-F03-R03", "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "method": "GPU", + "cell": "harness:same-work", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-03", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json", + "in_progress": false, + "coverage": "partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set", "release_identity": { - "commit": "", + "commit": "c30ab32c (release-2.0.1; the class v5 freeze 1c420786, fingerprint cbc5bd0a); the CUDA reader the kit's gen 5 worker 9bfcf728", "lockfile": "", - "binary": "", - "network_object": "", - "activation": "", + "binary": "igneum-pow sha256 7ba781db... (release-2.0.1 c30ab32c, built on build-4); igneum-worker-cuda gen 5 sha256 9bfcf728...", + "network_object": "igneum-devnet-4's class v5 object at epoch 2: id 0x81fbfa3aa413173f, epoch seed 3c3fab43... (the epoch-2 seed block, chain block 3423, common to every chain tonight: the split came after it), day 20734, era 0 seed 7c36b833... (class v5 reads no era; the id is the same under era zero), state stream state-epoch2.igsd1 (sha256 f36e6bba..., 21,132 bytes, 224 records, root 0xf798d1d8...) pulled at 22:18 UK from build-1's seed EVM RPC 27810", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", "profile_hashes": "" + }, + "claim_impact": "the same-work test's live-chain half (the coordinator's third row, 22:1x UK): the readers on the chain's own class v5 object at epoch 2 across the day switch 20734 to 20735; the node and pool readers run it on their release-line engines, the row those two can PASS without the class v6 branch", + "reviewer": "", + "at": "2026-10-08T21:36:08.520Z" + }, + "evidence_records": { + "harness:same-work": { + "requirement_id": "R2-F03-R03", + "decision": "NOT RUN", + "method": "GPU", + "cell": "harness:same-work", + "manifest_sha": "c30ab32c", + "run_id": "same-work-20261008-03", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json", + "in_progress": false, + "coverage": "partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set", + "release_identity": { + "commit": "c30ab32c (release-2.0.1; the class v5 freeze 1c420786, fingerprint cbc5bd0a); the CUDA reader the kit's gen 5 worker 9bfcf728", + "lockfile": "", + "binary": "igneum-pow sha256 7ba781db... (release-2.0.1 c30ab32c, built on build-4); igneum-worker-cuda gen 5 sha256 9bfcf728...", + "network_object": "igneum-devnet-4's class v5 object at epoch 2: id 0x81fbfa3aa413173f, epoch seed 3c3fab43... (the epoch-2 seed block, chain block 3423, common to every chain tonight: the split came after it), day 20734, era 0 seed 7c36b833... (class v5 reads no era; the id is the same under era zero), state stream state-epoch2.igsd1 (sha256 f36e6bba..., 21,132 bytes, 224 records, root 0xf798d1d8...) pulled at 22:18 UK from build-1's seed EVM RPC 27810", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", + "profile_hashes": "" + }, + "claim_impact": "the same-work test's live-chain half (the coordinator's third row, 22:1x UK): the readers on the chain's own class v5 object at epoch 2 across the day switch 20734 to 20735; the node and pool readers run it on their release-line engines, the row those two can PASS without the class v6 branch", + "reviewer": "", + "at": "2026-10-08T21:36:08.520Z" } }, "approvals": { @@ -11706,6 +12303,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F04-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11763,6 +12380,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F04-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11820,6 +12457,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F04-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11877,6 +12534,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F04-R04", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11933,6 +12610,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F05 (P1, the external review): the regression's harness is the owner lane's (hash lane, adversary lane, floor lane 3); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F05-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -11989,6 +12686,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F05 (P1, the external review): the regression's harness is the owner lane's (hash lane, adversary lane, floor lane 3); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F05-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12045,6 +12762,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F05 (P1, the external review): the regression's harness is the owner lane's (hash lane, adversary lane, floor lane 3); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F05-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12101,6 +12838,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F06 (P1, the external review): the regression's harness is the owner lane's (hash lane, research lane D); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F06-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12157,6 +12914,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F06 (P1, the external review): the regression's harness is the owner lane's (hash lane, research lane D); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F06-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12213,6 +12990,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F06 (P1, the external review): the regression's harness is the owner lane's (hash lane, research lane D); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F06-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12269,6 +13066,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F07 (P1, the external review): the regression's harness is the owner lane's (app lane, fleet lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F07-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12325,6 +13142,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F07 (P1, the external review): the regression's harness is the owner lane's (app lane, fleet lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F07-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12381,6 +13218,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F07 (P1, the external review): the regression's harness is the owner lane's (app lane, fleet lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F07-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12437,6 +13294,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F08 (P1, the external review): the regression's harness is the owner lane's (proving lane, fleet lane, site (ops page)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F08-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12493,6 +13370,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F08 (P1, the external review): the regression's harness is the owner lane's (proving lane, fleet lane, site (ops page)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F08-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12549,6 +13446,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F08 (P1, the external review): the regression's harness is the owner lane's (proving lane, fleet lane, site (ops page)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F08-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12606,6 +13523,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F09 (P1, the external review): the regression's harness is the owner lane's (research lane, floor lane 3, coordinator); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F09-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12663,6 +13600,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F09 (P1, the external review): the regression's harness is the owner lane's (research lane, floor lane 3, coordinator); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F09-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12720,6 +13677,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F09 (P1, the external review): the regression's harness is the owner lane's (research lane, floor lane 3, coordinator); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F09-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12776,6 +13753,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F10 (P2, the external review): the regression's harness is the owner lane's (worker lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F10-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12832,6 +13829,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F10 (P2, the external review): the regression's harness is the owner lane's (worker lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F10-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12888,6 +13905,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F10 (P2, the external review): the regression's harness is the owner lane's (worker lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F10-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -12944,6 +13981,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F11 (P2, the external review): the regression's harness is the owner lane's (Ember lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F11-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13000,6 +14057,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F11 (P2, the external review): the regression's harness is the owner lane's (Ember lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F11-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13056,6 +14133,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F11 (P2, the external review): the regression's harness is the owner lane's (Ember lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F11-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13111,6 +14208,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F12 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F12-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13166,6 +14283,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F12 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F12-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13221,6 +14358,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F12 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F12-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13277,6 +14434,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F13 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F13-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13333,6 +14510,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F13 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F13-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13389,6 +14586,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F13 (P1, the external review): the regression's harness is the owner lane's (pool lane (new)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F13-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13445,6 +14662,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F14 (P1, the external review): the regression's harness is the owner lane's (app lane, relay lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F14-R01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13501,6 +14738,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F14 (P1, the external review): the regression's harness is the owner lane's (app lane, relay lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F14-R02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13557,6 +14814,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "R2-F14 (P1, the external review): the regression's harness is the owner lane's (app lane, relay lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "R2-F14-R03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13619,6 +14896,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-01 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-01", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13667,6 +14964,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-02 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-02", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13715,6 +15032,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-03 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-03", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13763,6 +15100,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-04", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13811,6 +15168,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-05 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-05", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13859,6 +15236,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-06 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-06", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -13888,24 +15285,73 @@ "owner": "CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)", "manual_page": null, "owner_lane": "CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)", - "run_status": "NOT RUN", + "run_status": "BLOCKED", "master_status": "PROPOSED / NOT RUN", - "updated": "2026-10-08T20:10:24.556Z", + "run_id": "canary-20261008-01", + "evidence_path": "tools/ci/canary-check.sh; packaging/ota/publish-manifest.sh; packaging/ota/publish-public.sh", + "updated": "2026-10-08T21:00:32.846Z", "evidence_record": { - "reason": "INT-07 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", - "at": "2026-10-08T20:10:24.556Z", - "method": "static", "requirement_id": "INT-07", - "decision": "NOT RUN", - "reviewer": "", - "claim_impact": "", + "decision": "BLOCKED", + "method": "team-reported", + "cell": "canary:fresh-install", + "manifest_sha": "c30ab32c", + "run_id": "canary-20261008-01", + "evidence": "tools/ci/canary-check.sh; packaging/ota/publish-manifest.sh; packaging/ota/publish-public.sh", + "in_progress": false, + "coverage": "partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's", "release_identity": { - "commit": "", + "commit": "c30ab32c (release-2.0.1 final tip; 2.0.2 open at c608b341)", "lockfile": "", - "binary": "", - "network_object": "", + "binary": "the shipped 2.0.1 entries on aa0e0f45's binaries", + "network_object": "igneum-devnet-4, chain id 4465", "activation": "", "profile_hashes": "" + }, + "claim_impact": "INT-07's clean-install half reads BLOCKED until a release tip carries a PASS fresh-install canary record; no published entry may move before one does (rule 33)", + "reviewer": "", + "at": "2026-10-08T21:00:32.846Z" + }, + "evidence_records": { + "record": { + "reason": "INT-07 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-07", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + }, + "canary:fresh-install": { + "requirement_id": "INT-07", + "decision": "BLOCKED", + "method": "team-reported", + "cell": "canary:fresh-install", + "manifest_sha": "c30ab32c", + "run_id": "canary-20261008-01", + "evidence": "tools/ci/canary-check.sh; packaging/ota/publish-manifest.sh; packaging/ota/publish-public.sh", + "in_progress": false, + "coverage": "partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's", + "release_identity": { + "commit": "c30ab32c (release-2.0.1 final tip; 2.0.2 open at c608b341)", + "lockfile": "", + "binary": "the shipped 2.0.1 entries on aa0e0f45's binaries", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "INT-07's clean-install half reads BLOCKED until a release tip carries a PASS fresh-install canary record; no published entry may move before one does (rule 33)", + "reviewer": "", + "at": "2026-10-08T21:00:32.846Z" } }, "approvals": { @@ -13956,6 +15402,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-08 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-08", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14004,6 +15470,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-09 (R1 integration gate): the gate's harness is the owner lane's (app lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-09", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14052,6 +15538,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-10 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-10", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14100,6 +15606,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-11 (R1 integration gate): the gate's harness is the owner lane's (app lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-11", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14148,6 +15674,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-12 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-12", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14196,6 +15742,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-13 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-13", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14244,6 +15810,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-14 (R1 integration gate): the gate's harness is the owner lane's (Ember lane (a04fe3451877e2ff0) with the app lane); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-14", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14292,6 +15878,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-15 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-15", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14340,6 +15946,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-16 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-16", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14388,6 +16014,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-17 (R1 integration gate): the gate's harness is the owner lane's (proving lane (a6e8f84588b809d62)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-17", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, @@ -14436,6 +16082,26 @@ "profile_hashes": "" } }, + "evidence_records": { + "record": { + "reason": "INT-18 (R1 integration gate): the gate's harness is the owner lane's (research lane (ad6a2bd47d4a46105)); not yet named in the map", + "at": "2026-10-08T20:10:24.556Z", + "method": "static", + "requirement_id": "INT-18", + "decision": "NOT RUN", + "reviewer": "", + "claim_impact": "", + "release_identity": { + "commit": "", + "lockfile": "", + "binary": "", + "network_object": "", + "activation": "", + "profile_hashes": "" + }, + "in_progress": false + } + }, "approvals": { "scope_approved": null, "implementation_complete": null, diff --git a/docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json b/docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json new file mode 100644 index 000000000..8d4ec7688 --- /dev/null +++ b/docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json @@ -0,0 +1,248 @@ +{ + "case": "succession-360-window-300", + "floor": "240", + "expect": "refuse", + "phases": { + "below": { + "daaAtForge": 121, + "forge": { + "block": 105, + "hash": "0x87fe67d16fda7174b0706fedd4bdafcbabbb2f808897944d7ec687570b6fb91f", + "second": { + "block": 254, + "hash": "0x110d897b880b165caa6c40478cc3238b58926576260882198210889954ee199f" + }, + "shapes": [ + { + "shape": "p-prior-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + }, + { + "shape": "n-next-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + } + ] + }, + "observed": { + "paid": [], + "carried": [] + }, + "refusals": { + "H1": { + "invalid": 2, + "dropped": 0, + "pair": 1, + "statement": 1, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + }, + "H2": { + "invalid": 2, + "dropped": 0, + "pair": 1, + "statement": 1, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + } + } + }, + "atFloor": { + "daaAtForge": 288, + "forge": { + "block": 374, + "hash": "0x8ce7a062860107fc4eb0596c0c28e22fa61fbc0ff5287730c78fae69226dd792", + "second": { + "block": 511, + "hash": "0xba04be731e0ae6b637820c5ffef1901b7985349579b4c1a3ad795d67a710ffea" + }, + "shapes": [ + { + "shape": "p-prior-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + }, + { + "shape": "n-next-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + } + ] + }, + "observed": { + "paid": [], + "carried": [] + }, + "refusalsBefore": { + "H1": { + "invalid": 2, + "dropped": 0, + "pair": 1, + "statement": 1, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + }, + "H2": { + "invalid": 2, + "dropped": 0, + "pair": 1, + "statement": 1, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + } + }, + "refusalsAfter": { + "H1": { + "invalid": 4, + "dropped": 0, + "pair": 1, + "statement": 3, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + }, + "H2": { + "invalid": 4, + "dropped": 0, + "pair": 1, + "statement": 3, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + } + } + }, + "afterWindow": { + "daaAtForge": 675, + "forge": { + "block": 657, + "hash": "0xddb37d774fe5b5c0711a27984b6d25f7c2908ed58c14d00a69f9576274f41b46", + "second": { + "block": 786, + "hash": "0x525c035698dd1d756825d76b92019184023a6b5a3ef1221a51825bcc968a278f" + }, + "shapes": [ + { + "shape": "p-prior-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + }, + { + "shape": "n-next-pair-proof", + "accepted": true, + "new": true, + "reason": "accepted" + } + ] + }, + "observed": { + "paid": [], + "carried": [] + }, + "refusalsBefore": { + "H1": { + "invalid": 4, + "dropped": 0, + "pair": 1, + "statement": 3, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + }, + "H2": { + "invalid": 4, + "dropped": 0, + "pair": 1, + "statement": 3, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + } + }, + "refusalsAfter": { + "H1": { + "invalid": 6, + "dropped": 0, + "pair": 2, + "statement": 4, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 657 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 657 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 786 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 786 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + }, + "H2": { + "invalid": 6, + "dropped": 0, + "pair": 2, + "statement": 4, + "garbage": 0, + "reasons": [ + "a carried proof record's proof does not verify: shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 105 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 254 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 374 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 511 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926", + "a carried proof record's proof does not verify: shard record block 657 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9ed1b21bd53d (proof 92de5638f248a5c1): shard record block 657 shard 0 by 1bb65de716c3b466cd45a85b3ceddf7bcb9873e1821209ee76ec9", + "a carried proof record's proof does not verify: shard record block 786 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa92609d7c4943ba (proof 52f5ebdcc116da9f): shard record block 786 shard 0 by 990b90ac727bef6244fbbce29abcb47796dd1d197b2c4301aa926" + ] + } + } + } + }, + "node": "/srv/builds/igneum-wt-vcache/vendor/igneum-node/target/release/igneumd", + "slot": 0, + "ports": { + "base": 30890, + "suffix": 985 + }, + "startedAt": "2026-10-08T20:49:30.024Z", + "verdict": { + "pairBelow": 1, + "stmtBelow": 1, + "pairWindow": 0, + "stmtWindow": 2, + "pairAfter": 1, + "stmtAfter": 1, + "nothingPaid": true, + "pass": true + }, + "endedAt": "2026-10-08T21:04:37.315Z" +} \ No newline at end of file diff --git a/docs/release/evidence/ux-shipper-2026-10-08.md b/docs/release/evidence/ux-shipper-2026-10-08.md index 466a3731f..04a36c3e6 100644 --- a/docs/release/evidence/ux-shipper-2026-10-08.md +++ b/docs/release/evidence/ux-shipper-2026-10-08.md @@ -25,3 +25,7 @@ Registry: docs/plans/igneum-2.0-test-registry.json, suite UX. Owner lane: the sh - The shipped igneum-miner (the 4cdcc488 and ef0f2ed8 pairs) refused every block template whose coinbase exceeded a u64: on the founder's Mac mini at 19:41 "! template error: amount high word 2 (low word 2140158083214006468) on a network at 8 decimals, where every amount fits a u64", then "NODE SLOW: no template from the node in 29 pass(es)", 0 MH/s; rpc/core/src/error.rs:131. Cause: igneum/miner/src/main.rs installed the network's base unit (install_unit_from) only for `inspect`; `mine`, `watch`, `export-pack` and the prepare path read amounts at the 8-decimal width, so a merged coinbase above 18.4 IGN was refused. - The fleet at 19:44: the refusal on 40 of 43 mining boxes (hub-1 323 refusals, 120 NODE SLOW); hub-1's selected chain down to 2 to 4 miner keys over its last 300 EVM blocks (27 at 19:40) and 22 blocks in 14 minutes; 0 blocks per minute at 19:54: the cause of the solo branch and the vote split after the 19:15 outage. - The fix: release-2.0.0-node 7cfa422a (every miner command installs the base unit before any amount is read; the known-failed test with the mini's exact refusal; 777214af's first form did not compile). The clearing evidence is the fixed miner's live canary on build-1's seed (templates parsing, a MINER SUMMARY with a rate, a template whose coinbase exceeds a u64 joined), recorded as its own batch when the node lane prints it. + +## UX-06 clearing run canary-miner-fix-7cfa422a (PASS, 20:05 to 21:48 BST) +- The fixed miner (release-2.0.0-node 7cfa422a: every miner command installs the network's base unit before reading an amount) on build-1's seed, 20:05:11 to 20:06:11: 49 templates taken in 60 s, no "template error", no "amount high word", no NODE SLOW; `MINER SUMMARY 'mfix-canary' engine=igneum-pow found=0 rejected=0 fee=0 over 60.0s = 0.00 blocks/s, 0.006 MH/s, 1 template switches`; `VOTER SUMMARY votes_sent=20 votes_accepted=20 locks_seen=12 last_lock_index=270`. +- The fleet on the 2.0.1 kit: lp-4090-11 from 20:31 (zero refusals in 320 s, the first accepted block 1aa32e55… at 20:33:33, 186 accepted in 320 s); stages A and B (65 kept nodes) by 20:56:53; hub-1's miner at 21:43 (102 accepted in 343 s); the first lock after the roll, checkpoint 620 at 21:34:33 (80.8 percent of active). diff --git a/docs/site/audit-2.0.md b/docs/site/audit-2.0.md index 74ea36054..9189839c2 100644 --- a/docs/site/audit-2.0.md +++ b/docs/site/audit-2.0.md @@ -68,7 +68,8 @@ Labels: the five served labels are TEAM-REPORTED, MODELLED, PROPOSED, PENDING an | randomx.html | +14 -17. Generated from the litepaper's randomx section (50f517120) | Same as litepaper#randomx; rebuilt from litepaper#randomx: the dataset row reads the dataset policy (site-2.0-audit) | Same as litepaper#randomx: the 2 GB dataset row | measured, proposed, approximate | None | | receipt.html | +27 -46. "Devnet 3" becomes "the devnet"; the testnet chain entry gone | The two receipt kinds (transaction-inclusion and payment), the proof boundary, data availability, the three boundaries, the positioning line (5e5ba9b8a); both sentences start in capitals; the unlabelled 30 to 90 s finality figure dropped (site-2.0-audit) | Two sentences start in lower case, "the devnet, no value" | The receipt kind on every result; no five-label word. No label: "about 30 to 90 s after it executes" | None | | scenes.html | +11 -14. Chrome only; the body is unchanged | The legend reads finalised checkpoint and the Forge note finalised; the four words paragraph added (site-2.0-audit) | The legend reads pending, included, excluded, proven, locked checkpoint, and "everything under it is final" | No label | None | -| scorecard.html | +314, new (9bdee3727); in the sitemap (1281d01fb) | The whole page: twelve gates from the plan's section 23, evidence required, do not substitute, the Today label; the release evidence packet; the wording ladder | None | TEAM-REPORTED 4, MODELLED 3, PROPOSED 2, PENDING 5, EXCLUDED 3 | The reference-population sentences land at 21:00; the Sustained proving cell needs economics to serve the 24-hour reading as history; no square og PNG | +| prize.html | New: the disclosure prize terms page, from the scorecard shell; in the nav Learn panel, the sitemap, the share cards and the capture list | The terms: what it pays for (a placed or measured adversarial implementation that beats the served bracket under the one acceptance rule, or a reproduced shortcut in the served kit), what it does not pay for (confirmations, synthesis-only results, work outside the budget, excluded classes), judged in-house, the finding served either way, reports to hello@igneum.network | None | No label: the amount line reads "set by the founder and served here when set" | The amount | +| scorecard.html | +314, new (9bdee3727); in the sitemap (1281d01fb) | The whole page: twelve gates from the plan's section 23, evidence required, do not substitute, the Today label; the release evidence packet; the wording ladder | None | TEAM-REPORTED 4, MODELLED 3, PROPOSED 2, PENDING 5, EXCLUDED 3 | the Sustained proving cell needs economics to serve the 24-hour reading as history; no square og PNG | | swap.html | +37 -40. "Devnet 3" becomes "the devnet"; chain igneum-devnet-4; the addresses pointer becomes "docs/contracts"; the wallet version requirement gone | The intro: "on Igneum, with proven execution" | None found | No label: "Every swap is a devnet block" | `docs/contracts/` holds devnet-3.json and sepolia.json, no igneum-devnet-4 file; the swap og card PNG still prints "Devnet 3" | | tx.html | +24 -26. Title and crumb; network "The devnet"; chips and lock state "finalised" and "not yet finalised" | The four words and definitions (5c8fdfa29, b45bf6d45); the source line names one node on the build box; the fee sentence reads 80 percent to the miner and 20 percent to the developer registrations, none to the provers, as on economics (site-2.0-audit) | "Read from node1-dn3 on the build box since 12:25 UTC on 8 October 2026"; "The priority fee splits 80/20 between the including miner and the proving pool", which economics no longer states | No label | The explorer og card PNG still prints "Devnet 3" | | wallet.html | +15 -19. "0.1.5" becomes "the current build"; download v0.1.6; the testnet notice gone | Nothing | Screenshots from mock state of 7 October 2026 | One "Measured" heading; otherwise no label | None beyond the label | @@ -78,6 +79,4 @@ Labels: the five served labels are TEAM-REPORTED, MODELLED, PROPOSED, PENDING an - The share cards: explorer, swap, faucet and oracle PNGs were not re-rendered after their text changed in `site/og/pages.mjs` and still print the devnet number (the explorer card serves /explorer, /block, /address, /tx and /proving); the home card still prints the pre-reset line; scorecard has no square card. Rendering runs on a build box, never on the Mac. - /oracle states the deployed Sepolia contract's chain ids 4463 and 4464 until it is redeployed. - The miner page's hero screenshot is an older build. -- /prize does not exist yet (due by 12:00 tomorrow); it gets a line here when it lands. -- The reference-population sentences land at 21:00 (scorecard, facts page, litepaper#roadmap). -- The 4 GiB dataset step is PROPOSED pending the founder's word (litepaper#mining, the facts page row 7, miner, app, randomx). +- /prize serves its terms without an amount; the amount line fills when the founder sets it. diff --git a/igneum-pow/src/accept.rs b/igneum-pow/src/accept.rs index e02c92efe..f96ab824b 100644 --- a/igneum-pow/src/accept.rs +++ b/igneum-pow/src/accept.rs @@ -489,7 +489,11 @@ pub fn is_class_v4_shape(class: &LoadClass) -> bool { // class v5 (docs/design/class-v5-stored-state.md) is judged under the same rules: its state flag is set aside; // class v6 lane 1's index fold and re-weight table are set aside too (the address path and the op table are // not the shape) - && LoadClass { era: None, shadow: None, state: false, fold: false, rw: 0, ..*class } == LoadClass { shadow: None, ..V4_CLASS } + // the window and layer 8 off are set aside too (lane D's finding of 8 October 2026, 19:1x UK: a +nowin or +reg64c + // program was judged by the class v2 parts alone on the chain's path; the harness's own predicate hid it) + // and the era's drawn width (lane D's second finding, 20:0x UK: an era whose width set has more than one width + // writes the drawn width into `mix`, and the rule must judge every width of the family, not the pinned one alone) + && LoadClass { era: None, shadow: None, state: false, fold: false, rw: 0, nowin: false, reg64: false, reg64_chain: false, mix: V4_CLASS.mix, ..*class } == LoadClass { shadow: None, ..V4_CLASS } } /// One pass of the dataflow freshness over the base program then the shadow block (the order of one iteration), @@ -849,6 +853,12 @@ pub fn check_dynamic(p: &Program) -> Result { check_distinct_indices_v4(p)?; } } + // the reg64 window's liveness rule (the window's acceptance tool, wired 8 October 2026, 19:5x UK): keyed on the + // window flag so no other class's verdict moves; the arithmetic-only window is refused at its first dead register, + // the full chain passes (129 one-warp interpretations on the closed form, under a second) + if p.class.reg64 { + check_window_liveness(p)?; + } let half = (ACCEPT_HASHES / 2) as u32; let mut bias_max = 0u32; for (bit, &ones) in acc.bit_ones.iter().enumerate() { diff --git a/igneum-pow/src/bind.rs b/igneum-pow/src/bind.rs index 94edea2bd..dd18b3069 100644 --- a/igneum-pow/src/bind.rs +++ b/igneum-pow/src/bind.rs @@ -91,10 +91,21 @@ pub fn hex(bytes: &[u8]) -> String { /// Bytes from hex (either case). `None` on odd length or a bad digit. pub fn unhex(s: &str) -> Option> { - if s.len() % 2 != 0 { + // on bytes, never on char boundaries (the fuzz of 8 October 2026 found a multi-byte character inside the text + // panicked the slice; a non-ASCII byte is a bad digit) + let b = s.as_bytes(); + if b.len() % 2 != 0 { return None; } - (0..s.len()).step_by(2).map(|i| u8::from_str_radix(&s[i..i + 2], 16).ok()).collect() + let digit = |c: u8| -> Option { + match c { + b'0'..=b'9' => Some(c - b'0'), + b'a'..=b'f' => Some(c - b'a' + 10), + b'A'..=b'F' => Some(c - b'A' + 10), + _ => None, + } + }; + b.chunks(2).map(|c| Some(digit(c[0])? << 4 | digit(c[1])?)).collect() } impl Epoch { diff --git a/igneum-pow/src/emit.rs b/igneum-pow/src/emit.rs index 25f14e983..13ffe7d88 100644 --- a/igneum-pow/src/emit.rs +++ b/igneum-pow/src/emit.rs @@ -255,7 +255,11 @@ fn program_class_header_lines(p: &Program) -> String { return String::new(); } let mut s = String::new(); - if p.program_class() == ProgramClass::V5 { + if p.program_class() == ProgramClass::V6 { + s.push_str("// Program class v6 (the Igneum 2.0 D1 object, docs/design/class-v6-rotating-family.md): generator version 6, class v5's\n"); + s.push_str("// stored-state dataset with the index fold, the re-weight table and the 64-register window (the v6 flags in the class\n"); + s.push_str("// string); a worker that runs another class refuses this pack, and a job line names the class it wants (class=v6 era=).\n"); + } else if p.program_class() == ProgramClass::V5 { s.push_str("// Program class v5 (proof of stored state and of following, docs/design/class-v5-stored-state.md): generator version 5,\n"); s.push_str("// class v4 over a dataset whose every item is keyed by the window's execution state (IGNEUM_STATE_* below, leaves.bin);\n"); s.push_str("// a worker that runs another class refuses this pack, and a job line names the class it wants (class=v5 era=).\n"); @@ -352,7 +356,7 @@ fn class_header_lines(p: &Program) -> String { s.push_str(&format!("#define IGNEUM_LOAD_WIDTH_COUNTS {{ {}, {}, {} }} // loads of 4, 16, 64 bytes per program ", c[0], c[1], c[2])); s.push_str(&format!("#define IGNEUM_BYTES_PER_HASH {} -", p.bytes_per_hash())); +", p.bytes_per_hash_executed())); s.push_str(&format!("#define IGNEUM_FOLD_ROT {FOLD_ROT} ")); s.push_str(&format!("#define IGNEUM_FOLD_MUL {} @@ -503,8 +507,16 @@ fn shadow_block(p: &Program, dialect: CoreDialect) -> String { )); let ty = if dialect == CoreDialect::Cuda { "uint32_t" } else { "uint" }; s.push_str(&format!(" for ({ty} sh = 0u; sh < {reps}u; ++sh) {{\n")); + let prefix = dialect == CoreDialect::Cuda && p.address_mix() && reg64_prefix(); for (k, ins) in p.shadow.iter().enumerate() { + if prefix { + // F05 prefix form: the shadow's writes move S too (the fold reads the live registers) + s.push_str(&format!(" t_ = {};\n", reg64_term(ins.dst as usize))); + } s.push_str(&format!(" {} // s{k} {}\n", shadow_instr_line(dialect, ins), ins.op.name())); + if prefix { + s.push_str(&format!(" S ^= t_ ^ {};\n", reg64_term(ins.dst as usize))); + } } s.push_str(" }\n"); s @@ -1161,13 +1173,60 @@ fn reg_decl(p: &Program, ty: &str) -> String { return format!(" {ty} r0, r1, r2, r3, r4, r5, r6, r7;\n"); } let names: Vec = (0..p.registers()).map(|k| format!("r{k}")).collect(); - let m = if p.address_mix() { format!("\n {ty} m; // reg64 full chain: the address mix of all 64 registers before every load") } else { String::new() }; + let m = if p.address_mix() { + if ty == "uint32_t" && reg64_prefix() { + format!("\n {ty} m, S, p_, t_; // reg64 full chain in the F05 prefix form: S the running xor of the rotated registers, p_ the prefix, t_ the old term") + } else { + format!("\n {ty} m; // reg64 full chain: the address mix of all 64 registers before every load") + } + } else { + String::new() + }; format!(" {ty} {}; // reg64: 64 live registers per lane (two 32-register windows){m}\n", names.join(", ")) } /// reg64 full chain: the mix statement before a load, `m = r0; m = rotl_imm(m, 1u) ^ r1; ... ^ r63;` over the 63 /// registers other than the load's source `src` (the verifier's `addr_src`, the same chain), one line; the same /// text in the three dialects (`rotl_imm` is defined in each). +/// Review B's F05 (8 October 2026): the CUDA texts carry the reg64 address mix in its closed prefix form when this +/// switch is on (`igneum-pow export --reg64-prefix`): `S` is the xor of `a[k] = rotl(r[k], (63 - k) mod 32)` over +/// the 64 registers, kept per lane and updated after every write; a load's source is +/// `r[s] ^ ror(P_s, 1) ^ (S ^ P_s ^ a[s])` with `P_s` the xor of the first `s` terms. The same hash, the same vectors +/// (`verify::reg64_address_source`); a measurement text for the fleet, never the definition. OpenCL and Metal keep +/// the fold. +static REG64_PREFIX: std::sync::atomic::AtomicBool = std::sync::atomic::AtomicBool::new(false); + +pub fn set_reg64_prefix(on: bool) { + REG64_PREFIX.store(on, std::sync::atomic::Ordering::Relaxed); +} + +pub fn reg64_prefix() -> bool { + REG64_PREFIX.load(std::sync::atomic::Ordering::Relaxed) +} + +/// `rotl(rK, (63 - k) mod 32)` as text; a rotation of 0 is the register itself (`rotl_imm` takes 1..31). +fn reg64_term(k: usize) -> String { + let n = (63 - k) % 32; + if n == 0 { format!("r{k}") } else { format!("rotl_imm(r{k}, {n}u)") } +} + +/// The prefix-form mix statement before a load of source `src` (the F05 text): `m = ror(P, 1) ^ S ^ P ^ a[src]`. +fn reg64_prefix_mix_line(src: u8) -> String { + let s = src as usize; + let prefix: Vec = (0..s).map(reg64_term).collect(); + let p = if prefix.is_empty() { "0u".to_string() } else { prefix.join(" ^ ") }; + format!("p_ = {p}; m = rotr_var(p_, 1u) ^ S ^ p_ ^ {};", reg64_term(s)) +} + +/// The prefix form's running total after the register init: `S = a[0] ^ ... ^ a[63]`. +fn reg64_prefix_init(p: &Program) -> String { + if !p.class.reg64 || !p.address_mix() || !reg64_prefix() { + return String::new(); + } + let terms: Vec = (0..p.registers()).map(reg64_term).collect(); + format!(" // F05 prefix form: the running xor of every rotated register\n S = {};\n", terms.join(" ^ ")) +} + fn reg64_mix_line(p: &Program, src: u8) -> String { let mut s = String::new(); for k in 0..p.registers() { @@ -1223,8 +1282,13 @@ fn cuda_instr_lines(p: &Program, geom: DatasetGeom) -> String { let d = format!("r{}", ins.dst); let a = format!("r{}", ins.src); let b = format!("r{}", ins.src2); + let prefix = address_mix && reg64_prefix(); if address_mix && ins.op == Op::Load { - s.push_str(&format!(" {}\n", reg64_mix_line(p, ins.src))); + s.push_str(&format!(" {}\n", if prefix { reg64_prefix_mix_line(ins.src) } else { reg64_mix_line(p, ins.src) })); + } + if prefix { + // the old term of the destination, so S can drop it after the write + s.push_str(&format!(" t_ = {};\n", reg64_term(ins.dst as usize))); } let line = match ins.op { // Metal select(A, B, c) returns c ? B : A, so the true branch is imm2 here as well. @@ -1252,6 +1316,9 @@ fn cuda_instr_lines(p: &Program, geom: DatasetGeom) -> String { Op::Hot => hot_stmt(CoreDialect::Cuda, &d, &a), }; s.push_str(&format!(" {line} // {k} {}\n", ins.op.name())); + if prefix { + s.push_str(&format!(" S ^= t_ ^ {};\n", reg64_term(ins.dst as usize))); + } } s } @@ -1371,6 +1438,7 @@ pub fn cuda_kernel_geom(p: &Program, memhard: Option<&MixParams>, geom: DatasetG s.push_str(&init_line(p, "uint32_t", i)); } s.push_str(®64_init(p)); + s.push_str(®64_prefix_init(p)); s.push_str(&format!("\n for (uint32_t it = 0u; it < {ITERATIONS}u; ++it) {{\n uint32_t sel = r0;\n")); s.push_str(&cuda_instr_lines(p, geom)); s.push_str(&shadow_block(p, CoreDialect::Cuda)); @@ -1536,6 +1604,7 @@ pub fn cuda_kernel_bound_geom(p: &Program, memhard: Option<&MixParams>, geom: Da )); } s.push_str(®64_init(p)); + s.push_str(®64_prefix_init(p)); s.push_str(&format!("\n for (uint32_t it = 0u; it < {ITERATIONS}u; ++it) {{\n uint32_t sel = r0;\n")); s.push_str(&cuda_instr_lines(p, geom)); s.push_str(&shadow_block(p, CoreDialect::Cuda)); @@ -1947,7 +2016,10 @@ pub fn program_header(p: &Program, day: &str, ds: &DatasetSource) -> String { s.push_str("#define IGNEUM_LANES 32\n"); s.push_str(&format!("#define IGNEUM_ITERATIONS {ITERATIONS}\n")); s.push_str(&format!("#define IGNEUM_INSTR_COUNT {INSTR_COUNT}\n")); - s.push_str(&format!("#define IGNEUM_LOADS_PER_HASH {}\n", p.loads_per_hash())); + if p.class.reg64 { + s.push_str("// the executed counts per nonce (review B's V6-02): twice the drawn program's under the 64-register window\n"); + } + s.push_str(&format!("#define IGNEUM_LOADS_PER_HASH {}\n", p.loads_per_hash_executed())); s.push_str(&format!("#define IGNEUM_WIDE_LOADS_PER_HASH {}\n", p.wide_loads_per_hash())); s.push_str(&format!("#define IGNEUM_OP_MIX {}\n", jstr(&p.op_mix()))); s.push_str(&program_class_header_lines(p)); @@ -2189,7 +2261,7 @@ pub fn program_json(p: &Program, day: &str, ds: &DatasetSource) -> String { s.push_str(" \"registers\": 8,\n"); s.push_str(&format!(" \"iterations\": {ITERATIONS},\n")); s.push_str(&format!(" \"instruction_count\": {INSTR_COUNT},\n")); - s.push_str(&format!(" \"loads_per_hash\": {},\n", p.loads_per_hash())); + s.push_str(&format!(" \"loads_per_hash\": {},\n", p.loads_per_hash_executed())); if p.program_class() != ProgramClass::V2 { s.push_str(&format!(" \"program_class\": {},\n", jstr(p.program_class().name()))); if p.program_class() == ProgramClass::V4 { @@ -2239,7 +2311,7 @@ pub fn program_json(p: &Program, day: &str, ds: &DatasetSource) -> String { s.push_str(&format!(" \"load_slots\": {},\n", p.class.load_slots)); s.push_str(&format!(" \"load_mix_percent_4_16_64\": [{}, {}, {}],\n", p.class.mix[0], p.class.mix[1], p.class.mix[2])); s.push_str(&format!(" \"load_width_counts_4_16_64\": [{}, {}, {}],\n", c[0], c[1], c[2])); - s.push_str(&format!(" \"bytes_per_hash\": {},\n", p.bytes_per_hash())); + s.push_str(&format!(" \"bytes_per_hash\": {},\n", p.bytes_per_hash_executed())); if p.has_scratch() { s.push_str(&format!(" \"scratch_ops_per_hash\": {},\n", p.scratch_ops_per_hash())); s.push_str(&format!(" \"scratch_kib_per_warp\": {},\n", p.class.scratch_kb)); @@ -2610,19 +2682,42 @@ pub fn export_pack(epoch: &Epoch, day: &str, source: &str) -> Pack { v.hot_fnv = h.fnv1a64(); } let is_mh = memhard.is_some(); - let mut files = vec![ - ("program.json".to_string(), program_json(p, day, ds)), - ("vectors.json".to_string(), vectors_json_geom(p, day, geom, &bases, &outs, &v, source, is_mh)), + let texts: Vec<(String, String)> = vec![ ("kernel.cu".to_string(), cuda_kernel_geom(p, memhard, geom)), ("kernel.cl".to_string(), opencl_kernel_geom(p, memhard, geom)), - ("program.h".to_string(), program_header(p, day, ds)), - ("vectors.h".to_string(), vectors_header(p, &bases, &outs, &v, mask, source, is_mh)), ("program.metal".to_string(), metal_program_geom(p, geom, LoadSource::Stored)), // Header-bound kernels (3 October 2026, bind.rs): new files, the seven above are unchanged. ("program_bound.metal".to_string(), metal_program_bound_geom(p, geom)), ("kernel_bound.cu".to_string(), cuda_kernel_bound_geom(p, memhard, geom)), ("kernel_bound.cl".to_string(), opencl_kernel_bound_geom(p, memhard, geom)), ]; + // A06 (the external review of 8 October 2026): the pack authenticates its kernel texts by hash, not by metadata: + // identity.json carries the program id, the dataset and era identities and the BLAKE2b-256 of every kernel file. + // A file of its own, so every pinned pack's twelve files stay byte for byte (the readers ignore it). + let hashes: Vec = texts.iter().map(|(n, t)| format!(" {}: \"{}\"", jstr(n), hex_bytes(&crate::blake2b::blake2b_256(&[t.as_bytes()])))).collect(); + let identity = format!( + "{{\n \"program_id\": \"{:#018x}\",\n \"load_class\": {},\n \"generator\": {},\n \"day\": {},\n \"dataset_bytes\": {},\n \"kernel_blake2b256\": {{\n{}\n }},\n \"rule\": \"the external review's A06 (8 October 2026): a pack's program, dataset and work identities are distinct, and its kernel texts are authenticated by the hash of their bytes, never by the metadata beside them\"\n}}\n", + p.program_id(), + jstr(&p.class.name()), + p.generator, + jstr(day), + (ds.geom.words as u128) * 4, + hashes.join(",\n") + ); + // the pack's file order as the pinned packs carry it, identity.json second + let mut texts = texts.into_iter(); + let kernel_cu = texts.next().unwrap(); + let kernel_cl = texts.next().unwrap(); + let mut files = vec![ + ("program.json".to_string(), program_json(p, day, ds)), + ("identity.json".to_string(), identity), + ("vectors.json".to_string(), vectors_json_geom(p, day, geom, &bases, &outs, &v, source, is_mh)), + kernel_cu, + kernel_cl, + ("program.h".to_string(), program_header(p, day, ds)), + ("vectors.h".to_string(), vectors_header(p, &bases, &outs, &v, mask, source, is_mh)), + ]; + files.extend(texts); if let Some(mp) = memhard { files.push(("memhard.h".to_string(), cuda_memhard_header(p, mp))); files.push(("memhard.metal".to_string(), metal_memhard_for(p, mp))); diff --git a/igneum-pow/src/generator.rs b/igneum-pow/src/generator.rs index 61fe4874b..ce0084681 100644 --- a/igneum-pow/src/generator.rs +++ b/igneum-pow/src/generator.rs @@ -255,6 +255,11 @@ pub struct LoadClass { /// optimiser split [`NONLOAD_WEIGHTS_RW`] (sum 83, `or` never drawn); 2 the census lane's neighbouring table /// [`NONLOAD_WEIGHTS_RW2`] (sum 75). The draw rolls against the table's own sum ([`LoadClass::nonload_weights`]). pub rw: u8, + /// D2 experiment "layer 8 off" (the coordinator's order, 8 October 2026, 18:12 UK; a research class behind `+nowin`): + /// the era layout's window-layer draw is removed, every load site reads the whole dataset (`win = 0`, `off = 0`). + /// The program stream still consumes the two window draws per instruction, so the base program's instructions are + /// the class's without the flag; only the windows move. `false` for every other class. + pub nowin: bool, /// The 64-register window (the hash lane's reg64 measurement, 8 October 2026, a research class behind `+reg64` /// and `--reg64`): each lane holds 64 live 32-bit registers. r0..r7 are seeded as today, r8..r63 derived from them /// (`r[k] = r[k & 7] * 0x9E3779B9 + k`); the 64 drawn instructions run twice per iteration in an interleaved @@ -455,13 +460,13 @@ impl LoadClass { impl LoadClass { /// Generator version 2 as adopted on 4 October 2026: 16 loads of one word. The lottery hash. pub const V2: LoadClass = - LoadClass { mix: [100, 0, 0], load_slots: LOAD_SLOTS as u8, scratch: None, scratch_kb: 0, mixer_mult: 1, growth: false, era: None, hot: None, derive_len: 0, shadow: None, state: false, wide8: false, fold: false, rw: 0, reg64: false, reg64_chain: false }; + LoadClass { mix: [100, 0, 0], load_slots: LOAD_SLOTS as u8, scratch: None, scratch_kb: 0, mixer_mult: 1, growth: false, era: None, hot: None, derive_len: 0, shadow: None, state: false, wide8: false, fold: false, rw: 0, nowin: false, reg64: false, reg64_chain: false }; /// The construction decided for program class v3 on 5 October 2026 (Counter ASIC 2.0, `docs/plans/mixer-x4.md`): /// version 2 loads (16 slots of one word, no scratch, no width roll, so the program stream is version 2's), the /// mixer applied 4 times per round, and the cache growth rule. Name "mx4". pub const MX4: LoadClass = - LoadClass { mix: [100, 0, 0], load_slots: LOAD_SLOTS as u8, scratch: None, scratch_kb: 0, mixer_mult: 4, growth: true, era: None, hot: None, derive_len: 0, shadow: None, state: false, wide8: false, fold: false, rw: 0, reg64: false, reg64_chain: false }; + LoadClass { mix: [100, 0, 0], load_slots: LOAD_SLOTS as u8, scratch: None, scratch_kb: 0, mixer_mult: 4, growth: true, era: None, hot: None, derive_len: 0, shadow: None, state: false, wide8: false, fold: false, rw: 0, nowin: false, reg64: false, reg64_chain: false }; /// The era class over `base` (`docs/plans/era-layout.md`): the parameters drawn by [`era_draw`]; when `allowed` /// has more than one width the drawn width becomes the class mix (every load that width), otherwise the base @@ -634,6 +639,21 @@ impl LoadClass { LoadClass { rw, ..self } } + /// D2 "layer 8 off": the class with the window-layer draw removed (every load site reads the whole dataset). + pub fn with_nowin(self) -> LoadClass { + LoadClass { nowin: true, ..self } + } + + /// The class v6 object's draw rules (the external review of 8 October 2026, A02 and A08, fixed by construction for + /// every class carrying a v6 flag: the index fold, a re-weight table, the register window or layer 8 off): five + /// of the non-load slots are shuffles whose masks are the five lane dimensions 1, 2, 4, 8, 16 in a drawn order, so + /// every accepted program mixes all 32 lanes by construction; and a `mad` never names its destination as its + /// second source (`d = a * d + d` is `d * (a + 1)`, not a bijection in `d` when `a` is odd). Every other class + /// draws as before. + pub fn is_v6(&self) -> bool { + self.fold || self.rw != 0 || self.reg64 || self.nowin + } + /// The non-load op table this class draws from, in draw order, and its sum (the roll's range). The plain table /// for every class without the re-weight flag, so their streams are byte for byte what they were. pub fn nonload_weights(&self) -> (&'static [(Op, u64); 10], u64) { @@ -677,6 +697,10 @@ impl LoadClass { pub fn parse(s: &str) -> Option { // class v6 lane 1: "+fold" (the index fold) and "+rw" / "+rw2" (the re-weight table) over // any class, in any order, outermost of all + // D2 "layer 8 off": "+nowin" over any class, in any order with the other suffixes + if let Some(base) = s.strip_suffix("+nowin") { + return Some(LoadClass::parse(base)?.with_nowin()); + } if let Some(base) = s.strip_suffix("+fold") { return Some(LoadClass::parse(base)?.with_fold()); } @@ -829,6 +853,10 @@ impl LoadClass { if self.fold { return format!("{}+fold", LoadClass { fold: false, ..*self }.name()); } + if self.nowin { + // D2 "layer 8 off": "+nowin" sits inside "+fold" and "+rw" and outside "+reg64" and "+state" + return format!("{}+nowin", LoadClass { nowin: false, ..*self }.name()); + } if self.reg64 { // "+reg64" / "+reg64c": the 64-register window is a suffix on any class, outermost let base = LoadClass { reg64: false, reg64_chain: false, ..*self }.name(); @@ -935,6 +963,10 @@ pub const GENERATOR_VERSION_V4: u32 = 4; /// Generator version of a class v5 program (proof of stored state and of following, 7 October 2026, PROPOSED: /// `program_id(5, seed, attempt)`; `docs/design/class-v5-stored-state.md`). pub const GENERATOR_VERSION_V5: u32 = 5; +/// Class v6 (the Igneum 2.0 D1 object, 8 October 2026; review B's F03): the class v5 draw with the v6 rules (the index fold, the +/// re-weight table, the 64-register window with the full chain, the five shuffle dimensions and the mad operand rule by +/// construction, layer 8 off when the flag says so), generator 6. +pub const GENERATOR_VERSION_V6: u32 = 6; /// The program class of an epoch (Counter ASIC 2.0, 5 October 2026, `docs/plans/counter-asic-2-rollout.md`): one /// height switch in the node, `program_class_v3_activation_daa`, rounded up to an epoch boundary, decides which @@ -951,6 +983,8 @@ pub enum ProgramClass { /// Class v5 (`docs/design/class-v5-stored-state.md`, behind `program_class_v5_activation_daa`): class v4's program /// over a dataset whose every item is keyed by the window's execution state ([`V5_CLASS`]), generator 5. V5, + /// Class v6 (the Igneum 2.0 D1 object; review B's F03, 8 October 2026): [`V6_CLASS`], generator 6. + V6, } /// The load class of program class v3, decided 5 October 2026 (Counter ASIC 2.0, `docs/plans/counter-asic-2-status.md` @@ -973,6 +1007,9 @@ pub const V4_CLASS: LoadClass = LoadClass { shadow: Some(ShadowClass { instrs: V /// program draw, the shadow block, the era draw and the ladder rung are class v4's, draw for draw; only the item /// derivation and the program id change. pub const V5_CLASS: LoadClass = LoadClass { state: true, ..V4_CLASS }; +/// The class v6 object ("mx8+sh256x27+state+reg64c+fold+rw"): class v5 with the index fold, the k lane's re-weight table +/// and the 64-register window with the full chain; layer 8 off is the fifth flag, drawn by the chain's family flags. +pub const V6_CLASS: LoadClass = LoadClass { fold: true, rw: 1, reg64: true, reg64_chain: true, ..V5_CLASS }; /// The shadow block size of class v4 at every rung of the latency ladder (`docs/design/latency-ladder.md`): 256 /// instructions. The ladder moves the pass count alone. @@ -1037,6 +1074,8 @@ pub fn era_generator_of(base: &LoadClass) -> u32 { match ProgramClass::of_load_class(base) { Some(ProgramClass::V4) => GENERATOR_VERSION_V4, Some(ProgramClass::V5) => GENERATOR_VERSION_V5, + Some(ProgramClass::V6) => GENERATOR_VERSION_V6, + _ if base.is_v6() => GENERATOR_VERSION_V6, _ if base.state => GENERATOR_VERSION_V5, _ => GENERATOR_VERSION_V3, } @@ -1067,6 +1106,7 @@ impl ProgramClass { ProgramClass::V3 => V3_CLASS, ProgramClass::V4 => V4_CLASS, ProgramClass::V5 => V5_CLASS, + ProgramClass::V6 => V6_CLASS, } } @@ -1077,12 +1117,13 @@ impl ProgramClass { ProgramClass::V3 => GENERATOR_VERSION_V3, ProgramClass::V4 => GENERATOR_VERSION_V4, ProgramClass::V5 => GENERATOR_VERSION_V5, + ProgramClass::V6 => GENERATOR_VERSION_V6, } } /// Whether the class's dataset is keyed by the window's execution state (class v5). pub fn has_state(&self) -> bool { - *self == ProgramClass::V5 + matches!(self, ProgramClass::V5 | ProgramClass::V6) } /// The class of a generator version: 2, 3 and 4 are the three classes, anything else is no class this crate runs. @@ -1092,6 +1133,7 @@ impl ProgramClass { GENERATOR_VERSION_V3 => Some(ProgramClass::V3), GENERATOR_VERSION_V4 => Some(ProgramClass::V4), GENERATOR_VERSION_V5 => Some(ProgramClass::V5), + GENERATOR_VERSION_V6 => Some(ProgramClass::V6), _ => None, } } @@ -1103,6 +1145,7 @@ impl ProgramClass { ProgramClass::V3 => "v3", ProgramClass::V4 => "v4", ProgramClass::V5 => "v5", + ProgramClass::V6 => "v6", } } @@ -1112,6 +1155,7 @@ impl ProgramClass { "v3" => Some(ProgramClass::V3), "v4" => Some(ProgramClass::V4), "v5" => Some(ProgramClass::V5), + "v6" => Some(ProgramClass::V6), _ => None, } } @@ -1125,6 +1169,7 @@ impl ProgramClass { /// is v3, [`V4_CLASS`] is v4; a measurement class (a width, a derivation length, another shadow size) is none. pub fn of_load_class(class: &LoadClass) -> Option { let base = LoadClass { era: None, reg64: false, reg64_chain: false, ..*class }; + let v6base = LoadClass { era: None, nowin: false, ..*class }; if base == LoadClass::V2 { Some(ProgramClass::V2) } else if base == V3_CLASS { @@ -1133,6 +1178,8 @@ impl ProgramClass { Some(ProgramClass::V4) } else if base == V5_CLASS { Some(ProgramClass::V5) + } else if v6base == V6_CLASS { + Some(ProgramClass::V6) } else { None } @@ -1194,9 +1241,25 @@ impl Program { } out } + /// The drawn program's memory operations per nonce (16 load slots times the eight iterations on every class): + /// the count the acceptance rule and the draw's bookkeeping read (the acceptance judges the drawn program's + /// sites). The hash EXECUTES [`Program::loads_per_hash_executed`] of them, twice this under the 64-register + /// window; the served figures and the pack's headers name the executed count (review B's V6-02). pub fn loads_per_hash(&self) -> usize { self.instrs.iter().filter(|i| i.op.is_load()).count() * ITERATIONS } + + /// Memory operations the hash EXECUTES per nonce (review B's V6-02, 8 October 2026): the scheduled statements + /// (the drawn program's loads, twice under the 64-register window) times the eight iterations; asserted to + /// agree with the drawn count except by the window's factor of two. The emitters alone read it (program.h, + /// program.json): the acceptance reads the drawn count, so no verdict moves with the served figure (the first + /// form of this change, 0266c9ec0, routed the executed count into the acceptance and moved every reg64 verdict). + pub fn loads_per_hash_executed(&self) -> usize { + let drawn = self.loads_per_hash(); + let executed = self.scheduled().iter().filter(|i| i.op.is_load()).count() * ITERATIONS; + assert!(executed == drawn || (self.class.reg64 && executed == 2 * drawn), "the executed load count {executed} disagrees with the drawn {drawn}"); + executed + } pub fn wide_loads_per_hash(&self) -> usize { self.instrs.iter().filter(|i| i.op == Op::WLoad).count() * ITERATIONS } @@ -1204,9 +1267,21 @@ impl Program { self.instrs.iter().any(|i| i.op == Op::WLoad) } /// Dataset bytes read per hash: 4 per one-word load, 16 and 64 for the wider loads of the experiment. + /// Dataset bytes the drawn program's loads demand per nonce (the acceptance's and the draw's figure). pub fn bytes_per_hash(&self) -> usize { self.instrs.iter().filter(|i| i.op == Op::Load).map(|i| i.width as usize * 4).sum::() * ITERATIONS } + + /// Dataset bytes the hash's EXECUTED loads demand per nonce (review B's V6-02): the scheduled loads' widths in + /// words times 4, times the eight iterations; a demand figure, not the memory's transactions (a 4-byte load is + /// a 32-byte sector on NVIDIA and a 64-byte line on AMD; the served text names the model it quotes). The + /// emitters alone read it. + pub fn bytes_per_hash_executed(&self) -> usize { + let drawn = self.bytes_per_hash(); + let executed = self.scheduled().iter().filter(|i| i.op == Op::Load).map(|i| i.width as usize * 4).sum::() * ITERATIONS; + assert!(executed == drawn || (self.class.reg64 && executed == 2 * drawn), "the executed byte demand {executed} disagrees with the drawn {drawn}"); + executed + } /// Scratch read-modify-writes per hash (variant 5): each reads 16 bytes and writes 16 bytes. pub fn scratch_ops_per_hash(&self) -> usize { self.instrs.iter().filter(|i| i.op == Op::Scratch).count() * ITERATIONS @@ -1328,6 +1403,7 @@ impl Program { GENERATOR_VERSION_V3 => ProgramClass::V3, GENERATOR_VERSION_V4 => ProgramClass::V4, GENERATOR_VERSION_V5 => ProgramClass::V5, + GENERATOR_VERSION_V6 => ProgramClass::V6, _ => ProgramClass::V2, } } @@ -1458,6 +1534,14 @@ pub fn program_id_class_recipe(generator: u32, seed: &[u32; 8], attempt: u32, cl // class v6 lane 1: the index fold moves every era load address r.lit(b"fold/"); } + if class.nowin { + // D2 "layer 8 off": the window layer is part of the construction + r.lit(b"nowin/"); + } + if class.is_v6() { + // the v6 draw rules (A02 five shuffle dimensions, A08 the mad operand rule) are part of the construction + r.lit(b"v6draw/"); + } if class.rw != 0 { // class v6 lane 1: the re-weight table moves the op draw r.lit(b"rw/"); @@ -1626,6 +1710,23 @@ pub fn candidate_from_words_class( for &slot in &p[..slots] { is_load[slot as usize] = true; } + // class v6 (A02, by construction): five of the non-load slots are shuffles over the five lane dimensions in a + // drawn order; drawn from the stream after the load slots, so no other class's stream moves + let mut is_shfl = [false; INSTR_COUNT]; + let mut shfl_masks = [1u8, 2, 4, 8, 16]; + if class.is_v6() { + let rest = &mut p[slots..]; + for i in 0..5 { + let j = i + rng.below((rest.len() - i) as u64) as usize; + rest.swap(i, j); + is_shfl[rest[i] as usize] = true; + } + for i in 0..5 { + let j = i + rng.below((5 - i) as u64) as usize; + shfl_masks.swap(i, j); + } + } + let mut shfl_next = 0usize; // Variant 5: the first k drawn load slots (a uniform k-subset, the draw order is random) are scratch ops. let mut is_scratch = [false; INSTR_COUNT]; for &slot in &p[..class.scratch_slots()] { @@ -1652,7 +1753,7 @@ pub fn candidate_from_words_class( // class v6 lane 1: the index fold and the re-weight table are set aside too (the address path and the table are not // the shape; a +fold or +rw program draws its sources under the same rule) let source_rule_v4 = matches!(class.shadow, Some(ShadowClass { instrs: V4_SHADOW_INSTRS, .. })) - && LoadClass { era: None, shadow: None, state: false, fold: false, rw: 0, ..class } == LoadClass { shadow: None, ..V4_CLASS }; + && LoadClass { era: None, shadow: None, state: false, fold: false, rw: 0, nowin: false, reg64: false, reg64_chain: false, mix: V4_CLASS.mix, ..class } == LoadClass { shadow: None, ..V4_CLASS }; // the op table and the roll's range: the plain table at 75 for every class without the re-weight flag let (weights, weights_sum) = class.nonload_weights(); let mut fresh = [false; 8]; @@ -1682,6 +1783,9 @@ pub fn candidate_from_words_class( Op::Load }; } + if is_shfl[k] { + op = Op::Shfl; + } let dst = rng.below(8); let src = if op.is_load() { let mut eligible = [0u64; 8]; @@ -1710,12 +1814,21 @@ pub fn candidate_from_words_class( a } }; - let b = rng.below(8); + let mut b = rng.below(8); + // class v6 (A08, by construction): a mad's second source is never its destination + if class.is_v6() && op == Op::Mad && b == dst { + b = (b + 1) & 7; + } let imm = rng.next() as u32; let imm2 = rng.next() as u32; let rot = 1 + rng.below(31) as u32; let bit = rng.below(32); - let mask = 1u8 << rng.below(5); + let mut mask = 1u8 << rng.below(5); + // class v6 (A02): the reserved shuffle slots take the five dimensions in the drawn order + if is_shfl[k] { + mask = shfl_masks[shfl_next]; + shfl_next += 1; + } // Version 2 loads take no width roll, so a mixer class with version 2 loads draws the version 2 program let width = if class.takes_width_roll() { class.width_for_roll(rng.below(100)) } else { 1 }; let width = if op == Op::Load { width } else { 1 }; @@ -1723,7 +1836,8 @@ pub fn candidate_from_words_class( let (win, off) = if class.era.is_some() { let k = rng.below(3) as u8; let o = (rng.next() as u32 & ((1u32 << k) - 1)) as u8; - if op == Op::Load { + // D2 "layer 8 off": the draws are consumed (the stream is the class's) and every site reads the whole dataset + if op == Op::Load && !class.nowin { (k, o) } else { (0, 0) @@ -1963,6 +2077,7 @@ pub fn generate_from_seed_bytes_program_class(seed_string: &str, seed_bytes: &[u (ProgramClass::V3, Some(era)) => return generate_era(seed_string, seed_bytes, V3_CLASS, era, &V3_ALLOWED), (ProgramClass::V4, Some(era)) => return generate_era_generator(seed_string, seed_bytes, V4_CLASS, era, &V3_ALLOWED, GENERATOR_VERSION_V4), // Class v5: the same draw inside V5_CLASS (V4_CLASS plus the state flag, which the draw does not read), generator 5. + (ProgramClass::V6, Some(era)) => return generate_era_generator(seed_string, seed_bytes, V6_CLASS, era, &V3_ALLOWED, GENERATOR_VERSION_V6), (ProgramClass::V5, Some(era)) => return generate_era_generator(seed_string, seed_bytes, V5_CLASS, era, &V3_ALLOWED, GENERATOR_VERSION_V5), _ => {} } @@ -1980,11 +2095,11 @@ pub fn generate_from_seed_bytes_program_class(seed_string: &str, seed_bytes: &[u /// and class v4 at rung 0, is [`generate_from_seed_bytes_program_class`] byte for byte. The base program, the 16 loads /// and the era draw do not move with the rung: only the pass count of the shadow block does. pub fn generate_from_seed_bytes_program_class_shadow(seed_string: &str, seed_bytes: &[u8], class: ProgramClass, era_bytes: Option<&[u8]>, shadow_reps: u16) -> Program { - if !matches!(class, ProgramClass::V4 | ProgramClass::V5) || shadow_reps == 0 || shadow_reps == V4_SHADOW_REPS { + if !matches!(class, ProgramClass::V4 | ProgramClass::V5 | ProgramClass::V6) || shadow_reps == 0 || shadow_reps == V4_SHADOW_REPS { return generate_from_seed_bytes_program_class(seed_string, seed_bytes, class, era_bytes); } // class v5 at a rung: class v4's rung with the state flag, generator 5 - let (base, generator) = if class == ProgramClass::V5 { (v5_class_at(shadow_reps), GENERATOR_VERSION_V5) } else { (v4_class_at(shadow_reps), GENERATOR_VERSION_V4) }; + let (base, generator) = if class == ProgramClass::V6 { (LoadClass { fold: true, rw: 1, reg64: true, reg64_chain: true, ..v5_class_at(shadow_reps) }, GENERATOR_VERSION_V6) } else if class == ProgramClass::V5 { (v5_class_at(shadow_reps), GENERATOR_VERSION_V5) } else { (v4_class_at(shadow_reps), GENERATOR_VERSION_V4) }; match era_bytes { Some(era) => generate_era_generator(seed_string, seed_bytes, base, era, &V3_ALLOWED, generator), None => { @@ -2330,14 +2445,15 @@ mod tests { assert_eq!(v3.program_id(), program_id(GENERATOR_VERSION_V3, &v3.seed, v3.attempt)); assert_ne!(v3.program_id(), program_id(GENERATOR_VERSION, &v3.seed, v3.attempt)); assert_ne!(v3.program_id(), v2.program_id()); - for c in [ProgramClass::V2, ProgramClass::V3, ProgramClass::V4, ProgramClass::V5] { + for c in [ProgramClass::V2, ProgramClass::V3, ProgramClass::V4, ProgramClass::V5, ProgramClass::V6] { assert_eq!(ProgramClass::parse(c.name()), Some(c)); assert_eq!(ProgramClass::from_generator(c.generator_version()), Some(c)); assert_eq!(ProgramClass::from_u8(c.as_u8()), Some(c)); } assert_eq!(ProgramClass::from_generator(1), None); - assert_eq!(ProgramClass::from_generator(6), None); - assert_eq!(ProgramClass::parse("v6"), None); + assert_eq!(ProgramClass::from_generator(6), Some(ProgramClass::V6), "class v6 is generator 6 (review B's F03, 8 October 2026)"); + assert_eq!(ProgramClass::from_generator(7), None); + assert_eq!(ProgramClass::parse("v7"), None); assert_eq!(ProgramClass::default(), ProgramClass::V2); assert_eq!(ProgramClass::V2.load_class(), LoadClass::V2); assert!(!ProgramClass::V2.has_era() && ProgramClass::V3.has_era() && ProgramClass::V4.has_era() && ProgramClass::V5.has_era()); diff --git a/igneum-pow/src/main.rs b/igneum-pow/src/main.rs index 393b1eb81..205f6ce66 100644 --- a/igneum-pow/src/main.rs +++ b/igneum-pow/src/main.rs @@ -122,7 +122,8 @@ fn usage() -> ! { \x20 --era-widths 4[,16,32,64] the width set the era draws from, in bytes (default 4: pinned; more lets the era draw it; 32 only with the w32 class)\n\ \x20 --dataset-words N research class ds55: the dataset at N words (a multiple of 65,536 in 2^28 ..= 2^31; 1476395008 = 5.5 GiB); a non-power-of-two uses idx = (src * N) >> 32 in every load (spec 01 section 1.13.3), a power of two is --dataset-log2\n\\ \x20 --reg64 the 64-register window per lane over the class (research; the same as --class +reg64; CUDA, OpenCL and Metal texts)\n\ - \x20 --reg64-chain reg64 with the full-chain address mix: every load's address consumes all 64 registers (the same as --class +reg64c)" + \x20 --reg64-chain reg64 with the full-chain address mix: every load's address consumes all 64 registers (the same as --class +reg64c)\n\ + \x20 --reg64-prefix export: the CUDA texts carry the reg64 chain in its closed prefix form (review B's F05; the same hash and vectors, a measurement text)" ); std::process::exit(2) } @@ -189,6 +190,7 @@ fn parse() -> Args { a.reg64 = true; a.reg64_chain = true; } + "--reg64-prefix" => igneum_pow::emit::set_reg64_prefix(true), _ => usage(), } } @@ -229,10 +231,29 @@ fn main() { // gate G2 (5 October 2026, ported from branch ca2-era for the class v4 gate run): `--count N` prints // "nonce hash" for N consecutive 64-bit nonces from --nonce, one epoch build, to re-hash a worker's // found lines (the same prehash, target ff..ff) - for k in 0..a.count { - let n = a.nonce.wrapping_add(k); - println!("{n} {:016x}", e.hash_bound(&prehash, n)); + // one warp per 32 nonces (the P01 campaign, 8 October 2026: a million nonces per pack in minutes, not + // hours; the per-nonce form hashed the whole aligned group for every nonce) + let end = a.nonce.wrapping_add(a.count); + let mut n = a.nonce; + let mut out = String::with_capacity(1 << 16); + use std::io::Write; + let stdout = std::io::stdout(); + let mut lock = stdout.lock(); + while n != end { + let base = n & !31; + let warp = e.hash_warp_bound(&prehash, base); + let mut m = n; + while m != end && (m & !31) == base { + out.push_str(&format!("{m} {:016x}\n", warp[(m & 31) as usize])); + m = m.wrapping_add(1); + } + n = m; + if out.len() > (1 << 15) { + lock.write_all(out.as_bytes()).unwrap(); + out.clear(); + } } + lock.write_all(out.as_bytes()).unwrap(); return; } let init = igneum_pow::bind::block_init_words(&prehash, a.nonce); diff --git a/igneum-pow/src/packcheck.rs b/igneum-pow/src/packcheck.rs index a7cbea7f5..b75e5a073 100644 --- a/igneum-pow/src/packcheck.rs +++ b/igneum-pow/src/packcheck.rs @@ -199,14 +199,14 @@ pub fn verify_pack_texts_chain( // carries IGNEUM_STATE_ROOT_HEX (and the shadow block of v4) and no other generator does. let state_root_hex = define_str(program_h, "IGNEUM_STATE_ROOT_HEX"); match (class, state_root_hex.is_some()) { - (ProgramClass::V5, false) => return Err(PackFault::Disagree("IGNEUM_GENERATOR 5 (class v5) without IGNEUM_STATE_ROOT_HEX: not a class v5 pack".into())), - (ProgramClass::V5, true) => {} + (ProgramClass::V5 | ProgramClass::V6, false) => return Err(PackFault::Disagree("IGNEUM_GENERATOR 5 or 6 (a state class) without IGNEUM_STATE_ROOT_HEX: not a class v5 pack".into())), + (ProgramClass::V5 | ProgramClass::V6, true) => {} (_, true) => return Err(PackFault::Disagree(format!("IGNEUM_GENERATOR {generator} with class v5 state lines: a program over state leaves is generator 5 (export the pack as class v5)"))), _ => {} } match (class, shadow > 0) { (ProgramClass::V4, false) => return Err(PackFault::Disagree("IGNEUM_GENERATOR 4 (class v4) without IGNEUM_SHADOW_INSTRS: not a class v4 pack".into())), - (ProgramClass::V5, false) => return Err(PackFault::Disagree("IGNEUM_GENERATOR 5 (class v5) without IGNEUM_SHADOW_INSTRS: not a class v5 pack".into())), + (ProgramClass::V5 | ProgramClass::V6, false) => return Err(PackFault::Disagree("IGNEUM_GENERATOR 5 or 6 (a state class) without IGNEUM_SHADOW_INSTRS: not a class v5 pack".into())), // the class v4 stream sub-version (AP-F8-1 amendment, 7 October 2026): a generator 4 pack from before the // load-source rule carries no IGNEUM_PROGRAM_SUBVERSION and its program id is another stream's; refused (ProgramClass::V4, true) if define_u32(program_h, "IGNEUM_PROGRAM_SUBVERSION") != Some(u32::from(crate::generator::PROGRAM_SUBVERSION_V4)) => { diff --git a/igneum-pow/src/verify.rs b/igneum-pow/src/verify.rs index 75ea927b1..c0dc217b8 100644 --- a/igneum-pow/src/verify.rs +++ b/igneum-pow/src/verify.rs @@ -1172,3 +1172,91 @@ mod tests { assert!(!e.verify_block(0, w[0] - 1)); } } + + +/// Review B's F05 (8 October 2026): the reg64 full-chain address source in closed form. The reference fold +/// (`m = r[k0]; m = rotl(m, 1) ^ r[k1]; ...` over the 63 registers other than `s`, in index order) equals +/// `r[s] ^ ror(P_s, 1) ^ (S ^ P_s ^ a[s])` with `a[k] = rotl(r[k], (63 - k) mod 32)`, `S` the xor of every `a[k]` +/// and `P_s` the xor of `a[k]` for `k < s`: a prefix-xor structure answers every load from one `S` and one prefix, +/// which is the incremental form a chip would keep. The verifier keeps the fold as the definition; this form is the +/// test's and the fleet's measurement's. +pub fn reg64_address_source(r: &[u32; 64], s: usize) -> u32 { + let a = |k: usize| r[k].rotate_left(((63 - k) % 32) as u32); + let mut total = 0u32; + let mut prefix = 0u32; + for k in 0..64 { + total ^= a(k); + if k < s { + prefix ^= a(k); + } + } + r[s] ^ prefix.rotate_right(1) ^ (total ^ prefix ^ a(s)) +} + +/// The reference fold of [`reg64_address_source`] on one lane's registers, as `interpret_warp_core` computes it. +pub fn reg64_address_source_reference(r: &[u32; 64], s: usize) -> u32 { + let mut m = 0u32; + let mut started = false; + for (k, &v) in r.iter().enumerate() { + if k == s { + continue; + } + m = if started { m.rotate_left(1) ^ v } else { v }; + started = true; + } + r[s] ^ m +} + +#[cfg(test)] +mod reg64_mix_tests { + use super::*; + + /// Review B's F05, known-failed first: a form with one rotation off (every term rotated as if it sat after the + /// source) disagrees with the reference on some source; the closed form agrees on every source register over + /// 256 register states drawn from a fixed stream and over the states a real program leaves in its registers. + #[test] + fn reg64_closed_form_equals_the_reference_fold_on_every_source() { + let wrong = |r: &[u32; 64], s: usize| -> u32 { + let a = |k: usize| r[k].rotate_left(((63 - k) % 32) as u32); + let total: u32 = (0..64).map(a).fold(0, |x, y| x ^ y); + r[s] ^ total ^ a(s) + }; + let mut x = 0x9e37_79b9_7f4a_7c15u64; + let mut next = || { + x = x.wrapping_add(0x9e37_79b9_7f4a_7c15); + let mut z = x; + z = (z ^ (z >> 30)).wrapping_mul(0xbf58_476d_1ce4_e5b9); + z = (z ^ (z >> 27)).wrapping_mul(0x94d0_49bb_1331_11eb); + (z ^ (z >> 31)) as u32 + }; + let mut wrong_differs = false; + for _ in 0..256 { + let mut r = [0u32; 64]; + for v in r.iter_mut() { + *v = next(); + } + for s in 0..64 { + assert_eq!(reg64_address_source(&r, s), reg64_address_source_reference(&r, s), "source r{s}"); + if wrong(&r, s) != reg64_address_source_reference(&r, s) { + wrong_differs = true; + } + } + } + assert!(wrong_differs, "the known-failed form must disagree somewhere"); + // the init rule's registers (r0..r7 seeded, r[k] = r[k & 7] * 0x9e3779b9 + k) and a few real updates + let mut r = [0u32; 64]; + for (k, v) in r.iter_mut().enumerate().take(8) { + *v = next() ^ (k as u32); + } + for k in 8..64 { + r[k] = r[k & 7].wrapping_mul(0x9e37_79b9).wrapping_add(k as u32); + } + for step in 0..64 { + let d = (step * 7 + 3) % 64; + r[d] = r[d].wrapping_mul(r[(d + 13) % 64]).wrapping_add(next()); + for s in 0..64 { + assert_eq!(reg64_address_source(&r, s), reg64_address_source_reference(&r, s), "step {step} source r{s}"); + } + } + } +} diff --git a/igneum-pow/tests/ds55.rs b/igneum-pow/tests/ds55.rs index 821cd76cf..4bff40706 100644 --- a/igneum-pow/tests/ds55.rs +++ b/igneum-pow/tests/ds55.rs @@ -68,8 +68,11 @@ fn power_of_two_path_is_byte_identical_to_the_pinned_pack() { assert!(!e.dataset.geom.mulshift); assert_eq!(e.dataset.geom, DatasetGeom::pow2(28)); let out = export_pack(e, &day_label(), SOURCE); - assert_eq!(out.files.len(), 12, "the pack's twelve files"); + assert_eq!(out.files.len(), 13, "the pack's thirteen files"); for (name, text) in &out.files { + if name == "identity.json" { + continue; // A06's identity file is new beside the pinned twelve + } let want = pinned(name); assert!(text == &want, "mx8-devnet-epoch0/{name} differs from the default path's export"); } @@ -219,7 +222,7 @@ fn ds55_pack_fields_and_vectors() { assert_eq!(e.program.seed[0], 0x667d_0fbd); assert_eq!(e.program.seed[1], 0x7b8e_5963); let out = export_pack(e, &day_label(), SOURCE); - assert_eq!(out.files.len(), 12); + assert_eq!(out.files.len(), 13); let pj = &out.files.iter().find(|(n, _)| n == "program.json").unwrap().1; let j: Value = serde_json::from_str(pj).expect("program.json is valid JSON"); assert_eq!(j["program_id"].as_str().unwrap(), "0x73bcbfe8ccf988f1"); diff --git a/igneum-pow/tests/fuzz_parsers.rs b/igneum-pow/tests/fuzz_parsers.rs new file mode 100644 index 000000000..a52ac6ea3 --- /dev/null +++ b/igneum-pow/tests/fuzz_parsers.rs @@ -0,0 +1,132 @@ +//! POW-01 and POW-02's malformed-input half (the Test and Acceptance Standard, 8 October 2026): 10,000 mutated inputs +//! per parser, every one refused cleanly or accepted, never a panic. The parsers: the class string (`LoadClass::parse`, +//! `ProgramClass::parse`), the hex reader (`bind::unhex`), the IGSD1 state stream (`StateStream::decode`), the era +//! string form (`":<64 hex>"`, the exporter's `parse_era` re-stated here since main.rs keeps it private). The +//! mutations: byte flips, truncation, insertion, duplication and random bytes over a valid seed input, drawn from a +//! fixed SplitMix64 so the run is reproducible; a panic in any parser fails the test (the harness catches none). +use igneum_pow::bind::unhex; +use igneum_pow::generator::{LoadClass, ProgramClass}; +use igneum_pow::state::StateStream; + +struct Rng(u64); +impl Rng { + fn next(&mut self) -> u64 { + self.0 = self.0.wrapping_add(0x9e3779b97f4a7c15); + let mut z = self.0; + z = (z ^ (z >> 30)).wrapping_mul(0xbf58476d1ce4e5b9); + z = (z ^ (z >> 27)).wrapping_mul(0x94d049bb133111eb); + z ^ (z >> 31) + } + fn below(&mut self, n: usize) -> usize { + (self.next() % (n.max(1) as u64)) as usize + } +} + +/// One mutation of `seed`: a flipped byte, a truncation, an insertion, a doubled slice, or random bytes of a random length. +fn mutate(rng: &mut Rng, seed: &[u8]) -> Vec { + let mut v = seed.to_vec(); + match rng.below(6) { + 0 => { + if !v.is_empty() { + let i = rng.below(v.len()); + v[i] ^= 1 << rng.below(8); + } + } + 1 => { + let n = rng.below(v.len() + 1); + v.truncate(n); + } + 2 => { + let i = rng.below(v.len() + 1); + v.insert(i, rng.next() as u8); + } + 3 => { + if v.len() > 1 { + let a = rng.below(v.len()); + let b = a + rng.below(v.len() - a); + let slice = v[a..b].to_vec(); + v.splice(a..a, slice); + } + } + 4 => { + let n = rng.below(300); + v = (0..n).map(|_| rng.next() as u8).collect(); + } + _ => { + if !v.is_empty() { + let i = rng.below(v.len()); + v[i] = rng.next() as u8; + } + } + } + v +} + +const N: usize = 10_000; + +#[test] +fn class_strings_never_panic() { + let seeds = ["mx8+sh256x27+state+reg64c+fold+rw", "mx8+sh256x27+state+nowin", "w32m8g-erad810f22d+sh256x27+state", "v2", "mix50-35-15", "scr4k32+hot64k4a", "mx4", "p4,p16,p64", "w64x4", "mx8+rw2"]; + let mut rng = Rng(1); + let (mut some, mut none) = (0, 0); + for k in 0..N { + let s = mutate(&mut rng, seeds[k % seeds.len()].as_bytes()); + let text = String::from_utf8_lossy(&s); + match LoadClass::parse(&text) { + Some(c) => { + // an accepted string names back to something the parser accepts again + assert!(LoadClass::parse(&c.name()).is_some(), "{text:?} -> {} does not re-parse", c.name()); + some += 1; + } + None => none += 1, + } + let _ = ProgramClass::parse(&text); + } + println!("class strings: {some} accepted, {none} refused of {N}"); + assert!(none > N / 2, "the mutations refuse at least half"); +} + +#[test] +fn hex_and_era_strings_never_panic() { + let hex = "edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07"; + let mut rng = Rng(2); + let mut refused = 0; + for _ in 0..N { + let s = mutate(&mut rng, hex.as_bytes()); + let text = String::from_utf8_lossy(&s); + if unhex(&text).is_none() { + refused += 1; + } + // the era string ":<64 hex>" as the exporter reads it + let era = format!("{}:{}", rng.below(1000), text); + let parsed = era.split_once(':').and_then(|(n, h)| n.parse::().ok().zip(unhex(h))).filter(|(_, b)| b.len() == 32); + if let Some((_, b)) = parsed { + assert_eq!(b.len(), 32); + } + } + println!("hex strings: {refused} refused of {N}"); + assert!(refused > 0); +} + +#[test] +fn state_streams_never_panic() { + // a small valid stream: three records under a fixed root and block + let stream = StateStream { number: 159357, block: [7u8; 32], root: [9u8; 32], records: vec![vec![1, 2, 3], vec![], (0..200u8).collect()] }; + let valid = stream.encode(); + assert_eq!(StateStream::decode(&valid).map(|s| s.records.len()), Ok(3)); + let mut rng = Rng(3); + let (mut ok, mut err) = (0, 0); + for _ in 0..N { + let bytes = mutate(&mut rng, &valid); + match StateStream::decode(&bytes) { + Ok(s) => { + // an accepted stream re-encodes to the bytes it was read from + assert_eq!(s.encode(), bytes, "an accepted stream must round-trip"); + ok += 1; + } + Err(_) => err += 1, + } + } + println!("state streams: {ok} accepted, {err} refused of {N}"); + assert!(err > N / 2); +} diff --git a/igneum-pow/tests/mixer.rs b/igneum-pow/tests/mixer.rs index f4644ae8d..43ddeeb41 100644 --- a/igneum-pow/tests/mixer.rs +++ b/igneum-pow/tests/mixer.rs @@ -347,8 +347,8 @@ fn determinism_v3() { }; println!("determinism {}: two builds equal, against the pinned pack {}", class.name(), dir.display()); for (name, text) in &pa.files { - if name == "vectors.json" || name == "vectors.h" { - continue; // the source string differs ("a" here) + if name == "vectors.json" || name == "vectors.h" || name == "identity.json" { + continue; // the source string differs ("a" here); identity.json is new beside the pinned twelve (A06) } let on_disk = std::fs::read_to_string(dir.join(name)).unwrap(); assert_eq!(&on_disk, text, "{name}"); diff --git a/igneum-pow/tests/packs.rs b/igneum-pow/tests/packs.rs index 9b3aecf48..cd872c6a5 100644 --- a/igneum-pow/tests/packs.rs +++ b/igneum-pow/tests/packs.rs @@ -433,7 +433,9 @@ fn check_export(pack: &str) { if e.dataset.mode() == DatasetMode::MemoryHard { expected.extend(["memhard.h", "memhard.metal"]); } - assert_eq!(out.files.iter().map(|(n, _)| n.as_str()).collect::>(), expected); + let mut with_identity: Vec<&str> = expected.clone(); + with_identity.insert(1, "identity.json"); + assert_eq!(out.files.iter().map(|(n, _)| n.as_str()).collect::>(), with_identity); let mut on_disk: Vec = std::fs::read_dir(pack_dir(pack)) .unwrap() .map(|d| d.unwrap().file_name().to_string_lossy().to_string()) @@ -646,6 +648,9 @@ fn era_emitted_sources_match_and_loads_have_the_era_form() { let source = era_json(pack, "vectors.json")["source"].as_str().unwrap().to_string(); let out = export_pack(e, &day, &source); for (name, text) in &out.files { + if name == "identity.json" { + continue; // A06's identity file is new beside the pinned files + } let want = era_read(pack, name); assert!(text == &want, "{pack}/{name} differs from the emitter"); } @@ -655,7 +660,7 @@ fn era_emitted_sources_match_and_loads_have_the_era_form() { .filter(|n| !n.starts_with('.') && n != "seeds.txt") .collect(); on_disk.sort(); - let mut want: Vec = out.files.iter().map(|(n, _)| n.clone()).collect(); + let mut want: Vec = out.files.iter().map(|(n, _)| n.clone()).filter(|n| n != "identity.json").collect(); want.sort(); assert_eq!(on_disk, want, "{pack}: the pack holds the export's files and seeds.txt only"); let era = e.program.class.era.unwrap(); @@ -869,7 +874,7 @@ fn hot_packs_emitted_sources_and_load_forms() { let file = |name: &str| -> &str { &out.files.iter().find(|(n, _)| n == name).unwrap().1 }; hassert_same_text(pack, "vectors.json", file("vectors.json")); hassert_same_text(pack, "vectors.h", file("vectors.h")); - assert_eq!(out.files.len(), 12); + assert_eq!(out.files.len(), 13); // One form per dialect, exactly 16 - k masked dataset loads and k hot loads in every hash kernel; the fill // kernel is present once per source that builds the table. for (file, load, masked, hot) in [ @@ -974,6 +979,9 @@ fn v5_pack_is_the_v4_program_over_the_state_leaves() { let v = v5_json(pack, "vectors.json"); let out = export_pack(e, v["day"].as_str().unwrap(), v["source"].as_str().unwrap()); for (name, text) in &out.files { + if name == "identity.json" { + continue; // A06's identity file is new beside the pinned files + } assert_eq!(v5_read(pack, name), *text, "{pack}/{name} differs from the export"); } for (name, bytes) in &out.binaries { @@ -1032,8 +1040,11 @@ fn reg64_plain_path_reexports_the_pinned_devnet_pack_unchanged() { assert_eq!(e.program.registers(), 8); assert_eq!(e.program.scheduled(), e.program.instrs, "without the flag the schedule is the drawn program"); let out = export_pack(e, &day_label(pack), PINNED_SOURCE); - assert_eq!(out.files.len(), 12); + assert_eq!(out.files.len(), 13); for (name, text) in &out.files { + if name == "identity.json" { + continue; // A06's identity file is new beside the pinned twelve + } assert_same_text(pack, name, text); } } @@ -1222,4 +1233,64 @@ fn reg64_liveness_rule_refuses_the_subset_fold_and_passes_the_full_chain() { let mut chain = epoch_reg64_of_devnet(); chain.program.class = chain.program.class.with_reg64_chain(); assert_eq!(check_window_liveness(&chain.program), Ok(()), "the full chain keeps all 64 registers live across the chain"); + // wired into the acceptance (8 October 2026): `accept::check` refuses the arithmetic-only window as a dead register + // and never refuses the chain program for liveness; the plain pack's verdict does not move + use igneum_pow::accept::check; + assert!(matches!(check(&window.program), Err(Reject::DeadWindowRegister { .. })), "the acceptance refuses the arithmetic-only window"); + assert!(!matches!(check(&chain.program), Err(Reject::DeadWindowRegister { .. }) | Err(Reject::NotAWindow)), "the chain program is never refused for liveness"); + assert!(check(&plain.program).is_ok(), "the pinned devnet program's verdict does not move"); +} + +/// The external review's A07 (8 October 2026): the bound hash of a nonce is the lane of the aligned 32-nonce group that +/// contains it, in the verifier by construction (`Epoch::hash_bound`), across the group's tail and the low-32 rollover; +/// the high 32 bits of the nonce enter the init words, so two nonces 2^32 apart never share a hash. The launchers +/// refuse a job whose nonce_start is not 32-aligned or whose count is not a multiple of 32 (worker.cpp's job line). +#[test] +fn a07_bound_hash_is_group_aligned_across_tails_and_rollover() { + use igneum_pow::bind::block_init_words; + let e = epoch("mx8-devnet-epoch0"); + let prehash = [0x5au8; 32]; + for &n in &[0u64, 1, 2, 31, 32, 33, 63, (1u64 << 32) - 1, 1u64 << 32, (1u64 << 32) + 1, u64::MAX - 1, u64::MAX] { + let base = n & !31; + let warp = e.hash_warp_bound(&prehash, base); + assert_eq!(e.hash_bound(&prehash, n), warp[(n & 31) as usize], "nonce {n}: the lane of its aligned group"); + assert_eq!(e.hash_warp_bound(&prehash, n), warp, "nonce {n}: the group is the same from any of its nonces"); + let distinct: std::collections::HashSet = warp.iter().copied().collect(); + assert!(distinct.len() >= 31, "nonce {n}: the lanes of a group are distinct hashes"); + } + assert_ne!(e.hash_bound(&prehash, 2), e.hash_bound(&prehash, 2 + (1u64 << 32)), "the high 32 bits reach the hash"); + assert_ne!(block_init_words(&prehash, 2), block_init_words(&prehash, 2 + (1u64 << 32))); +} + +/// The external review's A04 (8 October 2026): the acceptance executes the shadow block as the hash does (class v4 +/// sub-version 3), so a shadow that zeroes the registers fails acceptance; the pinned program with its own shadow passes. +#[test] +fn a04_a_zeroing_shadow_fails_acceptance() { + use igneum_pow::accept::check; + // a class v4 program (the shadow block is class v4's): the same seed and era as the lib's program_classes test + let era = [7u8; 32]; + let p = generate_from_seed_bytes_program_class("igneum-genesis", b"igneum-genesis", ProgramClass::V4, Some(&era)); + assert!(check(&p).is_ok(), "the class v4 program of the genesis seed passes"); + let mut z = p.clone(); + assert!(!z.shadow.is_empty(), "class v4 has a shadow block"); + for ins in z.shadow.iter_mut() { + ins.op = Op::Xor; + ins.src = ins.dst; + } + assert!(check(&z).is_err(), "a shadow of xor d, d zeroes every register it touches and must fail"); +} + +/// The external review's A06 (8 October 2026): the pack's identity.json authenticates every kernel text by BLAKE2b-256. +#[test] +fn a06_program_json_hashes_every_kernel_text() { + let e = epoch("mx8-devnet-epoch0"); + let out = export_pack(&e, &day_label("mx8-devnet-epoch0"), "test"); + let file = |n: &str| out.files.iter().find(|(f, _)| f == n).map(|(_, t)| t.clone()).unwrap(); + let j: Value = serde_json::from_str(&file("identity.json")).unwrap(); + let h = j["kernel_blake2b256"].as_object().expect("kernel_blake2b256"); + assert_eq!(j["program_id"].as_str().unwrap(), format!("{:#018x}", e.program.program_id())); + for n in ["kernel.cu", "kernel.cl", "program.metal", "program_bound.metal", "kernel_bound.cu", "kernel_bound.cl"] { + let want: String = igneum_pow::blake2b::blake2b_256(&[file(n).as_bytes()]).iter().map(|x| format!("{x:02x}")).collect(); + assert_eq!(h[n].as_str().unwrap(), want, "{n}"); + } } diff --git a/igneum-pow/tests/v6fold.rs b/igneum-pow/tests/v6fold.rs index 956ae5b86..c66c73d65 100644 --- a/igneum-pow/tests/v6fold.rs +++ b/igneum-pow/tests/v6fold.rs @@ -8,7 +8,7 @@ use igneum_pow::accept::{index_bit_sigma, index_bit_sigma_max, ACCEPT_UNITS_DIST use igneum_pow::emit::export_pack; use igneum_pow::generator::{ candidate_class, generate_era_generator, LoadClass, Op, Program, ProgramClass, EraParams, INSTR_COUNT, NONLOAD_WEIGHTS, - NONLOAD_WEIGHTS_RW, NONLOAD_WEIGHTS_RW2, NONLOAD_WEIGHTS_RW2_SUM, NONLOAD_WEIGHTS_RW_SUM, V3_ALLOWED, V4_CLASS, V5_CLASS, + NONLOAD_WEIGHTS_RW, NONLOAD_WEIGHTS_RW2, NONLOAD_WEIGHTS_RW2_SUM, NONLOAD_WEIGHTS_RW_SUM, V3_ALLOWED, V3_CLASS, V4_CLASS, V5_CLASS, }; use igneum_pow::seed::seed_words_from_bytes; use igneum_pow::verify::{load_index, stride, DatasetGeom, Epoch, INDEX_FOLD_SHIFT}; @@ -182,6 +182,123 @@ fn class_v6_all_flags_parse_name_and_id() { assert!(p.class.era.unwrap().fold); } +/// 1c. D2 "layer 8 off" (8 October 2026): "+nowin" parses in any order and names back inside "+fold"/"+rw"; the draw +/// keeps every instruction of the class without the flag and sets every load site's window to the whole dataset; +/// the id moves; the era and the stride do not. +#[test] +fn nowin_removes_the_window_layer_and_nothing_else() { + let c = LoadClass::parse("mx8+sh256x27+state+nowin+fold+rw").unwrap(); + assert!(c.nowin && c.fold && c.rw == 1 && c.state); + assert_eq!(c.name(), "mx8+sh256x27+state+nowin+fold+rw"); + assert_eq!(LoadClass::parse("mx8+sh256x27+state+fold+rw+nowin"), Some(c)); + assert_eq!(LoadClass::parse("mx8+sh256x27+state+reg64c+nowin").unwrap().name(), "mx8+sh256x27+state+reg64c+nowin"); + assert!(!V5_CLASS.nowin); + let era = f8_bytes("era", 4); + let seed = f8_bytes("program", 4); + // both sides of the pair draw under the v6 rules (the five shuffle slots and the mad operand rule enter the + // stream for every class with a v6 flag), so the pair is the fold class with and without layer 8 off + let plain = candidate_class("p4-attack-f8", &seed, 0, LoadClass::era(V5_CLASS.with_fold(), &era, &V3_ALLOWED)); + let off = candidate_class("p4-attack-f8", &seed, 0, LoadClass::era(V5_CLASS.with_fold().with_nowin(), &era, &V3_ALLOWED)); + assert_ne!(plain.program_id(), off.program_id(), "the id carries the flag"); + assert_eq!(plain.instrs.len(), off.instrs.len()); + let mut windows_plain = 0; + for (a, b) in plain.instrs.iter().zip(off.instrs.iter()) { + assert_eq!((a.op, a.dst, a.src, a.src2, a.imm, a.imm2, a.rot, a.bit, a.mask, a.width), (b.op, b.dst, b.src, b.src2, b.imm, b.imm2, b.rot, b.bit, b.mask, b.width), "the instruction is the class's without the flag"); + assert_eq!((b.win, b.off), (0, 0), "every site reads the whole dataset"); + if a.win != 0 { + windows_plain += 1; + } + } + assert!(windows_plain > 0, "the plain draw has at least one shrunk window on this seed"); + assert_eq!(plain.shadow, off.shadow); + assert_eq!(plain.class.era.map(|e| EraParams { fold: e.fold, ..e }), off.class.era.map(|e| EraParams { fold: e.fold, ..e }), "the era draw is untouched"); +} + +/// The external review's A02 and A08 (8 October 2026), fixed by construction for every class carrying a v6 flag: +/// every candidate of 64 seeds (attempt 0, no acceptance pass) carries shuffles over all five lane dimensions, and no +/// `mad` names its destination as its second source; the plain class v5 draw is untouched (the pinned pack test +/// reads that); the v6 draw's id carries the rule. +#[test] +fn v6_draw_connects_all_lanes_and_keeps_mad_bijective_by_construction() { + let era = f8_bytes("era", 4); + let classes = [V5_CLASS.with_fold(), V5_CLASS.with_rw(1), V5_CLASS.with_nowin(), LoadClass::parse("mx8+sh256x27+state+reg64c+fold+rw").unwrap()]; + for c in classes { + assert!(c.is_v6()); + for k in 0..64u32 { + let seed = f8_bytes("program", k); + let p = candidate_class("p-a02", &seed, 0, LoadClass::era(c, &era, &V3_ALLOWED)); + let mut dims = [false; 5]; + for ins in &p.instrs { + if ins.op == Op::Shfl { + dims[ins.mask.trailing_zeros() as usize] = true; + } + if ins.op == Op::Mad { + assert_ne!(ins.src2, ins.dst, "seed {k} class {}: a mad with src2 == dst", c.name()); + } + } + assert!(dims.iter().all(|&d| d), "seed {k} class {}: shuffle dimensions {:?}", c.name(), dims); + assert_eq!(p.instrs.len(), 64); + assert_eq!(p.instrs.iter().filter(|i| i.op.is_load()).count(), 16, "the load slots are the class's"); + } + } + assert!(!V5_CLASS.is_v6() && !V3_CLASS.is_v6()); + // a plain class v5 candidate of the same seed can lack a dimension: the rule is the v6 construction's, not a filter + let seed = f8_bytes("program", 4); + let a = candidate_class("p-a02", &seed, 0, LoadClass::era(V5_CLASS, &era, &V3_ALLOWED)); + let b = candidate_class("p-a02", &seed, 0, LoadClass::era(V5_CLASS.with_fold(), &era, &V3_ALLOWED)); + assert_ne!(a.program_id(), b.program_id()); +} + +/// Lane D's finding (8 October 2026): every class v6 flag is set aside by the acceptance's class v4 shape predicate, +/// so a +nowin, +reg64 or +reg64c program is judged by the full rule (the fresh-source rule, the saturated-source +/// check, the index floors and the attempt cap with the last resort), not by the class v2 parts; the draw's source +/// rule reads the same shape. +#[test] +fn every_v6_flag_keeps_the_class_v4_acceptance_shape() { + use igneum_pow::accept::is_class_v4_shape; + use igneum_pow::generator::max_attempts_for; + let all = LoadClass::parse("mx8+sh256x27+state+reg64c+nowin+fold+rw").unwrap(); + for c in [V5_CLASS, V5_CLASS.with_nowin(), V5_CLASS.with_reg64(), V5_CLASS.with_reg64().with_reg64_chain(), V5_CLASS.with_fold(), all] { + assert!(is_class_v4_shape(&c), "{}", c.name()); + assert!(is_class_v4_shape(&LoadClass::era(c, &f8_bytes("era", 4), &V3_ALLOWED)), "{} under an era", c.name()); + assert_eq!(max_attempts_for(&c), max_attempts_for(&V5_CLASS), "{}: the same attempt cap and last resort", c.name()); + } + assert!(!is_class_v4_shape(&V3_CLASS) && !is_class_v4_shape(&LoadClass::V2)); + // lane D's second finding: an era drawn from a width set with more than one width writes the drawn width into + // `mix`; the shape (and so the full rule) must hold at every width of the family + let wide = LoadClass::era(V5_CLASS, &f8_bytes("era", 4), &[1u8, 4, 16]); + assert!(wide.era.is_some()); + assert!(is_class_v4_shape(&wide), "{} (mix {:?})", wide.name(), wide.mix); + assert!(is_class_v4_shape(&LoadClass::era(all, &f8_bytes("era", 9), &[1u8, 4, 16]))); +} + +/// Review B's F03 (8 October 2026): class v6 is a program class of its own, generator 6: the object class names it, +/// every class carrying a v6 flag draws as generator 6 under an era, the pack's program_class reads "v6", and the +/// class v5 draw and its generator number do not move. +#[test] +fn program_class_v6_is_generator_6() { + use igneum_pow::generator::{era_generator_of, GENERATOR_VERSION_V5, GENERATOR_VERSION_V6, V6_CLASS}; + assert_eq!(ProgramClass::parse("v6"), Some(ProgramClass::V6)); + assert_eq!(ProgramClass::V6.name(), "v6"); + assert_eq!(ProgramClass::V6.generator_version(), GENERATOR_VERSION_V6); + assert_eq!(ProgramClass::from_generator(6), Some(ProgramClass::V6)); + assert!(ProgramClass::V6.has_state()); + assert_eq!(ProgramClass::V6.load_class(), V6_CLASS); + assert_eq!(V6_CLASS.name(), "mx8+sh256x27+state+reg64c+fold+rw"); + assert_eq!(ProgramClass::of_load_class(&V6_CLASS), Some(ProgramClass::V6)); + assert_eq!(ProgramClass::of_load_class(&V6_CLASS.with_nowin()), Some(ProgramClass::V6)); + assert_eq!(ProgramClass::of_load_class(&V5_CLASS), Some(ProgramClass::V5)); + let era = f8_bytes("era", 4); + for c in [V6_CLASS, V6_CLASS.with_nowin(), V5_CLASS.with_fold(), V5_CLASS.with_rw(1), V5_CLASS.with_nowin()] { + assert_eq!(era_generator_of(&LoadClass::era(c, &era, &V3_ALLOWED)), GENERATOR_VERSION_V6, "{}", c.name()); + } + assert_eq!(era_generator_of(&LoadClass::era(V5_CLASS, &era, &V3_ALLOWED)), GENERATOR_VERSION_V5); + let seed = f8_bytes("program", 4); + let p = candidate_class("p-f03", &seed, 0, LoadClass::era(V6_CLASS, &era, &V3_ALLOWED)); + assert!(p.class.name().starts_with("mx8-era") && p.class.name().ends_with("+sh256x27+state+reg64c+fold+rw"), "{}", p.class.name()); + // candidate_class draws without stamping the generator; the era path stamps 6 (era_generator_of above) +} + /// 2. The fold's form: `y = x * M; y ^= y >> 16; y = rotl(y, R)`, and nothing else moves. The plain era's stride is /// `rotl(x * M, R)` byte for byte. #[test] @@ -201,14 +318,18 @@ fn fold_form_and_the_plain_stride_unchanged() { assert!(differ > 9_000, "the fold moved {differ} of 10,000 addresses"); // the program of a fold class is the program of the plain class: the same instructions when the same attempt // is accepted (the fold does not enter the draw; the indices it moves can move (c'') and (c''') verdicts) - let p = f8_program(4, ProgramClass::V4, false); - let f = f8_program(4, ProgramClass::V4, true); - if p.attempt == f.attempt { - assert_eq!(p.instrs, f.instrs); - assert_eq!(p.shadow, f.shadow); - } - assert_eq!(f.class.name(), format!("{}+fold", p.class.name())); + // since the review's draw rules (8 October 2026) a fold class draws under the v6 rules, so the pair is the v6 + // re-weight class with and without the fold: the same instructions, the fold moving the addresses alone + let era = f8_bytes("era", 4); + let seed = f8_bytes("program", 4); + let p = candidate_class("p4-attack-f8", &seed, 0, LoadClass::era(V5_CLASS.with_rw(1), &era, &V3_ALLOWED)); + let f = candidate_class("p4-attack-f8", &seed, 0, LoadClass::era(V5_CLASS.with_rw(1).with_fold(), &era, &V3_ALLOWED)); + assert_eq!(p.instrs, f.instrs); + assert_eq!(p.shadow, f.shadow); assert_ne!(p.program_id(), f.program_id()); + // the name orders the fold inside the re-weight suffix ("...+state+fold+rw"); both spellings parse to the class + assert!(f.class.name().ends_with("+sh256x27+state+fold+rw"), "{}", f.class.name()); + assert_eq!(LoadClass::parse("mx8+sh256x27+state+rw+fold"), Some(V5_CLASS.with_rw(1).with_fold())); // and load_index reads the fold through the era let ins = p.instrs.iter().find(|i| i.op == Op::Load).unwrap(); let (pe, fe) = (p.class.era.unwrap(), f.class.era.unwrap()); @@ -285,8 +406,11 @@ fn plain_class_draw_is_byte_identical_to_the_pinned_pack() { let e = Epoch { program, dataset }; assert_eq!(e.program.program_id(), PINNED_ID); let out = export_pack(&e, &format!("bytes:{DAY_HEX}"), SOURCE); - assert_eq!(out.files.len(), 12, "the pack's twelve files"); + assert_eq!(out.files.len(), 13, "the pack's thirteen files"); for (name, text) in &out.files { + if name == "identity.json" { + continue; // A06's identity file is new beside the pinned twelve + } let want = pinned(name); assert!(text == &want, "mx8-devnet-epoch0/{name} differs from the default path's export"); } diff --git a/infra/build-server/lib.sh b/infra/build-server/lib.sh index 25928427b..57a407b29 100755 --- a/infra/build-server/lib.sh +++ b/infra/build-server/lib.sh @@ -286,9 +286,16 @@ bs_wt_lock() { local d="$BS_ROOT_REMOTE/_locks/wt-$BS_WT" t0 holder t0=$(date +%s) while :; do - if bs_ssh "mkdir '$d' 2>/dev/null && printf 'pid %s since %sZ: %s\n' '$$' \"\$(date -u +%H:%M:%S)\" '${BS_TOOL:-build} $BS_CRATE_REL' > '$d/holder'"; then BS_WT_LOCKED="$d"; trap 'bs_wt_unlock' EXIT; return 0; fi + if bs_ssh "mkdir '$d' 2>/dev/null && printf 'pid %s host %s since %sZ: %s\n' '$$' '$(hostname -s)' \"\$(date -u +%H:%M:%S)\" '${BS_TOOL:-build} $BS_CRATE_REL' > '$d/holder'"; then BS_WT_LOCKED="$d"; trap 'bs_wt_unlock' EXIT; return 0; fi holder=$(bs_ssh "cat '$d/holder' 2>/dev/null; find '$d' -maxdepth 0 -mmin +180 -print 2>/dev/null | grep -q . && echo STALE" 2>/dev/null || true) case "$holder" in *STALE*) bs_log "worktree lock $d is older than 3 h; taking it over"; bs_ssh "rm -rf '$d'"; continue ;; esac + # the dead-holder class (8 October 2026, 21:11 to 22:11 UK): a build-remote killed by its pid never runs its EXIT trap, so the + # box kept its lock for the 3 h rule and the next run on that worktree waited an hour. The holder line names the Mac and + # the pid; a waiter on the same Mac whose pid is dead takes the lock over at once and says so. + case "$holder" in + "pid "*" host $(hostname -s) since "*) local hp; hp=$(printf '%s' "$holder" | sed -n 's/^pid \([0-9]*\) host .*/\1/p') + if [ -n "$hp" ] && ! kill -0 "$hp" 2>/dev/null; then bs_log "worktree lock $d held by pid $hp of this Mac, which is dead; taking it over"; bs_ssh "rm -rf '$d'"; continue; fi ;; + esac [ $(( $(date +%s) - t0 )) -lt 7200 ] || bs_die "gave up after 2 h waiting for the worktree lock $d (held: $holder)" [ $(( ($(date +%s) - t0) % 60 )) -lt 10 ] && bs_log "waiting for another run on worktree $BS_WT: ${holder:-?}" sleep 10 diff --git a/infra/fast-time/proving-enforcement.mjs b/infra/fast-time/proving-enforcement.mjs index 608a86fb3..90804b6a1 100644 --- a/infra/fast-time/proving-enforcement.mjs +++ b/infra/fast-time/proving-enforcement.mjs @@ -63,6 +63,9 @@ const WINDOW = sflag('window', '120'); const NEXT_PROOF = sflag('next-proof'); const PRIOR_IDS = sflag('prior-ids'); // "0x,0x" of the prior pair, default the manifest's const NEXT_IDS = sflag('next-ids'); // "0x,0x" of the next pair +// --drop-keys k1,k2: keys the 60x file lists that the node line under test does not know yet (OverrideParams refuses an +// unknown field); a node line behind master's file drops them +const DROP_KEYS = (sflag('drop-keys', '') || '').split(',').filter(Boolean); const EXPECT = sflag('expect', FLOOR === 'never' ? 'pay' : 'refuse'); const GENESIS_BITS = flag('genesis-bits', 0x1f010000); const CASE = sflag('case') || (SUCCESSION ? `succession-${SUCCESSION}-window-${WINDOW}` : `floor-${FLOOR}-expect-${EXPECT}`); @@ -94,7 +97,7 @@ await sleep(1000); rmSync(TMP, { recursive: true, force: true }); mkdirSync(TMP, { recursive: true }); const track = (proc) => { started.push(proc); try { appendFileSync(PIDS, `${proc.pid}\n`); } catch { } }; -const baseText = readFileSync(FILE, 'utf8'); +let baseText = readFileSync(FILE, 'utf8'); const field = (name) => { const m = new RegExp(`"${name}":\\s*([0-9]+)`).exec(baseText); return m ? +m[1] : undefined; }; function mergeOverrideText(text, fields) { let out = text; @@ -102,13 +105,14 @@ function mergeOverrideText(text, fields) { const extra = Object.entries(fields).map(([k, v]) => `"${k}": ${typeof v === 'string' && !/^\d+$/.test(v) && v !== 'true' && v !== 'false' ? JSON.stringify(v) : v}`).join(', '); return out.replace(/,?\s*}\s*$/, `,\n ${extra}\n}\n`); } +for (const k of DROP_KEYS) baseText = baseText.replace(new RegExp(`\\s*"${k}":\\s*[^,}\\n]+,?`), ''); const DAY_MS = field('pow_day_ms'); const manifest = JSON.parse(readFileSync(MANIFEST, 'utf8')); const override = `${TMP}/override.json`; writeFileSync(override, mergeOverrideText(baseText, { genesis_bits: GENESIS_BITS, skip_proof_of_work: false, proving_v0_activation_daa: '0', - proving_consensus_verify_daa: FLOOR === 'never' ? NEVER : FLOOR, + proving_consensus_verify_daa: SUCCESSION ? '0' : (FLOOR === 'never' ? NEVER : FLOOR), proving_shard_program_id: PRIOR_IDS ? PRIOR_IDS.split(',')[0] : manifest.shard.program_id, proving_aggregator_id: PRIOR_IDS ? PRIOR_IDS.split(',')[1] : manifest.aggregator.program_id, verifier_in_consensus: 'false', proving_key_succession_daa: SUCCESSION || NEVER, proving_key_succession_window_daa: WINDOW, @@ -182,8 +186,39 @@ const PAYOUT_A = '0x' + 'a1'.repeat(20), PAYOUT_B = '0x' + 'b2'.repeat(20); async function daa(node) { const s = await node.exec('igneum_getExecStatus', []); return Number(s.executedTipDaa ?? 0); } async function tipNumber(node) { const s = await node.exec('igneum_getExecStatus', []); return Number(s.executedTip ?? 0); } +async function sameTip(a, h) { + try { const x = await a.exec('igneum_getExecStatus', []); const y = await h.exec('igneum_getExecStatus', []); return x.executedTipHash && x.executedTipHash === y.executedTipHash; } catch { return false; } +} +/// Succession mode: the attacker's carrier is refused by the honest nodes and its chain dies with it; before the next +/// forge the attacker must be back on the honest tip (it follows the heavier honest chain), so the carrier it builds is +/// one the honest nodes will read. +async function rejoin(a, h, label) { + // 21:33 UK: pausing A's miner made the rejoin fail every time (A did not adopt H's chain in 300 s twice; with its + // miner running the rejoin took 15 to 130 s and failed once at 150 s), so the miner stays up and the wait is 600 s + for (let k = 0; k < 120; k++) { if (await sameTip(a, h)) { log(`${label}: A is on H1's tip (${k * 5} s)`); return true; } await sleep(5000); } + log(`${label}: A did not rejoin H1's tip in 600 s`); return false; +} + /// The seven shapes for shard 0 of A's chain block `n` (a block A has executed); returns what A's own pool answered. -async function forge(n, phase) { +/// The clocks that fit this shape (read from the 20:42 UK run on build-8, DAA about one per second): a rejoin after a +/// refused carrier took up to 100 s, so the second record of a phase lands 60 to 130 DAA after the first; the floor and +/// the window must leave room: --succession 360 --window 300 (below: records at about 100 and 230; window: about 370 and +/// 500 of 660; after: from 665), never --succession 240 --window 120, whose window closed on the second record. +/// Succession mode, one record per carrier (8 October 2026, 20:4x UK, read from the fix node's run: the attacker's +/// carrier dies with its refusal, so of two records forged on one block only the first is ever carried; the 18:49 run +/// on the pre-fix node read the other half for the same reason): the two shapes go on two blocks with a rejoin between. +async function forgeSuccession(phase, waitMs) { + let tip = await tipNumber(A); + const fa = await forge(Math.max(1, tip - 15), phase, 'p'); + await sleep(waitMs / 2); + await rejoin(A, H1, `${phase}: before the second shape`); + tip = await tipNumber(A); + const fb = await forge(Math.max(1, tip - 15), phase, 'n'); + await sleep(waitMs); // the second record's carrier and its refusal need the full wait (20:55 UK: a 60 s half missed the after-window one) + return { block: fa.block, hash: fa.hash, second: { block: fb.block, hash: fb.hash }, shapes: [...fa.shapes, ...fb.shapes] }; +} + +async function forge(n, phase, which = 'pn') { const plan = await A.exec('igneum_getShardPlan', ['0x' + n.toString(16), PAYOUT_A]); const block = plan.hash, statement = plan.shards[0].statement; const planB = await A.exec('igneum_getShardPlan', ['0x' + n.toString(16), PAYOUT_B]); @@ -196,6 +231,19 @@ async function forge(n, phase) { log(`${phase} ${name}: A's pool ${out.accepted ? 'accepted' : 'refused'} (${out.reason || ''})`); return out; }; + if (SUCCESSION) { + // the real proof under each pair, each with A's native statement: refused on its pair where the epoch does not + // accept it, on its statement (another chain's) where it does + if (which.includes('p') && REAL_PROOF && existsSync(REAL_PROOF)) { + const real = readFileSync(REAL_PROOF); + await submit('p-prior-pair-proof', signRecord('forger-p', CHAIN, block, n, 0, PAYOUT_A, statement, '0x' + sha256(real)).record, hex(real)); + } + if (which.includes('n') && NEXT_PROOF && existsSync(NEXT_PROOF)) { + const nextp = readFileSync(NEXT_PROOF); + await submit('n-next-pair-proof', signRecord('forger-n', CHAIN, block, n, 0, PAYOUT_B, statementB, '0x' + sha256(nextp)).record, hex(nextp)); + } + return { block: n, hash: block, shapes }; + } const empty = Buffer.alloc(0), wrong = randomBytes(1024); // (a) no proof bytes await submit('a-no-proof', signRecord('forger-a', CHAIN, block, n, 0, PAYOUT_A, statement, '0x' + sha256(empty)).record, '0x'); @@ -235,8 +283,10 @@ async function observe(n) { } const refusals = (node) => { const t = node.logText(); - return { invalid: (t.match(/IgneumInvalidProofRecord|invalid proof record|proof record .* does not verify|REFUSED/gi) || []).length, dropped: (t.match(/carried proofs did not arrive|did not deliver its carried proofs/g) || []).length, - pair: (t.match(/epoch does not accept|does not embed/g) || []).length, statement: (t.match(/public values hash to/g) || []).length }; + const reasons = t.match(/a carried proof record's proof does not verify: [^\n]*/g) || []; + return { invalid: (t.match(/consensus verify of [^\n]*REFUSED/g) || []).length, dropped: (t.match(/carried proofs did not arrive|did not deliver its carried proofs/g) || []).length, + pair: reasons.filter(r => /does not accept|does not embed/.test(r)).length, statement: reasons.filter(r => /public values hash to/.test(r)).length, + garbage: reasons.filter(r => /not a bincode SP1 proof|not a compressed SP1 proof/.test(r)).length, reasons: reasons.map(r => r.slice(0, 260)) }; }; try { @@ -250,9 +300,9 @@ try { log(`A at DAA ${d}, chain block ${tip}`); if (d >= floor) log(`WARNING: the floor ${floor} was crossed before the first forge (DAA ${d}); lengthen --floor`); // outside the 10-DAA exclusive window, where anyone may claim the shard (spec 07 7.2 item 4) - const n1 = Math.max(1, tip - 15); - const f1 = await forge(n1, 'below'); - await sleep(45000); + const f1 = SUCCESSION ? await forgeSuccession('below', 45000) : await forge(Math.max(1, tip - 15), 'below'); + const n1 = f1.block; + if (!SUCCESSION) await sleep(45000); const o1 = await observe(n1); result.phases.below = { daaAtForge: d, forge: f1, observed: o1, refusals: { H1: refusals(H1), H2: refusals(H2) } }; log(`below: H1 paid ${JSON.stringify(o1.paid)}; carried ${JSON.stringify(o1.carried)}`); @@ -260,11 +310,12 @@ try { if (floor !== Infinity) { while ((d = await daa(A)) < floor + 5) { log(`waiting for the floor: DAA ${d} of ${floor}`); await sleep(10000); } } else await sleep(AFTER * 1000 / 2); + if (SUCCESSION) await rejoin(A, H1, 'before the window forge'); tip = await tipNumber(A); - const n2 = Math.max(1, tip - 15); const beforeRefusals = { H1: refusals(H1), H2: refusals(H2) }; - const f2 = await forge(n2, 'at-floor'); - await sleep(AFTER * 1000); + const f2 = SUCCESSION ? await forgeSuccession('at-floor', AFTER * 1000) : await forge(Math.max(1, tip - 15), 'at-floor'); + const n2 = f2.block; + if (!SUCCESSION) await sleep(AFTER * 1000); const o2 = await observe(n2); const afterRefusals = { H1: refusals(H1), H2: refusals(H2) }; result.phases.atFloor = { daaAtForge: d, forge: f2, observed: o2, refusalsBefore: beforeRefusals, refusalsAfter: afterRefusals }; @@ -273,28 +324,27 @@ try { if (SUCCESSION) { const h = Number(SUCCESSION), w = Number(WINDOW); while ((d = await daa(A)) < h + w + 5) { log(`waiting for the window's end: DAA ${d} of ${h + w}`); await sleep(10000); } + await rejoin(A, H1, 'before the after-window forge'); tip = await tipNumber(A); - const n3 = Math.max(1, tip - 15); const r2 = { H1: refusals(H1), H2: refusals(H2) }; - const f3 = await forge(n3, 'after-window'); - await sleep(AFTER * 1000); + const f3 = await forgeSuccession('after-window', AFTER * 1000); + const n3 = f3.block; const o3 = await observe(n3); const r3 = { H1: refusals(H1), H2: refusals(H2) }; result.phases.afterWindow = { daaAtForge: d, forge: f3, observed: o3, refusalsBefore: r2, refusalsAfter: r3 }; const rb = result.phases.below.refusals, rw = afterRefusals; - // below H: the next-pair proof refused on its pair; in the window: no new pair refusal, both on statements; - // after H+W: the prior-pair proof refused on its pair - const pairBelow = rb.H1.pair > 0; - const pairWindow = rw.H1.pair - rb.H1.pair; - const stmtWindow = rw.H1.statement - rb.H1.statement; - const pairAfter = r3.H1.pair - r2.H1.pair; + // below H: the next-pair proof refused on its pair, the prior-pair proof on its statement (another chain's); + // in the window: both on their statements, none on a pair; after H+W: the prior-pair proof on its pair + const pairBelow = rb.H1.pair, stmtBelow = rb.H1.statement; + const pairWindow = rw.H1.pair - rb.H1.pair, stmtWindow = rw.H1.statement - rb.H1.statement; + const pairAfter = r3.H1.pair - r2.H1.pair, stmtAfter = r3.H1.statement - r2.H1.statement; const nothingPaid = (o1.paid || []).length === 0 && (o2.paid || []).length === 0 && (o3.paid || []).length === 0; - const pass = pairBelow && pairWindow === 0 && stmtWindow > 0 && pairAfter > 0 && nothingPaid; - result.verdict = { pairBelow, pairWindow, stmtWindow, pairAfter, nothingPaid, pass }; + const pass = pairBelow >= 1 && stmtBelow >= 1 && pairWindow === 0 && stmtWindow >= 2 && pairAfter >= 1 && stmtAfter >= 1 && nothingPaid; + result.verdict = { pairBelow, stmtBelow, pairWindow, stmtWindow, pairAfter, stmtAfter, nothingPaid, pass }; result.endedAt = new Date().toISOString(); mkdirSync(OUT.replace(/\/[^/]+$/, ''), { recursive: true }); writeFileSync(OUT, JSON.stringify(result, null, 2)); - log(`RESULT ${pass ? 'PASS' : 'FAIL'}: below H pair refusals=${rb.H1.pair}; window new pair refusals=${pairWindow}, new statement refusals=${stmtWindow}; after H+W new pair refusals=${pairAfter}; nothing paid=${nothingPaid}; ${OUT}`); + log(`RESULT ${pass ? 'PASS' : 'FAIL'}: below H pair=${pairBelow} statement=${stmtBelow}; window pair=${pairWindow} statement=${stmtWindow}; after H+W pair=${pairAfter} statement=${stmtAfter}; nothing paid=${nothingPaid}; ${OUT}`); await stopAll(); process.exit(pass ? 0 : 1); } diff --git a/packaging/ota/publish-manifest.sh b/packaging/ota/publish-manifest.sh index d9e88deff..c99b5def3 100755 --- a/packaging/ota/publish-manifest.sh +++ b/packaging/ota/publish-manifest.sh @@ -53,7 +53,7 @@ TOKEN_FILE="$HOME/.config/igneum/dl-token" SIGNER="$ROOT/app/igneum-app/target/release/igneum-ota-sign" PRODUCT="app" -VERSION="" MAC="" WIN="" NOTES="" ACTIVATION="" DEADLINE="" MIN_SUPPORTED="" CHANNEL="devnet" BASE="" DEST="" DEPLOY=0 VERIFY_ONLY=0 TRIES=12 +RELEASE_SHA="" CANARY_GUARD_SELF_TEST=0 VERSION="" MAC="" WIN="" NOTES="" ACTIVATION="" DEADLINE="" MIN_SUPPORTED="" CHANNEL="devnet" BASE="" DEST="" DEPLOY=0 VERIFY_ONLY=0 TRIES=12 NODE_BIN="" NET_DIGEST="" MOVE_CLOCK="" DIGEST_GUARD_SELF_TEST=0 OVERRIDE="" TUNING_FILE="" NO_TUNING=0 PUBLIC=0 while [ $# -gt 0 ]; do @@ -83,6 +83,8 @@ while [ $# -gt 0 ]; do --network-digest) NET_DIGEST="$2"; shift 2 ;; # the network's CURRENT digest (a 64-hex, or "log:[@user@host]" read by tools/digest-read.sh on the hub) --move-clock) MOVE_CLOCK="$2"; shift 2 ;; # "HH:MM UTC, ": the move's clock, when the entry's digest differs by design; logged in the notes --self-test-digest-guard) DIGEST_GUARD_SELF_TEST=1; shift ;; + --release-sha) RELEASE_SHA="$2"; shift 2 ;; # rule 33 (8 Oct 2026): the release tip's commit; its fresh-install canary record must read PASS (tools/ci/canary-check.sh) + --self-test-canary-guard) CANARY_GUARD_SELF_TEST=1; shift ;; *) echo "unknown argument: $1" >&2; exit 2 ;; esac done @@ -109,6 +111,47 @@ if [ "$DIGEST_GUARD_SELF_TEST" = 1 ]; then echo "digest guard self-test: a differing digest is refused without a move clock and accepted with one; an equal digest passes; the digest reader parses" exit 0 fi +# Rule 33 (the founder, 8 October 2026, 21:3x UK, "no more lost time"): a release entry may not publish without a fresh-install +# canary record for its sha (install from the artefact on a non-AVX-512 box with an empty datadir, genesis to tip, five minutes +# mining with zero refusals and an accepted block, one shard claimed, proved and paid or queued, a bounded quit, every line read +# back): tools/ci/canary/.json read by tools/ci/canary-check.sh. A write to a real downloads folder needs --release-sha and a +# PASS record; a loopback --base-url test write and --verify-only do not publish and are not gated. +canary_guard() { # [kind ...] -> 0 pass (the lines printed), 1 refused; a kind (mac, windows) asks for that entry's own artefact block + local sha="$1"; shift; local k + [ -n "$sha" ] || { echo "canary guard: REFUSED: a release entry needs --release-sha with a fresh-install canary record (rule 33; tools/ci/canary-check.sh --form)"; return 1; } + if [ $# -eq 0 ]; then bash "$TOOLS/ci/canary-check.sh" "$sha" || { echo "canary guard: REFUSED: the entry's sha ${sha:0:12} has no PASS fresh-install canary record (rule 33)"; return 1; }; return 0; fi + for k in "$@"; do bash "$TOOLS/ci/canary-check.sh" "$sha" --artefact "$k" || { echo "canary guard: REFUSED: the $k entry's sha ${sha:0:12} has no PASS fresh-install canary record for its own artefact (rule 33)"; return 1; }; done +} +if [ "$CANARY_GUARD_SELF_TEST" = 1 ]; then + bash "$TOOLS/ci/canary-check.sh" --self-test >/dev/null || exit 1 + d=$(mktemp -d); trap 'rm -rf "$d"' EXIT; S=0123456789abcdef0123456789abcdef01234567 + canary_guard "" >/dev/null 2>&1 && { echo "canary guard self-test: FAIL: an entry with no --release-sha was accepted"; exit 1; } + CANARY_DIR="$d" canary_guard "$S" >/dev/null 2>&1 && { echo "canary guard self-test: FAIL: a sha with no record was accepted"; exit 1; } + bash "$TOOLS/ci/canary-check.sh" --form | python3 -c " +import json,sys; r=json.load(sys.stdin); r['sha']='$S'; r['artefact']['sha256']='ab'*32; r['box']={'host':'build-4','isa_line':'kit-isa: clean'} +r['sync'].update(tip_height=10, seconds=1); r['quit']['seconds']=1; r['recorded_at']='t'; r['recorded_by']='self-test'; json.dump(r, open('$d/$S.json','w'))" + CANARY_DIR="$d" canary_guard "$S" >/dev/null 2>&1 || { echo "canary guard self-test: FAIL: a sha with a PASS record was refused"; exit 1; } + python3 -c "import json; p='$d/$S.json'; r=json.load(open(p)); r['mining']['refusals']=1; json.dump(r, open(p,'w'))" + CANARY_GUARD_FAILED=0; CANARY_DIR="$d" canary_guard "$S" >/dev/null 2>&1 && { echo "canary guard self-test: FAIL: a record with a refusal was accepted"; exit 1; } + python3 -c " +import json,copy; p='$d/$S.json'; r=json.load(open(p)); blk={k:r[k] for k in ('artefact','box','datadir','sync','mining','shard','quit','lines_read_back')}; blk['mining']['refusals']=0; arts=[] +for kind in ('fleet','windows','mac'): + b=copy.deepcopy(blk); b['kind']=kind; arts.append(b) +arts[1]['mining']['refusals']=3 +json.dump({'sha':r['sha'],'artefacts':arts,'verdict':'PASS','recorded_at':'t','recorded_by':'self-test'}, open(p,'w'))" + CANARY_DIR="$d" canary_guard "$S" mac >/dev/null 2>&1 || { echo "canary guard self-test: FAIL: the mac entry was refused though its own block passes"; exit 1; } + CANARY_DIR="$d" canary_guard "$S" windows >/dev/null 2>&1 && { echo "canary guard self-test: FAIL: the windows entry passed on a failing windows block"; exit 1; } + CANARY_DIR="$d" canary_guard "$S" mac windows >/dev/null 2>&1 && { echo "canary guard self-test: FAIL: a mac plus windows publish passed with the windows block failing"; exit 1; } + echo "canary guard self-test: no sha, no record and a failing record are refused; a PASS record passes; an entry publishes on its own artefact's block (mac passes, windows refused on its own failing block); the record check's own self-test passes" + exit 0 +fi +case "${BASE:-}" in http://127.0.0.1*|http://localhost*|http://\[::1\]*) CANARY_GATED=0 ;; *) CANARY_GATED=1 ;; esac +if [ "$VERIFY_ONLY" != 1 ] && [ "$CANARY_GATED" = 1 ] && [ -z "${IGNEUM_CANARY_SELF_TEST_SKIP:-}" ]; then + KINDS=""; [ -n "$MAC" ] && KINDS="$KINDS mac"; [ -n "$WIN" ] && KINDS="$KINDS windows" + # shellcheck disable=SC2086 + canary_guard "$RELEASE_SHA" $KINDS || exit 1 + NOTES="${NOTES:+$NOTES; }release: $RELEASE_SHA (fresh-install canary PASS)" +fi if [ -n "$NODE_BIN" ] || [ -n "$NET_DIGEST" ]; then [ -n "$NODE_BIN" ] && [ -n "$NET_DIGEST" ] || { echo "the digest guard needs both --node-bin and --network-digest" >&2; exit 2; } ENTRY_DIGEST=$(bash "$TOOLS/digest-read.sh" binary "$NODE_BIN") || exit 1 diff --git a/packaging/ota/publish-public.sh b/packaging/ota/publish-public.sh index 0f8b67b00..bd63d98a6 100755 --- a/packaging/ota/publish-public.sh +++ b/packaging/ota/publish-public.sh @@ -32,10 +32,11 @@ KEY="$CFG/ota-signing-key"; PUB_KEY="$CFG/ota-signing-key.pub" SIGNER="${IGNEUM_OTA_SIGN:-$ROOT/app/igneum-app/target/release/igneum-ota-sign}" # a built signer elsewhere (another worktree) HOST="https://dl.igneum.network" -DO_APP=0 DO_WALLET=0 HIVE="" DO_ALIASES=0 DRY=0 DEPLOY=0 VERIFY=0 PRUNE=1 DEST="" BASE="" TRIES=12 +RELEASE_SHA="" DO_APP=0 DO_WALLET=0 HIVE="" DO_ALIASES=0 DRY=0 DEPLOY=0 VERIFY=0 PRUNE=1 DEST="" BASE="" TRIES=12 while [ $# -gt 0 ]; do case "$1" in --app) DO_APP=1; shift ;; + --release-sha) RELEASE_SHA="$2"; shift 2 ;; # rule 33: the release tip's commit (read from the app manifest's notes when not given); its canary record must read PASS --wallet) DO_WALLET=1; shift ;; --hive) HIVE="$2"; shift 2 ;; --aliases) DO_ALIASES=1; shift ;; @@ -107,6 +108,26 @@ PY log " $name: $(python3 -c 'import json,sys; m=json.load(open(sys.argv[1])); print(m.get("version"), "+".join(m.get("platforms",{})))' "$out") written, signed, verified; URLs under $BASE_PUB" } +# Rule 33 (8 October 2026): nothing goes to dl/public/ for a release whose sha has no PASS fresh-install canary record. The app +# manifest carries "release: " in its notes (publish-manifest.sh --release-sha writes it); --release-sha overrides or supplies it +# for the HiveOS package. tools/ci/canary-check.sh reads tools/ci/canary/.json. +canary_gate() { # [kind ...]: each kind (mac, windows, hive) must have its own PASS artefact block; no kind = the whole record + local sha="$1" what="$2"; shift 2; local k; local chk; chk="$(cd "$(dirname "$0")/../.." && pwd)/tools/ci/canary-check.sh" + [ -n "$sha" ] || { echo "canary guard: REFUSED: $what names no release sha (publish the token entry with publish-manifest.sh --release-sha, or pass --release-sha here); rule 33" >&2; return 1; } + if [ $# -eq 0 ]; then bash "$chk" "$sha" | scrub || { echo "canary guard: REFUSED: ${sha:0:12} has no PASS fresh-install canary record; rule 33" >&2; return 1; }; return 0; fi + for k in "$@"; do bash "$chk" "$sha" --artefact "$k" | scrub || { echo "canary guard: REFUSED: $what: the $k entry's sha ${sha:0:12} has no PASS fresh-install canary record for its own artefact; rule 33" >&2; return 1; }; done +} +if [ "$DO_APP" = 1 ] && [ -z "${IGNEUM_CANARY_SELF_TEST_SKIP:-}" ]; then + sha="$RELEASE_SHA" + [ -n "$sha" ] || sha=$(python3 -c 'import json,re,sys; m=json.load(open(sys.argv[1])); x=re.search(r"release: ([0-9a-f]{8,40})", str(m.get("notes",""))); print(x.group(1) if x else "")' "$SRC/igneum-app-latest.json" 2>/dev/null || true) + kinds=$(python3 -c 'import json,sys; m=json.load(open(sys.argv[1])); ks=[] +for p in m.get("platforms",{}): + ks.append("mac" if "mac" in p.lower() or "darwin" in p.lower() else "windows" if "win" in p.lower() else p) +print(" ".join(ks))' "$SRC/igneum-app-latest.json" 2>/dev/null || true) + # shellcheck disable=SC2086 + canary_gate "$sha" "the app manifest" $kinds || exit 1 +fi +if [ -n "$HIVE" ] && [ -z "${IGNEUM_CANARY_SELF_TEST_SKIP:-}" ]; then canary_gate "$RELEASE_SHA" "the HiveOS package" hive || exit 1; fi if [ "$DO_APP" = 1 ]; then log "app manifest -> dl/public/"; publish_manifest igneum-app-latest.json; fi if [ "$DO_WALLET" = 1 ]; then log "wallet manifest -> dl/public/"; publish_manifest igneum-wallet-latest.json; fi if [ -n "$HIVE" ]; then diff --git a/proto-cuda/nvrtc/packfile-fuzz.c b/proto-cuda/nvrtc/packfile-fuzz.c new file mode 100644 index 000000000..9cafb5519 --- /dev/null +++ b/proto-cuda/nvrtc/packfile-fuzz.c @@ -0,0 +1,57 @@ +/* packfile-fuzz.c: POW-01's malformed-input half for the pack reader (8 October 2026). Copies a pack directory, mutates + * one of its files N times (a flipped byte, a truncation, an inserted byte, a doubled slice, random bytes) and calls + * pf_load on the copy each time; the run passes when every call returns 0 (refused with a message) or 1 (accepted), + * and the process never crashes. One line per 1,000 rounds, a RESULT line at the end. + * cc -O2 -o packfile-fuzz packfile-fuzz.c && ./packfile-fuzz + */ +#include "packfile.h" +#include + +static uint64_t rs = 0x1234567; +static uint64_t rnext(void) { rs += 0x9e3779b97f4a7c15ull; uint64_t z = rs; z = (z ^ (z >> 30)) * 0xbf58476d1ce4e5b9ull; z = (z ^ (z >> 27)) * 0x94d049bb133111ebull; return z ^ (z >> 31); } +static size_t below(size_t n) { return n ? (size_t)(rnext() % n) : 0; } + +static int copy_file(const char* from, const char* to) { + size_t n = 0; char* b = pf_read_file(from, &n); if (!b) { remove(to); return 0; } + FILE* f = fopen(to, "wb"); if (!f) { free(b); return 0; } + fwrite(b, 1, n, f); fclose(f); free(b); return 1; +} + +static void write_mutated(const char* src, const char* dst) { + size_t n = 0; char* b = pf_read_file(src, &n); + if (!b) { remove(dst); return; } /* a pack without this file: the mutation is its absence */ + size_t cap = n + 400; char* v = (char*)malloc(cap ? cap : 1); size_t len = n; if (n) memcpy(v, b, n); + switch (below(6)) { + case 0: if (len) v[below(len)] ^= (char)(1 << below(8)); break; + case 1: len = below(len + 1); break; + case 2: { size_t i = below(len + 1); memmove(v + i + 1, v + i, len - i); v[i] = (char)rnext(); len++; } break; + case 3: if (len > 1) { size_t a = below(len), bl = below(len - a); if (bl > 300) bl = 300; memmove(v + a + bl, v + a, len - a); memcpy(v + a, b + a, bl); len += bl; } break; + case 4: len = below(300); for (size_t i = 0; i < len; i++) v[i] = (char)rnext(); break; + default: if (len) v[below(len)] = (char)rnext(); break; + } + FILE* f = fopen(dst, "wb"); if (f) { fwrite(v, 1, len, f); fclose(f); } + free(v); free(b); +} + +int main(int argc, char** argv) { + if (argc < 4) { fprintf(stderr, "usage: packfile-fuzz \n"); return 2; } + const char* pack = argv[1]; long rounds = atol(argv[2]); const char* scratch = argv[3]; + const char* files[] = { "program.h", "vectors.h", "seeds.txt", "memhard.h" }; + mkdir(scratch, 0755); + char from[1024], to[1024]; + for (int i = 0; i < 4; i++) { snprintf(from, sizeof from, "%s/%s", pack, files[i]); snprintf(to, sizeof to, "%s/%s", scratch, files[i]); copy_file(from, to); } + PfPack pk; char err[512]; + int base = pf_load(pack, &pk, err, sizeof err); + printf("base pack %s: %s%s\n", pack, base ? "accepted" : "refused: ", base ? "" : err); + long accepted = 0, refused = 0; + for (long r = 0; r < rounds; r++) { + int which = (int)below(4); + for (int i = 0; i < 4; i++) { snprintf(from, sizeof from, "%s/%s", pack, files[i]); snprintf(to, sizeof to, "%s/%s", scratch, files[i]); if (i == which) write_mutated(from, to); else copy_file(from, to); } + memset(&pk, 0, sizeof pk); err[0] = 0; + int ok = pf_load(scratch, &pk, err, sizeof err); + if (ok) accepted++; else refused++; + if ((r + 1) % 1000 == 0) printf("round %ld: accepted %ld refused %ld\n", r + 1, accepted, refused); + } + printf("RESULT packfile-fuzz pack=%s rounds=%ld accepted=%ld refused=%ld crashes=0 verdict=PASS\n", pack, rounds, accepted, refused); + return 0; +} diff --git a/proto-cuda/nvrtc/packfile.h b/proto-cuda/nvrtc/packfile.h index f99ddd87d..edf156948 100644 --- a/proto-cuda/nvrtc/packfile.h +++ b/proto-cuda/nvrtc/packfile.h @@ -333,11 +333,13 @@ static int pf_load(const char* dir, PfPack* pk, char* err, size_t cap) { * kernel text, so this loader needs nothing new beyond the number and the class token), generator 5 is class v5 * (proof of stored state, 7 October 2026: class v4 over a dataset keyed by the window's state leaves, leaves.bin, * which the host uploads for igneum_build; the kernel text carries the leaf read). */ - if (pk->generator != 2 && pk->generator != 3 && pk->generator != 4 && pk->generator != 5) { - char m[200]; snprintf(m, sizeof(m), "program pack generator %u is not a generator version this worker runs (2, 3, 4 or 5)", (unsigned)pk->generator); + if (pk->generator != 2 && pk->generator != 3 && pk->generator != 4 && pk->generator != 5 && pk->generator != 6) { + char m[200]; snprintf(m, sizeof(m), "program pack generator %u is not a generator version this worker runs (2, 3, 4, 5 or 6)", (unsigned)pk->generator); free(prog); return pf_fail(err, cap, m); } - strcpy(pk->programClass, pk->generator == 5 ? "v5" : pk->generator == 4 ? "v4" : pk->generator == 3 ? "v3" : "v2"); + /* generator 6 (class v6, the Igneum 2.0 D1 object, 8 October 2026): class v5's stored-state dataset with the v6 rules in the kernel text; + * the worker runs it as it runs class v5 (the shadow block, the state leaves), the pack's texts carry the rest */ + strcpy(pk->programClass, pk->generator == 6 ? "v6" : pk->generator == 5 ? "v5" : pk->generator == 4 ? "v4" : pk->generator == 3 ? "v3" : "v2"); { /* Counter ASIC 3.0 (6 October 2026): the shadow block marks class v4. A generator 3 pack with IGNEUM_SHADOW_INSTRS * is a v4 program stamped as v3 (the old export path; it carried the v3 control's program id) and is refused; @@ -345,7 +347,7 @@ static int pf_load(const char* dir, PfPack* pk, char* err, size_t cap) { uint32_t shadow = 0; if (!pf_define_u32(prog, "IGNEUM_SHADOW_INSTRS", &shadow)) shadow = 0; if (pk->generator == 4 && shadow == 0) { free(prog); return pf_fail(err, cap, "program pack generator 4 (class v4) without IGNEUM_SHADOW_INSTRS: not a class v4 pack"); } - if (pk->generator == 5 && shadow == 0) { free(prog); return pf_fail(err, cap, "program pack generator 5 (class v5) without IGNEUM_SHADOW_INSTRS: not a class v5 pack (class v5 is class v4 over the state leaves)"); } + if ((pk->generator == 5 || pk->generator == 6) && shadow == 0) { free(prog); return pf_fail(err, cap, "program pack generator 5 (class v5) without IGNEUM_SHADOW_INSTRS: not a class v5 pack (class v5 is class v4 over the state leaves)"); } if (pk->generator == 3 && shadow != 0) { /* a generator 2 pack with a shadow is the measurement ladder (a class-bearing id) and loads */ char m[220]; snprintf(m, sizeof(m), "program pack generator %u with a shadow block (IGNEUM_SHADOW_INSTRS %u): a class v4 program is generator 4 (export the pack as class v4)", (unsigned)pk->generator, (unsigned)shadow); free(prog); return pf_fail(err, cap, m); @@ -365,8 +367,8 @@ static int pf_load(const char* dir, PfPack* pk, char* err, size_t cap) { pk->stateLeaves = 0; pk->stateLeavesFnv = 0; pk->stateRootHex[0] = 0; pk->stateBlockHex[0] = 0; strcpy(pk->stateLeavesFile, "leaves.bin"); if (!pf_define_u32(prog, "IGNEUM_STATE_LEAVES", &pk->stateLeaves)) pk->stateLeaves = 0; - if (pk->generator == 5 && pk->stateLeaves == 0) { free(prog); return pf_fail(err, cap, "program pack generator 5 (class v5) without IGNEUM_STATE_LEAVES: no state leaves to key the dataset (export the pack with --state)"); } - if (pk->generator != 5 && pk->stateLeaves != 0) { + if ((pk->generator == 5 || pk->generator == 6) && pk->stateLeaves == 0) { free(prog); return pf_fail(err, cap, "program pack generator 5 (class v5) without IGNEUM_STATE_LEAVES: no state leaves to key the dataset (export the pack with --state)"); } + if (pk->generator != 5 && pk->generator != 6 && pk->stateLeaves != 0) { char m[200]; snprintf(m, sizeof(m), "program pack generator %u carries IGNEUM_STATE_LEAVES %u: state leaves belong to class v5 (generator 5)", (unsigned)pk->generator, (unsigned)pk->stateLeaves); free(prog); return pf_fail(err, cap, m); } diff --git a/proto-metal/main.swift b/proto-metal/main.swift index 6c7e48823..87cda6f40 100644 --- a/proto-metal/main.swift +++ b/proto-metal/main.swift @@ -2992,9 +2992,10 @@ final class ServeDataset { /// Counter ASIC 2.0 and 3.0: the classes this worker runs from a prepared pack only (never from the Swift version 2 /// generator): class v3 (generator 3) and class v4 (generator 4, class v3 plus the latency-shadow block, which is in /// the pack's own program_bound.metal). Each carries an era seed. -func isPackClass(_ cls: String) -> Bool { cls == "v3" || cls == "v4" || cls == "v5" } // class v5 (7 October 2026): class v4 over the state leaves, from a pack +func isPackClass(_ cls: String) -> Bool { cls == "v3" || cls == "v4" || cls == "v5" || cls == "v6" } // class v5 (7 October 2026): class v4 over the state leaves, from a pack; class v6 (8 October 2026): class v5's stored-state dataset with the v6 rules in the kernel text (packfile.h db63e1e36: run as class v5) /// The class name of a pack's IGNEUM_GENERATOR (packfile.h's rule). -func packClassOf(generator: UInt32) -> String { generator == 5 ? "v5" : generator == 4 ? "v4" : generator == 3 ? "v3" : "v2" } +func packClassOf(generator: UInt32) -> String { generator == 6 ? "v6" : generator == 5 ? "v5" : generator == 4 ? "v4" : generator == 3 ? "v3" : "v2" } +func isStateClass(_ cls: String) -> Bool { cls == "v5" || cls == "v6" } // the classes keyed by the state leaves // The resident programs and datasets, shared by the job loop (main thread) and the prepare queue (background). final class ServeStore { @@ -3085,7 +3086,7 @@ func servePackProgram(_ gpu: GPU, _ store: ServeStore, seedHex: String, seed: [U } func refuse(_ why: String) -> NSError { NSError(domain: "pack", code: 2, userInfo: [NSLocalizedDescriptionKey: "pack \(dir): \(why)"]) } let generator = defineU32("IGNEUM_GENERATOR") ?? 1 - guard generator == 2 || generator == 3 || generator == 4 || generator == 5 else { throw refuse("program pack generator \(generator) is not a generator version this worker runs (2, 3, 4 or 5)") } + guard generator == 2 || generator == 3 || generator == 4 || generator == 5 || generator == 6 else { throw refuse("program pack generator \(generator) is not a generator version this worker runs (2, 3, 4, 5 or 6)") } let packClass = packClassOf(generator: generator) if let named = defineStr("IGNEUM_PROGRAM_CLASS"), named != packClass { throw refuse("program pack IGNEUM_PROGRAM_CLASS \"\(named)\" does not match IGNEUM_GENERATOR \(generator)") } // Counter ASIC 3.0 (6 October 2026): the shadow block marks class v4 (packfile.h's rule): a generator 3 pack with @@ -3093,9 +3094,9 @@ func servePackProgram(_ gpu: GPU, _ store: ServeStore, seedHex: String, seed: [U let shadow = defineU32("IGNEUM_SHADOW_INSTRS") ?? 0 if generator == 4 && shadow == 0 { throw refuse("program pack generator 4 (class v4) without IGNEUM_SHADOW_INSTRS: not a class v4 pack") } // class v5 (7 October 2026) is class v4 over the state leaves: the shadow block and IGNEUM_STATE_LEAVES both mark it - if generator == 5 && shadow == 0 { throw refuse("program pack generator 5 (class v5) without IGNEUM_SHADOW_INSTRS: not a class v5 pack") } - if generator == 5 && (defineU32("IGNEUM_STATE_LEAVES") ?? 0) == 0 { throw refuse("program pack generator 5 (class v5) without IGNEUM_STATE_LEAVES: no state leaves to key the dataset (export the pack with --state)") } - if generator != 5 && (defineU32("IGNEUM_STATE_LEAVES") ?? 0) != 0 { throw refuse("program pack generator \(generator) carries IGNEUM_STATE_LEAVES: state leaves belong to class v5 (generator 5)") } + if (generator == 5 || generator == 6) && shadow == 0 { throw refuse("program pack generator 5 (class v5) without IGNEUM_SHADOW_INSTRS: not a class v5 pack") } + if (generator == 5 || generator == 6) && (defineU32("IGNEUM_STATE_LEAVES") ?? 0) == 0 { throw refuse("program pack generator 5 (class v5) without IGNEUM_STATE_LEAVES: no state leaves to key the dataset (export the pack with --state)") } + if generator != 5 && generator != 6 && (defineU32("IGNEUM_STATE_LEAVES") ?? 0) != 0 { throw refuse("program pack generator \(generator) carries IGNEUM_STATE_LEAVES: state leaves belong to class v5 (generator 5)") } if generator == 3 && shadow != 0 { throw refuse("program pack generator \(generator) with a shadow block (IGNEUM_SHADOW_INSTRS \(shadow)): a class v4 program is generator 4 (export the pack as class v4)") } let eraHex = defineStr("IGNEUM_ERA_SEED_HEX") ?? "" if wantClass != "" && wantClass != packClass { throw refuse("program class mismatch: this pack is class \(packClass), the line names class \(wantClass) (export the pack again)") } @@ -3162,7 +3163,9 @@ func servePackDataset(_ gpu: GPU, _ store: ServeStore, dayHex: String, dir: Stri guard let fillFn = lib.makeFunction(name: "igneum_cache_fill"), let buildFn = lib.makeFunction(name: "igneum_build") else { throw refuse("memhard.metal lacks igneum_cache_fill or igneum_build") } let fillPipe = try gpu.device.makeComputePipelineState(function: fillFn) let buildPipe = try gpu.device.makeComputePipelineState(function: buildFn) - let words = 1 << datasetLog2 + // ds55 (the class v6 research packs, 8 October 2026): a non-power-of-two dataset carries IGNEUM_DATASET_WORDS (the + // buffer's size) and IGNEUM_DATASET_ITEMS beside IGNEUM_DATASET_LOG2 (the floor); the kernel text maps (src * words) >> 32 + let words = defineU64("IGNEUM_DATASET_WORDS").map { Int($0) } ?? (1 << datasetLog2) // Class v5 (docs/design/class-v5-stored-state.md, 7 October 2026): the window's state leaves, leaves.bin beside program.h // (IGNEUM_STATE_LEAVES leaves of 16 little-endian words), checked against the pack's count and FNV-1a 64 // (IGNEUM_STATE_LEAVES_FNV64) and bound as buffer 2 of igneum_build with the count in buffer 3 (packbench.swift's shape, @@ -3173,7 +3176,7 @@ func servePackDataset(_ gpu: GPU, _ store: ServeStore, dayHex: String, dir: Stri return UInt64(programH[Range(m.range(at: 1), in: programH)!], radix: 16) } let stateLeaves = defineU32("IGNEUM_STATE_LEAVES") ?? 0 - if (packClass == "v5") != (stateLeaves > 0) { throw refuse(packClass == "v5" ? "class v5 pack without IGNEUM_STATE_LEAVES" : "a class \(packClass) pack carries IGNEUM_STATE_LEAVES \(stateLeaves): state leaves belong to class v5") } + if isStateClass(packClass) != (stateLeaves > 0) { throw refuse(isStateClass(packClass) ? "class v5 pack without IGNEUM_STATE_LEAVES" : "a class \(packClass) pack carries IGNEUM_STATE_LEAVES \(stateLeaves): state leaves belong to class v5") } var leavesBuf: MTLBuffer? = nil var nLeaves: UInt32 = 0 if stateLeaves > 0 { diff --git a/proto-metal/packbench.swift b/proto-metal/packbench.swift index a382ddd7d..6e8a8fa88 100644 --- a/proto-metal/packbench.swift +++ b/proto-metal/packbench.swift @@ -93,8 +93,12 @@ let cacheFnvWant = hex64(vj["cache_fnv1a64"] as! String) let hotFnvWant: UInt64? = (vj["hot_fnv1a64"] as? String).map(hex64) guard let device = MTLCreateSystemDefaultDevice(), let queue = device.makeCommandQueue() else { fail("no Metal device") } -let words = 1 << datasetLog2 -let mask = UInt32(words - 1) +// ds55 (the class v6 research packs, 8 October 2026): a non-power-of-two dataset carries IGNEUM_DATASET_WORDS and +// IGNEUM_DATASET_ITEMS beside IGNEUM_DATASET_LOG2 (the floor); the buffer is sized by the words, the items by ITEMS, +// and the kernel text maps an address as (src * words) >> 32, so the mask is the kernel's business, not this host's +let datasetWordsDefine = defineU64("IGNEUM_DATASET_WORDS") +let words = datasetWordsDefine.map { Int($0) } ?? (1 << datasetLog2) +let mask = UInt32(truncatingIfNeeded: (1 << datasetLog2) - 1) let cacheWords = 1 << cacheLog2 func compile(_ file: String) -> MTLLibrary { @@ -138,7 +142,7 @@ func fnv1a64(_ p: UnsafeRawPointer, _ n: Int) -> UInt64 { for i in 0.. Result<()> { println!("RESULT id: {}", pinned.describe()); return Ok(()); } + // A host whose code writes a guest input layout the pinned pair does not read never builds an input for it: refused + // here with the source commit to build from (aggregate, chain and every fixture mode build guest inputs; id and the verify modes do not). + if !mode.starts_with("verify") { + pinned.manifest.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT)?; + } if mode == "verify" { // proving v0 (spec 7.7): the node's proof pool verifies a submitted shard proof off the consensus path return run_verify(&pinned, &arg("--proof").context("--proof ")?, &arg("--statement").context("--statement 0x")?); diff --git a/proving/igneum-prove/host/src/pinned.rs b/proving/igneum-prove/host/src/pinned.rs index 2843a2b4b..12f798d0b 100644 --- a/proving/igneum-prove/host/src/pinned.rs +++ b/proving/igneum-prove/host/src/pinned.rs @@ -61,6 +61,36 @@ pub struct Manifest { /// from its object, never from here). #[serde(default, skip_serializing_if = "Option::is_none")] pub succession: Option, + /// V6-10 provenance (8 October 2026): the commit the pinned pair was built from; the host for this pair is built + /// from it (the steward's release-manifest check reads it as an ancestor of the tree). + #[serde(default, skip_serializing_if = "Option::is_none")] + pub source_commit: Option, + /// The guest input layout the pinned pair reads (`igneum_prove_core::shard::GUEST_INPUT_FORMAT` of its source; absent + /// on a pin from before the field, which is format 1). A host whose code writes another layout refuses to start + /// (22:0x UK, 8 October 2026: a host from master wrote format 3 to the 5 October guests and read "public values are + /// 0 bytes" on a 3060 and a 4060; the kit's prover is built from `source_commit`, never from a tree of another format). + #[serde(default, skip_serializing_if = "Option::is_none")] + pub guest_input_format: Option, +} + +impl Manifest { + /// The input layout the pinned pair reads: the manifest's field, or 1 for a pin from before the field. + pub fn input_format(&self) -> u32 { + self.guest_input_format.unwrap_or(1) + } + /// Refuses a host whose code writes a layout the pinned pair does not read; the line names the source commit to + /// build the prover from instead. + pub fn check_input_format(&self, code_format: u32) -> Result<()> { + let pinned = self.input_format(); + if pinned == code_format { + return Ok(()); + } + anyhow::bail!( + "this host writes guest input format {code_format} and the pinned pair (shard {}) reads format {pinned}: the prover for this pair is built from the manifest's source commit {}, never from this tree (or the pin moves with the code: proving/igneum-prove/pin-guests.sh)", + self.shard.program_id, + self.source_commit.as_deref().unwrap_or("(absent: a pin from before provenance; its source is the commit that last changed elf/igneum-prove-program.elf)") + ) + } } /// The prior pair's block: the same per-program fields as the top level and the time it was pinned. @@ -227,6 +257,36 @@ pub fn claimed_program_id(proof: &SP1ProofWithPublicValues) -> Option { mod tests { use super::*; + /// Known-failed first: a manifest naming another input layout refuses the host with the source commit to build from; + /// a manifest naming none reads as format 1; the code's own format passes. + #[test] + fn a_pinned_pair_of_another_input_format_refuses_this_host_and_names_the_source_to_build() { + let mut m = Manifest::embedded().unwrap(); + m.guest_input_format = Some(igneum_prove_core::shard::GUEST_INPUT_FORMAT + 1); + m.source_commit = Some("abc123".into()); + let e = m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap_err().to_string(); + assert!(e.contains("built from the manifest's source commit abc123"), "{e}"); + m.guest_input_format = None; + assert_eq!(m.input_format(), 1, "a pin from before the field is format 1"); + if igneum_prove_core::shard::GUEST_INPUT_FORMAT != 1 { + let e = m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap_err().to_string(); + assert!(e.contains("reads format 1"), "{e}"); + } + m.guest_input_format = Some(igneum_prove_core::shard::GUEST_INPUT_FORMAT); + m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap(); + // the embedded manifest itself: Pinned::load still answers (id and the verify modes work on a held pin), and the + // input-format check either passes or names the source commit the prover is built from + let embedded = Manifest::embedded().unwrap(); + Pinned::load().unwrap(); + match embedded.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT) { + Ok(()) => assert_eq!(embedded.input_format(), igneum_prove_core::shard::GUEST_INPUT_FORMAT), + Err(e) => { + assert!(e.to_string().contains("guest input format"), "{e}"); + assert!(embedded.source_commit.is_some(), "a held pin names the source commit its prover is built from"); + } + } + } + #[test] fn manifest_parses_and_names_both_programs() { let m = Manifest::embedded().unwrap(); diff --git a/relay/clients/igneum-agent.ps1 b/relay/clients/igneum-agent.ps1 index 68b7437c4..7554e8ada 100644 --- a/relay/clients/igneum-agent.ps1 +++ b/relay/clients/igneum-agent.ps1 @@ -282,13 +282,25 @@ exit `$code $args = @('-NoProfile', '-ExecutionPolicy', 'Bypass', '-File', "`"$wrap`"") $code = 1 try { + # the wait is on the task's own process with a cap, never -Wait (PC 2, 8 October 2026, 21:28 UK: -Wait covers every + # descendant on the inherited console, so a task that started Igneum Miner held the agent for the app's whole life; the + # relay went silent for half an hour). The cap is the task's timeout (flags.timeout_minutes, default 60); a task that + # runs past it is ended by ITS pid and the result says so. + $capMin = 60; try { if ($task.flags.timeout_minutes) { $capMin = [int]$task.flags.timeout_minutes } } catch {} if ($elevated -and -not (Is-Admin)) { Log 'task needs administrator and the agent is not elevated: asking (UAC prompt on this PC)' - $p = Start-Process powershell.exe -ArgumentList $args -Verb RunAs -Wait -PassThru + $p = Start-Process powershell.exe -ArgumentList $args -Verb RunAs -PassThru } else { - $p = Start-Process powershell.exe -ArgumentList $args -NoNewWindow -Wait -PassThru + $p = Start-Process powershell.exe -ArgumentList $args -NoNewWindow -PassThru + } + if (-not $p.WaitForExit($capMin * 60 * 1000)) { + Log ("task #" + $id + " ran past its cap of " + $capMin + " min: ending its own shell pid " + $p.Id + " by pid") + Add-Content -Path $log -Value ("AGENT: task ended at its cap of " + $capMin + " min (pid " + $p.Id + ")") + Stop-Process -Id $p.Id -Force -ErrorAction SilentlyContinue + $p.WaitForExit(5000) | Out-Null } $code = $p.ExitCode + if ($null -eq $code) { $code = 124 } } catch { Log ("could not start the task: " + $_.Exception.Message); Add-Content -Path $log -Value ("AGENT ERROR: " + $_.Exception.Message) } $text = ''; if (Test-Path $log) { $text = Get-Content $log -Raw } # the marker on a line of its own (X28), and only when the task was queued with --reboot or --reboot-continue diff --git a/relay/test/service.test.mjs b/relay/test/service.test.mjs index 357efc61c..214879e78 100644 --- a/relay/test/service.test.mjs +++ b/relay/test/service.test.mjs @@ -39,6 +39,11 @@ test('the installer fills the manifest and registers, runs and reads back the ta assert.match(agentLab, /install Igneum Miner Lab on a fleet PC/, 'the refusal names the remedy'); // the founder's word (8 October 2026, 20:21 UK): a task that ends a process by its name is refused by construction assert.match(agentLab, /function Kill-By-Name-Refusal/, 'the agent refuses kill-by-name task bodies'); + // PC 2, 8 October 2026, 21:28 UK: Start-Process -Wait covered the Miner a task started and the agent hung for the app's + // life; the wait is on the task's own process with a cap (known-failed first) + assert.doesNotMatch(agentLab, /Start-Process powershell\.exe -ArgumentList \$args[^\n]*-Wait/, 'never -Wait on a task shell'); + assert.match(agentLab, /\$p\.WaitForExit\(\$capMin \* 60 \* 1000\)/, 'the wait is capped by the task timeout'); + assert.match(agentLab, /ending its own shell pid [^\n]*by pid/, 'a task past its cap is ended by its pid, never a name'); const shapes = [['Stop-Process -Na', 'me igneum-app -Force'], ['task', 'kill /IM igneumd.exe /F'], ['Get-Process -Na', 'me igneum-miner | Stop-Process'], ['pk', 'ill -f igneumd'], ['kill', 'all igneum-app']].map(p => p.join('')); for (const bad of shapes) { const pats = [/^\s*[^#\r\n]*\bStop-Process\b[^\r\n]*-Name\b/im, /^\s*[^#\r\n]*\btaskkill(\.exe)?\b[^\r\n]*\/IM\b/im, /^\s*[^#\r\n]*\bGet-Process\b[^\r\n]*-Name\b[^\r\n]*\|\s*Stop-Process/im, /^\s*[^#\r\n]*\b(pkill|killall)\b/im]; diff --git a/site/404.html b/site/404.html index 1102df2aa..ba5b80e78 100644 --- a/site/404.html +++ b/site/404.html @@ -117,7 +117,7 @@ main{flex:1}
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -157,7 +157,7 @@ main{flex:1}
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/acceptance.html b/site/acceptance.html index ea8ede581..b9019be8e 100644 --- a/site/acceptance.html +++ b/site/acceptance.html @@ -4,13 +4,13 @@ Igneum Test and Acceptance Standard: every case, shown as it passes - + - + @@ -24,7 +24,7 @@ - + @@ -260,7 +260,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -300,7 +300,7 @@
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -368,8 +368,8 @@
-
Igneum 2.0 acceptance

Test and Acceptance Standard 1.0

Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 172 cases: 3 passed under the standard, 74 running with team evidence, 4 failed, 1 blocked, 89 not run, 1 deferred

  • 3 pass
  • 4 fail
  • 1 blocked
  • 74 running
  • 89 not run
  • 1 deferred
The gates

Five gates, and the freeze before them.

A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

G0RUNNING

Freeze

Release identity

No formal run or public pass before approval.

8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred

  • GOV8 casesRUNNING
G1RUNNING

Baseline

D1

No validated hardware claim without reproduction.

16 cases: 0 passed under the standard, 10 running with team evidence, 6 not run, 0 deferred

  • GOV8 casesRUNNING
  • GPU8 casesRUNNING
G2BLOCKED

Experiments

D2

No improvement claim from a negative hypothesis.

32 cases: 1 passed under the standard, 22 running with team evidence, 1 blocked, 8 not run, 0 deferred

  • GOV8 casesRUNNING
  • GPU8 casesRUNNING
  • POW8 casesBLOCKED
  • ROT8 casesRUNNING
G3RUNNING

Adversary

D3

No broad resistance claim from one weak design.

16 cases: 0 passed under the standard, 11 running with team evidence, 5 not run, 0 deferred

  • GOV8 casesRUNNING
  • ADV8 casesRUNNING
G4FAIL

Coexistence

D4

No durability claim based on assumed chip expiry.

24 cases: 0 passed under the standard, 16 running with team evidence, 1 failed, 7 not run, 0 deferred

  • GOV8 casesRUNNING
  • ECO8 casesFAIL
  • INC8 casesRUNNING
G5RUNNING

No rescue

D5

No no-rescue claim from a founder-supported demo.

56 cases: 2 passed under the standard, 37 running with team evidence, 17 not run, 0 deferred

  • GOV8 casesRUNNING
  • ROT8 casesRUNNING
  • ZKP8 casesRUNNING
  • INC8 casesRUNNING
  • FIN8 casesRUNNING
  • OPS8 casesRUNNING
  • UX8 casesRUNNING

The three named gates

FAIL

Technical readiness

Execution control

No mainnet-ready claim with missing enforcement or safety.

64 cases: 3 passed under the standard, 41 running with team evidence, 3 failed, 1 blocked, 16 not run, 0 deferred

  • GOV8 casesRUNNING
  • POW8 casesBLOCKED
  • EVM8 casesRUNNING
  • ZKP8 casesRUNNING
  • CAP8 casesNOT RUN
  • FIN8 casesRUNNING
  • VER8 casesFAIL
  • UX8 casesRUNNING
RUNNING

Commercial evidence

Execution control

Devnet activity is insufficient.

24 cases: 0 passed under the standard, 4 running with team evidence, 19 not run, 1 deferred

  • GOV8 casesRUNNING
  • CAP8 casesNOT RUN
  • COM8 casesNOT RUN
FAIL

Leadership-contender decision

Execution control

Supports a scoped contention assessment, not a guaranteed rank.

172 cases: 3 passed under the standard, 74 running with team evidence, 4 failed, 1 blocked, 89 not run, 1 deferred

  • GOV8 casesRUNNING
  • GPU8 casesRUNNING
  • POW8 casesBLOCKED
  • ADV8 casesRUNNING
  • ROT8 casesRUNNING
  • ECO8 casesFAIL
  • EVM8 casesRUNNING
  • ZKP8 casesRUNNING
  • CAP8 casesNOT RUN
  • INC8 casesRUNNING
  • FIN8 casesRUNNING
  • VER8 casesFAIL
  • OPS8 casesRUNNING
  • UX8 casesRUNNING
  • COM8 casesNOT RUN
  • LEAD8 casesNOT RUN
  • REV44 casesNOT RUN
01GOV

Release identity and evidence

Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

RUNNING
Owner
Release lead + independent assurance
Gate
G0 / all gates G0 G1 G2 G3 G4 G5
Fixtures
F0 manifest; F1 source/build archives; F9 evidence vault
Plan pages
5, 21, 23, 25, 26, 27
8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred
GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

Steps

  1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
  2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
  3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

Accept

Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

Evidence the case requires

Signed F0; source-to-test map; claim inventory; unresolved-field register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

This manual supplies proposed test thresholds, not source-approved protocol parameters.

Steps

  1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
  2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
  3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

Accept

No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

Evidence the case requires

Approved profile register; timestamped holdout commitments; change log.

Evidence record of the run

What was run
the profiles approved as proposed by the founder at 18:2x UK before any confirmatory run; P13 deferred
Run by
CI steward (a2ecfa95d3206016c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide public source and documented build instructions to three unaffiliated operators.

Steps

  1. Build on clean declared environments without private files, tokens or founder assistance.
  2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
  3. Run reference vectors and restart a node using only documented artifacts.

Accept

All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

Evidence the case requires

Build logs; dependency lockfiles; binary comparison; operator attestations.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Enable append-only storage for run outputs and a separate analysis workspace.

Steps

  1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
  2. Recompute one published figure from raw records on a clean machine.
  3. Modify a retained artifact deliberately and test integrity verification.

Accept

Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

Evidence the case requires

Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Create controlled defective variants on an isolated network only.

Steps

  1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
  2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
  3. Confirm the baseline still accepts authorised valid cases.

Accept

Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

Evidence the case requires

Mutation catalogue; blinded run results; baseline controls; oracle review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

Steps

  1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
  2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
  3. For each claimed option, require the complete associated test set rather than a demonstration.

Accept

Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

Evidence the case requires

Scope manifest; activation scan; product-copy comparison; exclusions register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

Steps

  1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
  2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
  3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

Accept

No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

Evidence the case requires

Signed scoped reports; conflict declarations; finding/retest ledger.

Method
Independent specialist review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

Steps

  1. Calculate affected test dependencies and invalidate their former PASS statuses.
  2. Regenerate public status pages from F0 and the evidence register.
  3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

Accept

Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

Evidence the case requires

Dependency impact report; regenerated status page; rejected claim examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
02GPU

Whole-system GPU measurements

Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

RUNNING
Owner
GPU lead + three independent operators
Gate
G1 / G2 G1 G2
Fixtures
F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
Plan pages
6, 7, 8, 14, 18, 23
8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
GPU-01Cover the declared commodity populationPriority GATEProfile P02RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

Setup

Freeze the P02 cohort, supported role matrix and the final v6 configuration.

Steps

  1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
  2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
  3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

Accept

All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

Evidence the case requires

Cohort manifest; compatibility matrix; raw results by SKU and role.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
p02-fleet-pods-20261008-01
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

Setup

Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

Steps

  1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
  2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
  3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

Accept

Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

Evidence the case requires

Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261008-batch1
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

Setup

Build the baseline and window variant with identical dataset, reads and semantic workload.

Steps

  1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
  2. Measure paired complete-system energy and accepted throughput, including host work.
  3. Repeat during proving coexistence and expose any memory or scheduling cliff.

Accept

Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

Evidence the case requires

Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
p02-fleet-pods-20261008-01
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Use safe vendor-supported settings only; record operator permission and original settings.

Steps

  1. Sweep approved core and memory operating points while holding workload constant.
  2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
  3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

Accept

Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

Evidence the case requires

Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

Evidence record of the run

What was run
the memory-clock ladder at the lock (floor lane 1, b1b8d833)
Run by
hash lane (a690540514aa453d7)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

Setup

Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

Steps

  1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
  2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
  3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

Accept

Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

Evidence the case requires

Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261008-batch1
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the same hardware against clean, delayed, lossy and intermittent links in F4.

Steps

  1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
  2. Include reconnects, template changes, expired submissions and pool failover.
  3. Attribute loss to network, local software, validation and protocol causes.

Accept

Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

Evidence the case requires

Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Run the selected profile on actual reference machines for the P02 soak period.

Steps

  1. Track wall power, temperatures, clocks, memory and accepted work continuously.
  2. Inject safe power interruptions, process restarts and normal competing desktop load.
  3. Check restored settings and compare late-run efficiency with the first stable period.

Accept

No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

Evidence the case requires

Seven-day time series; crash reports; settings-restoration checks; drift analysis.

Evidence record of the run

What was run
the 5090 lock pass, 66 minutes at 1,300 MHz with the four-minute reserve (floor lane 1)
Run by
hash lane (a690540514aa453d7)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

Steps

  1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
  2. Recompute joules and total cost per accepted work from the shared raw schema.
  3. Investigate divergence before accepting a pooled headline or uncertainty band.

Accept

Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

Evidence the case requires

Three signed reproduction packs; reconciliation report; final baseline table.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
03POW

Proof-of-work correctness and coupling

Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

BLOCKED
Owner
Cryptography + GPU lead
Gate
G2 / technical readiness G2
Fixtures
F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
Plan pages
7, 9, 10, 23
8 cases: 1 passed under the standard, 6 running with team evidence, 1 blocked, 0 not run, 0 deferred
POW-01Match independent execution across every backendPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Implement an independently written reference evaluator, not a wrapper around the production GPU path.

Steps

  1. Execute the P01 corpus across every family, boundary seed and supported backend.
  2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
  3. Minimise every mismatch and rerun it on clean builds.

Accept

Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

Evidence the case requires

Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01PASSEvidence recordLast run 8 Oct 2026, 20:54 UK

Setup

Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

Steps

  1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
  2. Check bounds, valid dependencies, address distribution and forbidden encodings.
  3. Compare source-level operations with optimised compiled code for removed or altered work.

Accept

No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

Evidence the case requires

Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
census-v6-20261008-2034
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Take the 64-register candidate and the cheapest independently proposed storage organisations.

Steps

  1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
  2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
  3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

Accept

Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

Evidence the case requires

Liveness traces; alternative implementations; Pareto table; reviewer analysis.

Evidence record of the run

What was run
the connected-state class KILLED (1.10x against the 1.25x gate; live state costs a clock-gated file nothing)
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Experiment + independent hardware review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Use a candidate initially matched to baseline instruction count, read count and dataset size.

Steps

  1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
  2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
  3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

Accept

The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

Evidence the case requires

Matched workloads; GPU runs; redesigned core estimates; held-out results.

Evidence record of the run

What was run
the same experiment, D2(a) closed
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Controlled experiment
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04BLOCKEDEvidence none yetLast run 2026-10-08 18:13Z

Setup

Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

Steps

  1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
  2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
  3. Price any valid strategy against fresh evaluation; independently review all bindings.

Accept

Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

Evidence the case requires

Attack implementations; valid/invalid controls; work-cost analysis; binding review.

Evidence record of the run

What was run
the binding review: twelve reuse paths, none below the honest cost; five open questions B1 to B5
Run by
pool design seat (a3832b1c3b274b310)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
binding-review-2026-10-08-a05
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

Steps

  1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
  2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
  3. Sustain the approved hostile request rate while ordinary valid traffic continues.

Accept

All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

Evidence the case requires

CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
p01-partb-20261008-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

Steps

  1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
  2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
  3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

Accept

Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

Evidence the case requires

Scope decision; semantic specification; vectors; simplified datapath model.

Method
Conditional implementation test
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

Steps

  1. Retain their historic negative tests and realistic SRAM instruction-memory control.
  2. Inspect the release for reintroduction through renamed settings or hidden paths.
  3. Require a new written hypothesis and complete adversarial retest for any proposed return.

Accept

Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

Evidence the case requires

Decision register; binary/config scan; negative-control results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
04ADV

Programmable specialist adversaries

Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

RUNNING
Owner
Independent hardware team
Gate
G3 G3
Fixtures
F2 reference GPUs; F6 RTL/physical models; all published families
Plan pages
8, 10, 12, 22, 23
8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Provide the complete published family bank and future known parameter schedule to the reviewer.

Steps

  1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
  2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
  3. Verify its outputs against POW vectors before measuring any advantage.

Accept

At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

Evidence the case requires

Architecture reports; functional simulations; adaptation matrix; reviewer signature.

Evidence record of the run

What was run
the 18-family programmable core placed and routed (9.36 pJ per lane-op, k 0.64 same-node)
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Independent hardware study
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

Steps

  1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
  2. Include construction/update amortisation, bandwidth contention and retained state.
  3. Take the most favourable feasible point for the specialist into the complete-board model.

Accept

No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

Evidence the case requires

Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

Evidence record of the run

What was run
D2(b): the stored-half hybrid, memory sharing, recomputation priced (the placed hybrid 1.93x same-node at the mean hit)
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Model + adversarial implementation
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

Steps

  1. Compare moving computation, intermediate state or fetched data to each read location.
  2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
  3. Include interconnect, host, synchronisation, idle and conversion costs.

Accept

The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

Evidence the case requires

Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

Evidence record of the run

What was run
data-local execution moves nothing (2,112 bits of live state against an 80-bit read)
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Independent system modelling
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-04Measure profitable selective participationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Use all declared families plus held-out generated programs and the protocol difficulty rule.

Steps

  1. Identify favourable execution paths and add cheap fallbacks for other periods.
  2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
  3. Evaluate revenue and costs across the full schedule, not just average program energy.

Accept

Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

Evidence the case requires

Per-program advantage distribution; policy simulator; full-period returns.

Evidence record of the run

What was run
selective participation 9 percent spread across 2,000 era draws
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-05Validate physical and complete-board costsPriority GATEProfile P04RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

Steps

  1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
  2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
  3. Compare against a calibrated existing hardware block or equivalent validation case.

Accept

No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

Evidence the case requires

Netlist/physical reports; macro assumptions; bill of materials; model calibration.

Evidence record of the run

What was run
the complete GDDR7 machine 1.5x same-node, 1.8x a node ahead at the placed energy; the honest same-node bracket 1.5x to 2.1x: FAIL against P04 at R_E 1.5, served as such
Run by
k lane (a3c9601a6d4686fe1)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
FAIL against P04 at R_E 1.5
Method
Independent physical-design review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

Steps

  1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
  2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
  3. Evaluate measurement confidence and model-parameter sensitivity separately.

Accept

P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

Evidence the case requires

Node-specific reports; factor provenance; uncertainty and sensitivity tables.

Evidence record of the run

What was run
the node column: same-node and a node ahead kept separate (k 0.78 / 0.56 / 0.40 at N5 / N3 / N2)
Run by
k lane (a3c9601a6d4686fe1)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

Steps

  1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
  2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
  3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

Accept

The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

Evidence the case requires

Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

Evidence record of the run

What was run
the transition matrix: no row loses competitiveness, the three-year life holds, zero obsolescence credit
Run by
adversary lane (a1a9876a88f5a72fc)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

Steps

  1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
  2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
  3. Record unresolved modelling disagreements and future technology exclusions.

Accept

Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

Evidence the case requires

Two review reports; challenge log; final envelope; unresolved-limit statement.

Method
Independent challenge/review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
05ROT

Epochs, seeds and memory transitions

Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

RUNNING
Owner
Consensus + GPU leads
Gate
G5 / G2 G5 G2
Fixtures
F0 activation rules; F4 fault network; F5 historical and boundary vectors
Plan pages
7, 11, 19, 21
8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

Steps

  1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
  2. Restart nodes from both sides and replay the same headers.
  3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

Accept

All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

Evidence the case requires

Boundary vectors; node/miner traces; acceptance and reward matrix.

Evidence record of the run

What was run
the fast-time crossings PASS on 4cdcc488 (17:29:58) and 617cb441 (17:30:44) with the cold restart
Run by
fast-time lane (a8be71a0db962911c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use the retained schedule in F0, including coincident program, parameter and family changes.

Steps

  1. Run every known family transition and all coincident-boundary combinations on production code.
  2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
  3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

Accept

Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

Evidence the case requires

Transition matrix; code-path evidence; compile timing; old-client logs.

Evidence record of the run

What was run
the class v6 object crossing at its floor on 617cb441
Run by
fast-time lane (a8be71a0db962911c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

Steps

  1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
  2. Partition voters, restore them and test vote-key substitution through pools.
  3. Verify adoption and refusal behaviour of already running nodes.

Accept

The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

Evidence the case requires

Executable governance model; signed-vote corpus; coalition/partition results.

Evidence record of the run

What was run
the bring-forward mechanism specified in the D5 block
Run by
node lane (a283f5f0d364ceef0)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

Steps

  1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
  2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
  3. Validate inputs, parameters and proofs against independent vectors.

Accept

No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

Evidence the case requires

Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Stop checkpoint signing while mining continues, then cross seed and family boundaries.

Steps

  1. Remove the required signing weight and observe the documented fallback or safe pause.
  2. Prevent access to any founder seed service; restart from persisted state.
  3. Restore the stated fault assumptions and verify deterministic recovery.

Accept

Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

Evidence the case requires

Fault timeline; seed/certificate history; node-state comparison; recovery log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

Steps

  1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
  2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
  3. Measure data transfer, restart and excluded-card costs before approving progression.

Accept

No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

Evidence the case requires

Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Use matched baseline and ablated variants in the lab; do not change a running public network.

Steps

  1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
  2. Include favourable-period specialists and all retained known families.
  3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

Accept

Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

Evidence the case requires

Ablation report; decision log; complexity/cost comparison.

Evidence record of the run

What was run
the family gate's coverage (38,000 eras) and the rotation prototype paused as the no-rescue control
Run by
lane D family gate (a07a99a3788566af2)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
lane D family gate (a07a99a3788566af2)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze the complete published rule bank and known schedule for the five-year evaluation.

Steps

  1. Allow a programmable adversary to know and survive all planned changes.
  2. Remove assumed future emergency instructions and manual retirement actions from the model.
  3. Run the required ECO scenarios and link them to independent network-transition tests.

Accept

Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

Evidence the case requires

Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
06ECO

Five-year coexistence economics

Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

FAIL
Owner
Economics lead + independent reviewer
Gate
G4 G4
Fixtures
F6 adversarial costs; F7 scenario model; F2 operator costs
Plan pages
8, 13, 18, 24, 26
8 cases: 0 passed under the standard, 7 running with team evidence, 1 failed, 0 not run, 0 deferred
ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

Steps

  1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
  2. Use actual accepted work and independently verify units and period conversions.
  3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

Accept

All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

Evidence the case requires

Versioned model; unit fixtures; independent reconciliation; input sources.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-01b
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

Steps

  1. Evaluate marginal operation separately from recovery of a new purchase.
  2. Stress resale at zero, hardware failures, financing and replacement cycles.
  3. Report break-even power price and total cost relative to the strongest feasible specialist.

Accept

P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

Evidence the case requires

Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use three development cases: fully funded elsewhere, source-range low and source-range high.

Steps

  1. Evaluate private mining, public hardware sales and a hybrid business model.
  2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
  3. Re-evaluate GPU entry after the specialist fleet is already installed.

Accept

The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

Evidence the case requires

Business-model variants; sunk-cost case; full cash-flow and adaptation records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use independently reviewed dynamic operator policies, not fixed market shares.

Steps

  1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
  2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
  3. Compare equilibrium and transient outcomes across independent starting conditions.

Accept

Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

Evidence the case requires

Agent policies; sensitivity seeds; market-share paths; independent model review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

Steps

  1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
  2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
  3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

Accept

No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

Evidence the case requires

Scenario register; full result cube; boundary plots; failed-world explanations.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-01b
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

Steps

  1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
  2. Test flat/declining fees and no external proving income; separately introduce external demand.
  3. Calculate capacity and security-provider coverage after each reward transition.

Accept

Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

Evidence the case requires

Issuance/fee ledger; scenario cash flows; funding-shortfall report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

Steps

  1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
  2. Include ordinary-owner replacement, resale and reloading expenses.
  3. Run alternate bounded schedules without assigning automatic chip death.

Accept

The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

Evidence the case requires

Per-step cost/retention table; alternative schedules; approval record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

Steps

  1. Recalculate required worlds and perturb favourable assumptions against the team.
  2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
  3. Publish the sensitivity range and state which conclusions are conditional.

Accept

Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

Evidence the case requires

Independent report; rerun outputs; model limitations; approved claim envelope.

Method
Independent economic review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-01b
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
07EVM

Execution and developer compatibility

Keep familiar applications while making every difference and metering rule explicit and reproducible.

RUNNING
Owner
Execution lead + independent implementer
Gate
Technical readiness
Fixtures
F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
Plan pages
15, 25, 34, 35, 36, 37
8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

Setup

Pin the intended execution fork, revm version and all Igneum deviations in F0.

Steps

  1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
  2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
  3. Minimise mismatches and distinguish intended differences from implementation defects.

Accept

All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

Evidence the case requires

Fixture/version inventory; root/receipt diffs; deviation matrix.

Evidence record of the run

What was run
/compatibility 20 of 20 rows PASSED on igneum-devnet-4
Run by
reference-apps lane (a2060899d2a27d31c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use signed transfers, contract calls and deployment transactions with boundary field values.

Steps

  1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
  2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
  3. Check mempool admission and final consensus execution independently.

Accept

Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

Evidence the case requires

Signed corpus; admission/execution outcomes; account-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

Steps

  1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
  2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
  3. Mutate a block producer to omit or undercharge expensive work.

Accept

Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

Evidence the case requires

Metering traces; fee fixtures; estimator errors; invalid-block rejection.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use contracts sensitive to timestamp, height/context, randomness and ordering.

Steps

  1. Compare the declared Igneum semantics with developers' documented expectations.
  2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
  3. Run dependency reviews for applications using these values for economic decisions.

Accept

Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

Evidence the case requires

Context-contract results; threat notes; compatibility exclusions.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

Steps

  1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
  2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
  3. Compare expected application invariants with native execution and proved results.

Accept

Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

Evidence the case requires

Contract fixture hashes; transaction journeys; invariant and state comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

Steps

  1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
  2. Reindex from genesis or the documented trust anchor after pruning and restart.
  3. Compare logs, receipts and balances with independently validated chain state.

Accept

No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

Evidence the case requires

RPC conformance report; reindex comparison; reconnect/edge-case logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

Steps

  1. Measure CPU, memory, disk and proving cost against charged budgets.
  2. Saturate admission with invalid/expensive requests while valid workloads continue.
  3. Restart mid-execution and verify atomic state recovery.

Accept

P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

Evidence the case requires

Resource profiles; adversarial corpus; state recovery comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Prepare two authorised versions and malicious, stale or unknown versions.

Steps

  1. Cross activation with mixed clients, queued transactions and proofs from both versions.
  2. Bind each accepted proof to the correct execution semantics and program identity.
  3. Exercise a failed software distribution without altering consensus activation.

Accept

No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

Evidence the case requires

Upgrade vectors; mixed-version traces; manifest/version bindings.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
08ZKP

Consensus-enforced proof validity

The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

RUNNING
Owner
Proving + protocol leads; independent cryptography review
Gate
Technical readiness / G5 G5
Fixtures
F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
Plan pages
16, 20, 24, 25, 36, 37
8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Start from a native-correct statement and an independently verified valid proof.

Steps

  1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
  2. Submit the genuine proof as a positive control through ordinary network paths.
  3. Inspect block acceptance and resulting reward/state on unmodified validators.

Accept

Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

Evidence the case requires

Hostile record corpus; validator decisions; before/after balances; positive controls.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use valid proofs from authorised and unauthorised programs and parameter sets.

Steps

  1. Swap program digest, verifier version, security settings and verification key where applicable.
  2. Attempt downgrade through configuration, serialized metadata or an old node path.
  3. Test authorised boundary transitions and unsupported future identities.

Accept

Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

Evidence the case requires

Identity/parameter matrix; rejection traces; cryptographic review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

Steps

  1. Replay each proof under another network, job, epoch, shard range or state commitment.
  2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
  3. Check duplicated and reordered records across forks and replayed sync data.

Accept

Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

Evidence the case requires

Binding matrix; public-input hashes; replay traces; reward reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use proofs that commit to authorisation and all reward-relevant fields required by F0.

Steps

  1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
  2. Supply correct execution over malicious producer-provided consensus/reward inputs.
  3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

Accept

Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

Evidence the case requires

Mutation cases; reward derivation trace; signature/proof binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

Steps

  1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
  2. Crash validators between validation and reward application, then recover.
  3. Reconcile canonical payouts against the exact F0 duplicate policy.

Accept

Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

Evidence the case requires

Concurrency schedule; canonical payment ledger; crash/recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

Steps

  1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
  2. Alter shard ranges, roots and aggregation-program identity.
  3. Verify native execution, aggregate validity and coverage commitments independently.

Accept

Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

Evidence the case requires

Coverage corpus; aggregate/public-input verification; rejection ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

Steps

  1. Review soundness assumptions, parameter margins and consequences of performance patches.
  2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
  3. Cross-check an independent verifier or reference path and test crash containment.

Accept

P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

Evidence the case requires

Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

Method
Independent cryptographic review + testing
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Inspect block import, sync, RPC, light verification, database restoration and fast paths.

Steps

  1. Try bypassing validation via each path with a proof rejected by the normal path.
  2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
  3. Attempt to use proof-production status as ordering, voting or finality authority.

Accept

No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

Evidence the case requires

Path coverage report; bypass corpus; replacement run; authority checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
09CAP

Sustained proving and delivery

A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

NOT RUN
Owner
Proving lead + independent operators
Gate
Technical readiness / commercial track
Fixtures
F3 meaningful workload catalogue; F4 network; F8 external job harness
Plan pages
17, 18, 24, 25
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

Steps

  1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
  2. Record proof format, memory, energy, host and whether aggregation/compression are included.
  3. Repeat on the final release and label all configuration changes.

Accept

Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

Evidence the case requires

Historical/current manifests; proof verification; timing and memory records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

Steps

  1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
  2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
  3. Induce memory pressure and GPU task failure without losing wallet control.

Accept

Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

Evidence the case requires

Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

Steps

  1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
  2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
  3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

Accept

No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

Evidence the case requires

Stage event ledger; clock calibration; end-to-end latency/cost report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

Steps

  1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
  2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
  3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

Accept

P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

Evidence the case requires

Request/completion reconciliation; backlog series; held-out results; observer report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

Steps

  1. Observe admission, explicit backpressure, reservations and deadline estimates.
  2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
  3. Measure recovery time and ensure ordinary users are not silently starved.

Accept

P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

Evidence the case requires

Overload timeline; admission/refund logs; backlog-drain proof.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

Steps

  1. Measure actual completion distributions with network delay, competing load and failed attempts.
  2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
  3. Compare assignment frequency, paid completions and wasted work by tier.

Accept

P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

Evidence the case requires

Window sweep; paid-completion distribution; wasted-work and margin report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Remove input providers, assigned provers and the dominant aggregator independently and together.

Steps

  1. Have replacement operators retrieve authenticated inputs without founder files.
  2. Retry expired assignments while preserving idempotent reward and customer outcomes.
  3. Restore providers and test late submissions racing with replacements.

Accept

P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

Evidence the case requires

Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run the external workload using a customer-controlled verifier and independently operated workers.

Steps

  1. Verify every delivered proof against the contracted program and input commitment.
  2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
  3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

Accept

P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

Evidence the case requires

Customer verification log; proof-format contract; settlement reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
10INC

Rewards, incentives and selfish operators

Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

RUNNING
Owner
Protocol economics + proving leads
Gate
G4 / G5 G4 G5
Fixtures
F0 fee/reward rules; F4 adversarial operators; F7 incentive models
Plan pages
13, 16, 17, 18, 24, 26
8 cases: 0 passed under the standard, 5 running with team evidence, 3 not run, 0 deferred
INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use a deterministic short chain containing all reward types, fee paths and rounding cases.

Steps

  1. Calculate balances, total supply changes, burns and distributions independently.
  2. Execute identical blocks natively and through the proving path.
  3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

Accept

Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

Evidence the case requires

Independent accounting ledger; balance/supply diffs; boundary vectors.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

Steps

  1. Trace money from source to operator, protocol, developer and any burn.
  2. Compare node records, settlement records and Ember displays.
  3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

Accept

Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

Evidence the case requires

Money-flow register; UI reconciliation; rejected classifications.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Permit independent schedulers to mine, prove internally, prove externally or switch off.

Steps

  1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
  2. Run clients that ignore the official scheduling recommendation.
  3. Measure realised operator margin, internal capacity and network progress.

Accept

Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

Evidence the case requires

Scheduler source/policies; switching traces; capacity and margin series.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

Steps

  1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
  2. Observe hash participation, proof backlog, fees and recovery without an administrator.
  3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

Accept

Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

Evidence the case requires

Shock timeline; fee/hash/capacity paths; failure-region report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

Steps

  1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
  2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
  3. Price attacker costs and observe honest completion under the approved abuse load.

Accept

F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

Evidence the case requires

Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

Steps

  1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
  2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
  3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

Accept

Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

Evidence the case requires

Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use self-funded operators and related customer identities in the isolated economic model/network.

Steps

  1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
  2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
  3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

Accept

No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

Evidence the case requires

Circular-flow tests; ownership/conflict review; net-cash reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12RUNNINGEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Model control of hashing, signing, proving, aggregation and hardware supply separately.

Steps

  1. Remove each largest operational dependency and combine correlated failures.
  2. Measure replacement cost/time and whether essential roles share hidden ownership.
  3. Compare results with the approved fault model and no-rescue exercise.

Accept

No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

Evidence the case requires

Role/ownership map; dependency removals; recovery and concentration report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
11FIN

Consensus safety and recovery

Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

RUNNING
Owner
Consensus lead + independent formal/security review
Gate
G5 / technical readiness G5
Fixtures
F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
Plan pages
19, 21, 24, 25
8 cases: 2 passed under the standard, 6 running with team evidence, 0 not run, 0 deferred
FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

Steps

  1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
  2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
  3. Replay from independent checkpoints and from genesis where practical.

Accept

Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

Evidence the case requires

Block/ordering corpus; root/work diffs; real-node replay logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

Steps

  1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
  2. Delay messages and eligibility updates independently; keep total historical weights auditable.
  3. Try to form two certificates and reconnect nodes to observe accepted final history.

Accept

No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

Evidence the case requires

Signed votes; certificate attempts; voter-table snapshots; safety checker output.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Recover historical expiry failures where available; use the actual current authority-transition rules.

Steps

  1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
  2. Attempt independently renewed authority sets and conflicting checkpoint locks.
  3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

Accept

Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

Evidence the case requires

Expiry timeline; table/certificate history; historical regression tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Remove enough signing participation to invalidate the liveness assumption without forging votes.

Steps

  1. Continue mining and execution, cross seed boundaries and monitor proof queues.
  2. Check which user-visible states advance and which remain unfinalised.
  3. Restore eligible weight and bounded message delay, then verify recovery.

Accept

No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

Evidence the case requires

Signing/mining trace; UI/RPC states; recovery roots and timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use normal transitions, pool members retaining keys and malicious substitution attempts.

Steps

  1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
  2. Race updates across boundaries and replay old signed changes.
  3. Have a new node verify the authority chain from its declared trust anchor.

Accept

Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

Evidence the case requires

Authority-chain fixtures; substitution attacks; new-node verification log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

Steps

  1. Use previously eligible keys to build alternative histories after their operators disappear.
  2. Present these histories to recently offline and newly joining clients.
  3. Test replayed certificates, stale anchors and compromised signer subsets.

Accept

Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

Evidence the case requires

Long-range corpus; trust-anchor policy; key-compromise review; client results.

Evidence record of the run

What was run
bought and stolen keys in the simulator rows
Run by
finality lane (aca0f5ed924a2a99b)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Combine partitions with node crash, partial writes, restarts and proof backlog.

Steps

  1. Reconnect networks under bounded latency and restore required honest participation.
  2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
  3. Compare all honest nodes and customer-visible receipts after recovery.

Accept

P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

Evidence the case requires

Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08RUNNINGEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Use an independent model checker/scheduler and production-node scenarios from F4.

Steps

  1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
  2. Explore bounded adversarial message schedules and minimise any counterexample.
  3. Replay model findings on real code and have an independent reviewer assess uncovered states.

Accept

No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

Evidence the case requires

Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

Method
Model checking + real-node testing
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
12VER

Wallets, receipts and data availability

Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

FAIL
Owner
Wallet + light-client lead; independent security review
Gate
Technical readiness / claimed options
Fixtures
F0 trust/availability model; F5 malformed roots, receipts and authority chains
Plan pages
20, 25, 35, 37
8 cases: 0 passed under the standard, 4 running with team evidence, 3 failed, 1 not run, 0 deferred
VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

Steps

  1. Start from the approved trust anchor and verify every required link to the advertised state.
  2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
  3. Remove the bootstrap service and use another independently operated source.

Accept

The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

Evidence the case requires

Bootstrap corpus; trust-chain trace; fail-closed tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Use valid state proofs paired with wrong execution statements or stale authority histories.

Steps

  1. Cross voter and verifier changes with offline clients returning after long intervals.
  2. Alter roots, aggregate identity and proof/public-input bindings independently.
  3. Check local verification rather than merely a server-reported verified flag.

Accept

All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

Evidence the case requires

Client verification trace; corrupted inputs; offline/upgrade results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

Steps

  1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
  2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
  3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

Accept

Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

Evidence the case requires

Payment fixture corpus; receipt verification; merchant-facing status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

Steps

  1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
  2. Exercise legitimate authority updates and source reorganisations under the approved model.
  3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

Accept

The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

Evidence the case requires

Oracle code/parameters; attack cases; cost report; privilege disclosure.

Method
Claimed-option verification
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Remove founder archival/input services and start an independent operator from the documented entry point.

Steps

  1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
  2. Rebuild the expected state and continue validation/proving.
  3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

Accept

Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

Evidence the case requires

Download/reconstruction logs; data hashes; resource costs; dependency inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

Steps

  1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
  2. Test retrieval from independent peers and expiry/retry policy.
  3. Restore data and check that recovery cannot alter an already verified commitment.

Accept

No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

Evidence the case requires

Withholding corpus; peer retrieval traces; availability/status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

Steps

  1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
  2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
  3. Upgrade and recover without silently changing signing authority or exposing seed material.

Accept

No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

Evidence the case requires

Security review; canary-secret tests; signing fixtures; restore journey.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create included-only, executed, proven, finalised, reverted, stale and paused examples.

Steps

  1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
  2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
  3. Check statements about privacy, Ethereum security and device support.

Accept

No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

Evidence the case requires

Cross-surface screenshots/logs; state mapping; claim review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
13OPS

Independent operation and release security

A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

RUNNING
Owner
Operations + release leads; independent operators
Gate
G5 G5
Fixtures
F4 isolated multi-operator network; F0 signed releases; F9 telemetry
Plan pages
21, 24, 25, 26
8 cases: 0 passed under the standard, 2 running with team evidence, 6 not run, 0 deferred
OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

Steps

  1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
  2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
  3. Introduce scheduled faults and have independent operators recover using published instructions.

Accept

No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

Evidence the case requires

Operator roster/conflict checks; dependency removals; full activity/intervention log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start nodes without the default bootstrap host and give others adversarial peer lists.

Steps

  1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
  2. Use independent documented discovery paths and validate returned chain data.
  3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

Accept

No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

Evidence the case requires

Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:56 UK

Setup

Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

Steps

  1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
  2. Test explicit operator acceptance and the published signing-key incident procedure.
  3. Confirm that distribution-key possession cannot independently activate new consensus rules.

Accept

Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

Evidence the case requires

Package corpus; approval/activation traces; compromised-key rehearsal.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
site-manifest-20261008-01
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

Steps

  1. Crash during import, proof acceptance, reward application and snapshot generation.
  2. Restore from independently verified snapshots or re-sync through documented procedures.
  3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

Accept

No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

Evidence the case requires

Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run hostile test jobs with secret canaries and restrictive worker permissions.

Steps

  1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
  2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
  3. Retry on every supported isolation backend and check dependency vulnerability handling.

Accept

No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

Evidence the case requires

Sandbox penetration report; canary logs; resource limits; host-integrity checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use an authorised isolated load environment with declared resource and request-rate budgets.

Steps

  1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
  2. Measure legitimate traffic, memory/disk growth and validator CPU use.
  3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

Accept

P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

Evidence the case requires

Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

Steps

  1. Inject one instance of each monitored failure in the lab.
  2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
  3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

Accept

P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

Evidence the case requires

Alert matrix; detection timelines; independent runbook exercise.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a clean previous supported version and the final candidate with independent operators.

Steps

  1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
  2. Cross activation with mixed versions and unavailable founder distribution hosts.
  3. Re-run affected gates after changes and preserve prior failures and incident lessons.

Accept

No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

Evidence the case requires

Upgrade/replay logs; invalidation map; repeated gate signatures.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
14UX

Ember, payouts and operator control

Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

RUNNING
Owner
Desktop product + pool leads; independent usability study
Gate
Operator readiness / G5 G5
Fixtures
F2 supported desktops; F8 user study; F4 honest/malicious pools
Plan pages
14, 21, 25, 26
8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

Steps

  1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
  2. Record download/data preparation separately as well as complete end-to-end time.
  3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

Accept

P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

Evidence the case requires

Consent-based study records; task timings; failure reasons; compatibility outcomes.

Method
Independent observed user study
Cadence
Release candidate; repeat after relevant changes
Owner
update-return lane (a22d765a2e0355a9f)
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Run mining/proving on active desktops under contention and safe thermal stress.

Steps

  1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
  2. Crash or restart the UI while workers run and verify ownership of background processes.
  3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

Accept

P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

Evidence the case requires

Control timings; process/settings audit; restart and safety traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use known rewards, fees, energy readings, retries and operator-entered tariffs.

Steps

  1. Compare mining, internal proof and external proof income with authoritative ledgers.
  2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
  3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

Accept

P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

Evidence the case requires

UI/ledger comparisons; tariff fixtures; stale/negative examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use ordinary single-card balances and the actual pooling/payment path.

Steps

  1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
  2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
  3. Reconcile displayed balances with canonical entitlement and actual settlement.

Accept

P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

Evidence the case requires

Single-card payout ledger; pool failure record; custody/authorisation review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use an honest pool and a modified pool that replaces worker identity or voting credentials.

Steps

  1. Verify the consensus binding from performed work to the miner's retained key.
  2. Attempt substitution, replay and reassignment without the miner's authorisation.
  3. Leave the pool and verify retained voting/finality rights under F0.

Accept

No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

Evidence the case requires

Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
pool-2.0-20261008-01
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Provide a pool interface with declared job-declaration support and independent miner templates.

Steps

  1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
  2. Have a pool substitute or censor templates and test local verification/fallback.
  3. Measure payout and acceptance consequences without moving authority to the pool.

Accept

The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

Evidence the case requires

Template commitments; accepted-block evidence; malicious-pool/fallback report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

Steps

  1. Ask independent users to identify the issue, stop safely and follow the recommended action.
  2. Test explicit update approval, version visibility and a failed/corrupt update.
  3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

Accept

P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

Evidence the case requires

Observed tasks; update traces; sanitised export tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

Steps

  1. Compare Ember against independently optimised permissible implementations on identical work.
  2. Measure efficiency, fees, false rejection, installation and update transparency.
  3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

Accept

P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

Evidence the case requires

Matched software comparison; code/config review; fee/privilege inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
15COM

Paid demand and sustainable delivery

Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

NOT RUN
Owner
Commercial lead + independent financial/customer reviewer
Gate
Commercial evidence
Fixtures
F8 real consenting customers; F7 full service costs; private identity proofs
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 7 not run, 1 deferred
COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

Steps

  1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
  2. Run paid jobs through ordinary independently operated infrastructure.
  3. Have the customer verify usefulness, correctness and its reason for choosing the service.

Accept

The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

Evidence the case requires

Redacted contract; verified jobs; settlement proof; consented customer confirmation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P14 multi-customer observation period and ownership/conflict checks.

Steps

  1. Track paid purchases on distinct occasions, including refunds and stopped customers.
  2. Audit related parties, project reimbursements, token grants and circular funding.
  3. Reconcile external cash received with correctly delivered meaningful work.

Accept

P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

Evidence the case requires

Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

Steps

  1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
  2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
  3. Repeat under the declared demand and price sensitivities.

Accept

P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

Evidence the case requires

Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

Steps

  1. Count all accepted jobs, including failed, retried and abandoned cases.
  2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
  3. Compare offered capacity and quoted price with what was actually delivered.

Accept

P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

Evidence the case requires

Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

Steps

  1. Obtain comparable quotes or consented measured trials at the evaluation date.
  2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
  3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

Accept

P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

Evidence the case requires

Dated comparison; workload/security match; customer decision record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Follow all recruited customers through the P14 observation period, including churn.

Steps

  1. Remove disclosed trial incentives before measuring repeat demand.
  2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
  3. Review whether one affiliated or subsidised buyer dominates the apparent market.

Accept

P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

Evidence the case requires

Cohort/renewal ledger; churn notes; concentration and incentive report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13DEFERREDEvidence none yetLast run 2026-10-08 18:3x UK (the founder: forget P13 for now)

Setup

Prepare a costed plan for development, review, infrastructure, support and incident response.

Steps

  1. Separate committed resources from revenue dependent on adoption or token price.
  2. Stress lower income and an unexpected security/operations expense.
  3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

Accept

P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

Evidence the case requires

Budget and commitment evidence; downside plan; owner/continuity roster.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Recruit unaffiliated developers unfamiliar with unpublished implementation details.

Steps

  1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
  2. Record time, undocumented dependencies, workarounds and correctness issues.
  3. Retest after documentation fixes without founder-written hidden integration code.

Accept

P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

Evidence the case requires

Consented developer logs; public examples; issue closure; verified end-to-end journeys.

Method
Independent integration study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
16LEAD

Comparative leadership evidence

A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

NOT RUN
Owner
Independent assessment panel + product/economics reviewers
Gate
Leadership-contender decision
Fixtures
F8 peer/customer studies; full signed technical evidence; 90-day observation
Plan pages
4, 22, 25, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

Steps

  1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
  2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
  3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

Accept

The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

Evidence the case requires

Timestamped peer protocol; source/version records; comparison/exclusion rationale.

Method
Pre-registered comparative study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use matched user tasks and operating conditions on the selected GPU-first networks.

Steps

  1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
  2. Measure rejection/availability under the same network conditions; report fees separately.
  3. Use blinded analysis where possible and independent runs for decisive differences.

Accept

P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

Evidence the case requires

Matched task data; uncertainty/effect sizes; independent comparison report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
site lane (a846fd66b5403e35a)
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

Steps

  1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
  2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
  3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

Accept

All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

Evidence the case requires

Claim-to-evidence map; signed envelope review; limitations statement.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

Steps

  1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
  2. Report trial incentives separately and include every initial participant in retention denominators.
  3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

Accept

P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

Evidence the case requires

Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

Steps

  1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
  2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
  3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

Accept

P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

Evidence the case requires

Control/failure-domain map; uncertainty notes; concentration/removal results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe the final candidate and approved compatible updates for the full P16 real-time period.

Steps

  1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
  2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
  3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

Accept

P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

Evidence the case requires

90-day SLO ledger; independent probes; incident reports; change/retest history.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

Steps

  1. Check every mandatory and claimed-option test, source requirement and approved threshold.
  2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
  3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

Accept

Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

Evidence the case requires

Signed assessment; full status index; dissent/limitations; approved claim wording.

Method
Independent final assessment
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define material-change triggers and scheduled reviews before publishing the assessment.

Steps

  1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
  2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
  3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

Accept

Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

Evidence the case requires

Review calendar; invalidation drills; versioned public claim register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
17REV

REV: the external review's required regressions

44 regressions from 14 findings; each reads NOT RUN until its owner lane records a run

NOT RUN
Owner
the owner lanes per the dispatch table
Gate
Review findings closed
Fixtures
F0,F5
Plan pages
docs/analysis/review-2026-10-08-b/findings.json and docs/analysis/review-2026-10-08-b/dispatch.md
44 cases: 0 passed under the standard, 0 running with team evidence, 44 not run, 0 deferred
REV-F01-1Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F01 requires (review finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Accept

Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
F01
REV-F01-2Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F01 requires (review finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Accept

Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
F01
REV-F01-3Change payout, network, kind, program ID and activation context; no accepted misbinding.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F01 requires (review finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Change payout, network, kind, program ID and activation context; no accepted misbinding.

Accept

Change payout, network, kind, program ID and activation context; no accepted misbinding.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
F01
REV-F01-4A native two-node test must agree on block validity and payouts despite different cache histories.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F01 requires (review finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. A native two-node test must agree on block validity and payouts despite different cache histories.

Accept

A native two-node test must agree on block validity and payouts despite different cache histories.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
F01
REV-F02-1Release build cannot activate test bypass.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F02 requires (review finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Release build cannot activate test bypass.

Accept

Release build cannot activate test bypass.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
F02
REV-F02-2Missing oracle or pinned keys prevents service readiness after enforcement activation.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F02 requires (review finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing oracle or pinned keys prevents service readiness after enforcement activation.

Accept

Missing oracle or pinned keys prevents service readiness after enforcement activation.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
F02
REV-F02-3Missing proof bytes retry without incorrectly marking a valid block permanently invalid.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F02 requires (review finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Accept

Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
F02
REV-F03-1Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F03 requires (review finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Accept

Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
F03
REV-F03-2Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F03 requires (review finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Accept

Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
F03
REV-F03-3Cross every scheduled transition with old/new client behavior documented and identical rule identities.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F03 requires (review finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Accept

Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
F03
REV-F04-1Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F04 requires (review finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Accept

Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
F04
REV-F04-2Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F04 requires (review finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Accept

Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
F04
REV-F04-3Pause-only resume with historical backfill, missing historical data and all old keys returning.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F04 requires (review finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Pause-only resume with historical backfill, missing historical data and all old keys returning.

Accept

Pause-only resume with historical backfill, missing historical data and all old keys returning.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
F04
REV-F04-4Wallet, receipt and oracle consumers distinguish any weaker recovery state.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F04 requires (review finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Accept

Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
F04
REV-F05-1Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F05 requires (review finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Accept

Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
F05
REV-F05-2Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F05 requires (review finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Accept

Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
F05
REV-F05-3Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F05 requires (review finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Accept

Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
F05
REV-F06-1Acceptance/reference/emitter evaluate the same activated schedule.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F06 requires (review finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Acceptance/reference/emitter evaluate the same activated schedule.

Accept

Acceptance/reference/emitter evaluate the same activated schedule.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
F06
REV-F06-2Full live-dataset census on unseen seeds and the complete v6 pack.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F06 requires (review finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Full live-dataset census on unseen seeds and the complete v6 pack.

Accept

Full live-dataset census on unseen seeds and the complete v6 pack.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
F06
REV-F06-3A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F06 requires (review finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Accept

A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
F06
REV-F07-1Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F07 requires (review finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Accept

Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
F07
REV-F07-2OOM, process crash and stale work recover without losing wallet state or silently consuming power.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F07 requires (review finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Accept

OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
F07
REV-F07-316 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F07 requires (review finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. 16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Accept

16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
F07
REV-F08-1Report every eligible job outcome, including expired work; a bounded list cannot hide losses.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F08 requires (review finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Accept

Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
F08
REV-F08-2Consumer tiers complete and receive payment for declared jobs before claims about income.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F08 requires (review finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Consumer tiers complete and receive payment for declared jobs before claims about income.

Accept

Consumer tiers complete and receive payment for declared jobs before claims about income.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
F08
REV-F08-3Sustained real workload across class transitions, with restart/retry and no publisher intervention.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F08 requires (review finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Accept

Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
F08
REV-F09-1Generate all pass/fail cells directly from the declared inequalities and inputs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F09 requires (review finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Generate all pass/fail cells directly from the declared inequalities and inputs.

Accept

Generate all pass/fail cells directly from the declared inequalities and inputs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
F09
REV-F09-2Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F09 requires (review finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Accept

Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
F09
REV-F09-3GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F09 requires (review finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Accept

GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
F09
REV-F10-1Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F10 requires (review finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Accept

Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
F10
REV-F10-2Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F10 requires (review finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Accept

Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
F10
REV-F10-3Compare production throughput and wall energy, not only the isolated kernel timer.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F10 requires (review finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare production throughput and wall energy, not only the isolated kernel timer.

Accept

Compare production throughput and wall energy, not only the isolated kernel timer.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
F10
REV-F11-1Goal switch from an efficiency prior can explore higher core/power when policy allows.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F11 requires (review finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Goal switch from an efficiency prior can explore higher core/power when policy allows.

Accept

Goal switch from an efficiency prior can explore higher core/power when policy allows.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
F11
REV-F11-2Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F11 requires (review finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Accept

Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
F11
REV-F11-3Thermal/error/late-share events revert safely, including process or machine crash.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F11 requires (review finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Thermal/error/late-share events revert safely, including process or machine crash.

Accept

Thermal/error/late-share events revert safely, including process or machine crash.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
F11
REV-F12-1Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F12 requires (review finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Accept

Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F12
REV-F12-2Same signed transaction retried, fee replacement reconciled by intent, not a new payment.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F12 requires (review finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Accept

Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F12
REV-F12-3Receipt reorg and finality pause leave correct pending obligations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F12 requires (review finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Receipt reorg and finality pause leave correct pending obligations.

Accept

Receipt reorg and finality pause leave correct pending obligations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F12
REV-F13-1Repeated authorization rejected or atomically replaces and cleans prior state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F13 requires (review finding F13: Pool admission and membership need bounded resources).

Steps

  1. Repeated authorization rejected or atomically replaces and cleans prior state.

Accept

Repeated authorization rejected or atomically replaces and cleans prior state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F13
REV-F13-2Oversized unterminated frame rejected within fixed memory/time budget.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F13 requires (review finding F13: Pool admission and membership need bounded resources).

Steps

  1. Oversized unterminated frame rejected within fixed memory/time budget.

Accept

Oversized unterminated frame rejected within fixed memory/time budget.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F13
REV-F13-3Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F13 requires (review finding F13: Pool admission and membership need bounded resources).

Steps

  1. Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Accept

Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
F13
REV-F14-1Public build has no default arbitrary remote execution and a documented least-privilege boundary.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F14 requires (review finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Accept

Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
F14
REV-F14-2Automatic updates off remains off for urgent manifests until explicit action.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F14 requires (review finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Automatic updates off remains off for urgent manifests until explicit action.

Accept

Automatic updates off remains off for urgent manifests until explicit action.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
F14
REV-F14-3A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

The regression F14 requires (review finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Accept

A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
F14
Profiles

The numbers each case is held to.

17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

P00Approved as proposed

Frozen scope and approval

  1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
  2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
  3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

Cited by 58 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P01Approved as proposed

Correctness and negative-test depth

  1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
  2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
  3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P02Approved as proposed

Hardware coverage and reproducibility

  1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
  2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
  3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
  4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P03Approved as proposed

Candidate improvement and honest-card budget

  1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
  2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
  3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P04Approved as proposed

Scoped specialist-competition target

  1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
  2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
  3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
  4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P05Approved as proposed

Measurement and inference protocol

  1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
  2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
  3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
  4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P06Approved as proposed

Memory and support policy

  1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
  2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
  3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P07Approved as proposed

Proof service capacity and fairness

  1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
  2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
  3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
  4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
  5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P08Approved as proposed

Fault assumptions and recovery

  1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
  2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
  3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
  4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P09Approved as proposed

Security and bounded resource requirements

  1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
  2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
  3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
  4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P10Approved as proposed

Ordinary-operator product targets

  1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
  2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
  3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
  4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
  5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P11Approved as proposed

No-founder exercise and independence

  1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
  2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
  3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P12Approved as proposed

Five-year coexistence envelope

  1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
  2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
  3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
  4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
  5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P13Deferred by the founder

Maintenance continuity

  1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
  2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
  3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P14Approved as proposed

Genuine commercial and developer proof

  1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
  2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
  3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
  4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P15Approved as proposed

Comparative contention threshold

  1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
  2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
  3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
  4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P16Approved as proposed

Observed durability and claim freshness

  1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
  2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
  3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
  4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

Fixtures

What every run is built on.

F0

Release and assurance manifest

Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

F1

Clean build environments

Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

F2

Hardware and measurement lab

Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

F3

Workload and oracle catalogue

Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

F4

Authorised fault network

Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

F5

Negative and regression corpus

Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

F6

Specialist implementation pack

Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

F7

Economic and incentive models

Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

F8

User/customer/peer studies

Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

F9

Evidence and status vault

Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

What a full pass means

Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

Rules in force

  • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
  • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
  • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
  • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

- +
Igneum 2.0 acceptance

Test and Acceptance Standard 1.0

Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 190 cases: 2 passed under the standard, 0 running with team evidence, 6 failed, 182 not run, 0 deferred

  • 2 pass
  • 6 fail
  • 0 blocked
  • 0 running
  • 182 not run
  • 0 deferred
The gates

Five gates, and the freeze before them.

A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

G0NOT RUN

Freeze

Release identity

No formal run or public pass before approval.

8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred

  • GOV8 casesNOT RUN
G1NOT RUN

Baseline

D1

No validated hardware claim without reproduction.

16 cases: 0 passed under the standard, 0 running with team evidence, 16 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
G2FAIL

Experiments

D2

No improvement claim from a negative hypothesis.

32 cases: 0 passed under the standard, 0 running with team evidence, 2 failed, 30 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ROT8 casesNOT RUN
G3NOT RUN

Adversary

D3

No broad resistance claim from one weak design.

16 cases: 0 passed under the standard, 0 running with team evidence, 16 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ADV8 casesNOT RUN
G4FAIL

Coexistence

D4

No durability claim based on assumed chip expiry.

24 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 23 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ECO8 casesFAIL
  • INC8 casesNOT RUN
G5NOT RUN

No rescue

D5

No no-rescue claim from a founder-supported demo.

56 cases: 2 passed under the standard, 0 running with team evidence, 54 not run, 0 deferred

  • GOV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN

The three named gates

FAIL

Technical readiness

Execution control

No mainnet-ready claim with missing enforcement or safety.

64 cases: 2 passed under the standard, 0 running with team evidence, 5 failed, 57 not run, 0 deferred

  • GOV8 casesNOT RUN
  • POW8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • UX8 casesNOT RUN
NOT RUN

Commercial evidence

Execution control

Devnet activity is insufficient.

24 cases: 0 passed under the standard, 0 running with team evidence, 24 not run, 0 deferred

  • GOV8 casesNOT RUN
  • CAP8 casesNOT RUN
  • COM8 casesNOT RUN
FAIL

Leadership-contender decision

Execution control

Supports a scoped contention assessment, not a guaranteed rank.

190 cases: 2 passed under the standard, 0 running with team evidence, 6 failed, 182 not run, 0 deferred

  • GOV8 casesNOT RUN
  • GPU8 casesNOT RUN
  • POW8 casesFAIL
  • ADV8 casesNOT RUN
  • ROT8 casesNOT RUN
  • ECO8 casesFAIL
  • EVM8 casesNOT RUN
  • ZKP8 casesNOT RUN
  • CAP8 casesNOT RUN
  • INC8 casesNOT RUN
  • FIN8 casesNOT RUN
  • VER8 casesFAIL
  • OPS8 casesNOT RUN
  • UX8 casesNOT RUN
  • COM8 casesNOT RUN
  • LEAD8 casesNOT RUN
  • REV44 casesNOT RUN
  • INT18 casesNOT RUN
01GOV

Release identity and evidence

Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

NOT RUN
Owner
Release lead + independent assurance
Gate
G0 / all gates G0 G1 G2 G3 G4 G5
Fixtures
F0 manifest; F1 source/build archives; F9 evidence vault
Plan pages
5, 21, 23, 25, 26, 27
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

Steps

  1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
  2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
  3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

Accept

Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

Evidence the case requires

Signed F0; source-to-test map; claim inventory; unresolved-field register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

This manual supplies proposed test thresholds, not source-approved protocol parameters.

Steps

  1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
  2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
  3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

Accept

No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

Evidence the case requires

Approved profile register; timestamped holdout commitments; change log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide public source and documented build instructions to three unaffiliated operators.

Steps

  1. Build on clean declared environments without private files, tokens or founder assistance.
  2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
  3. Run reference vectors and restart a node using only documented artifacts.

Accept

All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

Evidence the case requires

Build logs; dependency lockfiles; binary comparison; operator attestations.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
18
Plan pages
5, 21, 23, 25, 26, 27
GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Enable append-only storage for run outputs and a separate analysis workspace.

Steps

  1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
  2. Recompute one published figure from raw records on a clean machine.
  3. Modify a retained artifact deliberately and test integrity verification.

Accept

Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

Evidence the case requires

Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Create controlled defective variants on an isolated network only.

Steps

  1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
  2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
  3. Confirm the baseline still accepts authorised valid cases.

Accept

Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

Evidence the case requires

Mutation catalogue; blinded run results; baseline controls; oracle review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

Steps

  1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
  2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
  3. For each claimed option, require the complete associated test set rather than a demonstration.

Accept

Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

Evidence the case requires

Scope manifest; activation scan; product-copy comparison; exclusions register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
19
Plan pages
5, 21, 23, 25, 26, 27
GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

Steps

  1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
  2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
  3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

Accept

No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

Evidence the case requires

Signed scoped reports; conflict declarations; finding/retest ledger.

Method
Independent specialist review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

Steps

  1. Calculate affected test dependencies and invalidate their former PASS statuses.
  2. Regenerate public status pages from F0 and the evidence register.
  3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

Accept

Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

Evidence the case requires

Dependency impact report; regenerated status page; rejected claim examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
CI steward (a2ecfa95d3206016c)
Design status
NOT RUN
Standard page
20
Plan pages
5, 21, 23, 25, 26, 27
02GPU

Whole-system GPU measurements

Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

NOT RUN
Owner
GPU lead + three independent operators
Gate
G1 / G2 G1 G2
Fixtures
F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
Plan pages
6, 7, 8, 14, 18, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
GPU-01Cover the declared commodity populationPriority GATEProfile P02NOT RUNEvidence recordLast run 8 Oct 2026, 20:59 UK

Setup

Freeze the P02 cohort, supported role matrix and the final v6 configuration.

Steps

  1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
  2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
  3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

Accept

All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

Evidence the case requires

Cohort manifest; compatibility matrix; raw results by SKU and role.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
hash-lane-20261008-batch2
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03NOT RUNEvidence recordLast run 8 Oct 2026, 19:41 UK

Setup

Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

Steps

  1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
  2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
  3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

Accept

Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

Evidence the case requires

Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261008-batch1
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03NOT RUNEvidence none yetLast run 8 Oct 2026, 21:18 UK

Setup

Build the baseline and window variant with identical dataset, reads and semantic workload.

Steps

  1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
  2. Measure paired complete-system energy and accepted throughput, including host work.
  3. Repeat during proving coexistence and expose any memory or scheduling cliff.

Accept

Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

Evidence the case requires

Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
amd-intel-energy-20261008-01
Design status
NOT RUN
Standard page
21
Plan pages
6, 7, 8, 14, 18, 23
GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Use safe vendor-supported settings only; record operator permission and original settings.

Steps

  1. Sweep approved core and memory operating points while holding workload constant.
  2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
  3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

Accept

Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

Evidence the case requires

Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06NOT RUNEvidence recordLast run 8 Oct 2026, 19:41 UK

Setup

Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

Steps

  1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
  2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
  3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

Accept

Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

Evidence the case requires

Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261008-batch1
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the same hardware against clean, delayed, lossy and intermittent links in F4.

Steps

  1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
  2. Include reconnects, template changes, expired submissions and pool failover.
  3. Attribute loss to network, local software, validation and protocol causes.

Accept

Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

Evidence the case requires

Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
22
Plan pages
6, 7, 8, 14, 18, 23
GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Run the selected profile on actual reference machines for the P02 soak period.

Steps

  1. Track wall power, temperatures, clocks, memory and accepted work continuously.
  2. Inject safe power interruptions, process restarts and normal competing desktop load.
  3. Check restored settings and compare late-run efficiency with the first stable period.

Accept

No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

Evidence the case requires

Seven-day time series; crash reports; settings-restoration checks; drift analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

Steps

  1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
  2. Recompute joules and total cost per accepted work from the shared raw schema.
  3. Investigate divergence before accepting a pooled headline or uncertainty band.

Accept

Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

Evidence the case requires

Three signed reproduction packs; reconciliation report; final baseline table.

Method
Independent reproduction
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
23
Plan pages
6, 7, 8, 14, 18, 23
03POW

Proof-of-work correctness and coupling

Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

FAIL
Owner
Cryptography + GPU lead
Gate
G2 / technical readiness G2
Fixtures
F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
Plan pages
7, 9, 10, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 2 failed, 6 not run, 0 deferred
POW-01Match independent execution across every backendPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Implement an independently written reference evaluator, not a wrapper around the production GPU path.

Steps

  1. Execute the P01 corpus across every family, boundary seed and supported backend.
  2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
  3. Minimise every mismatch and rerun it on clean builds.

Accept

Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

Evidence the case requires

Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
p01-20261008-01
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 21:38 UK

Setup

Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

Steps

  1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
  2. Check bounds, valid dependencies, address distribution and forbidden encodings.
  3. Compare source-level operations with optimised compiled code for removed or altered work.

Accept

No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

Evidence the case requires

Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
family-gate-20261008b
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04FAILEvidence none yetLast run 8 Oct 2026, 21:41 UK

Setup

Take the 64-register candidate and the cheapest independently proposed storage organisations.

Steps

  1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
  2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
  3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

Accept

Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

Evidence the case requires

Liveness traces; alternative implementations; Pareto table; reviewer analysis.

Method
Experiment + independent hardware review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
24
Plan pages
7, 9, 10, 23
POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04NOT RUNEvidence none yetLast run 8 Oct 2026, 21:41 UK

Setup

Use a candidate initially matched to baseline instruction count, read count and dataset size.

Steps

  1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
  2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
  3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

Accept

The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

Evidence the case requires

Matched workloads; GPU runs; redesigned core estimates; held-out results.

Method
Controlled experiment
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

Steps

  1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
  2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
  3. Price any valid strategy against fresh evaluation; independently review all bindings.

Accept

Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

Evidence the case requires

Attack implementations; valid/invalid controls; work-cost analysis; binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
binding-review-2026-10-08-a05
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

Steps

  1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
  2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
  3. Sustain the approved hostile request rate while ordinary valid traffic continues.

Accept

All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

Evidence the case requires

CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
p01-partb-20261008-01
Design status
NOT RUN
Standard page
25
Plan pages
7, 9, 10, 23
POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03FAILEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

Steps

  1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
  2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
  3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

Accept

Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

Evidence the case requires

Scope decision; semantic specification; vectors; simplified datapath model.

Method
Conditional implementation test
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
kills-20261008
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03NOT RUNEvidence recordLast run 8 Oct 2026, 20:59 UK

Setup

Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

Steps

  1. Retain their historic negative tests and realistic SRAM instruction-memory control.
  2. Inspect the release for reintroduction through renamed settings or hidden paths.
  3. Require a new written hypothesis and complete adversarial retest for any proposed return.

Accept

Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

Evidence the case requires

Decision register; binary/config scan; negative-control results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
hash-lane-20261008-batch2
Design status
NOT RUN
Standard page
26
Plan pages
7, 9, 10, 23
04ADV

Programmable specialist adversaries

Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

NOT RUN
Owner
Independent hardware team
Gate
G3 G3
Fixtures
F2 reference GPUs; F6 RTL/physical models; all published families
Plan pages
8, 10, 12, 22, 23
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Provide the complete published family bank and future known parameter schedule to the reviewer.

Steps

  1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
  2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
  3. Verify its outputs against POW vectors before measuring any advantage.

Accept

At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

Evidence the case requires

Architecture reports; functional simulations; adaptation matrix; reviewer signature.

Method
Independent hardware study
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

Steps

  1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
  2. Include construction/update amortisation, bandwidth contention and retained state.
  3. Take the most favourable feasible point for the specialist into the complete-board model.

Accept

No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

Evidence the case requires

Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

Method
Model + adversarial implementation
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

Steps

  1. Compare moving computation, intermediate state or fetched data to each read location.
  2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
  3. Include interconnect, host, synchronisation, idle and conversion costs.

Accept

The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

Evidence the case requires

Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

Method
Independent system modelling
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
27
Plan pages
8, 10, 12, 22, 23
ADV-04Measure profitable selective participationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Use all declared families plus held-out generated programs and the protocol difficulty rule.

Steps

  1. Identify favourable execution paths and add cheap fallbacks for other periods.
  2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
  3. Evaluate revenue and costs across the full schedule, not just average program energy.

Accept

Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

Evidence the case requires

Per-program advantage distribution; policy simulator; full-period returns.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-05Validate physical and complete-board costsPriority GATEProfile P04NOT RUNEvidence none yetLast run 8 Oct 2026, 21:41 UK

Setup

Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

Steps

  1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
  2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
  3. Compare against a calibrated existing hardware block or equivalent validation case.

Accept

No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

Evidence the case requires

Netlist/physical reports; macro assumptions; bill of materials; model calibration.

Method
Independent physical-design review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

Steps

  1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
  2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
  3. Evaluate measurement confidence and model-parameter sensitivity separately.

Accept

P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

Evidence the case requires

Node-specific reports; factor provenance; uncertainty and sensitivity tables.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
k lane (a3c9601a6d4686fe1)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
28
Plan pages
8, 10, 12, 22, 23
ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 21:41 UK

Setup

Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

Steps

  1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
  2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
  3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

Accept

The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

Evidence the case requires

Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:41 UK

Setup

Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

Steps

  1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
  2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
  3. Record unresolved modelling disagreements and future technology exclusions.

Accept

Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

Evidence the case requires

Two review reports; challenge log; final envelope; unresolved-limit statement.

Method
Independent challenge/review
Cadence
Release candidate; repeat after relevant changes
Owner
adversary lane (a1a9876a88f5a72fc)
Run
adversary-20261008-placed-8lane
Design status
NOT RUN
Standard page
29
Plan pages
8, 10, 12, 22, 23
05ROT

Epochs, seeds and memory transitions

Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

NOT RUN
Owner
Consensus + GPU leads
Gate
G5 / G2 G5 G2
Fixtures
F0 activation rules; F4 fault network; F5 historical and boundary vectors
Plan pages
7, 11, 19, 21
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

Steps

  1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
  2. Restart nodes from both sides and replay the same headers.
  3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

Accept

All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

Evidence the case requires

Boundary vectors; node/miner traces; acceptance and reward matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
f10-worker-20261008
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Use the retained schedule in F0, including coincident program, parameter and family changes.

Steps

  1. Run every known family transition and all coincident-boundary combinations on production code.
  2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
  3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

Accept

Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

Evidence the case requires

Transition matrix; code-path evidence; compile timing; old-client logs.

Evidence record of the run

What was run
the class v6 object crossing at its floor on 617cb441
Run by
fast-time lane (a8be71a0db962911c)
Under the standard
no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
Pass or fail today
not judged under the standard yet
Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

Steps

  1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
  2. Partition voters, restore them and test vote-key substitution through pools.
  3. Verify adoption and refusal behaviour of already running nodes.

Accept

The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

Evidence the case requires

Executable governance model; signed-vote corpus; coalition/partition results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
30
Plan pages
7, 11, 19, 21
ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

Steps

  1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
  2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
  3. Validate inputs, parameters and proofs against independent vectors.

Accept

No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

Evidence the case requires

Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Stop checkpoint signing while mining continues, then cross seed and family boundaries.

Steps

  1. Remove the required signing weight and observe the documented fallback or safe pause.
  2. Prevent access to any founder seed service; restart from persisted state.
  3. Restore the stated fault assumptions and verify deterministic recovery.

Accept

Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

Evidence the case requires

Fault timeline; seed/certificate history; node-state comparison; recovery log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

Steps

  1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
  2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
  3. Measure data transfer, restart and excluded-card costs before approving progression.

Accept

No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

Evidence the case requires

Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
31
Plan pages
7, 11, 19, 21
ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04NOT RUNEvidence recordLast run 8 Oct 2026, 21:38 UK

Setup

Use matched baseline and ablated variants in the lab; do not change a running public network.

Steps

  1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
  2. Include favourable-period specialists and all retained known families.
  3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

Accept

Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

Evidence the case requires

Ablation report; decision log; complexity/cost comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
lane D family gate (a07a99a3788566af2)
Run
family-gate-20261008b
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:38 UK

Setup

Freeze the complete published rule bank and known schedule for the five-year evaluation.

Steps

  1. Allow a programmable adversary to know and survive all planned changes.
  2. Remove assumed future emergency instructions and manual retirement actions from the model.
  3. Run the required ECO scenarios and link them to independent network-transition tests.

Accept

Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

Evidence the case requires

Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
family-gate-20261008b
Design status
NOT RUN
Standard page
32
Plan pages
7, 11, 19, 21
06ECO

Five-year coexistence economics

Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

FAIL
Owner
Economics lead + independent reviewer
Gate
G4 G4
Fixtures
F6 adversarial costs; F7 scenario model; F2 operator costs
Plan pages
8, 13, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 1 failed, 7 not run, 0 deferred
ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

Steps

  1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
  2. Use actual accepted work and independently verify units and period conversions.
  3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

Accept

All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

Evidence the case requires

Versioned model; unit fixtures; independent reconciliation; input sources.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

Steps

  1. Evaluate marginal operation separately from recovery of a new purchase.
  2. Stress resale at zero, hardware failures, financing and replacement cycles.
  3. Report break-even power price and total cost relative to the strongest feasible specialist.

Accept

P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

Evidence the case requires

Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use three development cases: fully funded elsewhere, source-range low and source-range high.

Steps

  1. Evaluate private mining, public hardware sales and a hybrid business model.
  2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
  3. Re-evaluate GPU entry after the specialist fleet is already installed.

Accept

The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

Evidence the case requires

Business-model variants; sunk-cost case; full cash-flow and adaptation records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
33
Plan pages
8, 13, 18, 24, 26
ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use independently reviewed dynamic operator policies, not fixed market shares.

Steps

  1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
  2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
  3. Compare equilibrium and transient outcomes across independent starting conditions.

Accept

Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

Evidence the case requires

Agent policies; sensitivity seeds; market-share paths; independent model review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

Steps

  1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
  2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
  3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

Accept

No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

Evidence the case requires

Scenario register; full result cube; boundary plots; failed-world explanations.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

Steps

  1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
  2. Test flat/declining fees and no external proving income; separately introduce external demand.
  3. Calculate capacity and security-provider coverage after each reward transition.

Accept

Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

Evidence the case requires

Issuance/fee ledger; scenario cash flows; funding-shortfall report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
34
Plan pages
8, 13, 18, 24, 26
ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

Steps

  1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
  2. Include ordinary-owner replacement, resale and reloading expenses.
  3. Run alternate bounded schedules without assigning automatic chip death.

Accept

The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

Evidence the case requires

Per-step cost/retention table; alternative schedules; approval record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12NOT RUNEvidence recordLast run 8 Oct 2026, 21:07 UK

Setup

Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

Steps

  1. Recalculate required worlds and perturb favourable assumptions against the team.
  2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
  3. Publish the sensitivity range and state which conclusions are conditional.

Accept

Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

Evidence the case requires

Independent report; rerun outputs; model limitations; approved claim envelope.

Method
Independent economic review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco05-20261008-02
Design status
NOT RUN
Standard page
35
Plan pages
8, 13, 18, 24, 26
07EVM

Execution and developer compatibility

Keep familiar applications while making every difference and metering rule explicit and reproducible.

NOT RUN
Owner
Execution lead + independent implementer
Gate
Technical readiness
Fixtures
F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
Plan pages
15, 25, 34, 35, 36, 37
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:10 UK

Setup

Pin the intended execution fork, revm version and all Igneum deviations in F0.

Steps

  1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
  2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
  3. Minimise mismatches and distinguish intended differences from implementation defects.

Accept

All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

Evidence the case requires

Fixture/version inventory; root/receipt diffs; deviation matrix.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use signed transfers, contract calls and deployment transactions with boundary field values.

Steps

  1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
  2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
  3. Check mempool admission and final consensus execution independently.

Accept

Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

Evidence the case requires

Signed corpus; admission/execution outcomes; account-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

Steps

  1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
  2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
  3. Mutate a block producer to omit or undercharge expensive work.

Accept

Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

Evidence the case requires

Metering traces; fee fixtures; estimator errors; invalid-block rejection.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
36
Plan pages
15, 25, 34, 35, 36, 37
EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use contracts sensitive to timestamp, height/context, randomness and ordering.

Steps

  1. Compare the declared Igneum semantics with developers' documented expectations.
  2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
  3. Run dependency reviews for applications using these values for economic decisions.

Accept

Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

Evidence the case requires

Context-contract results; threat notes; compatibility exclusions.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

Steps

  1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
  2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
  3. Compare expected application invariants with native execution and proved results.

Accept

Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

Evidence the case requires

Contract fixture hashes; transaction journeys; invariant and state comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:13 UK

Setup

Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

Steps

  1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
  2. Reindex from genesis or the documented trust anchor after pruning and restart.
  3. Compare logs, receipts and balances with independently validated chain state.

Accept

No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

Evidence the case requires

RPC conformance report; reindex comparison; reconnect/edge-case logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1744-evm
Design status
NOT RUN
Standard page
37
Plan pages
15, 25, 34, 35, 36, 37
EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

Steps

  1. Measure CPU, memory, disk and proving cost against charged budgets.
  2. Saturate admission with invalid/expensive requests while valid workloads continue.
  3. Restart mid-execution and verify atomic state recovery.

Accept

P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

Evidence the case requires

Resource profiles; adversarial corpus; state recovery comparisons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Prepare two authorised versions and malicious, stale or unknown versions.

Steps

  1. Cross activation with mixed clients, queued transactions and proofs from both versions.
  2. Bind each accepted proof to the correct execution semantics and program identity.
  3. Exercise a failed software distribution without altering consensus activation.

Accept

No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

Evidence the case requires

Upgrade vectors; mixed-version traces; manifest/version bindings.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
38
Plan pages
15, 25, 34, 35, 36, 37
08ZKP

Consensus-enforced proof validity

The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

NOT RUN
Owner
Proving + protocol leads; independent cryptography review
Gate
Technical readiness / G5 G5
Fixtures
F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
Plan pages
16, 20, 24, 25, 36, 37
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Start from a native-correct statement and an independently verified valid proof.

Steps

  1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
  2. Submit the genuine proof as a positive control through ordinary network paths.
  3. Inspect block acceptance and resulting reward/state on unmodified validators.

Accept

Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

Evidence the case requires

Hostile record corpus; validator decisions; before/after balances; positive controls.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use valid proofs from authorised and unauthorised programs and parameter sets.

Steps

  1. Swap program digest, verifier version, security settings and verification key where applicable.
  2. Attempt downgrade through configuration, serialized metadata or an old node path.
  3. Test authorised boundary transitions and unsupported future identities.

Accept

Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

Evidence the case requires

Identity/parameter matrix; rejection traces; cryptographic review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

Steps

  1. Replay each proof under another network, job, epoch, shard range or state commitment.
  2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
  3. Check duplicated and reordered records across forks and replayed sync data.

Accept

Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

Evidence the case requires

Binding matrix; public-input hashes; replay traces; reward reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
39
Plan pages
16, 20, 24, 25, 36, 37
ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use proofs that commit to authorisation and all reward-relevant fields required by F0.

Steps

  1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
  2. Supply correct execution over malicious producer-provided consensus/reward inputs.
  3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

Accept

Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

Evidence the case requires

Mutation cases; reward derivation trace; signature/proof binding review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01NOT RUNEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

Steps

  1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
  2. Crash validators between validation and reward application, then recover.
  3. Reconcile canonical payouts against the exact F0 duplicate policy.

Accept

Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

Evidence the case requires

Concurrency schedule; canonical payment ledger; crash/recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

Steps

  1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
  2. Alter shard ranges, roots and aggregation-program identity.
  3. Verify native execution, aggregate validity and coverage commitments independently.

Accept

Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

Evidence the case requires

Coverage corpus; aggregate/public-input verification; rejection ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
40
Plan pages
16, 20, 24, 25, 36, 37
ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

Steps

  1. Review soundness assumptions, parameter margins and consequences of performance patches.
  2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
  3. Cross-check an independent verifier or reference path and test crash containment.

Accept

P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

Evidence the case requires

Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

Method
Independent cryptographic review + testing
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:03 UK

Setup

Inspect block import, sync, RPC, light verification, database restoration and fast paths.

Steps

  1. Try bypassing validation via each path with a proof rejected by the normal path.
  2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
  3. Attempt to use proof-production status as ordering, voting or finality authority.

Accept

No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

Evidence the case requires

Path coverage report; bypass corpus; replacement run; authority checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
enforced-proving-20261008-01
Design status
NOT RUN
Standard page
41
Plan pages
16, 20, 24, 25, 36, 37
09CAP

Sustained proving and delivery

A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

NOT RUN
Owner
Proving lead + independent operators
Gate
Technical readiness / commercial track
Fixtures
F3 meaningful workload catalogue; F4 network; F8 external job harness
Plan pages
17, 18, 24, 25
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

Steps

  1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
  2. Record proof format, memory, energy, host and whether aggregation/compression are included.
  3. Repeat on the final release and label all configuration changes.

Accept

Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

Evidence the case requires

Historical/current manifests; proof verification; timing and memory records.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

Steps

  1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
  2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
  3. Induce memory pressure and GPU task failure without losing wallet control.

Accept

Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

Evidence the case requires

Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

Steps

  1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
  2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
  3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

Accept

No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

Evidence the case requires

Stage event ledger; clock calibration; end-to-end latency/cost report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
42
Plan pages
17, 18, 24, 25
CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

Steps

  1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
  2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
  3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

Accept

P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

Evidence the case requires

Request/completion reconciliation; backlog series; held-out results; observer report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

Steps

  1. Observe admission, explicit backpressure, reservations and deadline estimates.
  2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
  3. Measure recovery time and ensure ordinary users are not silently starved.

Accept

P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

Evidence the case requires

Overload timeline; admission/refund logs; backlog-drain proof.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

Steps

  1. Measure actual completion distributions with network delay, competing load and failed attempts.
  2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
  3. Compare assignment frequency, paid completions and wasted work by tier.

Accept

P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

Evidence the case requires

Window sweep; paid-completion distribution; wasted-work and margin report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
43
Plan pages
17, 18, 24, 25
CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Remove input providers, assigned provers and the dominant aggregator independently and together.

Steps

  1. Have replacement operators retrieve authenticated inputs without founder files.
  2. Retry expired assignments while preserving idempotent reward and customer outcomes.
  3. Restore providers and test late submissions racing with replacements.

Accept

P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

Evidence the case requires

Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run the external workload using a customer-controlled verifier and independently operated workers.

Steps

  1. Verify every delivered proof against the contracted program and input commitment.
  2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
  3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

Accept

P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

Evidence the case requires

Customer verification log; proof-format contract; settlement reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fleet lane (ac055d60427caab99)
Design status
NOT RUN
Standard page
44
Plan pages
17, 18, 24, 25
10INC

Rewards, incentives and selfish operators

Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

NOT RUN
Owner
Protocol economics + proving leads
Gate
G4 / G5 G4 G5
Fixtures
F0 fee/reward rules; F4 adversarial operators; F7 incentive models
Plan pages
13, 16, 17, 18, 24, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use a deterministic short chain containing all reward types, fee paths and rounding cases.

Steps

  1. Calculate balances, total supply changes, burns and distributions independently.
  2. Execute identical blocks natively and through the proving path.
  3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

Accept

Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

Evidence the case requires

Independent accounting ledger; balance/supply diffs; boundary vectors.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

Steps

  1. Trace money from source to operator, protocol, developer and any burn.
  2. Compare node records, settlement records and Ember displays.
  3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

Accept

Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

Evidence the case requires

Money-flow register; UI reconciliation; rejected classifications.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Permit independent schedulers to mine, prove internally, prove externally or switch off.

Steps

  1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
  2. Run clients that ignore the official scheduling recommendation.
  3. Measure realised operator margin, internal capacity and network progress.

Accept

Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

Evidence the case requires

Scheduler source/policies; switching traces; capacity and margin series.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
45
Plan pages
13, 16, 17, 18, 24, 26
INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

Steps

  1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
  2. Observe hash participation, proof backlog, fees and recovery without an administrator.
  3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

Accept

Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

Evidence the case requires

Shock timeline; fee/hash/capacity paths; failure-region report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

Steps

  1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
  2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
  3. Price attacker costs and observe honest completion under the approved abuse load.

Accept

F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

Evidence the case requires

Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

Steps

  1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
  2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
  3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

Accept

Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

Evidence the case requires

Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Standard page
46
Plan pages
13, 16, 17, 18, 24, 26
INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use self-funded operators and related customer identities in the isolated economic model/network.

Steps

  1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
  2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
  3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

Accept

No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

Evidence the case requires

Circular-flow tests; ownership/conflict review; net-cash reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
enforced-proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence recordLast run 8 Oct 2026, 20:55 UK

Setup

Model control of hashing, signing, proving, aggregation and hardware supply separately.

Steps

  1. Remove each largest operational dependency and combine correlated failures.
  2. Measure replacement cost/time and whether essential roles share hidden ownership.
  3. Compare results with the approved fault model and no-rescue exercise.

Accept

No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

Evidence the case requires

Role/ownership map; dependency removals; recovery and concentration report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
research lane (ad6a2bd47d4a46105)
Run
eco-d4-20261008-01
Design status
NOT RUN
Standard page
47
Plan pages
13, 16, 17, 18, 24, 26
11FIN

Consensus safety and recovery

Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

NOT RUN
Owner
Consensus lead + independent formal/security review
Gate
G5 / technical readiness G5
Fixtures
F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
Plan pages
19, 21, 24, 25
8 cases: 2 passed under the standard, 0 running with team evidence, 6 not run, 0 deferred
FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

Steps

  1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
  2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
  3. Replay from independent checkpoints and from genesis where practical.

Accept

Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

Evidence the case requires

Block/ordering corpus; root/work diffs; real-node replay logs.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

Steps

  1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
  2. Delay messages and eligibility updates independently; keep total historical weights auditable.
  3. Try to form two certificates and reconnect nodes to observe accepted final history.

Accept

No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

Evidence the case requires

Signed votes; certificate attempts; voter-table snapshots; safety checker output.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Recover historical expiry failures where available; use the actual current authority-transition rules.

Steps

  1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
  2. Attempt independently renewed authority sets and conflicting checkpoint locks.
  3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

Accept

Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

Evidence the case requires

Expiry timeline; table/certificate history; historical regression tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
48
Plan pages
19, 21, 24, 25
FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Remove enough signing participation to invalidate the liveness assumption without forging votes.

Steps

  1. Continue mining and execution, cross seed boundaries and monitor proof queues.
  2. Check which user-visible states advance and which remain unfinalised.
  3. Restore eligible weight and bounded message delay, then verify recovery.

Accept

No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

Evidence the case requires

Signing/mining trace; UI/RPC states; recovery roots and timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use normal transitions, pool members retaining keys and malicious substitution attempts.

Steps

  1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
  2. Race updates across boundaries and replay old signed changes.
  3. Have a new node verify the authority chain from its declared trust anchor.

Accept

Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

Evidence the case requires

Authority-chain fixtures; substitution attacks; new-node verification log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

Steps

  1. Use previously eligible keys to build alternative histories after their operators disappear.
  2. Present these histories to recently offline and newly joining clients.
  3. Test replayed certificates, stale anchors and compromised signer subsets.

Accept

Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

Evidence the case requires

Long-range corpus; trust-anchor policy; key-compromise review; client results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
team-2026-10-08
Design status
NOT RUN
Standard page
49
Plan pages
19, 21, 24, 25
FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Combine partitions with node crash, partial writes, restarts and proof backlog.

Steps

  1. Reconnect networks under bounded latency and restore required honest participation.
  2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
  3. Compare all honest nodes and customer-visible receipts after recovery.

Accept

P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

Evidence the case requires

Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
finality lane (aca0f5ed924a2a99b)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08NOT RUNEvidence recordLast run 8 Oct 2026, 20:43 UK

Setup

Use an independent model checker/scheduler and production-node scenarios from F4.

Steps

  1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
  2. Explore bounded adversarial message schedules and minimise any counterexample.
  3. Replay model findings on real code and have an independent reviewer assess uncovered states.

Accept

No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

Evidence the case requires

Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

Method
Model checking + real-node testing
Cadence
Release candidate; repeat after relevant changes
Owner
fast-time lane (a8be71a0db962911c)
Run
fin-v4-realnode-20261008T2025Z
Design status
NOT RUN
Standard page
50
Plan pages
19, 21, 24, 25
12VER

Wallets, receipts and data availability

Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

FAIL
Owner
Wallet + light-client lead; independent security review
Gate
Technical readiness / claimed options
Fixtures
F0 trust/availability model; F5 malformed roots, receipts and authority chains
Plan pages
20, 25, 35, 37
8 cases: 0 passed under the standard, 0 running with team evidence, 3 failed, 5 not run, 0 deferred
VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

Steps

  1. Start from the approved trust anchor and verify every required link to the advertised state.
  2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
  3. Remove the bootstrap service and use another independently operated source.

Accept

The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

Evidence the case requires

Bootstrap corpus; trust-chain trace; fail-closed tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Use valid state proofs paired with wrong execution statements or stale authority histories.

Steps

  1. Cross voter and verifier changes with offline clients returning after long intervals.
  2. Alter roots, aggregate identity and proof/public-input bindings independently.
  3. Check local verification rather than merely a server-reported verified flag.

Accept

All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

Evidence the case requires

Client verification trace; corrupted inputs; offline/upgrade results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

Steps

  1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
  2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
  3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

Accept

Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

Evidence the case requires

Payment fixture corpus; receipt verification; merchant-facing status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
51
Plan pages
20, 25, 35, 37
VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

Steps

  1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
  2. Exercise legitimate authority updates and source reorganisations under the approved model.
  3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

Accept

The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

Evidence the case requires

Oracle code/parameters; attack cases; cost report; privilege disclosure.

Method
Claimed-option verification
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09FAILEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Remove founder archival/input services and start an independent operator from the documented entry point.

Steps

  1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
  2. Rebuild the expected state and continue validation/proving.
  3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

Accept

Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

Evidence the case requires

Download/reconstruction logs; data hashes; resource costs; dependency inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

Steps

  1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
  2. Test retrieval from independent peers and expiry/retry policy.
  3. Restore data and check that recovery cannot alter an already verified commitment.

Accept

No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

Evidence the case requires

Withholding corpus; peer retrieval traces; availability/status checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
52
Plan pages
20, 25, 35, 37
VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

Steps

  1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
  2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
  3. Upgrade and recover without silently changing signing authority or exposing seed material.

Accept

No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

Evidence the case requires

Security review; canary-secret tests; signing fixtures; restore journey.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 20:46 UK

Setup

Create included-only, executed, proven, finalised, reverted, stale and paused examples.

Steps

  1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
  2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
  3. Check statements about privacy, Ethereum security and device support.

Accept

No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

Evidence the case requires

Cross-surface screenshots/logs; state mapping; claim review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
reference-apps lane (a2060899d2a27d31c)
Run
ra-20261008T1915-ver
Design status
NOT RUN
Standard page
53
Plan pages
20, 25, 35, 37
13OPS

Independent operation and release security

A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

NOT RUN
Owner
Operations + release leads; independent operators
Gate
G5 G5
Fixtures
F4 isolated multi-operator network; F0 signed releases; F9 telemetry
Plan pages
21, 24, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

Steps

  1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
  2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
  3. Introduce scheduled faults and have independent operators recover using published instructions.

Accept

No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

Evidence the case requires

Operator roster/conflict checks; dependency removals; full activity/intervention log.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Start nodes without the default bootstrap host and give others adversarial peer lists.

Steps

  1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
  2. Use independent documented discovery paths and validate returned chain data.
  3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

Accept

No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

Evidence the case requires

Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 21:50 UK

Setup

Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

Steps

  1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
  2. Test explicit operator acceptance and the published signing-key incident procedure.
  3. Confirm that distribution-key possession cannot independently activate new consensus rules.

Accept

Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

Evidence the case requires

Package corpus; approval/activation traces; compromised-key rehearsal.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
site-manifest-20261008-01
Design status
NOT RUN
Standard page
54
Plan pages
21, 24, 25, 26
OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

Steps

  1. Crash during import, proof acceptance, reward application and snapshot generation.
  2. Restore from independently verified snapshots or re-sync through documented procedures.
  3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

Accept

No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

Evidence the case requires

Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
node lane (a283f5f0d364ceef0)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Run hostile test jobs with secret canaries and restrictive worker permissions.

Steps

  1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
  2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
  3. Retry on every supported isolation backend and check dependency vulnerability handling.

Accept

No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

Evidence the case requires

Sandbox penetration report; canary logs; resource limits; host-integrity checks.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use an authorised isolated load environment with declared resource and request-rate budgets.

Steps

  1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
  2. Measure legitimate traffic, memory/disk growth and validator CPU use.
  3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

Accept

P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

Evidence the case requires

Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
55
Plan pages
21, 24, 25, 26
OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

Steps

  1. Inject one instance of each monitored failure in the lab.
  2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
  3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

Accept

P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

Evidence the case requires

Alert matrix; detection timelines; independent runbook exercise.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use a clean previous supported version and the final candidate with independent operators.

Steps

  1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
  2. Cross activation with mixed versions and unavailable founder distribution hosts.
  3. Re-run affected gates after changes and preserve prior failures and incident lessons.

Accept

No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

Evidence the case requires

Upgrade/replay logs; invalidation map; repeated gate signatures.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
build-server lane (a352e49ff4613df86)
Design status
NOT RUN
Standard page
56
Plan pages
21, 24, 25, 26
14UX

Ember, payouts and operator control

Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

NOT RUN
Owner
Desktop product + pool leads; independent usability study
Gate
Operator readiness / G5 G5
Fixtures
F2 supported desktops; F8 user study; F4 honest/malicious pools
Plan pages
14, 21, 25, 26
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence recordLast run 8 Oct 2026, 21:42 UK

Setup

Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

Steps

  1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
  2. Record download/data preparation separately as well as complete end-to-end time.
  3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

Accept

P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

Evidence the case requires

Consent-based study records; task timings; failure reasons; compatibility outcomes.

Method
Independent observed user study
Cadence
Release candidate; repeat after relevant changes
Owner
update-return lane (a22d765a2e0355a9f)
Run
ux-01-20261008-win-2.0.0
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Run mining/proving on active desktops under contention and safe thermal stress.

Steps

  1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
  2. Crash or restart the UI while workers run and verify ownership of background processes.
  3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

Accept

P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

Evidence the case requires

Control timings; process/settings audit; restart and safety traces.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Use known rewards, fees, energy readings, retries and operator-entered tariffs.

Steps

  1. Compare mining, internal proof and external proof income with authoritative ledgers.
  2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
  3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

Accept

P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

Evidence the case requires

UI/ledger comparisons; tariff fixtures; stale/negative examples.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
57
Plan pages
14, 21, 25, 26
UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10NOT RUNEvidence recordLast run 8 Oct 2026, 21:48 UK

Setup

Use ordinary single-card balances and the actual pooling/payment path.

Steps

  1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
  2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
  3. Reconcile displayed balances with canonical entitlement and actual settlement.

Accept

P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

Evidence the case requires

Single-card payout ledger; pool failure record; custody/authorisation review.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
pool-2.0-20261008-03
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09NOT RUNEvidence recordLast run 8 Oct 2026, 21:48 UK

Setup

Use an honest pool and a modified pool that replaces worker identity or voting credentials.

Steps

  1. Verify the consensus binding from performed work to the miner's retained key.
  2. Attempt substitution, replay and reassignment without the miner's authorisation.
  3. Leave the pool and verify retained voting/finality rights under F0.

Accept

No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

Evidence the case requires

Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
pool design seat (a3832b1c3b274b310)
Run
pool-2.0-20261008-03
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:32 UK

Setup

Provide a pool interface with declared job-declaration support and independent miner templates.

Steps

  1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
  2. Have a pool substitute or censor templates and test local verification/fallback.
  3. Measure payout and acceptance consequences without moving authority to the pool.

Accept

The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

Evidence the case requires

Template commitments; accepted-block evidence; malicious-pool/fallback report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
201-7cfa422a-aa0e0f45
Design status
NOT RUN
Standard page
58
Plan pages
14, 21, 25, 26
UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 21:42 UK

Setup

Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

Steps

  1. Ask independent users to identify the issue, stop safely and follow the recommended action.
  2. Test explicit update approval, version visibility and a failed/corrupt update.
  3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

Accept

P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

Evidence the case requires

Observed tasks; update traces; sanitised export tests.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
shipper (ae892a8b0f78fe31c)
Run
ux-01-20261008-win-2.0.0
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 19:28 UK

Setup

Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

Steps

  1. Compare Ember against independently optimised permissible implementations on identical work.
  2. Measure efficiency, fees, false rejection, installation and update transparency.
  3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

Accept

P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

Evidence the case requires

Matched software comparison; code/config review; fee/privilege inventory.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
hash lane (a690540514aa453d7)
Run
200-417c4a57-b2
Design status
NOT RUN
Standard page
59
Plan pages
14, 21, 25, 26
15COM

Paid demand and sustainable delivery

Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

NOT RUN
Owner
Commercial lead + independent financial/customer reviewer
Gate
Commercial evidence
Fixtures
F8 real consenting customers; F7 full service costs; private identity proofs
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

Steps

  1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
  2. Run paid jobs through ordinary independently operated infrastructure.
  3. Have the customer verify usefulness, correctness and its reason for choosing the service.

Accept

The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

Evidence the case requires

Redacted contract; verified jobs; settlement proof; consented customer confirmation.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use the P14 multi-customer observation period and ownership/conflict checks.

Steps

  1. Track paid purchases on distinct occasions, including refunds and stopped customers.
  2. Audit related parties, project reimbursements, token grants and circular funding.
  3. Reconcile external cash received with correctly delivered meaningful work.

Accept

P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

Evidence the case requires

Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

Steps

  1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
  2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
  3. Repeat under the declared demand and price sensitivities.

Accept

P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

Evidence the case requires

Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
60
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

Steps

  1. Count all accepted jobs, including failed, retried and abandoned cases.
  2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
  3. Compare offered capacity and quoted price with what was actually delivered.

Accept

P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

Evidence the case requires

Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

Steps

  1. Obtain comparable quotes or consented measured trials at the evaluation date.
  2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
  3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

Accept

P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

Evidence the case requires

Dated comparison; workload/security match; customer decision record.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Follow all recruited customers through the P14 observation period, including churn.

Steps

  1. Remove disclosed trial incentives before measuring repeat demand.
  2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
  3. Review whether one affiliated or subsidised buyer dominates the apparent market.

Accept

P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

Evidence the case requires

Cohort/renewal ledger; churn notes; concentration and incentive report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
61
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Prepare a costed plan for development, review, infrastructure, support and incident response.

Steps

  1. Separate committed resources from revenue dependent on adoption or token price.
  2. Stress lower income and an unexpected security/operations expense.
  3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

Accept

P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

Evidence the case requires

Budget and commitment evidence; downside plan; owner/continuity roster.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Recruit unaffiliated developers unfamiliar with unpublished implementation details.

Steps

  1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
  2. Record time, undocumented dependencies, workarounds and correctness issues.
  3. Retest after documentation fixes without founder-written hidden integration code.

Accept

P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

Evidence the case requires

Consented developer logs; public examples; issue closure; verified end-to-end journeys.

Method
Independent integration study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
62
Plan pages
4, 17, 18, 24, 26, 27, 31, 32, 33
16LEAD

Comparative leadership evidence

A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

NOT RUN
Owner
Independent assessment panel + product/economics reviewers
Gate
Leadership-contender decision
Fixtures
F8 peer/customer studies; full signed technical evidence; 90-day observation
Plan pages
4, 22, 25, 27, 31, 32, 33
8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

Steps

  1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
  2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
  3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

Accept

The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

Evidence the case requires

Timestamped peer protocol; source/version records; comparison/exclusion rationale.

Method
Pre-registered comparative study
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Use matched user tasks and operating conditions on the selected GPU-first networks.

Steps

  1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
  2. Measure rejection/availability under the same network conditions; report fees separately.
  3. Use blinded analysis where possible and independent runs for decisive differences.

Accept

P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

Evidence the case requires

Matched task data; uncertainty/effect sizes; independent comparison report.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
site lane (a846fd66b5403e35a)
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

Steps

  1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
  2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
  3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

Accept

All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

Evidence the case requires

Claim-to-evidence map; signed envelope review; limitations statement.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
63
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

Steps

  1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
  2. Report trial incentives separately and include every initial participant in retention denominators.
  3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

Accept

P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

Evidence the case requires

Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

Steps

  1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
  2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
  3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

Accept

P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

Evidence the case requires

Control/failure-domain map; uncertainty notes; concentration/removal results.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Observe the final candidate and approved compatible updates for the full P16 real-time period.

Steps

  1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
  2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
  3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

Accept

P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

Evidence the case requires

90-day SLO ledger; independent probes; incident reports; change/retest history.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
64
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

Setup

Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

Steps

  1. Check every mandatory and claimed-option test, source requirement and approved threshold.
  2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
  3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

Accept

Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

Evidence the case requires

Signed assessment; full status index; dissent/limitations; approved claim wording.

Method
Independent final assessment
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:22 UK

Setup

Define material-change triggers and scheduled reviews before publishing the assessment.

Steps

  1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
  2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
  3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

Accept

Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

Evidence the case requires

Review calendar; invalidation drills; versioned public claim register.

Method
Automated + independent review
Cadence
Release candidate; repeat after relevant changes
Owner
main / the founder
Design status
NOT RUN
Standard page
65
Plan pages
4, 22, 25, 27, 31, 32, 33
17REV

REV: the external review's required regressions

44 regressions from 14 findings; each reads NOT RUN until its owner lane records a run

NOT RUN
Owner
the owner lanes per the dispatch table
Gate
Review findings closed
Fixtures
F0,F5
Plan pages
docs/analysis/review-2026-10-08-b/findings.json and docs/analysis/review-2026-10-08-b/dispatch.md; ids from the master traceability register
44 cases: 0 passed under the standard, 0 running with team evidence, 44 not run, 0 deferred
R2-F01-R01Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Accept

Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R02Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Accept

Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R03Change payout, network, kind, program ID and activation context; no accepted misbinding.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. Change payout, network, kind, program ID and activation context; no accepted misbinding.

Accept

Change payout, network, kind, program ID and activation context; no accepted misbinding.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F01-R04A native two-node test must agree on block validity and payouts despite different cache histories.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F01 requires (review R2 finding F01: Proof-verdict cache omits the statement being verified).

Steps

  1. A native two-node test must agree on block validity and payouts despite different cache histories.

Accept

A native two-node test must agree on block validity and payouts despite different cache histories.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, node lane
Design status
NOT RUN
Plan pages
R2-F01
R2-F02-R01Release build cannot activate test bypass.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Release build cannot activate test bypass.

Accept

Release build cannot activate test bypass.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R02Missing oracle or pinned keys prevents service readiness after enforcement activation.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing oracle or pinned keys prevents service readiness after enforcement activation.

Accept

Missing oracle or pinned keys prevents service readiness after enforcement activation.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F02-R03Missing proof bytes retry without incorrectly marking a valid block permanently invalid.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F02 requires (review R2 finding F02: Proof-rule infrastructure can fail open).

Steps

  1. Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Accept

Missing proof bytes retry without incorrectly marking a valid block permanently invalid.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, CI steward
Design status
NOT RUN
Plan pages
R2-F02
R2-F03-R01Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Accept

Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R02Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Accept

Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
R2-F03
R2-F03-R03Cross every scheduled transition with old/new client behavior documented and identical rule identities.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F03 requires (review R2 finding F03: The bundle contains a v6 candidate, not a demonstrated integrated v6 release).

Steps

  1. Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Accept

Cross every scheduled transition with old/new client behavior documented and identical rule identities.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward, hash lane (ProgramClass::V6 on freeze), pool lane
Design status
NOT RUN
Plan pages
R2-F03
R2-F04-R01Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Accept

Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R02Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Accept

Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R03Pause-only resume with historical backfill, missing historical data and all old keys returning.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Pause-only resume with historical backfill, missing historical data and all old keys returning.

Accept

Pause-only resume with historical backfill, missing historical data and all old keys returning.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F04-R04Wallet, receipt and oracle consumers distinguish any weaker recovery state.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F04 requires (review R2 finding F04: Finality v4 recovery deliberately has a weaker safety boundary).

Steps

  1. Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Accept

Wallet, receipt and oracle consumers distinguish any weaker recovery state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane, reference apps, site (explorer)
Design status
NOT RUN
Plan pages
R2-F04
R2-F05-R01Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Accept

Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R02Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Accept

Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F05-R03Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F05 requires (review R2 finding F05: reg64 address coupling has an exact incremental alternative).

Steps

  1. Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Accept

Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, adversary lane, floor lane 3
Design status
NOT RUN
Plan pages
R2-F05
R2-F06-R01Acceptance/reference/emitter evaluate the same activated schedule.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Acceptance/reference/emitter evaluate the same activated schedule.

Accept

Acceptance/reference/emitter evaluate the same activated schedule.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R02Full live-dataset census on unseen seeds and the complete v6 pack.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. Full live-dataset census on unseen seeds and the complete v6 pack.

Accept

Full live-dataset census on unseen seeds and the complete v6 pack.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F06-R03A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F06 requires (review R2 finding F06: The v6 acceptance and census gates are not complete for the final execution).

Steps

  1. A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Accept

A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
hash lane, research lane D
Design status
NOT RUN
Plan pages
R2-F06
R2-F07-R01Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Accept

Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R02OOM, process crash and stale work recover without losing wallet state or silently consuming power.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Accept

OOM, process crash and stale work recover without losing wallet state or silently consuming power.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F07-R0316 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F07 requires (review R2 finding F07: VRAM admission and proving deadlines need one operator-level scheduler).

Steps

  1. 16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Accept

16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, fleet lane
Design status
NOT RUN
Plan pages
R2-F07
R2-F08-R01Report every eligible job outcome, including expired work; a bounded list cannot hide losses.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Accept

Report every eligible job outcome, including expired work; a bounded list cannot hide losses.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R02Consumer tiers complete and receive payment for declared jobs before claims about income.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Consumer tiers complete and receive payment for declared jobs before claims about income.

Accept

Consumer tiers complete and receive payment for declared jobs before claims about income.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F08-R03Sustained real workload across class transitions, with restart/retry and no publisher intervention.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F08 requires (review R2 finding F08: The proving pipeline reports waste and deadline censoring, not sustained capacity).

Steps

  1. Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Accept

Sustained real workload across class transitions, with restart/retry and no publisher intervention.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane, fleet lane, site (ops page)
Design status
NOT RUN
Plan pages
R2-F08
R2-F09-R01Generate all pass/fail cells directly from the declared inequalities and inputs.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Generate all pass/fail cells directly from the declared inequalities and inputs.

Accept

Generate all pass/fail cells directly from the declared inequalities and inputs.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R02Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Accept

Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F09-R03GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F09 requires (review R2 finding F09: The economic model explicitly retains a failed specialist case).

Steps

  1. GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Accept

GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane, floor lane 3, coordinator
Design status
NOT RUN
Plan pages
R2-F09
R2-F10-R01Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Accept

Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R02Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Accept

Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F10-R03Compare production throughput and wall energy, not only the isolated kernel timer.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F10 requires (review R2 finding F10: CUDA production readback has an existing OpenCL optimization to borrow).

Steps

  1. Compare production throughput and wall energy, not only the isolated kernel timer.

Accept

Compare production throughput and wall energy, not only the isolated kernel timer.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
worker lane (new)
Design status
NOT RUN
Plan pages
R2-F10
R2-F11-R01Goal switch from an efficiency prior can explore higher core/power when policy allows.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Goal switch from an efficiency prior can explore higher core/power when policy allows.

Accept

Goal switch from an efficiency prior can explore higher core/power when policy allows.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R02Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Accept

Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F11-R03Thermal/error/late-share events revert safely, including process or machine crash.Priority P2Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F11 requires (review R2 finding F11: Ember needs workload-aware identity and objective-aware search).

Steps

  1. Thermal/error/late-share events revert safely, including process or machine crash.

Accept

Thermal/error/late-share events revert safely, including process or machine crash.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (new)
Design status
NOT RUN
Plan pages
R2-F11
R2-F12-R01Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Accept

Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R02Same signed transaction retried, fee replacement reconciled by intent, not a new payment.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Accept

Same signed transaction retried, fee replacement reconciled by intent, not a new payment.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F12-R03Receipt reorg and finality pause leave correct pending obligations.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F12 requires (review R2 finding F12: Pool payouts have a broadcast-before-durable-intent window).

Steps

  1. Receipt reorg and finality pause leave correct pending obligations.

Accept

Receipt reorg and finality pause leave correct pending obligations.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F12
R2-F13-R01Repeated authorization rejected or atomically replaces and cleans prior state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Repeated authorization rejected or atomically replaces and cleans prior state.

Accept

Repeated authorization rejected or atomically replaces and cleans prior state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R02Oversized unterminated frame rejected within fixed memory/time budget.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Oversized unterminated frame rejected within fixed memory/time budget.

Accept

Oversized unterminated frame rejected within fixed memory/time budget.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F13-R03Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F13 requires (review R2 finding F13: Pool admission and membership need bounded resources).

Steps

  1. Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Accept

Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (new)
Design status
NOT RUN
Plan pages
R2-F13
R2-F14-R01Public build has no default arbitrary remote execution and a documented least-privilege boundary.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Accept

Public build has no default arbitrary remote execution and a documented least-privilege boundary.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R02Automatic updates off remains off for urgent manifests until explicit action.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. Automatic updates off remains off for urgent manifests until explicit action.

Accept

Automatic updates off remains off for urgent manifests until explicit action.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
R2-F14-R03A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.Priority P1Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

The regression R2-F14 requires (review R2 finding F14: Developer fleet control must not silently become the public client trust model).

Steps

  1. A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Accept

A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change.

Evidence the case requires

The run record of the regression as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane, relay lane
Design status
NOT RUN
Plan pages
R2-F14
18INT

INT: the master edition's integration gates (R1, the full-system review)

18 integration gates; each reads NOT RUN until its owner lane records a run

NOT RUN
Owner
the owner lanes per the coordinator's crosswalk
Gate
Integration gates closed
Fixtures
F0,F5
Plan pages
docs/plans/igneum-2.0-master/traceability.json integration_gates
18 cases: 0 passed under the standard, 0 running with team evidence, 18 not run, 0 deferred
INT-01Real proof H cannot authenticate a different statement under a warm cache.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-01 of the master edition (R1 / Additional regression gates).

Steps

  1. Real proof H cannot authenticate a different statement under a warm cache.

Accept

Real proof H cannot authenticate a different statement under a warm cache.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-02Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-02 of the master edition (R1 / Additional regression gates).

Steps

  1. Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Accept

Warm/cold/relay/restart/concurrent cache order does not change block or payout decisions; negative cache isolated.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-03Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-03 of the master edition (R1 / Additional regression gates).

Steps

  1. Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Accept

Durable payout outbox survives every crash/RPC boundary without duplicate or lost liabilities.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Design status
NOT RUN
Plan pages
R1
INT-04Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-04 of the master edition (R1 / Additional regression gates).

Steps

  1. Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Accept

Corrupt existing pool state, disk-full and reorg cause safe recovery, not silent empty balances.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Design status
NOT RUN
Plan pages
R1
INT-05The supplied finality implementation matches the approved anchor rule after >window healing.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-05 of the master edition (R1 / Additional regression gates).

Steps

  1. The supplied finality implementation matches the approved anchor rule after >window healing.

Accept

The supplied finality implementation matches the approved anchor rule after >window healing.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-06Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-06 of the master edition (R1 / Additional regression gates).

Steps

  1. Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Accept

Recovery tests state and preserve their weaker fault bound; interfaces never label it as a stronger guarantee.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
node lane (a283f5f0d364ceef0)
Design status
NOT RUN
Plan pages
R1
INT-07One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-07 of the master edition (R1 / Additional regression gates).

Steps

  1. One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Accept

One v6 object agrees in node, pool, CPU verifier and each supported GPU host across activation.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-08Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-08 of the master edition (R1 / Additional regression gates).

Steps

  1. Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Accept

Census, production acceptance, schedule counters and live-dataset tests use the identical frozen contract.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-09Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-09 of the master edition (R1 / Additional regression gates).

Steps

  1. Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Accept

Eight- and twelve-GiB epoch transitions recover deliberately without relying on repeated OOM/watchdog cycles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-10Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-10 of the master edition (R1 / Additional regression gates).

Steps

  1. Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Accept

Metal/CUDA/OpenCL exact dataset geometry agrees; unsupported packs reject before launch.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)
Design status
NOT RUN
Plan pages
R1
INT-11Only a memory-reserved proving job launches; mining buffers really release when required.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-11 of the master edition (R1 / Additional regression gates).

Steps

  1. Only a memory-reserved proving job launches; mining buffers really release when required.

Accept

Only a memory-reserved proving job launches; mining buffers really release when required.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
app lane
Design status
NOT RUN
Plan pages
R1
INT-12Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-12 of the master edition (R1 / Additional regression gates).

Steps

  1. Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Accept

Transient shard errors can retry safely; expiration, loss and paid work remain distinct durable outcomes.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62) and fleet lane (ac055d60427caab99)
Design status
NOT RUN
Plan pages
R1
INT-13Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-13 of the master edition (R1 / Additional regression gates).

Steps

  1. Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Accept

Ember cannot retain a rate-ineligible prior; material workload changes invalidate incompatible profiles.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-14Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-14 of the master edition (R1 / Additional regression gates).

Steps

  1. Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Accept

Protected helper and per-device leases restore owned settings on normal/abnormal exit; real ACL/security tests.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
Ember lane (a04fe3451877e2ff0) with the app lane
Design status
NOT RUN
Plan pages
R1
INT-15Public PoP replay is not session authorization; payout/server/network binding enforced.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-15 of the master edition (R1 / Additional regression gates).

Steps

  1. Public PoP replay is not session authorization; payout/server/network binding enforced.

Accept

Public PoP replay is not session authorization; payout/server/network binding enforced.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Design status
NOT RUN
Plan pages
R1
INT-16Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-16 of the master edition (R1 / Additional regression gates).

Steps

  1. Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Accept

Pool parsing/queues/connection and crypto budgets remain bounded under controlled adversarial traffic.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
pool lane (a1c484c48a62948c2)
Design status
NOT RUN
Plan pages
R1
INT-17Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-17 of the master edition (R1 / Additional regression gates).

Steps

  1. Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Accept

Missing oracle/keys/mandatory real-proof fixture blocks the applicable production acceptance gate.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
proving lane (a6e8f84588b809d62)
Design status
NOT RUN
Plan pages
R1
INT-18Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.Priority P0Profile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 21:10 UK

Setup

Integration gate INT-18 of the master edition (R1 / Additional regression gates).

Steps

  1. Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Accept

Whole-system economics pass the strongest feasible adversary, including sunk development and multi-epoch survival.

Evidence the case requires

The run record of the gate as its owner lane records it through tools/ci/test-record.mjs.

Method
Automated + independent review
Cadence
Every release candidate
Owner
research lane (ad6a2bd47d4a46105)
Design status
NOT RUN
Plan pages
R1
Profiles

The numbers each case is held to.

17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

P00Approved as proposed

Frozen scope and approval

  1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
  2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
  3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

Cited by 76 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P01Approved as proposed

Correctness and negative-test depth

  1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
  2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
  3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P02Approved as proposed

Hardware coverage and reproducibility

  1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
  2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
  3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
  4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P03Approved as proposed

Candidate improvement and honest-card budget

  1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
  2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
  3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P04Approved as proposed

Scoped specialist-competition target

  1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
  2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
  3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
  4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P05Approved as proposed

Measurement and inference protocol

  1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
  2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
  3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
  4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P06Approved as proposed

Memory and support policy

  1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
  2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
  3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P07Approved as proposed

Proof service capacity and fairness

  1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
  2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
  3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
  4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
  5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P08Approved as proposed

Fault assumptions and recovery

  1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
  2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
  3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
  4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P09Approved as proposed

Security and bounded resource requirements

  1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
  2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
  3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
  4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P10Approved as proposed

Ordinary-operator product targets

  1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
  2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
  3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
  4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
  5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P11Approved as proposed

No-founder exercise and independence

  1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
  2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
  3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P12Approved as proposed

Five-year coexistence envelope

  1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
  2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
  3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
  4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
  5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P13Deferred by the founder

Maintenance continuity

  1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
  2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
  3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P14Approved as proposed

Genuine commercial and developer proof

  1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
  2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
  3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
  4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P15Approved as proposed

Comparative contention threshold

  1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
  2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
  3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
  4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

P16Approved as proposed

Observed durability and claim freshness

  1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
  2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
  3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
  4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

Fixtures

What every run is built on.

F0

Release and assurance manifest

Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

F1

Clean build environments

Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

F2

Hardware and measurement lab

Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

F3

Workload and oracle catalogue

Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

F4

Authorised fault network

Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

F5

Negative and regression corpus

Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

F6

Specialist implementation pack

Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

F7

Economic and incentive models

Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

F8

User/customer/peer studies

Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

F9

Evidence and status vault

Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

What a full pass means

Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

Rules in force

  • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
  • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
  • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
  • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

+ + + + + + + + + +
+
+
Disclosure prize
+

A better adversary, or a reproduced shortcut.

+

A GPU-secured network for Ethereum-compatible applications and verifiable computation. The prize rewards a finding that moves the served chip bracket or breaks the served kit, never a confirmation of what the project already states. These are the terms; the amount is set by the founder and served here when set.

+
+
+

What the prize pays for

+
+ + + + + +
FindingWhat qualifiesAgainst what
(a) An adversarial implementationA placed-and-routed or measured implementation (synthesis alone does not qualify) that beats the served energy or cost bracket against the best practical GPU implementation, under the one acceptance rule and the published budgetThe served sentence on the chip model, its per-tier line and the acceptance standard’s P04 target
(b) A reproduced shortcutA hash computed with fewer dataset reads or less work than the generator’s, reproduced on the served harnessThe served kit: the generator, the verifier, the dataset policy and the measurement harness pinned by digest in the release manifest
+

What it does not pay for

+

Confirmations of the served figures. Synthesis-only rows. Results outside the published budget (the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness, hardware accessibility). Findings on classes already on the excluded list (the long program, the select tree, the wide read, the scratchpad, the mixed FP32 candidate, the connected-state variant: the negative controls).

+

How a claim is made and judged

+

A claim is a written report with the harness run that reproduces it. It is judged in-house, under the plan’s in-house rule, against the one acceptance rule, and the finding is served whatever the verdict: a finding that beats the bracket replaces the served sentence with its label, and a finding that does not is published with the reason. Send the report to hello@igneum.network.

+

The amount

+

The amount is set by the founder and served here when set. No figure is served before his word.

+

Terms as the Counter ASIC coordinator set them on 8 October 2026 under the plan’s in-house rule (the pins, p. 12 of the plan). No chip percentages, no rank. Not legal advice.

+
+
+ + + + + + + diff --git a/site/provenance.html b/site/provenance.html index 1c47d338c..030bb5b9b 100644 --- a/site/provenance.html +++ b/site/provenance.html @@ -130,7 +130,7 @@ table{min-width:560px}
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -170,7 +170,7 @@ table{min-width:560px}
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/proving.html b/site/proving.html index 9f460128a..b5d00bc28 100644 --- a/site/proving.html +++ b/site/proving.html @@ -156,7 +156,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -196,7 +196,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/randomx.html b/site/randomx.html index 6fcdd68e0..4f6d3b667 100644 --- a/site/randomx.html +++ b/site/randomx.html @@ -129,7 +129,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -169,7 +169,7 @@
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/receipt.html b/site/receipt.html index 32c9adda1..b55919e64 100644 --- a/site/receipt.html +++ b/site/receipt.html @@ -135,7 +135,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -175,7 +175,7 @@
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/release-manifest.json b/site/release-manifest.json index 0c83933ef..8ee49e974 100644 --- a/site/release-manifest.json +++ b/site/release-manifest.json @@ -1,6 +1,6 @@ { "format": "igneum-release-manifest-v1", - "generated": "2026-10-08T19:57:00Z", + "generated": "2026-10-08T19:59:00Z", "read_at": "read 8 October 2026, 17:2x UK, from the node lane's line on build-1's seed (the re-cut node 4cdcc488) at the first block", "labels": { "measured": "read from a running node, a binary or a record", @@ -66,7 +66,8 @@ "app": { "name": "Ember", "channel": "devnet-4", - "note": "the macOS build is 2.0.0 (unsigned tonight; a signed and notarized build follows); the Windows and HiveOS builds are the 0.3.26 line until the 2.0.0 cut ships for them; the versions block carries each file's SHA-256" + "version": "2.0.1", + "note": "2.0.1 on every platform (Mac 20:16, HiveOS 20:25, Windows 20:56 UK, 8 October 2026); 2.0.0 is withdrawn (its miner could not read this network's block templates) and every 2.0.0 install updates itself to 2.0.1; the Mac build is unsigned tonight; min_supported_version 2.0.1" } }, "mining": { @@ -207,11 +208,11 @@ "url": "https://dl.igneum.network/dl/public/Igneum-Miner-2.0.1-7cfa422a-aa0e0f45.dmg" }, "miner-windows": { - "version": "2.0.0", - "file": "Igneum-Miner-Setup-2.0.0.exe", - "sha256": "793a631dc2084e6d6f778f13602d674a0c134af746b6355c25d3998c2be18b79", - "size": 63803668, - "url": "https://dl.igneum.network/dl/public/Igneum-Miner-Setup-2.0.0.exe" + "version": "2.0.1", + "file": "Igneum-Miner-Setup-2.0.1.exe", + "sha256": "ce6bb00cd738fa08348fd8121781479109a5b2c2059a04fe7c22ad7aa3f12bf9", + "size": 63831654, + "url": "https://dl.igneum.network/dl/public/Igneum-Miner-Setup-2.0.1.exe" }, "wallet-mac": { "version": "0.1.6", @@ -221,7 +222,7 @@ "url": "https://dl.igneum.network/dl/public/Igneum-Wallet-0.1.6.dmg" } }, - "versions_updated": "2026-10-08T19:44:46Z", + "versions_updated": "2026-10-08T19:51:38Z", "sources": { "network": "the node lane's read of build-1's seed (igneum-devnet-4) at the first block, 8 October 2026, 17:14 UK", "node": "the node lane's line: release-2.0.0-node 4cdcc488, igneumd/2.0.0-4cdcc488", diff --git a/site/scenes.html b/site/scenes.html index 371c56187..57ab8a928 100644 --- a/site/scenes.html +++ b/site/scenes.html @@ -121,7 +121,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -161,7 +161,7 @@
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/scorecard.html b/site/scorecard.html index fbe2b0190..7f06db72a 100644 --- a/site/scorecard.html +++ b/site/scorecard.html @@ -103,7 +103,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -143,7 +143,7 @@

Source: docs/plans/igneum-2.0-plan.txt, section 23 (the acceptance scorecard) and the pins in docs/plans/igneum-2.0.md; the Today column is the facts page’s label for the rows each gate cites, and moves only with those rows. The five labels: TEAM-REPORTED, MODELLED, PROPOSED, PENDING, EXCLUDED. The public mirror follows master; a link that answers 404 is a file not yet synced.

+

A finding that moves a gate the other way, a placed or measured adversary that beats the served bracket or a reproduced shortcut in the served kit, earns the disclosure prize; the terms are on that page.

The release evidence packet

A source commit, exact parameters, the test procedure, the raw result, the independent-reproduction status, the review scope and the unresolved limitations accompany every material claim. On this site that packet is the facts page’s row: its Version or commit, Reproducible test, Result and Independent verification cells, with the limitations stated in the row. A claim without a packet is not served.

The wording ladder

diff --git a/site/sitemap.xml b/site/sitemap.xml index 65c737d9d..d136c7bb9 100644 --- a/site/sitemap.xml +++ b/site/sitemap.xml @@ -1,7 +1,7 @@ https://igneum.network/2026-10-07weekly1.0 - https://igneum.network/litepaperhttps://igneum.network/economics2026-10-07monthly0.9https://igneum.network/scorecard2026-10-08monthly0.9https://igneum.network/audit2026-10-08monthly0.9https://igneum.network/docs2026-10-08monthly0.9https://igneum.network/tuning2026-10-08monthly0.9 + https://igneum.network/litepaperhttps://igneum.network/economics2026-10-07monthly0.9https://igneum.network/scorecard2026-10-08monthly0.9https://igneum.network/prize2026-10-08monthly0.9https://igneum.network/audit2026-10-08monthly0.9https://igneum.network/docs2026-10-08monthly0.9https://igneum.network/tuning2026-10-08monthly0.9 https://igneum.network/litepaperhttps://igneum.network/economics2026-10-07monthly0.9https://igneum.network/scorecard2026-10-08monthly0.9https://igneum.network/acceptance2026-10-08monthly0.9 https://igneum.network/miner2026-10-07weekly0.8 https://igneum.network/app2026-10-07weekly0.8 diff --git a/site/swap.html b/site/swap.html index 81a4230a0..aa6ca2ce7 100644 --- a/site/swap.html +++ b/site/swap.html @@ -140,7 +140,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:13px;overflo
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -180,7 +180,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:13px;overflo
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/tuning.html b/site/tuning.html index 3b802c80b..61b50b19d 100644 --- a/site/tuning.html +++ b/site/tuning.html @@ -130,7 +130,7 @@ table{min-width:560px}
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -170,7 +170,7 @@ table{min-width:560px}
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/tx.html b/site/tx.html index e4450e055..10bd7c285 100644 --- a/site/tx.html +++ b/site/tx.html @@ -157,7 +157,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -197,7 +197,7 @@ main{padding-bottom:100px}.card{background:var(--row);border:1px solid var(--lin
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/site/wallet.html b/site/wallet.html index 0e0c5ae2c..b308d1e5c 100644 --- a/site/wallet.html +++ b/site/wallet.html @@ -139,7 +139,7 @@
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. @@ -179,7 +179,7 @@
Learn
LitepaperThe design, as published. IncomeWhat your card would mine, from the live network. - EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. + EconomicsThe emission, the split and the fees, each with its line in the node.ScorecardThe twelve acceptance gates, their evidence and where each stands.PrizeA better adversary or a reproduced shortcut, never a confirmation: the terms.AcceptanceThe Test and Acceptance Standard, case by case, as each one passes.Site auditEvery page, what the reset changed and what is open.DocumentsThe plan, the standard, the specifications and the evidence files, by path. LedgerEvery criticism, answered or conceded. What Igneum does not claimThe limits, stated first. Igneum vs RandomXWhat was kept and what was rebuilt for GPUs. diff --git a/tools/chip-model/rtl/Makefile b/tools/chip-model/rtl/Makefile index dea28cc08..cf77c1d4e 100644 --- a/tools/chip-model/rtl/Makefile +++ b/tools/chip-model/rtl/Makefile @@ -23,8 +23,14 @@ CPUSET = $(if $(LEASE_ON),--cpuset-cpus {cpuset},) DOCKER := $(LEASEPFX) docker run --rm -u $(UID_GID) -e HOME=/tmp -e NUM_CORES=$(THREADS) $(CPUSET) -v $(WORK):/work ORFS := $(DOCKER) -w /OpenROAD-flow-scripts/flow $(ORFS_IMG) SIM := $(DOCKER) -w /work $(SIM_IMG) +# NO_DOCKER=1: the box IS the ORFS image (a rented pod started from openroad/orfs:latest with iverilog installed +# and /work a symlink to this directory); the same targets run natively. +ifeq ($(NO_DOCKER),1) +ORFS := env NUM_CORES=$(THREADS) bash -c 'cd /OpenROAD-flow-scripts/flow && exec "$$@"' -- +SIM := env +endif -DESIGNS := arx mul prmt lop3 fold shfl xbar scratch tile core8 core32 core32r16 core8r64 core8i1k core8sel core32all +DESIGNS := arx mul prmt lop3 fold shfl xbar scratch tile core8 core32 core32r16 core8r64 core8i1k core8sel core32all core8g core8r64g coretm cs64 fp32 top = $(shell sed -n 's/^$(1) \([^ ]*\) .*/\1/p' flow/designs.txt) # per-family simulation tags (the op field fixed per row where the family has several ops) @@ -37,13 +43,18 @@ SIMS_shfl := mix SIMS_xbar := mix SIMS_scratch := mix SIMS_tile := mix -SIMS_core8 := mix mixld:+loads=1 -SIMS_core32 := mix mixld:+loads=1 -SIMS_core32r16 := mix mixld:+loads=1 -SIMS_core8r64 := mix +SIMS_core8 := s150:+cycles=150 s600:+cycles=600 +SIMS_core32 := s150:+cycles=150 s600:+cycles=600 +SIMS_core32r16 := s150:+cycles=150 s600:+cycles=600 +SIMS_core8r64 := s150:+cycles=150 s600:+cycles=600 SIMS_core8i1k := mix SIMS_core8sel := mix SIMS_core32all := mix +SIMS_core8g := s150:+cycles=150 s600:+cycles=600 +SIMS_core8r64g := s150:+cycles=150 s600:+cycles=600 +SIMS_coretm := mix +SIMS_cs64 := s150:+cycles=150 s600:+cycles=600 +SIMS_fp32 := mix fadd:+op=0 fmul:+op=1 ffma:+op=2 fcvt:+op=3 .PHONY: rows table clean @@ -65,6 +76,7 @@ sim-%: flow-% power-%: sim-% $(ORFS) make DESIGN_CONFIG=/work/flow/$*.mk RUN_SCRIPT=/work/flow/power.tcl RUN_LOG_NAME_STEM=power run 2>&1 | tee logs/power-$*.log + rm -f sim/$*/*.vcd # the traces run to gigabytes each; the power log keeps every number (a full disk killed four runs on 8 October 2026) # synthesis-only row (no placement, no parasitics): the 14:45 fallback synth-%: diff --git a/tools/chip-model/rtl/flow/asap7_icg_model.v b/tools/chip-model/rtl/flow/asap7_icg_model.v new file mode 100644 index 000000000..bd9c405a8 --- /dev/null +++ b/tools/chip-model/rtl/flow/asap7_icg_model.v @@ -0,0 +1,12 @@ +// Behavioural model of the ASAP7 integrated clock gate (latch_posedge_precontrol: the enable is latched while the +// clock is low, the gated clock is CLK AND the latched enable OR test). The liberty carries no function for it. +module ICGx1_ASAP7_75t_R(input CLK, input ENA, input SE, output GCLK); + reg en = 0; + always @(CLK or ENA or SE) if (!CLK) en = ENA | SE; + assign GCLK = CLK & en; +endmodule +module ICGx2_ASAP7_75t_R(input CLK, input ENA, input SE, output GCLK); + reg en = 0; + always @(CLK or ENA or SE) if (!CLK) en = ENA | SE; + assign GCLK = CLK & en; +endmodule diff --git a/tools/chip-model/rtl/flow/collect.py b/tools/chip-model/rtl/flow/collect.py index 842842019..79e01aff7 100644 --- a/tools/chip-model/rtl/flow/collect.py +++ b/tools/chip-model/rtl/flow/collect.py @@ -6,7 +6,7 @@ import re, sys, os, csv work = sys.argv[1] if len(sys.argv) > 1 else '.' # ops per cycle per design (the per-op divisor) and the GPU row each family is read against -OPS = {'arx': 1, 'mul': 1, 'prmt': 1, 'lop3': 1, 'fold': 1, 'shfl': 32, 'xbar': 32, 'scratch': 1, 'tile': 512, 'core8': 8, 'core32': 32, 'core32r16': 32, 'core8r64': 8, 'core8i1k': 8, 'core8sel': 8, 'core32all': 32} +OPS = {'arx': 1, 'mul': 1, 'prmt': 1, 'lop3': 1, 'fold': 1, 'shfl': 32, 'xbar': 32, 'scratch': 1, 'tile': 512, 'core8': 8, 'core32': 32, 'core32r16': 32, 'core8r64': 8, 'core8i1k': 8, 'core8sel': 8, 'core32all': 32, 'core8g': 8, 'core8r64g': 8, 'coretm': 1, 'cs64': 8, 'fp32': 1} # 5090 measured pJ per counted op: (unlocked, at the 1,300 MHz lock); 15.1a GPU = { 'arx:mix': (11.3, 6.2), 'arx:add': (11.3, 6.2), 'arx:sub': (11.3, 6.2), 'arx:xor': (11.3, 6.2), 'arx:or': (11.3, 6.2), @@ -17,7 +17,7 @@ GPU = { 'shfl:mix': (55.8, 29.4), 'xbar:mix': (55.8, 29.4), 'scratch:mix': (2400.0, 1400.0), # the card's L2 hit (no shared-memory probe measured: owed) 'tile:mix': (4.1, 2.2), - 'core8:mix': (11.3, 6.2), 'core8:mixld': (11.3, 6.2), 'core32:mix': (11.3, 6.2), 'core32:mixld': (11.3, 6.2), 'core32r16:mix': (11.3, 6.2), 'core8r64:mix': (11.3, 6.2), 'core8i1k:mix': (11.3, 6.2), 'core8sel:mix': (11.3, 6.2), 'core32all:mix': (11.3, 6.2), # the class v4 draw: read against int_arx (the packs job read the whole mix at 10.8 / 6.4) # dependent u8 m8n8k16 per MAC; the wide s8 tile reads 1.36 / 0.83 + 'core8:mix': (11.3, 6.2), 'core8:mixld': (11.3, 6.2), 'core32:mix': (11.3, 6.2), 'core32:mixld': (11.3, 6.2), 'core32r16:mix': (11.3, 6.2), 'core8r64:mix': (11.3, 6.2), 'core8i1k:mix': (11.3, 6.2), 'core8sel:mix': (11.3, 6.2), 'core32all:mix': (11.3, 6.2), 'core8g:mix': (11.3, 6.2), 'core8r64g:mix': (11.3, 6.2), 'coretm:mix': (11.3, 6.2), 'cs64:mix': (11.3, 6.2), 'fp32:mix': (9.2, 5.2), 'fp32:fadd': (9.2, 5.2), 'fp32:fmul': (9.2, 5.2), 'fp32:ffma': (9.2, 5.2), 'fp32:fcvt': (9.2, 5.2), # the class v4 draw: read against int_arx (the packs job read the whole mix at 10.8 / 6.4) # dependent u8 m8n8k16 per MAC; the wide s8 tile reads 1.36 / 0.83 } # per-node energy scaling from ASAP7 (a 7 nm-class predictive PDK at 0.70 V), approximate and claimed: # N7 -> N5 x0.70 (TSMC: "30 percent lower power at the same speed"), N5 -> N3E x0.72 (TSMC: 25 to 30 percent), @@ -67,10 +67,10 @@ for d in OPS: pairs = [('vcd:s150', 'vcd:s600', 150, 600), ('vcd:short', 'vcd:synth', 150, 800), ('vcd:s150', 'vcd:s400', 150, 400)] for sh, lg, cs, cl in pairs: if sh in rows and lg in rows: - rows['vcd:steady'] = steady(rows, period, sh, lg, cs, cl, 1028 if d in ('core8i1k', 'core32all') else LOAD_CYCLES) + rows['vcd:steady'] = steady(rows, period, sh, lg, cs, cl, 1028 if d in ('core8i1k', 'core32all') else (452 if d == 'cs64' else LOAD_CYCLES)) for tag, r in rows.items(): sub = tag.split(':')[1] if ':' in tag else 'prop' - key = f'{d}:{sub}' if sub in ('add','sub','xor','or','rotl','rotr','mul','mulhi','mad','mixld') else f'{d}:mix' + key = f'{d}:{sub}' if sub in ('add','sub','xor','or','rotl','rotr','mul','mulhi','mad','mixld','fadd','fmul','ffma','fcvt') else f'{d}:mix' gpu = GPU.get(key, (None, None)) pj = r['total'] * period * 1e-12 / OPS[d] * 1e12 # W * s / ops -> pJ pj_dyn = (r['internal'] + r['switching']) * period / OPS[d] diff --git a/tools/chip-model/rtl/flow/core8g.mk b/tools/chip-model/rtl/flow/core8g.mk new file mode 100644 index 000000000..c2601b8b8 --- /dev/null +++ b/tools/chip-model/rtl/flow/core8g.mk @@ -0,0 +1,18 @@ +# ORFS design config for the programmable shadow core (core8: core_v6_8), ASAP7. +export PLATFORM = asap7 +export DESIGN_NAME = core_v6_8 +export DESIGN_NICKNAME = core8g +export VERILOG_FILES = /work/rtl/core_v6_8.v +export VERILOG_INCLUDE_DIRS = /work/rtl +export SDC_FILE = /work/flow/core8g.sdc +export CORE_UTILIZATION = 40 +export CORE_ASPECT_RATIO = 1 +export CORE_MARGIN = 0.5 +export PLACE_DENSITY = 0.55 +export CORNER = TC +export SKIP_LAST_GASP = 1 +export WORK_HOME = /work/out/core8g +export SYNTH_MEMORY_MAX_BITS = 2000000 +# the adversary's register file: clock gating inferred (the ICG cells allowed back in) +export INFER_CLKGATES = 1 +export DONT_USE_CELLS = *x1p*_ASAP7* *xp*_ASAP7* SDF* diff --git a/tools/chip-model/rtl/flow/core8g.sdc b/tools/chip-model/rtl/flow/core8g.sdc new file mode 100644 index 000000000..10f3be2bd --- /dev/null +++ b/tools/chip-model/rtl/flow/core8g.sdc @@ -0,0 +1,10 @@ +current_design core_v6_8 +set clk_name core_clock +set clk_port_name clk +set clk_period 1500 +set clk_io_pct 0.2 +set clk_port [get_ports $clk_port_name] +create_clock -name $clk_name -period $clk_period $clk_port +set non_clock_inputs [all_inputs -no_clocks] +set_input_delay [expr $clk_period * $clk_io_pct] -clock $clk_name $non_clock_inputs +set_output_delay [expr $clk_period * $clk_io_pct] -clock $clk_name [all_outputs] diff --git a/tools/chip-model/rtl/flow/core8r64g.mk b/tools/chip-model/rtl/flow/core8r64g.mk new file mode 100644 index 000000000..e43857538 --- /dev/null +++ b/tools/chip-model/rtl/flow/core8r64g.mk @@ -0,0 +1,18 @@ +# ORFS design config for the programmable shadow core (core8: core_v6_8r64), ASAP7. +export PLATFORM = asap7 +export DESIGN_NAME = core_v6_8r64 +export DESIGN_NICKNAME = core8r64g +export VERILOG_FILES = /work/rtl/core_v6_8r64.v +export VERILOG_INCLUDE_DIRS = /work/rtl +export SDC_FILE = /work/flow/core8r64g.sdc +export CORE_UTILIZATION = 40 +export CORE_ASPECT_RATIO = 1 +export CORE_MARGIN = 0.5 +export PLACE_DENSITY = 0.55 +export CORNER = TC +export SKIP_LAST_GASP = 1 +export WORK_HOME = /work/out/core8r64g +export SYNTH_MEMORY_MAX_BITS = 2000000 +# the adversary's register file: clock gating inferred (the ICG cells allowed back in) +export INFER_CLKGATES = 1 +export DONT_USE_CELLS = *x1p*_ASAP7* *xp*_ASAP7* SDF* diff --git a/tools/chip-model/rtl/flow/core8r64g.sdc b/tools/chip-model/rtl/flow/core8r64g.sdc new file mode 100644 index 000000000..ffb92a9cd --- /dev/null +++ b/tools/chip-model/rtl/flow/core8r64g.sdc @@ -0,0 +1,10 @@ +current_design core_v6_8r64 +set clk_name core_clock +set clk_port_name clk +set clk_period 1500 +set clk_io_pct 0.2 +set clk_port [get_ports $clk_port_name] +create_clock -name $clk_name -period $clk_period $clk_port +set non_clock_inputs [all_inputs -no_clocks] +set_input_delay [expr $clk_period * $clk_io_pct] -clock $clk_name $non_clock_inputs +set_output_delay [expr $clk_period * $clk_io_pct] -clock $clk_name [all_outputs] diff --git a/tools/chip-model/rtl/flow/coretm.mk b/tools/chip-model/rtl/flow/coretm.mk new file mode 100644 index 000000000..ee4daff66 --- /dev/null +++ b/tools/chip-model/rtl/flow/coretm.mk @@ -0,0 +1,18 @@ +# ORFS design config for the programmable shadow core (core8: core_tm_8r64), ASAP7. +export PLATFORM = asap7 +export DESIGN_NAME = core_tm_8r64 +export DESIGN_NICKNAME = coretm +export VERILOG_FILES = /work/rtl/core_tm_8r64.v +export VERILOG_INCLUDE_DIRS = /work/rtl +export SDC_FILE = /work/flow/coretm.sdc +export CORE_UTILIZATION = 40 +export CORE_ASPECT_RATIO = 1 +export CORE_MARGIN = 0.5 +export PLACE_DENSITY = 0.55 +export CORNER = TC +export SKIP_LAST_GASP = 1 +export WORK_HOME = /work/out/coretm +export SYNTH_MEMORY_MAX_BITS = 2000000 +# the adversary's register file: clock gating inferred (the ICG cells allowed back in) +export INFER_CLKGATES = 1 +export DONT_USE_CELLS = *x1p*_ASAP7* *xp*_ASAP7* SDF* diff --git a/tools/chip-model/rtl/flow/coretm.sdc b/tools/chip-model/rtl/flow/coretm.sdc new file mode 100644 index 000000000..904853df5 --- /dev/null +++ b/tools/chip-model/rtl/flow/coretm.sdc @@ -0,0 +1,10 @@ +current_design core_tm_8r64 +set clk_name core_clock +set clk_port_name clk +set clk_period 1500 +set clk_io_pct 0.2 +set clk_port [get_ports $clk_port_name] +create_clock -name $clk_name -period $clk_period $clk_port +set non_clock_inputs [all_inputs -no_clocks] +set_input_delay [expr $clk_period * $clk_io_pct] -clock $clk_name $non_clock_inputs +set_output_delay [expr $clk_period * $clk_io_pct] -clock $clk_name [all_outputs] diff --git a/tools/chip-model/rtl/flow/cs64.mk b/tools/chip-model/rtl/flow/cs64.mk new file mode 100644 index 000000000..66f9c9f51 --- /dev/null +++ b/tools/chip-model/rtl/flow/cs64.mk @@ -0,0 +1,18 @@ +# ORFS design config for the programmable shadow core (core8: core_v6_8cs64), ASAP7. +export PLATFORM = asap7 +export DESIGN_NAME = core_v6_8cs64 +export DESIGN_NICKNAME = cs64 +export VERILOG_FILES = /work/rtl/core_v6_8cs64.v +export VERILOG_INCLUDE_DIRS = /work/rtl +export SDC_FILE = /work/flow/cs64.sdc +export CORE_UTILIZATION = 40 +export CORE_ASPECT_RATIO = 1 +export CORE_MARGIN = 0.5 +export PLACE_DENSITY = 0.55 +export CORNER = TC +export SKIP_LAST_GASP = 1 +export WORK_HOME = /work/out/cs64 +export SYNTH_MEMORY_MAX_BITS = 2000000 +# the adversary's register file: clock gating inferred (the ICG cells allowed back in) +export INFER_CLKGATES = 1 +export DONT_USE_CELLS = *x1p*_ASAP7* *xp*_ASAP7* SDF* diff --git a/tools/chip-model/rtl/flow/cs64.sdc b/tools/chip-model/rtl/flow/cs64.sdc new file mode 100644 index 000000000..8ab79b15b --- /dev/null +++ b/tools/chip-model/rtl/flow/cs64.sdc @@ -0,0 +1,10 @@ +current_design core_v6_8cs64 +set clk_name core_clock +set clk_port_name clk +set clk_period 1500 +set clk_io_pct 0.2 +set clk_port [get_ports $clk_port_name] +create_clock -name $clk_name -period $clk_period $clk_port +set non_clock_inputs [all_inputs -no_clocks] +set_input_delay [expr $clk_period * $clk_io_pct] -clock $clk_name $non_clock_inputs +set_output_delay [expr $clk_period * $clk_io_pct] -clock $clk_name [all_outputs] diff --git a/tools/chip-model/rtl/flow/designs.txt b/tools/chip-model/rtl/flow/designs.txt index af4f9566e..292d1983d 100644 --- a/tools/chip-model/rtl/flow/designs.txt +++ b/tools/chip-model/rtl/flow/designs.txt @@ -14,3 +14,8 @@ core8r64 core_v6_8r64 1500 core8i1k core_v6_8i1k 1500 core8sel core_v6_8sel 1500 core32all core_v6_32all 1500 +core8g core_v6_8 1500 +core8r64g core_v6_8r64 1500 +coretm core_tm_8r64 1500 +cs64 core_v6_8cs64 1500 +fp32 lane_fp32 2000 diff --git a/tools/chip-model/rtl/flow/fp32.mk b/tools/chip-model/rtl/flow/fp32.mk new file mode 100644 index 000000000..cb508f48a --- /dev/null +++ b/tools/chip-model/rtl/flow/fp32.mk @@ -0,0 +1,15 @@ +# ORFS design config for the mul shadow-core family (top lane_fp32), ASAP7. +export PLATFORM = asap7 +export DESIGN_NAME = lane_fp32 +export DESIGN_NICKNAME = fp32 +export VERILOG_FILES = /work/rtl/fp32_units.v +export VERILOG_INCLUDE_DIRS = /work/rtl +export SDC_FILE = /work/flow/fp32.sdc +export CORE_UTILIZATION = 40 +export CORE_ASPECT_RATIO = 1 +export CORE_MARGIN = 0.5 +export PLACE_DENSITY = 0.55 +export CORNER = TC +export SKIP_LAST_GASP = 1 +export WORK_HOME = /work/out/fp32 + diff --git a/tools/chip-model/rtl/flow/fp32.sdc b/tools/chip-model/rtl/flow/fp32.sdc new file mode 100644 index 000000000..b729bbae1 --- /dev/null +++ b/tools/chip-model/rtl/flow/fp32.sdc @@ -0,0 +1,10 @@ +current_design lane_fp32 +set clk_name core_clock +set clk_port_name clk +set clk_period 2000 +set clk_io_pct 0.2 +set clk_port [get_ports $clk_port_name] +create_clock -name $clk_name -period $clk_period $clk_port +set non_clock_inputs [all_inputs -no_clocks] +set_input_delay [expr $clk_period * $clk_io_pct] -clock $clk_name $non_clock_inputs +set_output_delay [expr $clk_period * $clk_io_pct] -clock $clk_name [all_outputs] diff --git a/tools/chip-model/rtl/flow/livestate.py b/tools/chip-model/rtl/flow/livestate.py new file mode 100644 index 000000000..f729ddd05 --- /dev/null +++ b/tools/chip-model/rtl/flow/livestate.py @@ -0,0 +1,79 @@ +#!/usr/bin/env python3 +"""Live-state analysis of a drawn shadow program on an R-register window (the coordinator's order, 15:3x UK). +The program is drawn as the core testbench draws it: NPROG instructions with the class v4 op weights, a load on +one instruction in 16 (the dependent memory wait), dst/src/src2 uniform over the R registers, and the result +fold reading every register at the end of the block. For every load (wait) the script reports the live set: +registers whose current value is read later (by an instruction, a later address, or the fold) before being +overwritten, split into those that feed a later ADDRESS or the RESULT and those that die inside an arithmetic +block. Dead writes (overwritten before any read) are counted too. Usage: livestate.py R [NPROG] [seeds]""" +import random, sys +R = int(sys.argv[1]) if len(sys.argv) > 1 else 64 +N = int(sys.argv[2]) if len(sys.argv) > 2 else 256 +SEEDS = int(sys.argv[3]) if len(sys.argv) > 3 else 64 +W = [('add',12),('xor',10),('mul',8),('mad',8),('shfl',8),('rotl',7),('sub',6),('mulhi',6),('rotr',6),('or',4)] +ops = [o for o,w in W for _ in range(w)] +def draw(rng): + prog = [] + for k in range(N): + op = 'load' if k % 16 == 15 else rng.choice(ops) + d, s, s2 = rng.randrange(R), rng.randrange(R), rng.randrange(R) + reads = [s] if op not in ('load',) else [s] # the load's address comes from src + if op in ('add','xor','mul','mad','sub','or','rotr','shfl','mulhi','rotl'): reads.append(d) # dst is read too (r[d] op= ...) + if op == 'mad': reads.append(s2) + if op == 'rotl': reads = [d] + prog.append((op, d, reads)) + return prog +tot_live = tot_addr = tot_dead = tot_waits = 0 +live_min, live_max = R, 0 +for seed in range(SEEDS): + rng = random.Random(seed) + prog = draw(rng) + # a value's "version" = (reg, write index); the fold at the end reads every register + # forward pass: for each instruction i and register r, next read of r's current value before its next write + n = len(prog) + # necessity: a version is NECESSARY if it reaches an address (a load's src) or the fold, transitively + # compute transitively by backward dataflow over versions + writes_at = {} # (i) -> reg written + # build version ids: version of reg r valid after instruction i + cur = {r: ('init', r) for r in range(R)} + uses = {} # version -> list of (consumer index, consumer version or 'addr'/'fold') + versions = set(cur.values()) + deps = {} # version -> set of versions it reads + for i, (op, d, reads) in enumerate(prog): + srcs = [cur[r] for r in reads] + if op == 'load': + v = ('load', i); deps[v] = set() # the returned word: its ADDRESS depends on srcs + for s in srcs: uses.setdefault(s, []).append(('addr', i)) + else: + v = (op, i); deps[v] = set(srcs) + for s in srcs: uses.setdefault(s, []).append(('op', i)) + cur[d] = v; versions.add(v) + fold = set(cur.values()) + # necessary = reaches an address or the fold + necessary = set(fold) + for v, us in uses.items(): + if any(k == 'addr' for k, _ in us): necessary.add(v) + changed = True + while changed: + changed = False + for v in list(versions): + if v in necessary: + for s in deps.get(v, ()): + if s not in necessary: necessary.add(s); changed = True + # per wait: the versions live at the load (written before it, read after it) + last_read = {} + for v, us in uses.items(): + last_read[v] = max(i for _, i in us) + for v in fold: last_read[v] = n + written_at = {v: (v[1] if v[0] != 'init' else -1) for v in versions} + for i, (op, d, reads) in enumerate(prog): + if op != 'load': continue + live = [v for v in versions if written_at[v] < i and last_read.get(v, -1) > i] + nec = [v for v in live if v in necessary] + tot_live += len(live); tot_addr += len(nec); tot_waits += 1 + live_min = min(live_min, len(live)); live_max = max(live_max, len(live)) + dead = sum(1 for v in versions if v[0] not in ('init',) and v not in uses and v not in fold) + tot_dead += dead +print(f'R = {R}, NPROG = {N}, {SEEDS} drawn programs, {tot_waits} waits') +print(f'live values at a wait: mean {tot_live/tot_waits:.1f} of {R} (min {live_min}, max {live_max}); of which necessary (reach a later address or the result): {tot_addr/tot_waits:.1f}') +print(f'dead writes (overwritten before any read): {tot_dead/SEEDS:.1f} per {N}-instruction block ({100*tot_dead/SEEDS/N:.1f} percent)') diff --git a/tools/chip-model/rtl/flow/pod.sh b/tools/chip-model/rtl/flow/pod.sh new file mode 100755 index 000000000..8344fc4ab --- /dev/null +++ b/tools/chip-model/rtl/flow/pod.sh @@ -0,0 +1,9 @@ +#!/usr/bin/env bash +# pod.sh: bootstrap a rented pod started from openroad/orfs:latest (RunPod, root): iverilog, /work -> this dir. +set -euo pipefail +cd "$(dirname "$0")/.." +export DEBIAN_FRONTEND=noninteractive +command -v iverilog >/dev/null || { apt-get update -qq >/dev/null 2>&1; apt-get install -y -qq iverilog rsync python3 >/dev/null 2>&1; } +[ -e /work ] || ln -s "$(pwd)" /work +export PATH=/OpenROAD-flow-scripts/tools/install/OpenROAD/bin:/OpenROAD-flow-scripts/tools/install/yosys/bin:$PATH +echo "pod ready: $(nproc) cores, $(free -g | awk '/Mem/{print $2}') GB, yosys $(yosys -V | cut -d' ' -f2), $(which iverilog)" diff --git a/tools/chip-model/rtl/flow/sim.sh b/tools/chip-model/rtl/flow/sim.sh index 88b05666d..f288d1c23 100755 --- a/tools/chip-model/rtl/flow/sim.sh +++ b/tools/chip-model/rtl/flow/sim.sh @@ -4,6 +4,7 @@ set -euo pipefail name=$1; tag=$2; shift 2 out=/work/sim/$name simcells=$(yosys-config --datdir)/simcells.v -iverilog -g2005 -I /work/tb -o $out/sim_$tag $out/sim_net.v /work/tb/tb_$(sed -n "s/^$name \([^ ]*\) .*/\1/p" /work/flow/designs.txt).v $simcells +tbfile=${TB:-/work/tb/tb_$(sed -n "s/^$name \([^ ]*\) .*/\1/p" /work/flow/designs.txt).v} +iverilog -g2005 -I /work/tb -o $out/sim_$tag $out/sim_net.v /work/flow/asap7_icg_model.v $tbfile $simcells ( cd $out && vvp -n sim_$tag "$@" | tee sim_$tag.log && mv dump.vcd $tag.vcd ) ls -la $out/$tag.vcd diff --git a/tools/chip-model/rtl/rtl/core_tm.v b/tools/chip-model/rtl/rtl/core_tm.v new file mode 100644 index 000000000..3e702511b --- /dev/null +++ b/tools/chip-model/rtl/rtl/core_tm.v @@ -0,0 +1,82 @@ +// The adversary's time-multiplexed core: ONE execution port (every class unit, once) serving LANES lanes' instruction +// streams round-robin, each lane's state (REGS x 32-bit) kept in its own bank; the imem and sequencer shared. +// One lane-op per cycle. Compared with core_v6 at the same LANES x REGS this removes LANES-1 copies of the units and +// keeps the register state and the imem: the energy per lane-op is the state's cost plus one unit set's. +// The butterfly shuffle across lanes needs every lane's source register in the same cycle, so the shuffle reads the +// bank-wide source column (as the SIMD core does) and the lane in turn takes its word. Loads return on ld_val. +`include "lane_common.vh" +module core_tm #(parameter LANES = 8, parameter LOG_LANES = 3, parameter REGS = 64, parameter LOG_REGS = 6, + parameter IW = 40, parameter IMEM_LOG = 8) ( + input clk, input rst, input run, + input prog_we, input [9:0] prog_addr, input [IW-1:0] prog_data, + input cfg_en, input [9:0] cfg_n, input [31:0] cfg_m, input [4:0] cfg_r, input [31:0] cfg_wm, input [31:0] cfg_off, input [31:0] cfg_mask, input [63:0] cfg_sel, + input [31:0] ld_val, + output [31:0] addr, output [31:0] out); + localparam IMEM = 1 << IMEM_LOG; + reg [IW-1:0] imem [0:IMEM-1]; + reg [IMEM_LOG-1:0] pc; reg [IMEM_LOG-1:0] n_q; reg [IW-1:0] ir; reg [LOG_LANES-1:0] lane; + reg [31:0] m_q, wm_q, off_q, mask_q; reg [4:0] r_q; + integer i; + // the sequencer: the same instruction is issued to each lane in turn (LANES cycles per instruction) + always @(posedge clk) begin + if (prog_we) imem[prog_addr[IMEM_LOG-1:0]] <= prog_data; + if (rst) begin pc <= 0; ir <= 0; lane <= 0; n_q <= {IMEM_LOG{1'b1}}; m_q <= 32'h9e3779b1; r_q <= 5'd13; wm_q <= 32'h0fffffc0; off_q <= 3; mask_q <= 32'h0fffffff; end + else begin + if (cfg_en) begin n_q <= cfg_n[IMEM_LOG-1:0]; m_q <= cfg_m | 1; r_q <= cfg_r; wm_q <= cfg_wm; off_q <= cfg_off; mask_q <= cfg_mask; end + if (run) begin + if (lane == {LOG_LANES{1'b1}}) begin ir <= imem[pc]; pc <= (pc == n_q) ? {IMEM_LOG{1'b0}} : pc + 1'b1; end + lane <= lane + 1'b1; + end + end + end + wire [3:0] op = ir[3:0]; + wire [LOG_REGS-1:0] dst = ir[4 +: LOG_REGS]; wire [LOG_REGS-1:0] src = ir[4+LOG_REGS +: LOG_REGS]; wire [LOG_REGS-1:0] src2 = ir[4+2*LOG_REGS +: LOG_REGS]; + wire [4:0] imm = ir[4+3*LOG_REGS +: 5]; wire [7:0] aux = ir[9+3*LOG_REGS +: 8]; + wire is_load = (op == 4'd12); + wire [4:0] rn = (imm == 0) ? 5'd1 : imm; + wire [LOG_LANES-1:0] smask = imm[LOG_LANES-1:0]; + // the banked state: one bank per lane, read through the lane select (a chip's SRAM bank select) + reg [31:0] rf [0:LANES*REGS-1]; + wire [31:0] d = rf[lane*REGS + dst]; + wire [31:0] s = rf[lane*REGS + src]; + wire [31:0] s2 = rf[lane*REGS + src2]; + wire [31:0] sx = rf[(lane ^ smask)*REGS + src]; // the shuffle partner's source word + // the one execution port + function [7:0] pick; input [63:0] b; input [3:0] k; reg [7:0] v; + begin v = b[8*k[2:0] +: 8]; pick = k[3] ? {8{v[7]}} : v; end + endfunction + wire [4:0] sn = (s[4:0] == 0) ? 5'd1 : s[4:0]; + wire mad = (op == 4'd8); + wire [63:0] p = (mad ? s : d) * (mad ? s2 : s); + wire [63:0] bytes = {s, d}; wire [15:0] sel = {aux, aux}; + wire [31:0] prm = {pick(bytes, sel[15:12]), pick(bytes, sel[11:8]), pick(bytes, sel[7:4]), pick(bytes, sel[3:0])}; + reg [31:0] lp; integer b; + always @* for (b = 0; b < 32; b = b + 1) lp[b] = aux[{d[b], s[b], s2[b]}]; + reg [31:0] r; + always @* begin + case (op) + 4'd0, 4'd13: r = d + s; + 4'd1, 4'd15: r = d - s; + 4'd2, 4'd14: r = d ^ s; + 4'd3: r = d | s; + 4'd4: r = `ROTL32(d, rn); + 4'd5: r = `ROTR32(d, sn); + 4'd6: r = p[31:0]; + 4'd7: r = p[63:32]; + 4'd8: r = p[31:0] + d; + 4'd9: r = d ^ sx; + 4'd10: r = prm; + 4'd11: r = lp; + default: r = ld_val ^ (32'h9e3779b9 * (lane + 1)); + endcase + end + wire [31:0] fx = s * m_q; + wire [4:0] frn = (r_q == 0) ? 5'd1 : r_q; + wire [31:0] fy = `ROTL32(fx, frn); + assign addr = is_load ? (((fy & wm_q) | off_q) & mask_q) : 32'd0; + always @(posedge clk) begin + if (rst) begin for (i = 0; i < LANES*REGS; i = i + 1) rf[i] <= 32'h9e3779b9 * (i + 1); end + else if (run) rf[lane*REGS + dst] <= r; + end + assign out = r; +endmodule diff --git a/tools/chip-model/rtl/rtl/core_tm_8r64.v b/tools/chip-model/rtl/rtl/core_tm_8r64.v new file mode 100644 index 000000000..5db91edc4 --- /dev/null +++ b/tools/chip-model/rtl/rtl/core_tm_8r64.v @@ -0,0 +1,7 @@ +`include "core_tm.v" +module core_tm_8r64(input clk, input rst, input run, input prog_we, input [9:0] prog_addr, input [39:0] prog_data, + input cfg_en, input [9:0] cfg_n, input [31:0] cfg_m, input [4:0] cfg_r, input [31:0] cfg_wm, input [31:0] cfg_off, input [31:0] cfg_mask, input [63:0] cfg_sel, + input [31:0] ld_val, output [31:0] addr, output [31:0] out); + core_tm #(.LANES(8), .LOG_LANES(3), .REGS(64), .LOG_REGS(6), .IW(40)) c(.clk(clk), .rst(rst), .run(run), .prog_we(prog_we), .prog_addr(prog_addr), .prog_data(prog_data), + .cfg_en(cfg_en), .cfg_n(cfg_n), .cfg_m(cfg_m), .cfg_r(cfg_r), .cfg_wm(cfg_wm), .cfg_off(cfg_off), .cfg_mask(cfg_mask), .cfg_sel(cfg_sel), .ld_val(ld_val), .addr(addr), .out(out)); +endmodule diff --git a/tools/chip-model/rtl/rtl/core_v6_8cs64.v b/tools/chip-model/rtl/rtl/core_v6_8cs64.v new file mode 100644 index 000000000..4d482e2c8 --- /dev/null +++ b/tools/chip-model/rtl/rtl/core_v6_8cs64.v @@ -0,0 +1,7 @@ +`include "core_v6.v" +module core_v6_8cs64(input clk, input rst, input run, input prog_we, input [9:0] prog_addr, input [40-1:0] prog_data, + input cfg_en, input [9:0] cfg_n, input [63:0] cfg_sel, input [31:0] cfg_m, input [4:0] cfg_r, input [31:0] cfg_wm, input [31:0] cfg_off, input [31:0] cfg_mask, + input [31:0] ld_val, output [31:0] addr, output [31:0] out); + core_v6 #(.LANES(8), .LOG_LANES(3), .REGS(64), .LOG_REGS(6), .IW(40), .IMEM_LOG(9)) c(.clk(clk), .rst(rst), .run(run), .prog_we(prog_we), .prog_addr(prog_addr), .prog_data(prog_data), + .cfg_en(cfg_en), .cfg_n(cfg_n), .cfg_sel(cfg_sel), .cfg_m(cfg_m), .cfg_r(cfg_r), .cfg_wm(cfg_wm), .cfg_off(cfg_off), .cfg_mask(cfg_mask), .ld_val(ld_val), .addr(addr), .out(out)); +endmodule diff --git a/tools/chip-model/rtl/rtl/fp32_units.v b/tools/chip-model/rtl/rtl/fp32_units.v new file mode 100644 index 000000000..73a76c0a4 --- /dev/null +++ b/tools/chip-model/rtl/rtl/fp32_units.v @@ -0,0 +1,123 @@ +// The adversary's simplified FP32 units for the mixed-resource lane's candidate (class-v6-mixedfp): inputs are +// f(x) = as_float((x & 0x807FFFFF) | ((96 + ((x >> 23) & 63)) << 23)): never zero, denormal, NaN or Inf; exponents +// in [96, 159]; results normal or +0 (exact cancellation). The units drop NaN/Inf/denormal handling and the flags, +// keep the full 24-bit mantissa path, a full alignment and a full normaliser (the mantissas are uniform), RNE. +// Each lane reads two or three registers of an 8 x 32-bit window, applies f(), computes, xors the bits into dst. +`include "lane_common.vh" +// ---- the shared pieces ---- +module fp_unpack(input [31:0] x, output s, output [8:0] e, output [23:0] m); + assign s = x[31]; + assign e = 9'd96 + {3'b0, x[28:23]}; // the masked exponent, 96..159 + assign m = {1'b1, x[22:0]}; +endmodule +module lzc48(input [47:0] v, output reg [5:0] n); // leading-zero count (v != 0) + integer i; always @* begin n = 6'd47; for (i = 47; i >= 0; i = i - 1) if (v[i]) begin n = 6'd47 - i; i = -1; end end +endmodule +module lzc32(input [31:0] v, output reg [5:0] n); + integer i; always @* begin n = 6'd31; for (i = 31; i >= 0; i = i - 1) if (v[i]) begin n = 6'd31 - i; i = -1; end end +endmodule +// ---- the FMA: fma(a, b, c) = a*b + c, one rounding (RNE), exponents in the lane's ranges ---- +module fp_fma(input [31:0] a, input [31:0] b, input [31:0] c, output [31:0] y); + wire sa, sb, sc; wire [8:0] ea, eb, ec; wire [23:0] ma, mb, mc; + fp_unpack ua(a, sa, ea, ma); fp_unpack ub(b, sb, eb, mb); fp_unpack uc(c, sc, ec, mc); + wire [47:0] prod = ma * mb; // 48-bit product, binary point after bit 46 + wire sp = sa ^ sb; + wire [9:0] ep = {1'b0, ea} + {1'b0, eb} - 10'd127; // product exponent (bias kept), 65..192 + // align the addend to the product: a 100-bit window keeps full precision for exponent gaps up to about 96 (the lane's bound) + wire [9:0] diff = (ep >= {1'b0, ec}) ? ep - {1'b0, ec} : {1'b0, ec} - ep; + wire prod_big = (ep >= {1'b0, ec}); + wire [99:0] pw = {2'b0, prod, 50'b0}; + wire [99:0] cw = {2'b0, mc, 24'b0, 50'b0}; // the addend at the product's scale when exponents equal + wire [6:0] sh = (diff > 10'd99) ? 7'd99 : diff[6:0]; + wire [99:0] smw = prod_big ? (cw >> sh) : (pw >> sh); + wire [99:0] bgw = prod_big ? pw : cw; + wire sbig = prod_big ? sp : sc; wire ssmall = prod_big ? sc : sp; + wire [9:0] ebig = prod_big ? ep : {1'b0, ec}; + wire [100:0] sum = (sbig == ssmall) ? ({1'b0, bgw} + {1'b0, smw}) : ({1'b0, bgw} - {1'b0, smw}); + wire [100:0] mag = sum[100] ? (~sum + 1'b1) : sum; // two's complement when the subtraction went negative + wire ssum = sum[100] ? ssmall : sbig; + // normalise: find the leading one in the 101-bit magnitude + reg [6:0] lz; integer i; + always @* begin lz = 7'd100; for (i = 100; i >= 0; i = i - 1) if (mag[i]) begin lz = 7'd100 - i; i = -1; end end + wire [100:0] norm = mag << lz; // leading one at bit 100 + wire [23:0] mant = norm[100:77]; + wire guard = norm[76]; wire sticky = |norm[75:0]; + wire round_up = guard & (sticky | mant[0]); + wire [24:0] mr = {1'b0, mant} + round_up; + wire carry = mr[24]; + wire [9:0] eres = ebig + 10'd2 - lz + carry; // the leading one of bgw sat at bit 98 (two headroom bits) + wire zero = (mag == 0); + wire [7:0] eout = eres[7:0]; + assign y = zero ? 32'h0 : {ssum, eout, carry ? mr[23:1] : mr[22:0]}; +endmodule +// ---- the adder and the multiplier as their own units ---- +module fp_add(input [31:0] a, input [31:0] b, output [31:0] y); + wire sa, sb; wire [8:0] ea, eb; wire [23:0] ma, mb; + fp_unpack ua(a, sa, ea, ma); fp_unpack ub(b, sb, eb, mb); + wire abig = (ea > eb) || (ea == eb && ma >= mb); + wire [8:0] ebig = abig ? ea : eb; wire [8:0] esm = abig ? eb : ea; + wire [23:0] mbig = abig ? ma : mb; wire [23:0] msm = abig ? mb : ma; + wire sbig = abig ? sa : sb; wire ssm = abig ? sb : sa; + wire [8:0] diff = ebig - esm; wire [6:0] sh = (diff > 9'd70) ? 7'd70 : diff[6:0]; + wire [73:0] bw = {1'b0, mbig, 49'b0}; wire [73:0] sw = {1'b0, msm, 49'b0} >> sh; + wire [74:0] sum = (sbig == ssm) ? ({1'b0, bw} + {1'b0, sw}) : ({1'b0, bw} - {1'b0, sw}); + reg [6:0] lz; integer i; + always @* begin lz = 7'd74; for (i = 74; i >= 0; i = i - 1) if (sum[i]) begin lz = 7'd74 - i; i = -1; end end + wire [74:0] norm = sum << lz; + wire [23:0] mant = norm[74:51]; wire guard = norm[50]; wire sticky = |norm[49:0]; + wire round_up = guard & (sticky | mant[0]); + wire [24:0] mr = {1'b0, mant} + round_up; wire carry = mr[24]; + wire [9:0] eres = {1'b0, ebig} + 10'd1 - lz + carry; + wire zero = (sum == 0); + assign y = zero ? 32'h0 : {sbig, eres[7:0], carry ? mr[23:1] : mr[22:0]}; +endmodule +module fp_mul(input [31:0] a, input [31:0] b, output [31:0] y); + wire sa, sb; wire [8:0] ea, eb; wire [23:0] ma, mb; + fp_unpack ua(a, sa, ea, ma); fp_unpack ub(b, sb, eb, mb); + wire [47:0] prod = ma * mb; + wire top = prod[47]; + wire [23:0] mant = top ? prod[47:24] : prod[46:23]; + wire guard = top ? prod[23] : prod[22]; wire sticky = top ? |prod[22:0] : |prod[21:0]; + wire round_up = guard & (sticky | mant[0]); + wire [24:0] mr = {1'b0, mant} + round_up; wire carry = mr[24]; + wire [9:0] eres = {1'b0, ea} + {1'b0, eb} - 10'd127 + top + carry; + assign y = {sa ^ sb, eres[7:0], carry ? mr[23:1] : mr[22:0]}; +endmodule +// ---- int32 to float, RNE ---- +module fp_cvt(input [31:0] a, output [31:0] y); + wire s = a[31]; wire [31:0] mag = s ? (~a + 1'b1) : a; + wire [5:0] lz; lzc32 l(mag, lz); + wire [31:0] norm = mag << lz; // leading one at bit 31 + wire [23:0] mant = norm[31:8]; wire guard = norm[7]; wire sticky = |norm[6:0]; + wire round_up = guard & (sticky | mant[0]); + wire [24:0] mr = {1'b0, mant} + round_up; wire carry = mr[24]; + wire [7:0] e = 8'd127 + 8'd31 - lz + carry; + assign y = (mag == 0) ? 32'h0 : {s, e, carry ? mr[23:1] : mr[22:0]}; +endmodule +// ---- the lane: op 0 fadd, 1 fmul, 2 ffma, 3 fcvt; d ^= bits(result) ---- +module lane_fp32( + input clk, input rst, + input [1:0] op, input [2:0] dst, input [2:0] src, input [2:0] src2, + input ld_en, input [31:0] ld_val, + output [31:0] out); + reg [31:0] rf [0:7]; + reg [1:0] op_q; reg [2:0] dst_q, src_q, src2_q; reg ld_q; reg [31:0] ld_val_q; + integer i; + always @(posedge clk) begin + if (rst) begin op_q <= 0; dst_q <= 0; src_q <= 0; src2_q <= 0; ld_q <= 0; ld_val_q <= 0; end + else begin op_q <= op; dst_q <= dst; src_q <= src; src2_q <= src2; ld_q <= ld_en; ld_val_q <= ld_val; end + end + wire [31:0] d = rf[dst_q]; wire [31:0] s = rf[src_q]; wire [31:0] s2 = rf[src2_q]; + wire [31:0] ya, ym, yf, yc; + fp_add A(d, s, ya); + fp_mul M(d, s, ym); + fp_fma F(s, s2, d, yf); + fp_cvt C(s, yc); + reg [31:0] res; + always @* case (op_q) 2'd0: res = d ^ ya; 2'd1: res = d ^ ym; 2'd2: res = d ^ yf; default: res = d ^ yc; endcase + always @(posedge clk) begin + if (rst) begin for (i = 0; i < 8; i = i + 1) rf[i] <= 32'h9e3779b9 * (i + 1) + 9; end + else rf[dst_q] <= ld_q ? ld_val_q : res; + end + assign out = res; +endmodule diff --git a/tools/chip-model/rtl/tb/tb_core_common.vh b/tools/chip-model/rtl/tb/tb_core_common.vh index 38e969897..5a6f88d70 100644 --- a/tools/chip-model/rtl/tb/tb_core_common.vh +++ b/tools/chip-model/rtl/tb/tb_core_common.vh @@ -21,10 +21,32 @@ module tb; @(negedge clk); cfg_en = 1; cfg_n = `NPROG - 1; cfg_sel = `SEL; cfg_m = 32'h9e3779b1; cfg_r = 5'd13; cfg_wm = 32'h0fffffc0; cfg_off = 3; cfg_mask = 32'h0fffffff; @(negedge clk); cfg_en = 0; // the program: `NPROG instructions drawn with the class v4 weights +`ifdef CS + // the connected-state draw: step = load + 27-instruction spine block; `NPROG = 16 x 28 = 448 + begin : cs + integer st, q, last0, last1, last2, last3, mreg, areg, dreg, sreg, s2reg; + areg = 0; mreg = 1; + for (st = 0; st < `NPROG / 28; st = st + 1) begin + @(negedge clk); w = {$random, $random}; mreg = $random & 63; + prog_we = 1; prog_addr = st*28; prog_data = {w[`IW-1:4], 4'd12}; prog_data[4 +: 6] = mreg; prog_data[10 +: 6] = areg; // load: dst m_j, src a_j + last0 = mreg; last1 = mreg; last2 = mreg; last3 = mreg; + for (q = 0; q < 27; q = q + 1) begin + @(negedge clk); w = {$random, $random}; opc = draw_op($random); dreg = $random & 63; + case ($random & 3) 0: sreg = last0; 1: sreg = last1; 2: sreg = last2; default: sreg = last3; endcase + s2reg = last0; + if (q == 26 && !(opc == 4'd0 || opc == 4'd1 || opc == 4'd2 || opc == 4'd8 || opc == 4'd9)) opc = 4'd0; // the last instruction injects + prog_we = 1; prog_addr = st*28 + 1 + q; prog_data = {w[`IW-1:4], opc}; prog_data[4 +: 6] = dreg; prog_data[10 +: 6] = sreg; prog_data[16 +: 6] = s2reg; + last3 = last2; last2 = last1; last1 = last0; last0 = dreg; + end + areg = last0; + end + end +`else for (k = 0; k < `NPROG; k = k + 1) begin @(negedge clk); w = {$random, $random}; opc = (loads && (k % 16 == 15)) ? 4'd12 : draw_op($random); prog_we = 1; prog_addr = k; prog_data = {w[`IW-1:4], opc}; end +`endif @(negedge clk); prog_we = 0; run = 1; for (n = 0; n < cycles; n = n + 1) begin @(negedge clk); ld_val = $random; acc = acc ^ out ^ addr; diff --git a/tools/chip-model/rtl/tb/tb_core_tm_8r64.v b/tools/chip-model/rtl/tb/tb_core_tm_8r64.v new file mode 100644 index 000000000..954ae207f --- /dev/null +++ b/tools/chip-model/rtl/tb/tb_core_tm_8r64.v @@ -0,0 +1,6 @@ +`define TOP core_tm_8r64 +`define HALF 750 +`define IW 40 +`define NPROG 256 +`define SEL 64'hfedcba9876543210 +`include "tb_core_common.vh" diff --git a/tools/chip-model/rtl/tb/tb_core_v6_8_legacy.v b/tools/chip-model/rtl/tb/tb_core_v6_8_legacy.v new file mode 100644 index 000000000..9607238cf --- /dev/null +++ b/tools/chip-model/rtl/tb/tb_core_v6_8_legacy.v @@ -0,0 +1,3 @@ +`define TOP core_v6_8 +`define HALF 750 +`include "tb_core_legacy.vh" diff --git a/tools/chip-model/rtl/tb/tb_core_v6_8cs64.v b/tools/chip-model/rtl/tb/tb_core_v6_8cs64.v new file mode 100644 index 000000000..83d71eb03 --- /dev/null +++ b/tools/chip-model/rtl/tb/tb_core_v6_8cs64.v @@ -0,0 +1,7 @@ +`define TOP core_v6_8cs64 +`define HALF 750 +`define IW 40 +`define NPROG 448 +`define CS 1 +`define SEL 64'hfedcba9876543210 +`include "tb_core_common.vh" diff --git a/tools/chip-model/rtl/tb/tb_lane_fp32.v b/tools/chip-model/rtl/tb/tb_lane_fp32.v new file mode 100644 index 000000000..721a54e69 --- /dev/null +++ b/tools/chip-model/rtl/tb/tb_lane_fp32.v @@ -0,0 +1,22 @@ +`timescale 1ps/1ps +module tb; + reg clk = 0, rst = 1; reg [1:0] op = 0; reg [2:0] dst = 0, src = 0, src2 = 0; reg ld_en = 0; reg [31:0] ld_val = 0; + wire [31:0] out; + lane_fp32 dut(.clk(clk), .rst(rst), .op(op), .dst(dst), .src(src), .src2(src2), .ld_en(ld_en), .ld_val(ld_val), .out(out)); + integer n, fixed_op, cycles; reg [31:0] acc = 0; + always #1000 clk = ~clk; + // a reference check of the units against the host's float arithmetic is the mixed lane's own (the ranges are its); + // this bench drives random registers and reports the checksum + initial begin + if (!$value$plusargs("op=%d", fixed_op)) fixed_op = -1; + if (!$value$plusargs("cycles=%d", cycles)) cycles = 3000; + $dumpfile("dump.vcd"); $dumpvars(0, tb.dut); + repeat (4) @(negedge clk); rst = 0; + for (n = 0; n < cycles; n = n + 1) begin + @(negedge clk); + op = (fixed_op < 0) ? $random : fixed_op; dst = $random; src = $random; src2 = $random; + ld_en = (($random & 7) == 0); ld_val = $random; acc = acc ^ out; + end + $display("CHECKSUM %08x", acc); $finish; + end +endmodule diff --git a/tools/ci/README.md b/tools/ci/README.md index 4557b253a..9c7f37798 100644 --- a/tools/ci/README.md +++ b/tools/ci/README.md @@ -11,13 +11,16 @@ | gh's active account is the stored Igneum entry (`gh-account-check.sh`, in Igneum's own gh directory `~/.config/gh-igneum` through `gh-env.sh`, never the founder's) | A push or a landing from this Mac while Igneum's gh directory names any other account as active, or none (the refusal names the one step: the founder or main stores the Igneum token there with `GH_CONFIG_DIR=~/.config/gh-igneum gh auth login --with-token`; no lane does); skipped with a line while `github-suspended` stands. RULE: no lane switches gh accounts on this Mac, ever; the second owner's login belongs to other projects and must never touch Igneum; the stored entry's name is in ~/.config/igneum/gh-user, never in the repository. | 7 October 2026, 21:41 UK: a lane switched gh to the other login during the suspension; nobody could say which | | F02 (Review B): the proof-rule test bypass cannot reach a release build (`proof-rule-bypass-check.sh`; a cell of the node matrix) | An env read of IGNEUM_TEST_SKIP_PROOF_RULE with no cfg(test) or cfg(feature) guard in the 12 lines above, or under a feature in the crate's default features; a release igneumd carrying the bypass string. Red on every node sha until the proving lane's change (the read under a non-default feature or cfg(test)) lands | 8 Oct 2026 | +| the guest input format moves with the pinned guests (`guest-format-check.sh`; the diff rule in `merge-to-master.sh`, the tree rule in the gate) | A proving host whose GUEST_INPUT_FORMAT moved while the pinned guests stayed (8 October 2026, the V6-07 sub-lane: a master-built host failed every proof against the 5 October pair) | | the test map merges structurally at a landing (`test-map-merge.py`) and the harness page regenerates from the merged map (`merge-to-master.sh`) | Nothing by itself: two lanes adding cells collided as text and the regenerated page lost rule 26's race; the merge now keeps master's cells plus the branch's, minus what the branch removed and master left, and regenerates the page | 8 Oct 2026 | | a push that lost the ref race retries without re-running the hook (`merge-to-master.sh` `push_race`, 12 tries) | Nothing by itself: under one landing a minute a 70-second hook per try never won master's compare-and-swap (Review B's landing lost three in a row); once the hook has passed on the first try and the rejection is a ref race, later tries push --no-verify (both parents gated) | 8 Oct 2026 | | the kit ISA check (`kit-isa-check.sh`; in the gate as a self-test, in `merge-to-master.sh` over any executable a landing adds under packaging/kits or bin, and in the shipper's cut gate over the kit) | Any binary whose disassembly carries a zmm register, an EVEX opmask or an EVEX-only mnemonic (AVX-512): a fleet binary comes only from the cross-build kit at the x86-64-v3 baseline, never from a box's native gate build (79 fleet hosts died on one, 8 Oct 2026) | 8 Oct 2026 | | kill-by-name rule 5 and the no-kill shim (`kill-by-name-check.sh`, `no-kill-shim/{pkill,killall}` exit 97 when first in PATH) | A `pgrep -f`/`pkill -f` pattern that is a bare path, a log name or an unanchored word; only `^`-anchored command patterns, the bracket form, a variable, -x or -F pass (fifteen Mac processes died to a grep, 8 Oct 2026) | 8 Oct 2026 | | a "cut" batch needs its read-back (`test-record.mjs`) | A batch declaring `cut` without the binary's build-N:/srv path, its commit string read back equal to the manifest sha, and the kit ISA check's clean line; a sha is cut only when its binary exists on build-1 with its commit string read back | 8 Oct 2026 | +| rule 33: a release entry publishes only with a PASS fresh-install canary record for its sha (`canary-check.sh`; `tools/ci/canary/.json`, the form from `--form`; refused without by `packaging/ota/publish-manifest.sh --release-sha`, `publish-public.sh` and deploy-win.sh; the canary cell maps INT-07) | A release entry published before its sha had run a fresh install on a non-AVX-512 box with an empty datadir, synced, mined five minutes with zero refusals, claimed, proved and paid or queued one shard and quit inside a bound, every line read back (the founder's "no more lost time", 8 October 2026) | | the INT suite is generated from the master edition's integration gates (`int-suite.mjs`; the owner per the coordinator's crosswalk) and INT-17 is a rule of the writer: a cell declaring a missing oracle, pinned keys or mandatory real-proof fixture writes BLOCKED, never PASS | A registry whose INT suite drifts from traceability.json; a batch cell with `prereqs` where any is not "present" written as anything but BLOCKED | 8 Oct 2026 | | the REV suite is generated from an external review's findings.json and dispatch.md (`review-suite.mjs`; one case per required regression, NOT RUN, the owner from the dispatch table) | A registry whose REV suite differs from the generator's output (--check) | 8 Oct 2026 | +| F03 (Review B): one release manifest (`packaging/release-manifest.json` on a release branch) and every component built from it (`release-manifest-check.sh`, `build-from-manifest.sh`) | A tree whose own pins disagree with the manifest: the Windows node-source pin, the proving manifest's elf and vk sha256s and the files' hashes, the node fork's freeze fingerprint, the pool's vendored node checkout, a redefined EpochSeeds in the pool (the shadow_reps seam closes by a build against the pinned node); the build script puts the fork at the manifest's node sha and checks kaspad with igneum-pow (rule 19), the miner, the pool, the app and the prove host on a box | 8 Oct 2026 | | a registry landing carries its batches (`tools/ci/batches/.json`; `merge-to-master.sh` replays them onto master's copy at the merge) | Nothing by itself: the registry is a hot file, and a branch whose own copy of it was recorded during a seven-minute gate lost the race to another lane's rows three times in a row (8 Oct 2026, 19:1x UK). A branch that adds batch files is merged with master's registry, every added batch replayed through `test-record.mjs --record` (idempotent), and the evidence rules run on the merged result; rule 26 does not bind the registry path for such a branch | 8 Oct 2026 | | the registry's evidence rules (`registry-evidence-check.sh`, called by `merge-to-master.sh` after rule 26) | A landing that sets a case's run_status to PASS without an evidence_path that exists (in the tree at the landing, or on a build box over ssh; a box that does not answer is a line, not a refusal); a landing that changes a file under docs/analysis/ or a path a registry row names without moving that row's `updated` (the row and its evidence move together, GOV-04); a PASS whose evidence record pins another manifest than the registry's pinned_manifest_sha (stale evidence reads NOT RUN, GOV-08); a run_status written while the registry carries no approval block (thresholds before results, GOV-02) | 8 Oct 2026 | | the acceptance layer (`test-record.mjs`, `test-map.json`, `test-map-doc.mjs`; the founder's Test and Acceptance Standard, docs/plans/igneum-2.0-test-registry.json) | An automated case of the registry with no cell in the map and no NOT RUN reason; a map naming an unknown case; a stale harness-map page (generated from the JSON); the recorder's self-test: a run batch writes run_status, run_id, evidence_path, updated and the evidence record to the mapped cases only, never an accept text, and a case with no harness reads NOT RUN with its reason, never PASS by inference | 8 Oct 2026 | diff --git a/tools/ci/batches/adversary-20261008-placed-8lane.json b/tools/ci/batches/adversary-20261008-placed-8lane.json new file mode 100644 index 000000000..cc7243925 --- /dev/null +++ b/tools/ci/batches/adversary-20261008-placed-8lane.json @@ -0,0 +1,20 @@ +{ + "run_id": "adversary-20261008-placed-8lane", + "manifest_sha": "3a8874fef", + "evidence_dir": "docs/analysis/class-v6/multi-family-adversary.md", + "cells": [ + { + "cell": "adversary:mf-placed", + "status": "RUNNING", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "method": "model" + }, + { + "cell": "adversary:d2b", + "status": "RUNNING", + "evidence": "docs/analysis/class-v6/multi-family-adversary.md", + "method": "model", + "note": "evidence cited at the document (section 13, D2(b) restated on the placed rows); the mf flow's results file tools/chip-model/mf/results/d2b-n5.md stays on the branch and is cited after it lands (the recorder cites only files in the tree)" + } + ] +} diff --git a/tools/ci/batches/canary-20261008-01.json b/tools/ci/batches/canary-20261008-01.json new file mode 100644 index 000000000..171d3cdc4 --- /dev/null +++ b/tools/ci/batches/canary-20261008-01.json @@ -0,0 +1,28 @@ +{ + "run_id": "canary-20261008-01", + "manifest_sha": "c30ab32c", + "method": "team-reported", + "evidence_dir": "tools/ci/canary (no record yet)", + "boxes": [], + "release_identity": { + "commit": "c30ab32c (release-2.0.1 final tip; 2.0.2 open at c608b341)", + "lockfile": "", + "binary": "the shipped 2.0.1 entries on aa0e0f45's binaries", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "", + "profile_hashes": "" + }, + "claim_impact": "INT-07's clean-install half reads BLOCKED until a release tip carries a PASS fresh-install canary record; no published entry may move before one does (rule 33)", + "note": "Rule 33 recorded at 21:4x UK: the canary cell exists, its check and the publish-path guards are in the tree; no 2.0.x sha has a record yet, so the case is BLOCKED (prerequisite: the shipper's 2.0.2 canary tonight writes tools/ci/canary/.json).", + "cells": [ + { + "cell": "canary:fresh-install", + "cases": [ + "INT-07" + ], + "status": "BLOCKED", + "evidence": "tools/ci/canary-check.sh; packaging/ota/publish-manifest.sh; packaging/ota/publish-public.sh", + "note": "no fresh-install canary record exists for any 2.0.x release tip; the 2.0.2 canary is the shipper's tonight" + } + ] +} diff --git a/tools/ci/batches/canary-miner-fix-7cfa422a.json b/tools/ci/batches/canary-miner-fix-7cfa422a.json new file mode 100644 index 000000000..84a18e38d --- /dev/null +++ b/tools/ci/batches/canary-miner-fix-7cfa422a.json @@ -0,0 +1,11 @@ +{ + "run_id": "canary-miner-fix-7cfa422a", + "manifest_sha": "7cfa422a", + "evidence_dir": "docs/release/evidence", + "cells": [ + {"cell": "suite:miner", "cases": ["UX-06"], "status": "PASS", "method": "team-reported", + "evidence": "docs/release/evidence/ux-shipper-2026-10-08.md", + "note": "the fixed miner 7cfa422a on build-1's seed, 20:05:11 to 20:06:11 BST: 49 templates taken in 60 s, no template error, no amount-high-word refusal, no NODE SLOW; MINER SUMMARY 0.006 MH/s (cpu), VOTER votes 20 of 20; lp-4090-11 on the kit from 20:31: zero refusals, 186 blocks accepted in 320 s; the whole fleet's miners on it by 21:48", + "claim_impact": "the miner takes every template the network gives it, including coinbases above a u64"} + ] +} diff --git a/tools/ci/batches/census-v6-chainseed-20261008-2230.json b/tools/ci/batches/census-v6-chainseed-20261008-2230.json new file mode 100644 index 000000000..0366086c9 --- /dev/null +++ b/tools/ci/batches/census-v6-chainseed-20261008-2230.json @@ -0,0 +1,6 @@ +{ + "run_id": "census-v6-chainseed-20261008-2230", + "manifest_sha": "1a938abe4", + "evidence_dir": "docs/analysis/class-v6/rows/chainseed-census-1a938abe4", + "cells": [ { "cell": "census:class-v6", "status": "PASS", "method": "native", "evidence": "docs/analysis/class-v6/rows/chainseed-census-1a938abe4.md" } ] +} diff --git a/tools/ci/batches/census-v6-live-20261008-2210.json b/tools/ci/batches/census-v6-live-20261008-2210.json new file mode 100644 index 000000000..e82061b42 --- /dev/null +++ b/tools/ci/batches/census-v6-live-20261008-2210.json @@ -0,0 +1,13 @@ +{ + "run_id": "census-v6-live-20261008-2210", + "manifest_sha": "1a938abe4", + "evidence_dir": "docs/analysis/class-v6/rows/live-dataset-census-1a938abe4", + "cells": [ + { + "cell": "census:class-v6", + "status": "PASS", + "evidence": "docs/analysis/class-v6/rows/live-dataset-census-1a938abe4.md", + "method": "native" + } + ] +} \ No newline at end of file diff --git a/tools/ci/batches/enforced-proving-20261008-02.json b/tools/ci/batches/enforced-proving-20261008-02.json new file mode 100644 index 000000000..837429187 --- /dev/null +++ b/tools/ci/batches/enforced-proving-20261008-02.json @@ -0,0 +1,17 @@ +{ + "run_id": "enforced-proving-20261008-02", + "manifest_sha": "3f672661", + "evidence_dir": "docs/plans/proving-enforcement", + "boxes": [ + "build-8" + ], + "method": "native", + "cells": [ + { + "cell": "harness:proving-enforcement", + "status": "PASS", + "evidence": "docs/plans/proving-enforcement/succession-360-window-300-vcache-7.json" + } + ], + "note": "Key succession across a boundary on the review B F01/F02 fix node 3f672661 (harness-unsafe build, both pairs embedded): six refusals on the right ground (below H the next pair on its pair and the prior on its statement; in the window both on their statements, none on a pair; after H+W the prior on its pair and the next on its statement), nothing paid; 21:34 to 22:04 UK, floor 360, window 300, two records per phase." +} \ No newline at end of file diff --git a/tools/ci/batches/f03-manifest-20261008-01.json b/tools/ci/batches/f03-manifest-20261008-01.json new file mode 100644 index 000000000..d8910cdcc --- /dev/null +++ b/tools/ci/batches/f03-manifest-20261008-01.json @@ -0,0 +1,39 @@ +{ + "run_id": "f03-manifest-20261008-01", + "manifest_sha": "c30ab32c", + "method": "static", + "evidence_dir": "build-1:/srv/artefacts/tas/f03-manifest-20261008-01 (build-from-manifest-c30ab32c-build4.log, sha256 6040ded8e99f0871\u2026); the build tree build-4:/srv/builds/igneum-wt-f03-201 at c30ab32c", + "boxes": [ + "build-4" + ], + "release_identity": { + "commit": "c30ab32c", + "lockfile": "the release tree's Cargo.lock files at c30ab32c", + "binary": "cargo check only: no binary is claimed by this cell; the fleet binaries are the shipper's kit on aa0e0f45", + "network_object": "igneum-devnet-4, chain id 4465", + "activation": "none (a build fact)", + "profile_hashes": "release-manifest-check: every component's own pin equals packaging/release-manifest.json" + }, + "claim_impact": "F03's first rung: one manifest, one build, no unpublished vendor tree; the same-work rung (R02) and the transition rung (R03) stay NOT RUN until the readers run on the job context", + "note": "R2-F03-R01, the clean build from one manifest: every component builds from packaging/release-manifest.json on release-2.0.1's final tip c30ab32c with the node vendored at the manifest's sha 7cfa422a as a real checkout (vendor/igneum-node and vendor/igneum-node-exec; a link ships as nothing); the pool builds only from the release tree (its igneum-pow is the class v5 freeze cbc5bd0a, rule 19; master's a65e4c5a refuses it). Earlier runs on aa0e0f45 were red on the pool (KeyReveal.sig_scheme, the pool-review-b shape not yet in the tree) and on prove-host (the exec vendor missing); both closed by the tree, not by the script. The workers are the kit's cross-build (the shipper's kit-isa line), not this build. The build: tools/ci/build-from-manifest.sh --box 4 on release-2.0.1 c30ab32c, 21:11 to 21:14 UK, kaspad with igneum-pow, igneum-miner, igneum-pool, igneum-app and igneum-prove-host all check green from packaging/release-manifest.json, and release-manifest-check reads every component's own pin equal to the manifest; the log on build-1 (sha256 6040ded8e99f0871...). Re-recorded at the guest-format landing (21:5x UK): on master the row read NOT RUN beside its PASS cell through the lifted reason-only record; the recorder now drops that placeholder when a real cell lands.", + "cells": [ + { + "cell": "harness:release-manifest", + "cases": [ + "R2-F03-R01" + ], + "status": "PASS", + "evidence": "build-1:/srv/artefacts/tas/f03-manifest-20261008-01/build-from-manifest-c30ab32c-build4.log; build-4:/srv/builds/igneum-wt-f03-201; tools/ci/build-from-manifest.sh; tools/ci/release-manifest-check.sh" + }, + { + "cell": "check:freeze", + "cases": [ + "GOV-01" + ], + "status": "NOT RUN", + "in_progress": true, + "evidence": "docs/plans/igneum-2.0-f0-manifest.md; build-4:/srv/builds/igneum-wt-f03-201/vendor/igneum-node/packaging/pow-freeze.txt; build-4:/srv/builds/igneum-wt-f03-201", + "note": "GOV-01 moves with its evidence page: the F0 manifest's cut-tip row gained the final tip c30ab32c and the 21:14 UK build-from-manifest fact; the freeze itself is unchanged (class v5 1c420786, fingerprint cbc5bd0a) and GOV-01 stays NOT RUN in progress until the signing block at 23:30" + } + ] +} diff --git a/tools/ci/batches/floor-k-20261008-rows-repeat.json b/tools/ci/batches/floor-k-20261008-rows-repeat.json new file mode 100644 index 000000000..f525f5993 --- /dev/null +++ b/tools/ci/batches/floor-k-20261008-rows-repeat.json @@ -0,0 +1,26 @@ +{ + "run_id": "floor-k-20261008-rows-repeat", + "manifest_sha": "86e5b0fb", + "cut_tip": "class-v6-floor-k 86e5b0fb (the amendment carries shadow-k.md; floor lane 2's rows ADV-05 and ADV-06 move with it on its word, method model, no decision changed; the steward's rows no longer cite the directory since d2e1c192)", + "evidence_dir": "docs/analysis/class-v6/floor/shadow-k.md", + "boxes": [], + "cells": [ + { + "cell": "adversary:mf-placed", + "cases": [ + "ADV-05" + ], + "status": "RUNNING", + "method": "model", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "note": "repeat for ADV-05 at this manifest on floor lane 2's word (placed and routed RTL on ASAP7, a model); the rtl directory tools/chip-model/rtl/ is the flow, cited by its document since the recorder takes files only" + }, + { + "cell": "review:k-lane-shadow-k", + "status": "NOT RUN", + "method": "model", + "evidence": "docs/analysis/class-v6/floor/shadow-k.md", + "note": "repeat of team-2026-10-08 for ADV-06 at this manifest on floor lane 2's word; no decision changed" + } + ] +} diff --git a/tools/ci/batches/hash-lane-20261008-batch3.json b/tools/ci/batches/hash-lane-20261008-batch3.json new file mode 100644 index 000000000..8f1e528be --- /dev/null +++ b/tools/ci/batches/hash-lane-20261008-batch3.json @@ -0,0 +1,19 @@ +{ + "run_id": "hash-lane-20261008-batch3", + "manifest_sha": "1a938abe4", + "evidence_dir": "docs/analysis/class-v6/rows", + "cells": [ + { + "cell": "harness:p01-vectors", + "status": "PASS", + "method": "native", + "evidence": "docs/analysis/class-v6/rows/pairing-20261008.md" + }, + { + "cell": "suite:pow", + "status": "PASS", + "method": "native", + "evidence": "docs/analysis/class-v6/rows/pairing-20261008.md" + } + ] +} diff --git a/tools/ci/batches/incident-u64-coinbase-2026-10-08.json b/tools/ci/batches/incident-u64-coinbase-2026-10-08.json new file mode 100644 index 000000000..4b54c8321 --- /dev/null +++ b/tools/ci/batches/incident-u64-coinbase-2026-10-08.json @@ -0,0 +1,11 @@ +{ + "run_id": "incident-u64-coinbase-2026-10-08", + "manifest_sha": "4cdcc488", + "evidence_dir": "docs/release/evidence", + "cells": [ + {"cell": "suite:miner", "cases": ["UX-06"], "status": "FAIL", "method": "team-reported", + "evidence": "docs/release/evidence/ux-shipper-2026-10-08.md", + "note": "the shipped miner (4cdcc488, ef0f2ed8) refused every block template whose coinbase exceeded a u64 (rpc/core/src/error.rs:131; the base unit installed only for `inspect`); the fleet fell to a two-key branch, 0 blocks per minute at 19:54 BST", + "claim_impact": "no miner could take the work templates the network gave it above 18.4 IGN of merged subsidy"} + ] +} diff --git a/tools/ci/batches/kills-20261008.json b/tools/ci/batches/kills-20261008.json index f2484f46e..153cb4ed3 100644 --- a/tools/ci/batches/kills-20261008.json +++ b/tools/ci/batches/kills-20261008.json @@ -15,5 +15,5 @@ "evidence": "docs/analysis/class-v6/mixed-fp32.md; docs/analysis/class-v6/rows/pow-07-fp32-unreachable.md" } ], - "note": " Evidence narrowed at 21:3x UK from the class-v6 directory to the two experiments' own files (a directory citation bound every file beneath it to these rows and refused every other lane's class-v6 landing); the verdicts are unchanged." + "note": " Evidence narrowed at 21:3x UK from the class-v6 directory to the two experiments' own files (a directory citation bound every file beneath it to these rows and refused every other lane's class-v6 landing); the verdicts are unchanged. Replayed at the rule 33 landing (21:4x UK): the narrowed evidence reaches master's rows only through a replay, and the merge replayed added batches alone until this landing." } diff --git a/tools/ci/batches/kit-class-v6-20261008-01.json b/tools/ci/batches/kit-class-v6-20261008-01.json new file mode 100644 index 000000000..716817aa9 --- /dev/null +++ b/tools/ci/batches/kit-class-v6-20261008-01.json @@ -0,0 +1,17 @@ +{ + "run_id": "kit-class-v6-20261008-01", + "manifest_sha": "ef0f2ed8", + "evidence_dir": "docs/design/class-v5-stored-state.md", + "boxes": [ + "build-1" + ], + "cells": [ + { + "cell": "kit:class-v6-fingerprints", + "status": "RUNNING", + "evidence": "docs/design/class-v5-stored-state.md; build-1:/srv/artefacts/packs/packs-class-v6-20261008T202808Z.zip; build-1:/srv/builds/_log/v5-class/kits-20261008T202808Z/emu-check.log", + "note": "docs/design/class-v5-stored-state.md section 0, the class v6 kit row: the generator 6 packs hl-v6-all 4de7b836cc40a4ea and hl-v6-foldrw d7eba30115d26dd4 read e8f4f3289c6ee1fc and 6ce3dc344a613500 on the CPU emulation check, the CUDA 4090, Metal and Apple OpenCL (20:41 to 20:52 UK); the RTX 5090, RX 7600 and Arc rows the morning's; the kit zip 4 bb66a546 (kernel texts byte-identical to zip 3)" + } + ], + "method": "GPU" +} diff --git a/tools/ci/batches/pool-2.0-20261008-03.json b/tools/ci/batches/pool-2.0-20261008-03.json new file mode 100644 index 000000000..f0fce2d7b --- /dev/null +++ b/tools/ci/batches/pool-2.0-20261008-03.json @@ -0,0 +1,14 @@ +{ + "run_id": "pool-2.0-20261008-03", + "manifest_sha": "986252e73", + "method": "native", + "evidence_dir": "docs/analysis/pool", + "cells": [ + { + "cell": "suite:pool", + "status": "RUNNING", + "method": "native", + "evidence": "docs/analysis/pool/pool-pair-2026-10-08.md" + } + ] +} \ No newline at end of file diff --git a/tools/ci/batches/same-work-20261008-01.json b/tools/ci/batches/same-work-20261008-01.json new file mode 100644 index 000000000..d8db076bb --- /dev/null +++ b/tools/ci/batches/same-work-20261008-01.json @@ -0,0 +1,37 @@ +{ + "run_id": "same-work-20261008-01", + "manifest_sha": "c30ab32c", + "method": "GPU", + "evidence_dir": "build-1:/srv/artefacts/tas/same-work-20261008-01", + "boxes": [ + "build-4 (CPU reference)", + "tas-p01-5090", + "tas-p01-4090", + "tas-p01-3090" + ], + "release_identity": { + "lockfile": "", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", + "profile_hashes": "", + "commit": "c30ab32c; the CPU reference class-v6 1a938abe4; the CUDA reader the kit's gen 6 worker 804a6f7f", + "binary": "igneum-pow sha256 0d3f3fca...; igneum-worker-cuda sha256 804a6f7f...", + "network_object": "the frozen class v6 object: pack hl-v6-all (tgz sha256 9131431015e102f4..., re-exported byte for byte from class-v6 1a938abe4 on build-4 at 21:44 UK, every file's sha256 equal), id 0x4de7b836cc40a4ea, epoch seed edc4fa84... (the genesis seeds) over the node1 state stream" + }, + "claim_impact": "POW-01's CUDA half across a dataset-day switch on the frozen object: CUDA against the CPU reference bit for bit on three ranges with the day switch at nonce 1572864. NOT same-work evidence: the node engine refuses this seed/stream pair (IgneumEngine::epoch_for's class v5 check wants the stream's block af89be5d... to equal the epoch seed edc4fa84...), so the node and pool readers cannot read it; the coordinator's ruling 22:0x UK keeps it as the CUDA and CPU-only row", + "network_label": "on an island, not a network", + "note": "Context 01 at build-1:/srv/artefacts/tas/same-work-20261008-01/job-context.json (sha256 d2540e02...). CPU reference: igneum-pow hash-bound (class-v6 1a938abe4, binary 0d3f3fca...) on build-4, 21:46 to 21:55 UK, ref-D c49fed11... over [0, 1572864), ref-D1 5ae1220d... over [1572864, 3145728); ref-D's first million lines equal the hash lane's P01 reference /srv/artefacts/packs/p01-vectors/hl-v6-all.txt byte for byte. The node1 state stream (block af89be5d...) was written on build-4 at 15:34 UK, before the 20:00 UK split; the cell carries the island label by main's 22:2x UK rule. CUDA: runs after context 02 on the three pods (the fleet lane's runner), evidence cuda--.json beside the context; in progress at the time of this record.", + "cells": [ + { + "cell": "harness:p01-vectors", + "cases": [ + "POW-01" + ], + "status": "NOT RUN", + "method": "GPU", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-01/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-01/references/ref-D1.txt", + "note": "the CUDA reads on the frozen object across the day switch are running after context 02; CPU reference written and cross-checked against the hash lane's P01 file; in progress", + "network_label": "on an island, not a network", + "in_progress": true + } + ] +} \ No newline at end of file diff --git a/tools/ci/batches/same-work-20261008-02.json b/tools/ci/batches/same-work-20261008-02.json new file mode 100644 index 000000000..08a8dcc0d --- /dev/null +++ b/tools/ci/batches/same-work-20261008-02.json @@ -0,0 +1,50 @@ +{ + "run_id": "same-work-20261008-02", + "manifest_sha": "c30ab32c", + "method": "GPU", + "evidence_dir": "build-1:/srv/artefacts/tas/same-work-20261008-02", + "boxes": [ + "build-4 (CPU reference, pool D1 pairing)", + "build-2 (node reader)", + "tas-p01-5090", + "tas-p01-4090", + "tas-p01-3090" + ], + "release_identity": { + "lockfile": "", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", + "profile_hashes": "", + "commit": "c30ab32c (packaging/release-manifest.json on release-2.0.1; node 7cfa422a); the readers: node same-work-node cc23f9bd (igneum-node, off class-v6-node-review e8773ff5, paired with class-v6 1a938abe4), CPU reference class-v6 1a938abe4, CUDA the kit's gen 6 worker 804a6f7f, pool pool-recheck-202 00c7e1db over class-v6-node-review e8773ff5", + "binary": "igneum-miner recheck-vectors sha256 9d563c41...; igneum-pow sha256 0d3f3fca...; igneum-worker-cuda sha256 804a6f7f...; igneum-pool sha256 b9fb3a60... (D1 pairing) and 2f6378e4... (kit)", + "network_object": "the chain-seed class v6 object: epoch seed af89be5d... (the node1 state stream's block 159357, root 1c583d35..., stream sha256 abb58003...) with the genesis era seed edc4fa84..., generator 6, id 0x2a1d6caab4c24564 (the hash lane's 22:00 UK ruling; their independent export hl-v6-all-cs a4742bfe... equals packs/chain-seed-d20730 file by file)" + }, + "claim_impact": "R2-F03-R02 and R03 on one job context (the chain-seed class v6 object) across the readers that can run it tonight: node, CPU reference, CUDA and pool on three phases with the dataset-day switch at nonce 1572864; PASS only when every reader agrees bit for bit on every nonce; Metal and OpenCL are the morning's", + "network_label": "on an island, not a network", + "note": "The same-work run (the coordinator's ruling 22:0x UK: six readers on one context; the frozen-object context 01 is the CUDA and CPU-only row). The node1 state stream (block af89be5d..., written on build-4 at 15:34 UK, before the 20:00 UK split) keys every item; every cell carries the island label by main's 22:2x UK rule. Day D = 20730 (bytes ...2ffa50), D+1 = 20731 (...2ffb50); phase 2 switches at 1572864 (the midpoint, 32-aligned); genesis day index 20730 and dataset 2^28 words for the engine's growth rule (doublings 0 on both days). CPU reference: igneum-pow hash-bound (class-v6 1a938abe4, binary 0d3f3fca...) on build-4, 21:48 to 21:57 UK, ref-D 7c7be9b5... over [0, 1572864), ref-D1 cad7849f... over [1572864, 3145728); the hash lane's independent million-nonce reference hl-v6-all-cs.txt (b77c61d8..., 22:03 UK) equals ref-D's first million lines byte for byte. Node reader: PASS on all three phases (22:17, 22:21, 22:25 UK; 1,048,576 agree each, 0 disagree, 0 missing; the boundary switched: d28fcfd70ba70a64 before, 45905ff3d608dc12 after, both equal to the reference; the program id unchanged across the day). Reader faults recorded, not disagreements: the node reader's first phase 1 at 22:10 UK read FAIL on every nonce with the program id equal because the standalone engine held the genesis day at 0 and the growth rule doubled the cache fourteen times (fixed at cc23f9bd: install_pow_genesis from the context and the pack, the live miner's own call); the pool lane's D1-pairing run at 22:17 UK hit the same class (its nonce 0 and 1 hashes equal the pre-fix node hashes byte for byte), fix sent 22:18 UK, rerun pending. The pool on the 2.0.2 kit as pinned (release-2.0.2 00c7e1db, node 7cfa422a) is BLOCKED: its node's ProgramClass enum ends at V5, so a class=v6 job line is unnameable (pool/kit-row/pool-{1,2,3}.json carry that refusal in the driver's shape). CUDA: the 5090's phase 1 PASS at 22:00 and 22:24 UK (gen 6 worker 804a6f7f, 47.6 s); phases 2 and 3 running at the time of this record (the fleet lane's runner restarted at 22:22 UK for the three-context file; its stray phase 2 and 3 lines at 22:23 were the restart's artefact, overwritten by the clean sequence). Rule 24 on same-work-node cc23f9bd on build-2: crate check rc 0, igneum-miner suite 30 passed 0 failed.", + "cells": [ + { + "cell": "harness:same-work", + "cases": [ + "R2-F03-R02" + ], + "status": "NOT RUN", + "method": "GPU", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-1.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-2.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-3.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node.log; build-1:/srv/artefacts/tas/same-work-20261008-02/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-02/references/ref-D1.txt; build-1:/srv/artefacts/tas/same-work-20261008-02/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/pool-1.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/pool-2.json; build-1:/srv/artefacts/tas/same-work-20261008-02/pool/kit-row/pool-3.json", + "note": "node PASS x3, CPU reference written and cross-checked, CUDA 5090 phase 1 PASS and phases 2 and 3 running, pool D1 pairing rerun pending after the install fix, pool kit row BLOCKED by its V5 pins, Metal and OpenCL NOT RUN until the morning (Metal 08:30 UK on the mini, OpenCL 08:30 UK on PC 1); the case stays NOT RUN in progress until every reader has read", + "network_label": "on an island, not a network", + "in_progress": true + }, + { + "cell": "harness:same-work", + "cases": [ + "R2-F03-R03" + ], + "status": "NOT RUN", + "method": "GPU", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-1.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-2.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node-3.json; build-1:/srv/artefacts/tas/same-work-20261008-02/node/node.log; build-1:/srv/artefacts/tas/same-work-20261008-02/references/ref-D.txt; build-1:/srv/artefacts/tas/same-work-20261008-02/references/ref-D1.txt; build-1:/srv/artefacts/tas/same-work-20261008-02/job-context.json", + "note": "the dataset-day transition in phase 2: the node reader switched program and dataset at nonce 1572864 with the program id unchanged and both boundary hashes equal to the reference; the CUDA and pool phase 2 reads are pending; in progress", + "network_label": "on an island, not a network", + "in_progress": true + } + ] +} \ No newline at end of file diff --git a/tools/ci/batches/same-work-20261008-03.json b/tools/ci/batches/same-work-20261008-03.json new file mode 100644 index 000000000..407664c63 --- /dev/null +++ b/tools/ci/batches/same-work-20261008-03.json @@ -0,0 +1,50 @@ +{ + "run_id": "same-work-20261008-03", + "manifest_sha": "c30ab32c", + "method": "GPU", + "evidence_dir": "build-1:/srv/artefacts/tas/same-work-20261008-03", + "boxes": [ + "build-4 (CPU reference)", + "build-2 (program-id witness)", + "tas-p01-5090", + "tas-p01-4090", + "tas-p01-3090" + ], + "release_identity": { + "lockfile": "", + "activation": "none (a re-check of hashes against one job context, no chain state changes)", + "profile_hashes": "", + "commit": "c30ab32c (release-2.0.1; the class v5 freeze 1c420786, fingerprint cbc5bd0a); the CUDA reader the kit's gen 5 worker 9bfcf728", + "binary": "igneum-pow sha256 7ba781db... (release-2.0.1 c30ab32c, built on build-4); igneum-worker-cuda gen 5 sha256 9bfcf728...", + "network_object": "igneum-devnet-4's class v5 object at epoch 2: id 0x81fbfa3aa413173f, epoch seed 3c3fab43... (the epoch-2 seed block, chain block 3423, common to every chain tonight: the split came after it), day 20734, era 0 seed 7c36b833... (class v5 reads no era; the id is the same under era zero), state stream state-epoch2.igsd1 (sha256 f36e6bba..., 21,132 bytes, 224 records, root 0xf798d1d8...) pulled at 22:18 UK from build-1's seed EVM RPC 27810" + }, + "claim_impact": "the same-work test's live-chain half (the coordinator's third row, 22:1x UK): the readers on the chain's own class v5 object at epoch 2 across the day switch 20734 to 20735; the node and pool readers run it on their release-line engines, the row those two can PASS without the class v6 branch", + "network_label": "on an island, not a network", + "note": "On an island, not a network: build-1's seed is one of devnet-4's islands since the epoch-3 cut (21:34 UK), its stream pulled at 22:18 UK; epoch 2's object predates the split. Context 03 at build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json (sha256 53837a96...). The witness for the id: igneum-miner program-id reads class v5 attempt 0 id 81fbfa3aa413173f under era 7c36b833... and era 00..00 alike, from the miner at same-work-node cc23f9bd on build-2 (the class v5 engine path; the 2.0.1 pair's miner ef0f2ed8 on build-1 has no program-id subcommand), and the node lane's placed (c) read gave the same id; the hand's RPC 26870 answered no published state stream for the block at 22:18 UK. Packs v5-epoch2-d20734 and d20735 (both id 0x81fbfa3aa413173f) exported from release-2.0.1's igneum-pow on build-4 at 22:19 UK; the CPU references run on build-4 under watchers from 22:20 UK (about 300 nonces a second a run); CUDA follows on the pods after contexts 02 and 01. Node and pool: the recheck subcommand is not on a release-line branch tonight, so those cells read NOT RUN with the 08:30 UK clock as the coordinator set; a labelled extra row from cc23f9bd's miner runs beside them when the references land.", + "cells": [ + { + "cell": "harness:same-work", + "cases": [ + "R2-F03-R02" + ], + "status": "NOT RUN", + "method": "GPU", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json; build-1:/srv/artefacts/tas/same-work-20261008-03/state-epoch2.igsd1", + "note": "CPU reference running (about 23:45 UK), CUDA after it, node and pool NOT RUN with the 08:30 UK clock on the release lines; in progress", + "network_label": "on an island, not a network", + "in_progress": true + }, + { + "cell": "harness:same-work", + "cases": [ + "R2-F03-R03" + ], + "status": "NOT RUN", + "method": "GPU", + "evidence": "build-1:/srv/artefacts/tas/same-work-20261008-03/job-context.json", + "note": "the day switch 20734 to 20735 at nonce 1572864 on the live object; readers pending; in progress", + "network_label": "on an island, not a network", + "in_progress": true + } + ] +} \ No newline at end of file diff --git a/tools/ci/batches/site-manifest-20261008-01.json b/tools/ci/batches/site-manifest-20261008-01.json index 8c55d248e..d26b41804 100644 --- a/tools/ci/batches/site-manifest-20261008-01.json +++ b/tools/ci/batches/site-manifest-20261008-01.json @@ -3,6 +3,17 @@ "manifest_sha": "3f1a3f332", "evidence_dir": "site", "cells": [ - {"cell": "site:manifest", "cases": ["OPS-03"], "status": "NOT RUN", "in_progress": true, "method": "static", "evidence": "site/release-manifest.json at the landing sha", "note": "the manifest regenerated from the dl index (the 2.0.1 Mac and HiveOS entries, 8 October 2026 20:16 and 20:25 UK) and the node's start line; read back at /release.json after the deploy", "claim_impact": "the versions block on /release.json, /download and /miner; no claim moves"} + { + "cell": "site:manifest", + "cases": [ + "OPS-03" + ], + "status": "NOT RUN", + "in_progress": true, + "method": "static", + "evidence": "site/release-manifest.json", + "note": "the manifest regenerated from the dl index (the 2.0.1 entries on every platform: Mac 20:16, HiveOS 20:25, Windows 20:56 UK, 8 October 2026; 2.0.0 withdrawn) and the node's start line; read back at /release.json after the deploy", + "claim_impact": "the versions block on /release.json, /download and /miner; no claim moves" + } ] } diff --git a/tools/ci/batches/ux-01-20261008-win-2.0.0.json b/tools/ci/batches/ux-01-20261008-win-2.0.0.json new file mode 100644 index 000000000..32acdab3d --- /dev/null +++ b/tools/ci/batches/ux-01-20261008-win-2.0.0.json @@ -0,0 +1,14 @@ +{ + "run_id": "ux-01-20261008-win-2.0.0", + "manifest_sha": "aa354ed5", + "evidence_dir": "docs/plans/evidence/UX-01-20261008.md", + "cells": [ + { + "cell": "pc:install-update", + "status": "RUNNING", + "evidence": "docs/plans/evidence/UX-01-20261008.md", + "method": "team-reported" + } + ], + "method": "team-reported" +} diff --git a/tools/ci/build-from-manifest.sh b/tools/ci/build-from-manifest.sh new file mode 100755 index 000000000..41c27259e --- /dev/null +++ b/tools/ci/build-from-manifest.sh @@ -0,0 +1,33 @@ +#!/usr/bin/env bash +# F03 (Review B): every component is built from the one release manifest. Reads packaging/release-manifest.json of this tree, +# puts the node fork at the manifest's node sha under vendor/igneum-node (the pool's path dependency, so the EpochSeeds seam closes +# by a build against the pinned node), then on a box at gate priority (tools/build-remote.sh): cargo check of kaspad with the +# igneum-pow feature (rule 19 proves the generator's fingerprint at build time), igneum-miner, the pool crate (igneum-pool), the app +# crate (igneum-app) and the prove host; then tools/ci/release-manifest-check.sh over the tree and the fork. One red = exit 1. +# tools/ci/build-from-manifest.sh [--box N] [--dry] from the release branch's worktree; --dry prints the plan +set -euo pipefail +ROOT=$(git rev-parse --show-toplevel); cd "$ROOT"; BOX=""; DRY=0 +while [ $# -gt 0 ]; do case "$1" in --box) BOX="$2"; shift 2 ;; --dry) DRY=1; shift ;; *) echo "unknown $1" >&2; exit 2 ;; esac; done +M=packaging/release-manifest.json; [ -f "$M" ] || { echo "build-from-manifest: no $M on this tree" >&2; exit 2; } +NODE=$(python3 -c "import json;print(json.load(open('$M'))['node']['sha'])"); FP=$(python3 -c "import json;print(json.load(open('$M'))['generator']['fingerprint'])") +echo "build-from-manifest: node $NODE, generator fingerprint ${FP:0:16}, miner app $(git rev-parse --short HEAD)" +FORK=vendor/igneum-node; MIRROR="${IGNEUM_NODE_MIRROR:-build@188.40.146.49:/srv/igneum-node.git}" +if [ "$DRY" = 1 ]; then echo "plan: $FORK at $NODE from $MIRROR; cargo check kaspad(+igneum-pow), igneum-miner, igneum-pool, igneum-app, igneum-prove-host on box ${BOX:-auto} at gate priority; then release-manifest-check.sh $FORK"; exit 0; fi +if [ -d "$FORK/.git" ] || [ -f "$FORK/.git" ]; then git -C "$FORK" fetch -q "$MIRROR" "$NODE" 2>/dev/null || git -C "$FORK" fetch -q "$MIRROR" release-2.0.0-node; git -C "$FORK" checkout -q --detach "$NODE" +else mkdir -p vendor && git clone -q "$MIRROR" "$FORK" && git -C "$FORK" checkout -q --detach "$NODE"; fi +# the proving workspace names the same fork vendor/igneum-node-exec (proving/igneum-prove/Cargo.toml): a second checkout at the same +# sha, never a link (build-remote ships directories as overlays to the box; a link ships as nothing) +if [ -L vendor/igneum-node-exec ]; then rm -f vendor/igneum-node-exec; fi +if [ -d vendor/igneum-node-exec/.git ] || [ -f vendor/igneum-node-exec/.git ]; then git -C vendor/igneum-node-exec fetch -q "$MIRROR" "$NODE" 2>/dev/null || true; git -C vendor/igneum-node-exec checkout -q --detach "$NODE" +else git -C "$FORK" worktree add -q --detach "$ROOT/vendor/igneum-node-exec" "$NODE" 2>/dev/null || git clone -q "$MIRROR" vendor/igneum-node-exec && git -C vendor/igneum-node-exec checkout -q --detach "$NODE"; fi +echo "build-from-manifest: $FORK at $(git -C "$FORK" rev-parse --short HEAD); vendor/igneum-node-exec at $(git -C vendor/igneum-node-exec rev-parse --short HEAD)" +run() { local name="$1" dir="$2"; shift 2; echo "build-from-manifest: $name"; ( cd "$dir" && IGNEUM_AGENT=f03 bash "$ROOT/tools/build-remote.sh" ${BOX:+--box "$BOX"} --no-fetch --priority gate -- "$@" ) > "/tmp/f03-$name.log" 2>&1 || { echo "build-from-manifest: RED: $name (see /tmp/f03-$name.log)" >&2; grep -m3 -E '^error|RED|panicked' "/tmp/f03-$name.log" | cut -c1-160 >&2; return 1; }; echo "build-from-manifest: $name ok"; } +rc=0 +run kaspad "$FORK" check --release -p kaspad --features kaspad/igneum-pow || rc=1 +run igneum-miner "$FORK" check --release -p igneum-miner || rc=1 +run igneum-pool pool check --release || rc=1 +run igneum-app app/igneum-app check --release || rc=1 +run prove-host proving/igneum-prove check --release -p igneum-prove-host || rc=1 +bash tools/ci/release-manifest-check.sh "$FORK" || rc=1 +[ "$rc" = 0 ] && echo "build-from-manifest: every component builds from the manifest and every pin agrees" +exit $rc diff --git a/tools/ci/canary-check.sh b/tools/ci/canary-check.sh new file mode 100755 index 000000000..85d315279 --- /dev/null +++ b/tools/ci/canary-check.sh @@ -0,0 +1,174 @@ +#!/usr/bin/env bash +# Rule 33 (the founder's "no more lost time", 8 October 2026, 21:3x UK): a release entry may not publish without a +# fresh-install canary record for its sha. The record is one JSON file in the tree, tools/ci/canary/.json (the +# release tip's commit, 8 to 40 hex), written by the lane that ran the canary, with the eight lines the founder named, +# each read back with its evidence path on a box (build-N:/srv/... or /srv/...). This check reads the record and says +# PASS or names the first line that is missing or failing; the publish path (packaging/ota/publish-manifest.sh, +# packaging/ota/publish-public.sh, deploy-win.sh) refuses an entry whose sha has no PASS record. +# +# tools/ci/canary-check.sh [--artefact ] exit 0: PASS (the line printed); 1: no record or a line fails (named); 2: bad args +# a record holds one artefact block at the top level, or an "artefacts" list (one block per entry's artefact: +# kind fleet | windows | mac | hive, each from its own non-AVX-512 box with its own eight lines); --artefact asks +# for that kind's block, so a Mac entry publishes on the Mac canary and the Windows entry waits for its own +# tools/ci/canary-check.sh --form prints the record form (every field, with what it must hold) +# tools/ci/canary-check.sh --self-test +# +# The record (tools/ci/canary/.json): +# sha the release tip's commit (the file name's sha, full or 8+) +# artefact {url or path, sha256}: what was installed, the published artefact itself, not a box's native build +# box {host, isa_line}: a non-AVX-512 box; isa_line is the kit-isa clean line read on it (tools/ci/kit-isa-check.sh) +# or the host's cpu flags line showing no avx512 +# datadir {path, empty_at_start: true, read_back}: the empty datadir before the install +# sync {genesis_height: 0, tip_height, seconds, read_back}: genesis to the network's tip +# mining {minutes >= 5, refusals: 0, accepted_blocks >= 1, read_back} +# shard {claimed: true, proved: true, paid_or_queued: "paid" | "queued", read_back} +# quit {bounded: true, seconds, read_back}: the process ends on its own quit inside the bound +# lines_read_back a list of the eight line names, each with an evidence path on a box +# verdict "PASS" (anything else is not a canary record for publishing) +# recorded_at, recorded_by UTC stamp, the lane +set -euo pipefail +HERE="$(cd "$(dirname "$0")" && pwd -P)"; ME="$HERE/$(basename "$0")"; ROOT="${CANARY_ROOT:-$(cd "$HERE/../.." && pwd -P)}" +DIR="${CANARY_DIR:-$ROOT/tools/ci/canary}" + +form() { + cat <<'EOF' +{ + "sha": "", + "artefact": {"url": "https://dl.igneum.network/public/", "sha256": "<64 hex>"}, + "box": {"host": "build-N or ", "isa_line": "kit-isa: clean ... | cpu flags: no avx512"}, + "datadir": {"path": "/srv/canary//data", "empty_at_start": true, "read_back": "build-N:/srv/canary//01-datadir.txt"}, + "sync": {"genesis_height": 0, "tip_height": 0, "seconds": 0, "read_back": "build-N:/srv/canary//02-sync.txt"}, + "mining": {"minutes": 5, "refusals": 0, "accepted_blocks": 1, "read_back": "build-N:/srv/canary//03-mining.txt"}, + "shard": {"claimed": true, "proved": true, "paid_or_queued": "paid", "read_back": "build-N:/srv/canary//04-shard.txt"}, + "quit": {"bounded": true, "seconds": 0, "read_back": "build-N:/srv/canary//05-quit.txt"}, + "lines_read_back": [ + {"line": "install", "evidence": "build-N:/srv/canary//00-install.txt"}, + {"line": "box", "evidence": "build-N:/srv/canary//00-box.txt"}, + {"line": "datadir", "evidence": "build-N:/srv/canary//01-datadir.txt"}, + {"line": "sync", "evidence": "build-N:/srv/canary//02-sync.txt"}, + {"line": "mining", "evidence": "build-N:/srv/canary//03-mining.txt"}, + {"line": "shard", "evidence": "build-N:/srv/canary//04-shard.txt"}, + {"line": "quit", "evidence": "build-N:/srv/canary//05-quit.txt"}, + {"line": "version", "evidence": "build-N:/srv/canary//00-version.txt"} + ], + "verdict": "PASS", + "recorded_at": "", + "recorded_by": "" +} +EOF +} + +check() { # [kind] -> prints the verdict line; 0 pass, 1 fail + local sha="$1" kind="${2:-}" f + case "$sha" in *[!0-9a-fA-F]*|"") echo "canary: REFUSED: '$sha' is not a commit sha"; return 1 ;; esac + [ "${#sha}" -ge 8 ] || { echo "canary: REFUSED: the sha must be 8 hex or more"; return 1; } + f=""; for c in "$DIR/$sha.json" "$DIR"/"${sha:0:8}"*.json; do [ -f "$c" ] && { f="$c"; break; }; done + [ -n "$f" ] || { echo "canary: REFUSED: no fresh-install canary record for ${sha:0:12} (rule 33: tools/ci/canary/.json, the eight lines read back; tools/ci/canary-check.sh --form)"; return 1; } + python3 - "$f" "$sha" "$kind" <<'PY' +import json, sys +f, sha = sys.argv[1], sys.argv[2].lower() +try: r = json.load(open(f)) +except Exception as e: print(f"canary: REFUSED: {f} is not JSON: {e}"); sys.exit(1) +def red(m): print(f"canary: REFUSED: {sha[:12]}: {m} ({f})"); sys.exit(1) +def need(obj, key, typ=None): + if key not in obj: red(f"the record has no '{key}'") + v = obj[key] + if typ and not isinstance(v, typ): red(f"'{key}' is not {typ.__name__ if not isinstance(typ, tuple) else '/'.join(t.__name__ for t in typ)}") + return v +rs = str(need(r, 'sha')).lower() +if not (rs.startswith(sha) or sha.startswith(rs)) or len(rs) < 8: red(f"the record's sha {rs[:12]} is not {sha[:12]}") +def box_path(p): return isinstance(p, str) and (':/' in p or p.startswith('/srv/')) +want_kind = sys.argv[3] if len(sys.argv) > 3 else '' +blocks = r['artefacts'] if isinstance(r.get('artefacts'), list) else [r] +if not blocks: red('the artefacts list is empty') +if want_kind: + blocks = [b for b in blocks if str(b.get('kind', b.get('artefact', {}).get('kind', ''))).lower() == want_kind.lower()] + if not blocks: red(f"no artefact block of kind '{want_kind}' (the entry's own canary: fleet, windows, mac or hive, each from its own box)") +lines_out = [] +for r_ in blocks: + r = r_ + a = need(r, 'artefact', dict) + if not (a.get('url') or a.get('path')): red("artefact names no url or path (the published artefact, not a native build)") + if not (isinstance(a.get('sha256'), str) and len(a['sha256']) == 64): red("artefact.sha256 is not 64 hex") + b = need(r, 'box', dict) + if not b.get('host'): red("box.host is empty") + isa = str(b.get('isa_line', '')).lower() + if not isa or ('clean' not in isa and 'no avx512' not in isa and 'no avx-512' not in isa): red("box.isa_line does not read a non-AVX-512 box (the kit-isa clean line or a cpu flags line with no avx512)") + d = need(r, 'datadir', dict) + if d.get('empty_at_start') is not True: red("datadir.empty_at_start is not true") + if not box_path(d.get('read_back')): red("datadir.read_back is not a box path") + s = need(r, 'sync', dict) + if s.get('genesis_height') != 0: red("sync.genesis_height is not 0 (the sync starts at genesis)") + if not (isinstance(s.get('tip_height'), int) and s['tip_height'] > 0): red("sync.tip_height is not a positive height") + if not box_path(s.get('read_back')): red("sync.read_back is not a box path") + m = need(r, 'mining', dict) + if not (isinstance(m.get('minutes'), (int, float)) and m['minutes'] >= 5): red("mining.minutes is under 5") + if m.get('refusals') != 0: red(f"mining.refusals is {m.get('refusals')!r}, not 0") + if not (isinstance(m.get('accepted_blocks'), int) and m['accepted_blocks'] >= 1): red("mining.accepted_blocks is under 1") + if not box_path(m.get('read_back')): red("mining.read_back is not a box path") + h = need(r, 'shard', dict) + if h.get('claimed') is not True or h.get('proved') is not True: red("shard.claimed and shard.proved must both be true") + if h.get('paid_or_queued') not in ('paid', 'queued'): red("shard.paid_or_queued must be 'paid' or 'queued'") + if not box_path(h.get('read_back')): red("shard.read_back is not a box path") + q = need(r, 'quit', dict) + if q.get('bounded') is not True: red("quit.bounded is not true") + if not (isinstance(q.get('seconds'), (int, float)) and q['seconds'] >= 0): red("quit.seconds is not a number") + if not box_path(q.get('read_back')): red("quit.read_back is not a box path") + lines = need(r, 'lines_read_back', list) + names = {str(x.get('line')) for x in lines if isinstance(x, dict)} + want = {'install', 'box', 'datadir', 'sync', 'mining', 'shard', 'quit', 'version'} + missing = sorted(want - names) + if missing: red(f"lines_read_back lacks {', '.join(missing)}") + for x in lines: + if isinstance(x, dict) and x.get('line') in want and not box_path(x.get('evidence')): red(f"line {x.get('line')} has no box evidence path") + top = json.load(open(f)) + v = r.get('verdict', top.get('verdict')) + if v != 'PASS': red(f"verdict is {v!r}, not PASS") + if not (r.get('recorded_at') or top.get('recorded_at')) or not (r.get('recorded_by') or top.get('recorded_by')): red("recorded_at or recorded_by is empty") + lines_out.append(f"{r.get('kind', 'artefact')} on {b['host']} ({str(a.get('sha256'))[:12]}…): genesis to {s['tip_height']} in {s.get('seconds')} s, {m['minutes']} min mining, 0 refusals, {m['accepted_blocks']} accepted, one shard {h['paid_or_queued']}, quit in {q['seconds']} s; eight lines read back") +print(f"canary: PASS: {sha[:12]} fresh-install canary: " + '; '.join(lines_out) + f"; recorded {blocks[0].get('recorded_at') or json.load(open(f)).get('recorded_at')} by {blocks[0].get('recorded_by') or json.load(open(f)).get('recorded_by')}") +PY +} + +if [ "${1:-}" = --form ]; then form; exit 0; fi +if [ "${1:-}" = --self-test ]; then + d=$(mktemp -d); trap 'rm -rf "$d"' EXIT; fails=0; export CANARY_DIR="$d" + SHA=0123456789abcdef0123456789abcdef01234567 + form | python3 -c " +import json,sys; r=json.load(sys.stdin); r['sha']='$SHA'; r['artefact']['sha256']='ab'*32; r['box']={'host':'build-4','isa_line':'kit-isa: clean: no AVX-512 encoding in 3 binaries'} +r['sync'].update(tip_height=3847, seconds=412); r['mining'].update(minutes=5, refusals=0, accepted_blocks=2); r['quit']['seconds']=3; r['recorded_at']='2026-10-08T21:30:00Z'; r['recorded_by']='shipper' +json.dump(r, open('$d/$SHA.json','w'))" + bash "$ME" "$SHA" >/dev/null 2>&1 || { echo "self-test failed: a complete PASS record was refused: $(bash "$ME" "$SHA" 2>&1)"; fails=1; } + bash "$ME" "${SHA:0:12}" >/dev/null 2>&1 || { echo "self-test failed: the record was not found by its short sha"; fails=1; } + out=$(bash "$ME" ffffffffffff 2>&1) && { echo "self-test failed: a sha with no record passed"; fails=1; }; case "$out" in *"no fresh-install canary record"*) ;; *) echo "self-test failed: the missing record was not named: $out"; fails=1 ;; esac + mut() { python3 -c " +import json,sys; p='$d/$SHA.json'; r=json.load(open(p)); exec(sys.argv[1]); json.dump(r, open(p,'w'))" "$1"; } + for case in "r['mining']['refusals']=1|refusals" "r['mining']['minutes']=4|under 5" "r['mining']['accepted_blocks']=0|accepted_blocks" "r['shard']['proved']=False|shard.claimed and shard.proved" "r['shard']['paid_or_queued']='lost'|paid_or_queued" "r['quit']['bounded']=False|quit.bounded" "r['datadir']['empty_at_start']=False|empty_at_start" "r['sync']['genesis_height']=100|genesis" "r['box']['isa_line']='avx512f present'|non-AVX-512" "r['lines_read_back']=r['lines_read_back'][:7]|lacks version" "r['lines_read_back'][2]['evidence']='notes.txt'|no box evidence" "r['verdict']='FAIL'|not PASS" "r['artefact']={'url':'x','sha256':'short'}|sha256"; do + cp "$d/$SHA.json" "$d/keep.json"; mut "${case%%|*}" + out=$(bash "$ME" "$SHA" 2>&1) && { echo "self-test failed: a record with ${case%%|*} passed"; fails=1; } + case "$out" in *"${case##*|}"*) ;; *) echo "self-test failed: the failing line was not named for ${case%%|*}: $out"; fails=1 ;; esac + cp "$d/keep.json" "$d/$SHA.json" + done + # the multi-artefact form: one file per sha, an artefacts list (fleet, windows, mac), each block its own box and eight lines; --artefact picks one + python3 -c " +import json; p='$d/$SHA.json'; r=json.load(open(p)); blk={k:r[k] for k in ('artefact','box','datadir','sync','mining','shard','quit','lines_read_back')} +import copy; arts=[] +for kind,host in (('fleet','lp-4090-11'),('windows','pc-2'),('mac','mini')): + b=copy.deepcopy(blk); b['kind']=kind; b['box']['host']=host; b['artefact']['url']='https://dl.igneum.network/public/'+kind; arts.append(b) +m={'sha':r['sha'],'artefacts':arts,'verdict':'PASS','recorded_at':r['recorded_at'],'recorded_by':'shipper'}; json.dump(m, open(p,'w'))" + bash "$ME" "$SHA" >/dev/null 2>&1 || { echo "self-test failed: a three-artefact record was refused: $(bash "$ME" "$SHA" 2>&1)"; fails=1; } + bash "$ME" "$SHA" --artefact mac >/dev/null 2>&1 || { echo "self-test failed: the mac block of a three-artefact record was refused"; fails=1; } + out=$(bash "$ME" "$SHA" --artefact hive 2>&1) && { echo "self-test failed: a kind with no block passed"; fails=1; }; case "$out" in *"no artefact block of kind 'hive'"*) ;; *) echo "self-test failed: the missing kind was not named: $out"; fails=1 ;; esac + python3 -c "import json; p='$d/$SHA.json'; r=json.load(open(p)); r['artefacts'][1]['mining']['refusals']=2; json.dump(r, open(p,'w'))" + out=$(bash "$ME" "$SHA" --artefact windows 2>&1) && { echo "self-test failed: a failing windows block passed under --artefact windows"; fails=1; } + bash "$ME" "$SHA" --artefact mac >/dev/null 2>&1 || { echo "self-test failed: the mac block was refused because the windows block fails (each entry publishes on its own canary)"; fails=1; } + out=$(bash "$ME" "$SHA" 2>&1) && { echo "self-test failed: the whole record passed with one failing block"; fails=1; } + echo "not json" > "$d/$SHA.json"; bash "$ME" "$SHA" >/dev/null 2>&1 && { echo "self-test failed: a non-JSON record passed"; fails=1; } + out=$(bash "$ME" "not-a-sha" 2>&1) && { echo "self-test failed: a non-sha argument passed"; fails=1; } + [ "$fails" = 0 ] && echo "self-test passed: a complete fresh-install canary record is PASS and found by its short sha; no record, a refusal, under five minutes, no accepted block, an unproved or lost shard, an unbounded quit, a non-empty datadir, a sync not from genesis, an AVX-512 box, a missing read-back line, a non-box evidence path, a non-PASS verdict or a bad artefact hash is refused and named; a one-file-per-sha record with an artefacts list (fleet, windows, mac, hive) passes whole or per --artefact kind, and a failing block fails its own kind and the whole, never another kind" + exit $fails +fi +KIND=""; SHA_ARG="" +while [ $# -gt 0 ]; do case "$1" in --artefact) KIND="$2"; shift 2 ;; *) SHA_ARG="$1"; shift ;; esac; done +[ -n "$SHA_ARG" ] || { echo "usage: $0 [--artefact ] | --form | --self-test" >&2; exit 2; } +check "$SHA_ARG" "$KIND" diff --git a/tools/ci/canary/README.md b/tools/ci/canary/README.md new file mode 100644 index 000000000..e211aa835 --- /dev/null +++ b/tools/ci/canary/README.md @@ -0,0 +1 @@ +# Rule 33 fresh-install canary records, one per release tip sha (tools/ci/canary-check.sh --form; the publish path refuses an entry without a PASS record here) diff --git a/tools/ci/checks.txt b/tools/ci/checks.txt index 055e68453..24693bf53 100644 --- a/tools/ci/checks.txt +++ b/tools/ci/checks.txt @@ -80,7 +80,10 @@ the registry's evidence rules: a PASS names evidence that exists, a touched evid the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump) F02 (Review B): the proof-rule test bypass cannot reach a release build: an env read with no cfg guard or under a default feature is red; a release binary carrying the bypass string is red (self-test) the test map merges structurally at a landing: master's cells plus the branch's, minus what the branch removed and master left (self-test) +rule 33: a release entry publishes only with a PASS fresh-install canary record for its sha (the record check and the publish guard, self-tests) +the guest input format moves with the pinned guests: the elf manifest's guest_input_format equals the source constant where the field exists, a format bump without a guest change is refused at the merge (self-test, then the tree) the REV suite is generated from Review B's findings and dispatch and matches them (self-test, then the tree) +F03 (Review B): every component's own pin equals packaging/release-manifest.json where a release branch carries one (self-test, then the tree) the public ledger (docs/ledger-public.md) is what docs/fud-ledger.md generates: one row per item, no commit ids, times or team names (self-test first) the ledger page reads both entry heading forms (M1 and AP-F8-1) so no in-house pass row is dropped from /ledger (known-failed first) every workflow job carries timeout-minutes (site 15, changes 10, pow 60, sims 45; the hung-job class of 7 October 2026) diff --git a/tools/ci/export-exclude.txt b/tools/ci/export-exclude.txt index aab450e01..33848ab1b 100644 --- a/tools/ci/export-exclude.txt +++ b/tools/ci/export-exclude.txt @@ -43,6 +43,7 @@ docs/design/app-audit-2026-10-08.md docs/ledger-public-pre-2.0.md # 8 October 2026: the Devnet 3 proving pipeline record (the fleet lane: box names, the operations record, the external review quoted) docs/analysis/proving-pipeline-2026-10-08.md +docs/design/key-succession-schedule.md docs/analysis/v6-10-guest-repin-2026-10-08.md docs/analysis/class-v6/coexistence-model.md docs/analysis/class-v6/operator-simulation.md diff --git a/tools/ci/guest-format-check.sh b/tools/ci/guest-format-check.sh new file mode 100755 index 000000000..fcc5a6df4 --- /dev/null +++ b/tools/ci/guest-format-check.sh @@ -0,0 +1,67 @@ +#!/usr/bin/env bash +# The guest input format moves with the pinned guests (the V6-07 sub-lane's fault, 8 October 2026, 22:0x UK: master's proving host +# wrote GUEST_INPUT_FORMAT 3 while the pinned guests were the 5 October pair, so a master-built host failed every proof). +# +# tools/ci/guest-format-check.sh the landing rule: a diff that changes the GUEST_INPUT_FORMAT constant in +# proving/igneum-prove/core/src/shard.rs without changing a file under +# proving/igneum-prove/elf/ is red (the guests must be repinned with the format) +# tools/ci/guest-format-check.sh --tree [] the tree rule: proving/igneum-prove/elf/manifest.json's guest_input_format, when +# the field exists, equals the source constant; a manifest without the field is a +# named line (a pre-provenance pin; igneum-prove-pin writes the field since 7d38077d); a +# mismatch with a source_commit names the commit the kit's prover builds from (not red) +# tools/ci/guest-format-check.sh --self-test +set -euo pipefail +HERE="$(cd "$(dirname "$0")" && pwd -P)"; ME="$HERE/$(basename "$0")" +SRC="proving/igneum-prove/core/src/shard.rs"; ELF_DIR="proving/igneum-prove/elf"; MANIFEST="$ELF_DIR/manifest.json" + +src_format() { # -> the constant's value, or empty + sed -n 's/^pub const GUEST_INPUT_FORMAT: u32 = \([0-9][0-9]*\);.*/\1/p' "$1" | head -1 +} +diff_rule() { # + local base="$1" head="$2" b h touched + b=$(git show "$base:$SRC" 2>/dev/null | src_format /dev/stdin || true) + h=$(git show "$head:$SRC" 2>/dev/null | src_format /dev/stdin || true) + [ -n "$h" ] || { echo "guest-format: no GUEST_INPUT_FORMAT constant at $head (nothing to check)"; return 0; } + if [ "$b" = "$h" ]; then echo "guest-format: the guest input format is unchanged ($h)"; return 0; fi + touched=$(git diff --name-only "$base" "$head" -- "$ELF_DIR/" | grep -c . || true) + if [ "${touched:-0}" -gt 0 ]; then echo "guest-format: the format moves ${b:-none} to $h with $touched file(s) under $ELF_DIR/ (the guests repinned with it)"; return 0; fi + echo "guest-format: REFUSED: GUEST_INPUT_FORMAT moves ${b:-none} to $h in $SRC with no change under $ELF_DIR/ (the pinned guests would refuse every input; repin the guests with the format and land both together)" + return 1 +} +tree_rule() { # [] + local root="${1:-.}" s m + [ -f "$root/$SRC" ] || { echo "guest-format: no $SRC in this tree (nothing to check)"; return 0; } + s=$(src_format "$root/$SRC"); [ -n "$s" ] || { echo "guest-format: no GUEST_INPUT_FORMAT constant in $SRC (nothing to check)"; return 0; } + [ -f "$root/$MANIFEST" ] || { echo "guest-format: REFUSED: no $MANIFEST beside a source format $s"; return 1; } + m=$(python3 -c 'import json,sys; d=json.load(open(sys.argv[1])); v=d.get("guest_input_format"); print("" if v is None else v)' "$root/$MANIFEST" 2>/dev/null || true) + sc=$(python3 -c 'import json,sys; d=json.load(open(sys.argv[1])); print(d.get("source_commit") or "")' "$root/$MANIFEST" 2>/dev/null || true) + if [ -z "$m" ]; then echo "guest-format: the pinned guests' manifest names no guest_input_format (a pre-provenance pin); the source format is $s; unverified until the guests are repinned with the field"; return 0; fi + if [ "$m" = "$s" ]; then echo "guest-format: the pinned guests and the source agree on guest input format $s"; return 0; fi + # a mismatch with provenance: the kit's prover is built from the manifest's source_commit (its format is the guests'), never this + # tree's tip, until the pin moves (the coordinator's shape, 8 October 2026 22:1x UK); without provenance nothing says which host + # the guests take and the tree is red + if [ -n "$sc" ]; then echo "guest-format: the pinned guests read guest input format $m from source_commit ${sc:0:12}; this tree's constant is $s, so the kit's prover builds from ${sc:0:12}, never this tip, until the guests are repinned"; return 0; fi + echo "guest-format: REFUSED: the pinned guests read guest input format $m, the source constant is $s, and the manifest names no source_commit (a host built from this tree fails every proof; repin the guests with provenance or move the constant back)" + return 1 +} +if [ "${1:-}" = --self-test ]; then + d=$(mktemp -d); trap 'rm -rf "$d"' EXIT; fails=0 + ( cd "$d" && git init -q -b master . && mkdir -p "$(dirname "$SRC")" "$ELF_DIR" && printf 'pub const GUEST_INPUT_FORMAT: u32 = 2;\n' > "$SRC" && printf 'elf' > "$ELF_DIR/a.elf" && printf '{"format":"v1"}\n' > "$MANIFEST" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m base && git tag base + git checkout -q -b bump && printf 'pub const GUEST_INPUT_FORMAT: u32 = 3;\n' > "$SRC" && git -c user.name=t -c user.email=t@t commit -qam bump && git tag bump-alone + git checkout -q -b both base && printf 'pub const GUEST_INPUT_FORMAT: u32 = 3;\n' > "$SRC" && printf 'elf3' > "$ELF_DIR/a.elf" && printf '{"format":"v1","guest_input_format":3}\n' > "$MANIFEST" && git -c user.name=t -c user.email=t@t commit -qam both && git tag bump-with-guests + git checkout -q -b other base && printf 'x' > other.txt && git add -A && git -c user.name=t -c user.email=t@t commit -q -m other && git tag no-bump + git checkout -q -b off base && printf 'pub const GUEST_INPUT_FORMAT: u32 = 3;\n' > "$SRC" && printf '{"format":"v1","guest_input_format":2}\n' > "$MANIFEST" && git -c user.name=t -c user.email=t@t commit -qam off && git tag off + git checkout -q -b prov base && printf 'pub const GUEST_INPUT_FORMAT: u32 = 3;\n' > "$SRC" && printf '{"format":"v1","guest_input_format":1,"source_commit":"15bb6cdd4aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"}\n' > "$MANIFEST" && git -c user.name=t -c user.email=t@t commit -qam prov && git tag prov ) >/dev/null 2>&1 || { echo "self-test failed: the fixture did not build"; exit 1; } + out=$( cd "$d" && bash "$ME" base bump-alone 2>&1 ) && { echo "self-test failed: a format bump with no guest change passed"; fails=1; }; case "$out" in *"no change under"*) ;; *) echo "self-test failed: the bump was not named: $out"; fails=1 ;; esac + ( cd "$d" && bash "$ME" base bump-with-guests >/dev/null 2>&1 ) || { echo "self-test failed: a format bump with repinned guests was refused: $( cd "$d" && bash "$ME" base bump-with-guests 2>&1 )"; fails=1; } + ( cd "$d" && bash "$ME" base no-bump >/dev/null 2>&1 ) || { echo "self-test failed: a diff without a format change was refused"; fails=1; } + ( cd "$d" && git checkout -q both && bash "$ME" --tree . >/dev/null 2>&1 ) || { echo "self-test failed: an agreeing manifest was refused: $( cd "$d" && bash "$ME" --tree . 2>&1 )"; fails=1; } + out=$( cd "$d" && git checkout -q off && bash "$ME" --tree . 2>&1 ) && { echo "self-test failed: a manifest format off the source passed"; fails=1; }; case "$out" in *"read guest input format 2, the source constant is 3"*) ;; *) echo "self-test failed: the mismatch was not named: $out"; fails=1 ;; esac + out=$( cd "$d" && git checkout -q prov && bash "$ME" --tree . 2>&1 ) || { echo "self-test failed: a mismatch with provenance (the kit's prover from source_commit) was refused: $out"; fails=1; }; case "$out" in *"builds from 15bb6cdd4aaa"*) ;; *) echo "self-test failed: the provenance line was not named: $out"; fails=1 ;; esac + out=$( cd "$d" && git checkout -q base && bash "$ME" --tree . 2>&1 ) || { echo "self-test failed: a pre-provenance manifest (no field) was refused: $out"; fails=1; }; case "$out" in *"names no guest_input_format"*) ;; *) echo "self-test failed: the unverified pin was not named: $out"; fails=1 ;; esac + [ "$fails" = 0 ] && echo "self-test passed: a GUEST_INPUT_FORMAT bump without a change under the elf directory is refused and named, with repinned guests it passes, a diff without the bump passes; in the tree an agreeing manifest passes, a manifest whose guest_input_format is off the source with no provenance is refused and named, one with a source_commit names the host's commit, a pin without the field is a named line" + exit $fails +fi +if [ "${1:-}" = --tree ]; then tree_rule "${2:-.}"; exit $?; fi +[ $# -eq 2 ] || { echo "usage: $0 | --tree [] | --self-test" >&2; exit 2; } +diff_rule "$1" "$2" diff --git a/tools/ci/int-suite.mjs b/tools/ci/int-suite.mjs index 3f31534c7..ea3c3af1d 100644 --- a/tools/ci/int-suite.mjs +++ b/tools/ci/int-suite.mjs @@ -24,7 +24,7 @@ export function suite(tr) { return { code: 'INT', title: 'INT: the master edition\'s integration gates (R1, the full-system review)', source: 'docs/plans/igneum-2.0-master/traceability.json integration_gates', gate: 'Integration gates closed', owner: 'the owner lanes per the coordinator\'s crosswalk', fixtures: ['F0', 'F5'], summary: `${tests.length} integration gates; each reads NOT RUN until its owner lane records a run`, tests }; } export function merge(reg, s) { const old = (reg.suites || []).find((x) => x.code === s.code); const live = new Map((old?.tests || []).map((t) => [t.id, t])); - for (const t of s.tests) { const o = live.get(t.id); if (o) for (const k of ['run_status', 'run_id', 'evidence_path', 'updated', 'evidence_record', 'in_progress_since', 'deferral_note', 'approvals']) if (k in o) t[k] = o[k]; } + for (const t of s.tests) { const o = live.get(t.id); if (o) for (const k of ['run_status', 'run_id', 'evidence_path', 'updated', 'evidence_record', 'evidence_records', 'blocked_on', 'method_recorded', 'in_progress_since', 'deferral_note', 'approvals']) if (k in o) t[k] = o[k]; } if (old?.notes) s.notes = old.notes; reg.suites = [...(reg.suites || []).filter((x) => x.code !== s.code), s]; return reg; } const canon = (o) => JSON.stringify(o, (k, v) => (v && typeof v === 'object' && !Array.isArray(v)) ? Object.fromEntries(Object.keys(v).sort().map((x) => [x, v[x]])) : v); function mapReasons(map, s) { const mapped = new Set(Object.values(map.cells || {}).flatMap((c) => c.cases || [])); map.not_run = map.not_run || {}; let n = 0; @@ -33,8 +33,8 @@ if (args.includes('--self-test')) { let fails = 0; const tr = { integration_gates: [{ id: 'INT-01', requirement: 'r one', status: 'PROPOSED / NOT RUN', source: 'R1' }, { id: 'INT-05', requirement: 'r five', status: 'x', source: 'R1' }, { id: 'INT-07', requirement: 'r seven', status: 'x', source: 'R1' }] }; const s = suite(tr); if (!(s.tests[2].definition && /V6-12/.test(s.tests[2].definition) && s.tests[2].accept === 'r seven')) { console.log('self-test failed: INT-07 does not carry V6-12 as a definition beside its verbatim requirement'); fails = 1; } if (!(s.tests.length === 3 && s.tests[0].id === 'INT-01' && s.tests[0].accept === 'r one' && /proving/.test(s.tests[0].owner_lane) && /node/.test(s.tests[1].owner_lane) && s.tests[0].run_status === 'NOT RUN' && s.tests[0].source[0] === 'R1')) { console.log('self-test failed: the INT cases are not shaped from the gates with the crosswalk owners'); fails = 1; } - const reg = { suites: [{ code: 'INT', notes: [{ text: 'n' }], tests: [{ id: 'INT-01', run_status: 'NOT RUN', in_progress_since: 't', run_id: 'r' }] }] }; const m = merge(reg, s); const i = m.suites.find((x) => x.code === 'INT'); - if (!(i.tests[0].in_progress_since === 't' && i.tests[1].run_status === 'NOT RUN' && i.notes?.length === 1)) { console.log('self-test failed: regenerating lost live fields or notes'); fails = 1; } + const reg = { suites: [{ code: 'INT', notes: [{ text: 'n' }], tests: [{ id: 'INT-01', run_status: 'NOT RUN', in_progress_since: 't', evidence_records: { 'c:x': { decision: 'PASS' } }, run_id: 'r' }] }] }; const m = merge(reg, s); const i = m.suites.find((x) => x.code === 'INT'); + if (!(i.tests[0].in_progress_since === 't' && i.tests[0].evidence_records?.['c:x']?.decision === 'PASS' && i.tests[1].run_status === 'NOT RUN' && i.notes?.length === 1)) { console.log('self-test failed: regenerating lost live fields or notes'); fails = 1; } const map = { cells: { c: { cases: ['INT-01'] } }, not_run: {} }; if (!(mapReasons(map, s) === 2 && !map.not_run['INT-01'] && /node lane/.test(map.not_run['INT-05']) && /CI steward/.test(map.not_run['INT-07']))) { console.log('self-test failed: the map reasons'); fails = 1; } if (!fails) console.log('self-test passed: one INT case per integration gate, the requirement verbatim, source R1, NOT RUN, the owner from the crosswalk; regenerating keeps live fields and notes; unmapped gates get a NOT RUN reason naming the owner'); process.exit(fails); } diff --git a/tools/ci/merge-to-master.sh b/tools/ci/merge-to-master.sh index 08d8faa24..a342687fd 100755 --- a/tools/ci/merge-to-master.sh +++ b/tools/ci/merge-to-master.sh @@ -283,7 +283,7 @@ success 4 u push run node tools/ci/test-record.mjs --record tools/ci/batches/r-branch.json >/dev/null && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "batch r-branch" git checkout -q master; printf '{"run_id":"r-master","manifest_sha":"m","method":"native","cells":[{"cell":"c2","status":"NOT RUN","evidence":"tools/ci/test-map.json"}]}\n' > /tmp/r-master.json node tools/ci/test-record.mjs --record /tmp/r-master.json >/dev/null && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "master row" ) >/dev/null 2>&1 - out=$( cd "$rb" && TIP=$(git rev-parse master) && SHA=$(git rev-parse branch) && BASE=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=A "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge with replay" 2>&1 && python3 -c " + out=$( cd "$rb" && TIP=$(git rev-parse master) && SHA=$(git rev-parse branch) && BASE=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=AM "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge with replay" 2>&1 && python3 -c " import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); t={c['id']:c.get('run_id') for s in d['suites'] for c in s['tests']}; print('rows', t)" ) case "$out" in *"'X-1': 'r-branch'"*"'X-2': 'r-master'"*|*"'X-2': 'r-master'"*"'X-1': 'r-branch'"*) ;; *) echo "self-test failed: the batch replay did not land both the branch's row and master's row: $out"; fails=1 ;; esac # the page race: the branch adds cell c3 to the map (page regenerated), master adds c4 (page regenerated); the merge regenerates the page with both @@ -295,8 +295,17 @@ import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); t={c # both at once: the branch records a batch (its registry copy conflicts with master's) and adds a map cell; the page must regenerate # after the registry is rebuilt, never from a copy with conflict markers (8 October 2026, 20:24 UK: the REV landing lost to this) ( cd "$rb" && git checkout -q -b both pbase && printf '{"run_id":"r-both","manifest_sha":"m","method":"native","cells":[{"cell":"c1","status":"NOT RUN","evidence":"tools/ci/test-map.json"}]}\n' > tools/ci/batches/r-both.json && node tools/ci/test-record.mjs --record tools/ci/batches/r-both.json >/dev/null && python3 -c "import json; m=json.load(open('tools/ci/test-map.json')); m['cells']['c5']={'command':'v','box_class':'b','fixtures':[],'cases':['X-1']}; json.dump(m,open('tools/ci/test-map.json','w'))" && node tools/ci/test-map-doc.mjs >/dev/null 2>&1; git add -A; git -c user.name=t -c user.email=t@t commit -q -m both ) >/dev/null 2>&1 - out=$( cd "$rb" && TIP=$(git rev-parse master) && SHA=$(git rev-parse both) && BASE=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=A "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && MAP_CHANGED=1 && MAP_PATH=tools/ci/test-map.json && PAGE_PATH=docs/plans/igneum-2.0-test-harness-map.md && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge both" 2>&1 && grep -c -E '^### c[45]$' docs/plans/igneum-2.0-test-harness-map.md && python3 -c "import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); print('ok' if any(c.get('run_id')=='r-both' for s in d['suites'] for c in s['tests']) else 'no-batch')" ) + out=$( cd "$rb" && TIP=$(git rev-parse master) && SHA=$(git rev-parse both) && BASE=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=AM "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && MAP_CHANGED=1 && MAP_PATH=tools/ci/test-map.json && PAGE_PATH=docs/plans/igneum-2.0-test-harness-map.md && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge both" 2>&1 && grep -c -E '^### c[45]$' docs/plans/igneum-2.0-test-harness-map.md && python3 -c "import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); print('ok' if any(c.get('run_id')=='r-both' for s in d['suites'] for c in s['tests']) else 'no-batch')" ) case "$out" in *replayed*2*ok*) ;; *) echo "self-test failed: a landing with both a batch and a map change did not land both (the page before the registry rebuild?): $out"; fails=1 ;; esac + # a MODIFIED batch replays too (8 October 2026, 21:4x UK: a re-record of the kills batch on a branch never reached master's rows because + # the replay read added batches only): master carries r-mod.json, the branch re-records it as FAIL, the merge must move X-2 to FAIL + ( cd "$rb" && git checkout -q master && git tag premod && printf '{"run_id":"r-mod","manifest_sha":"m","method":"native","cells":[{"cell":"c2","status":"NOT RUN","evidence":"tools/ci/test-map.json"}]}\n' > tools/ci/batches/r-mod.json && node tools/ci/test-record.mjs --record tools/ci/batches/r-mod.json >/dev/null && git add -A && git -c user.name=t -c user.email=t@t commit -q -m r-mod && git tag mbase + git checkout -q -b mod mbase && printf '{"run_id":"r-mod","manifest_sha":"m","method":"native","cells":[{"cell":"c2","status":"FAIL","evidence":"tools/ci/test-map.json"}]}\n' > tools/ci/batches/r-mod.json && node tools/ci/test-record.mjs --record tools/ci/batches/r-mod.json >/dev/null && git add -A && git -c user.name=t -c user.email=t@t commit -q -m mod + git checkout -q master && printf '{"run_id":"r-m2","manifest_sha":"m","method":"native","cells":[{"cell":"c1","status":"NOT RUN","evidence":"tools/ci/test-map.json"}]}\n' > tools/ci/batches/r-m2.json && node tools/ci/test-record.mjs --record tools/ci/batches/r-m2.json >/dev/null && git add -A && git -c user.name=t -c user.email=t@t commit -q -m m2 ) >/dev/null 2>&1 || { echo "self-test failed: the modified-batch fixture did not build"; fails=1; } + out=$( cd "$rb" && TIP=$(git rev-parse master) && SHA=$(git rev-parse mod) && BASE=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=AM "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && MAP_CHANGED=0 && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge mod" 2>&1 && python3 -c " +import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); t={c['id']:c.get('run_status') for s in d['suites'] for c in s['tests']}; print('status', t)" ) + case "$out" in *"'X-2': 'FAIL'"*) ;; *) echo "self-test failed: a batch modified on the branch did not replay onto master's registry: $out"; fails=1 ;; esac + ( cd "$rb" && git checkout -q master && git reset -q --hard premod && git checkout -q both ) >/dev/null 2>&1 # the fixture back to where the later cases expect it push_race "To x ! [remote rejected] HEAD -> master (failed to update ref) remote: error: cannot lock ref 'refs/heads/master': is at a but expected b" || { echo "self-test failed: a lost compare-and-swap was not read as a race"; fails=1; } @@ -313,7 +322,7 @@ error: failed to push some refs" && { echo "self-test failed: a red check was re rm -rf "$ld/master-landing"; unset IGNEUM_LOCK_SSH IGNEUM_LOCK_DIR IGNEUM_LOCK_CAP IGNEUM_LOCK_STALE IGNEUM_LOCK_POLL # the branch-side merge of master under the lock: master moved (c4 and a row), the branch (c3 and a batch) takes it with the transforms ( cd "$rb" && git checkout -q both ) >/dev/null 2>&1 - out=$( cd "$rb" && git checkout -q both && TIP=$(git rev-parse master) && SHA=$(git rev-parse both) && BASE0=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=A "$BASE0" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && MAP_CHANGED=1 && MAP_PATH=tools/ci/test-map.json && PAGE_PATH=docs/plans/igneum-2.0-test-harness-map.md && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge master into both" branch 2>&1 && git merge-base --is-ancestor master HEAD && echo ancestor && grep -c -E '^### c[45]$' docs/plans/igneum-2.0-test-harness-map.md && python3 -c "import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); print('ok' if any(c.get('run_id')=='r-both' for s in d['suites'] for c in s['tests']) and any(c.get('run_id')=='r-master' for s in d['suites'] for c in s['tests']) else 'rows-lost')" ) + out=$( cd "$rb" && git checkout -q both && TIP=$(git rev-parse master) && SHA=$(git rev-parse both) && BASE0=$(git merge-base "$TIP" "$SHA") && BATCHES=$(git diff --name-only --diff-filter=AM "$BASE0" "$SHA" -- tools/ci/batches/ | grep -E '\.json$') && MAP_CHANGED=1 && MAP_PATH=tools/ci/test-map.json && PAGE_PATH=docs/plans/igneum-2.0-test-harness-map.md && REGISTRY_PATH=docs/plans/igneum-2.0-test-registry.json && AUTHOR=(-c user.name=t -c user.email=t@t) && export TEST_RECORD_ROOT="$rb" && merge_with_batches "$TIP" "$SHA" "merge master into both" branch 2>&1 && git merge-base --is-ancestor master HEAD && echo ancestor && grep -c -E '^### c[45]$' docs/plans/igneum-2.0-test-harness-map.md && python3 -c "import json; d=json.load(open('docs/plans/igneum-2.0-test-registry.json')); print('ok' if any(c.get('run_id')=='r-both' for s in d['suites'] for c in s['tests']) and any(c.get('run_id')=='r-master' for s in d['suites'] for c in s['tests']) else 'rows-lost')" ) case "$out" in *ancestor*2*ok*) ;; *) echo "self-test failed: the branch-side merge of master under the lock did not carry master's rows and cells plus the branch's: $out"; fails=1 ;; esac [ "$fails" = 0 ] && echo "self-test passed: a GitHub remote is refused with exit 2 while the suspension marker stands and a mirror remote is not; the CI rule binds a GitHub remote only; a landed master is fast-forwarded to every mirror and a refused mirror push is a line, not a failure; a green branch run merges; a red one is refused; an unknown read is waited through and refused only at the deadline; a queued run is waited for with the clock; an unrun branch is pushed once and then waited for; a red master refuses every merge but the declared fix; a registry landing's batches replay onto master's copy at the merge; a map change regenerates the harness page at the merge; a push that lost the ref race retries without re-running the hook; the master-landing lock holds for the whole landing and master merges into the branch under it" exit $fails @@ -349,7 +358,7 @@ git fetch -q "$REMOTE" master if ! git merge-base --is-ancestor "$REMOTE/master" "$SHA"; then echo "merge-to-master: master moved since the branch point ($(git rev-parse --short "$REMOTE/master")); merging it into $BRANCH under the lock" PRE_SHA="$SHA"; BASE0=$(git merge-base "$SHA" "$REMOTE/master") - BATCHES=$(git diff --name-only --diff-filter=A "$BASE0" "$SHA" -- tools/ci/batches/ | grep -E '\.json$' || true); NOTES=$(git diff --name-only --diff-filter=A "$BASE0" "$SHA" -- tools/ci/notes/ | grep -E '\.json$' || true) + BATCHES=$(git diff --name-only --diff-filter=AM "$BASE0" "$SHA" -- tools/ci/batches/ | grep -E '\.json$' || true); NOTES=$(git diff --name-only --diff-filter=AM "$BASE0" "$SHA" -- tools/ci/notes/ | grep -E '\.json$' || true) MAP_CHANGED=0; git diff --quiet "$BASE0" "$SHA" -- "${MAP_PATH:-tools/ci/test-map.json}" 2>/dev/null || MAP_CHANGED=1 REGISTRY_PATH="${REGISTRY_PATH:-docs/plans/igneum-2.0-test-registry.json}"; MAP_PATH="${MAP_PATH:-tools/ci/test-map.json}"; PAGE_PATH="${PAGE_PATH:-docs/plans/igneum-2.0-test-harness-map.md}" [ -n "$NOTES" ] || [ "$MAP_CHANGED" = 1 ] || git diff --quiet "$BASE0" "$SHA" -- "$REGISTRY_PATH" 2>/dev/null || BATCHES="${BATCHES:-.}" @@ -366,8 +375,8 @@ bash tools/ci/rule24-crate-gate.sh "$BASE" "$SHA" || { echo "merge-to-master: RE # every batch the branch added onto master's copy of the registry (tools/ci/test-record.mjs --record, idempotent), so the branch's # copy is never what lands and rule 26 does not bind the registry path for such a branch (the evidence rules run on the merged result) REGISTRY_PATH="${REGISTRY_PATH:-docs/plans/igneum-2.0-test-registry.json}" -BATCHES=$(git diff --name-only --diff-filter=A "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$' || true) -NOTES=$(git diff --name-only --diff-filter=A "$BASE" "$SHA" -- tools/ci/notes/ | grep -E '\.json$' || true) # {suite, text}, replayed through test-record.mjs --note-file +BATCHES=$(git diff --name-only --diff-filter=AM "$BASE" "$SHA" -- tools/ci/batches/ | grep -E '\.json$' || true) +NOTES=$(git diff --name-only --diff-filter=AM "$BASE" "$SHA" -- tools/ci/notes/ | grep -E '\.json$' || true) # {suite, text}, replayed through test-record.mjs --note-file REVGEN=0; git diff --quiet "$BASE" "$SHA" -- tools/ci/review-suite.mjs tools/ci/int-suite.mjs docs/analysis/review-2026-10-08-b/findings.json docs/analysis/review-2026-10-08-b/dispatch.md docs/plans/igneum-2.0-master/traceability.json 2>/dev/null || REVGEN=1 # the REV and INT suites regenerate on the merged tree [ -n "$NOTES" ] || [ "$REVGEN" = 1 ] && BATCHES="${BATCHES:-.}" # the registry is rebuilt from master's copy whenever any transform rides RULE26_SKIP_PATHS=""; [ -n "$BATCHES" ] && RULE26_SKIP_PATHS="$REGISTRY_PATH" @@ -384,6 +393,9 @@ if [ -n "$KITBINS" ]; then bash tools/ci/kit-isa-check.sh $KITBINS || { echo "me RULE26_SKIP_PATHS="$RULE26_SKIP_PATHS" bash tools/ci/rule26-no-revert.sh "$BASE" "$SHA" "$REMOTE/master" || { echo "merge-to-master: REFUSED by rule 26 (above)" >&2; exit 1; } # the registry's evidence rules (8 October 2026, 18:4x UK): a PASS carries existing evidence, a touched evidence file moves with its # row, stale evidence never reads PASS, a run_status needs the approval (GOV-02, GOV-04, GOV-08) +# the guest input format moves with the pinned guests (the V6-07 sub-lane's fault, 8 October 2026 22:0x UK): a landing that changes +# GUEST_INPUT_FORMAT without a change under proving/igneum-prove/elf/ is refused +bash tools/ci/guest-format-check.sh "$BASE" "$SHA" || { echo "merge-to-master: REFUSED: the guest input format moved without the guests (above)" >&2; exit 1; } [ -n "$BATCHES" ] || bash tools/ci/registry-evidence-check.sh "$BASE" "$SHA" || { echo "merge-to-master: REFUSED by the registry's evidence rules (above)" >&2; exit 1; } # with batches the rules run on the merged result below for i in $(seq 1 "$TRIES"); do git fetch -q "$REMOTE" master; TIP=$(git rev-parse "$REMOTE/master") diff --git a/tools/ci/p01-vectors.py b/tools/ci/p01-vectors.py index 8ed7f724d..626abc67c 100755 --- a/tools/ci/p01-vectors.py +++ b/tools/ci/p01-vectors.py @@ -11,7 +11,16 @@ the worker never answered. tools/ci/p01-vectors.py --worker [--worker-arg=X ...] --pack --reference --count 1000000 (a worker argument that itself starts with "--" must be given as --worker-arg=--serve; argparse reads "--worker-arg --serve" as two options) [--start 0] [--job-nonces 1048576] [--prehash <64 hex>] [--manifest ] --out + tools/ci/p01-vectors.py --worker [--worker-arg X ...] --job-context --phase 1|2|3 --out tools/ci/p01-vectors.py --self-test +The job context (the same-work test, docs/plans/igneum-2.0-same-work-test.md) names two packs and two references (day D and +day D+1), the prehash, the range width (range_log2, 20) and the boundary nonce; phase N runs nonces [(N-1)*2^w, N*2^w): phase 1 +under day D, phase 3 under day D+1, phase 2 under day D up to the boundary nonce and day D+1 from it, no job line crossing the +boundary, and the evidence carries the boundary block (the nonce, the program id and day bytes on each side, the two hashes +either side) that the readers are compared on. A worker holds one (epoch, day) pair, so before any job the driver sends the +worker `prepare ` and waits for its `prepared` line (a `prepare-failed` line or +a ready line saying `prepare 0` is an error: the day switch cannot be driven); the first job on day D+1 then switches the pair, +as the miner does at a real day switch. The job line is pool.rs's: `job class= era=`. """ import argparse, json, os, subprocess, sys, tempfile, time @@ -31,21 +40,62 @@ def pack_fields(pack): cls = j.get('program_class', '?'); era = j.get('era_seed_bytes', '') return j.get('seed_bytes', ''), j['dataset']['day_bytes'], cls, era, j.get('program_id', '?'), j.get('generator', '?') +def segments_for(a): + """[(start, end, pack dir, reference path)] with no job crossing a segment edge; one segment for the plain form.""" + if not a.job_context: return [(a.start, a.start + a.count, a.pack, a.reference)], None + jc = json.load(open(a.job_context)); w = int(jc.get('range_log2', 20)); n = int(a.phase) + if n not in (1, 2, 3): raise SystemExit('p01-vectors: --phase must be 1, 2 or 3') + base = os.path.dirname(os.path.abspath(a.job_context)) + pth = lambda x: x if os.path.isabs(x) else os.path.join(base, x) + packs, refs = jc['packs'], jc['references'] + s0, e0 = (n - 1) << w, n << w + if n == 1: segs = [(s0, e0, pth(packs['D']), pth(refs['D']))] + elif n == 3: segs = [(s0, e0, pth(packs['D1']), pth(refs['D1']))] + else: + b = int(jc['boundary_nonce']) + if not (s0 < b < e0): raise SystemExit(f'p01-vectors: the boundary nonce {b} is not inside phase 2 [{s0}, {e0})') + segs = [(s0, b, pth(packs['D']), pth(refs['D'])), (b, e0, pth(packs['D1']), pth(refs['D1']))] + a.start, a.count = s0, e0 - s0 + if jc.get('prehash'): a.prehash = jc['prehash'] + if jc.get('manifest') and not a.manifest: a.manifest = jc['manifest'] + return segs, jc + def run(a): - ref = read_reference(a.reference) - seed_bytes, day_bytes, cls, era, program_id, generator = pack_fields(a.pack) + segs, jc = segments_for(a) + ref = {}; seg_fields = [] + for (ss, se, pack, rpath) in segs: + r = read_reference(rpath); ref.update({k: v for k, v in r.items() if ss <= k < se}); seg_fields.append((ss, se, pack_fields(pack))) + seed_bytes, day_bytes, cls, era, program_id, generator = seg_fields[0][2] + def fields_at(n): + for (ss, se, f) in seg_fields: + if ss <= n < se: return ss, se, f + return None p = subprocess.Popen([a.worker] + a.worker_arg, stdin=subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True, bufsize=1) ready = None; t0 = time.time() for line in p.stdout: if line.startswith('ready'): ready = line.strip(); break if time.time() - t0 > 120: break if not ready: p.kill(); return {'error': 'the worker never said ready'}, 2 + prepared = None + if len(seg_fields) > 1: + # the second segment's pair (day D+1) is prepared before any job: the worker builds it in the background and the first + # job on that day switches to it; a worker without prepare support cannot be driven across the boundary + if ' prepare 0' in ready: p.kill(); return {'error': f'the worker has no prepare support (ready line: {ready}); phase 2 needs it for the day switch'}, 2 + ss2, se2, (sb2, db2, _c2, _er2, _pid2, _gen2) = seg_fields[1] + p.stdin.write(f"prepare {sb2} {db2} {segs[1][2]}\n"); p.stdin.flush() + t1 = time.time() + for line in p.stdout: + if line.startswith('prepared '): prepared = line.strip(); break + if line.startswith('prepare-failed'): p.kill(); return {'error': f'the worker refused the day D+1 pair: {line.strip()[:300]}'}, 2 + if time.time() - t1 > 900: break + if not prepared: p.kill(); return {'error': 'the worker never said prepared for the day D+1 pair (900 s)'}, 2 got = {}; agree = 0; disagree = []; seq = 0; start = a.start; end = a.start + a.count; pending = set() def feed(): nonlocal seq, start while start < end and len(pending) < 4: - n = min(a.job_nonces, end - start); seq += 1 - p.stdin.write(f"job {seq} {a.prehash} {'f'*16} {start} {n} {seed_bytes} {day_bytes} class={cls} era={era}\n"); p.stdin.flush() + ss, se, (sb, db, c, er, _pid, _gen) = fields_at(start) + n = min(a.job_nonces, end - start, se - start); seq += 1 # a job never crosses a segment edge (the day boundary) + p.stdin.write(f"job {seq} {a.prehash} {'f'*16} {start} {n} {sb} {db} class={c} era={er}\n"); p.stdin.flush() pending.add(seq); start += n feed() for line in p.stdout: @@ -68,11 +118,21 @@ def run(a): except Exception: pass p.wait(timeout=30) missing = [n for n in range(a.start, end) if n not in got] - ev = {'case': 'POW-01', 'profile': 'P01', 'pack': os.path.basename(os.path.abspath(a.pack)), 'program_id': program_id, 'generator': generator, 'class': cls, + pack_name = os.path.basename(os.path.abspath(a.pack)) if a.pack else ', '.join(os.path.basename(os.path.abspath(s[2])) for s in segs) + ev = {'case': 'POW-01', 'profile': 'P01', 'pack': pack_name, 'program_id': program_id, 'generator': generator, 'class': cls, 'worker': a.worker, 'worker_args': a.worker_arg, 'device_line': ready, 'manifest_sha': a.manifest, 'prehash': a.prehash, 'nonces': {'start': a.start, 'count': a.count}, 'answered': len(got), 'agree': agree, 'disagree': disagree_count[0], 'missing': len(missing), 'first_disagreements': disagree, 'first_missing': missing[:10], 'worker_errors': errors[:10], 'seconds': round(time.time() - t0, 1), 'at': time.strftime('%Y-%m-%dT%H:%M:%SZ', time.gmtime())} - ev['verdict'] = 'PASS' if (agree == a.count and not disagree and not missing) else 'FAIL' + if jc is not None: + ev['job_context'] = os.path.abspath(a.job_context); ev['phase'] = int(a.phase); ev['object'] = jc.get('object') + ev['segments'] = [{'start': ss, 'end': se, 'program_id': f[4], 'day_bytes': f[1], 'class': f[2], 'pack': os.path.basename(os.path.abspath(sg[2]))} for (ss, se, f), sg in zip(seg_fields, segs)] + if prepared: ev['prepare_line'] = prepared + if len(seg_fields) == 2: + b = seg_fields[1][0]; fb, fa = seg_fields[0][2], seg_fields[1][2] + ev['boundary'] = {'nonce': b, 'program_id_before': fb[4], 'program_id_after': fa[4], 'day_bytes_before': fb[1], 'day_bytes_after': fa[1], + 'hash_before': got.get(b - 1), 'hash_after': got.get(b), 'reference_before': ref.get(b - 1), 'reference_after': ref.get(b), + 'switched': bool(fb[1] != fa[1] and got.get(b - 1) == ref.get(b - 1) and got.get(b) == ref.get(b))} + ev['verdict'] = 'PASS' if (agree == a.count and not disagree and not missing and (jc is None or len(seg_fields) < 2 or ev['boundary']['switched'])) else 'FAIL' return ev, (0 if ev['verdict'] == 'PASS' else 1) disagree_count = [0]; errors = [] @@ -84,14 +144,20 @@ def self_test(): # a fake worker: hashes nonce n as (n * 0x9e3779b97f4a7c15) mod 2^64; nonce 7 wrong when WRONG=1; nonce 9 never answered when DROP=1 w = os.path.join(d, 'worker.py') open(w, 'w').write('''import sys, os -print("ready fake-gpu 0 prepare 1", flush=True) +print("ready fake-gpu 0 prepare " + ("0" if os.environ.get("NOPREPARE") == "1" else "1"), flush=True) +resident = {os.environ.get("RESIDENT", "cc" * 19)} # the pack's day (the real worker starts on its --pack); another day needs prepare first, as the real worker (day seed mismatch otherwise) for line in sys.stdin: p = line.split() + if p[0] == "prepare": + if os.environ.get("PREPFAIL") == "1": print(f"prepare-failed {p[1]} {p[2]} nvcc exit 1", flush=True); continue + resident.add(p[2]); print(f"prepared {p[1]} {p[2]} 12.0 nvcc 10.0 cache 1.0 dataset 1.0 resident 2 programs 2 datasets", flush=True); continue if p[0] != "job": continue seq, start, n = int(p[1]), int(p[4]), int(p[5]) + if p[7] not in resident: print(f"error {seq} day seed mismatch: the job's day seed {p[7]} is not resident", flush=True); print(f"done {seq} 0 0", flush=True); continue for k in range(start, start + n): if os.environ.get("DROP") == "1" and k == 9: continue h = (k * 0x9e3779b97f4a7c15) % (1 << 64) + if p[7] == "dd" * 19: h ^= 0xdd00dd00dd00dd00 # day D+1's bytes hash differently (a reader on the wrong day disagrees) if os.environ.get("WRONG") == "1" and k == 7: h ^= 1 print(f"found {seq} {k} {h:016x}", flush=True) print(f"done {seq} {n} 1.0", flush=True) @@ -107,15 +173,46 @@ for line in sys.stdin: if not (rc == 1 and ev.get('verdict') == 'FAIL' and ev['disagree'] == 1 and ev['first_disagreements'][0]['nonce'] == 7): print(f"self-test failed: one wrong hash was not a FAIL naming nonce 7: rc={rc} {ev.get('first_disagreements')}"); fails = 1 rc, ev = go({'DROP': '1'}, 'drop') if not (rc == 1 and ev['missing'] == 1 and ev['first_missing'] == [9]): print(f"self-test failed: an unanswered nonce was not a FAIL naming nonce 9: rc={rc} {ev.get('first_missing')}"); fails = 1 - if not fails: print('self-test passed: a clean million-shape run is PASS with the counts; one wrong hash is FAIL naming the nonce, the gpu and cpu hashes; an unanswered nonce is FAIL naming it; the job lines carry the pack fields and the all-pass target') + # the job-context form: two packs (day D cc.., day D+1 dd..), two references, range_log2 4 (16 nonces a phase), boundary 24 inside phase 2 + pack2 = os.path.join(d, 'pack2'); os.makedirs(pack2) + json.dump({'seed_bytes': 'aa' * 32, 'program_class': 'v5', 'era_seed_bytes': 'bb' * 32, 'program_id': '0x2', 'generator': 5, 'dataset': {'day_bytes': 'dd' * 19, 'log2_words': 20}}, open(os.path.join(pack2, 'program.json'), 'w')) + refD = os.path.join(d, 'refD.txt'); open(refD, 'w').write(''.join(f"{k} {(k * 0x9e3779b97f4a7c15) % (1 << 64):016x}\n" for k in range(0, 48))) + refD1 = os.path.join(d, 'refD1.txt'); open(refD1, 'w').write(''.join(f"{k} {((k * 0x9e3779b97f4a7c15) % (1 << 64)) ^ 0xdd00dd00dd00dd00:016x}\n" for k in range(0, 48))) + jc = os.path.join(d, 'job-context.json') + json.dump({'object': 'fake', 'prehash': '00' * 31 + '01', 'range_log2': 4, 'boundary_nonce': 24, 'manifest': 'deadbeef', 'packs': {'D': pack, 'D1': pack2}, 'references': {'D': refD, 'D1': refD1}}, open(jc, 'w')) + def gojc(phase, tag, boundary=None, env=None): + if boundary is not None: + j = json.load(open(jc)); j['boundary_nonce'] = boundary; json.dump(j, open(jc, 'w')) + out = os.path.join(d, f'{tag}.json'); e = dict(os.environ); e.update(env or {}) + r = subprocess.run([sys.executable, __file__, '--worker', sys.executable, '--worker-arg', w, '--job-context', jc, '--phase', str(phase), '--job-nonces', '8', '--out', out], capture_output=True, text=True, env=e) + return r.returncode, (json.load(open(out)) if os.path.exists(out) else {}), r.stdout + r.stderr + for ph, s0, pid in ((1, 0, '0x1'), (3, 32, '0x2')): + rc, ev, o = gojc(ph, f'jc{ph}', env={'RESIDENT': 'dd' * 19} if ph == 3 else None) # phase 3's worker starts on the day D+1 pack + if not (rc == 0 and ev.get('verdict') == 'PASS' and ev['nonces'] == {'start': s0, 'count': 16} and ev['segments'][0]['program_id'] == pid and 'boundary' not in ev): print(f"self-test failed: phase {ph} of the job context was not a PASS on its range and pack: rc={rc} {ev.get('nonces')} {ev.get('segments')} {o[-200:]}"); fails = 1 + rc, ev, o = gojc(2, 'jc2') + b = ev.get('boundary', {}) + if not (rc == 0 and ev.get('verdict') == 'PASS' and ev['nonces'] == {'start': 16, 'count': 16} and b.get('nonce') == 24 and b.get('program_id_before') == '0x1' and b.get('program_id_after') == '0x2' and b.get('switched') is True and len(ev['segments']) == 2): print(f"self-test failed: phase 2 did not switch pack at the boundary nonce 24 with the boundary block: rc={rc} {b} {o[-200:]}"); fails = 1 + if not (b.get('switched') is True and str(ev.get('prepare_line', '')).startswith('prepared ' + 'aa' * 32 + ' ' + 'dd' * 19) and ev['segments'][1]['pack'] == 'pack2'): print(f"self-test failed: phase 2 did not prepare the day D+1 pair before the first job on it: {ev.get('prepare_line')} {ev.get('segments')}"); fails = 1 + rc, ev, o = gojc(2, 'jc2noprep', env={'NOPREPARE': '1'}) + if rc != 2 or 'no prepare support' not in o: print(f"self-test failed: a worker without prepare support was not refused for phase 2: rc={rc} {o[-200:]}"); fails = 1 + rc, ev, o = gojc(2, 'jc2prepfail', env={'PREPFAIL': '1'}) + if rc != 2 or 'refused the day D+1 pair' not in o: print(f"self-test failed: a prepare-failed line was not an error: rc={rc} {o[-200:]}"); fails = 1 + rc, ev, o = gojc(2, 'jc2bad', boundary=40) + if rc == 0 or 'not inside phase 2' not in o: print(f"self-test failed: a boundary outside phase 2 was not refused: rc={rc} {o[-200:]}"); fails = 1 + if not fails: print('self-test passed: a clean million-shape run is PASS with the counts; one wrong hash is FAIL naming the nonce, the gpu and cpu hashes; an unanswered nonce is FAIL naming it; the job-context form runs each phase on its range and pack, splits phase 2 at the boundary nonce with the boundary block, and refuses a boundary outside phase 2; the job lines carry the pack fields and the all-pass target') return fails if __name__ == '__main__': if '--self-test' in sys.argv: sys.exit(self_test()) - ap = argparse.ArgumentParser(); ap.add_argument('--worker', required=True); ap.add_argument('--worker-arg', action='append', default=[]); ap.add_argument('--pack', required=True) - ap.add_argument('--reference', required=True); ap.add_argument('--count', type=int, default=1_000_000); ap.add_argument('--start', type=int, default=0); ap.add_argument('--job-nonces', type=int, default=1 << 20) + ap = argparse.ArgumentParser(); ap.add_argument('--worker', required=True); ap.add_argument('--worker-arg', action='append', default=[]); ap.add_argument('--pack', default='') + ap.add_argument('--reference', default=''); ap.add_argument('--count', type=int, default=1_000_000); ap.add_argument('--start', type=int, default=0); ap.add_argument('--job-nonces', type=int, default=1 << 20) ap.add_argument('--prehash', default='00' * 31 + '01'); ap.add_argument('--manifest', default=''); ap.add_argument('--out', required=True) - a = ap.parse_args(); ev, rc = run(a) + ap.add_argument('--job-context', default=''); ap.add_argument('--phase', type=int, default=0) + a = ap.parse_args() + if a.job_context and not a.phase: ap.error('--job-context needs --phase 1|2|3') + if not a.job_context and not (a.pack and a.reference): ap.error('--pack and --reference, or --job-context with --phase') + ev, rc = run(a) os.makedirs(os.path.dirname(os.path.abspath(a.out)), exist_ok=True); json.dump(ev, open(a.out, 'w'), indent=2) + if 'error' in ev: print(f"p01-vectors: ERROR: {ev['error']} -> {a.out}"); sys.exit(rc) print(f"p01-vectors: {ev.get('verdict', 'ERROR')}: answered {ev.get('answered')} agree {ev.get('agree')} disagree {ev.get('disagree')} missing {ev.get('missing')} in {ev.get('seconds')} s -> {a.out}") sys.exit(rc) diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 88b019638..d90ab8119 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -179,7 +179,10 @@ tree_checks() { run "the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump)" bash tools/ci/kit-isa-check.sh --self-test run "F02 (Review B): the proof-rule test bypass cannot reach a release build: an env read with no cfg guard or under a default feature is red; a release binary carrying the bypass string is red (self-test)" bash tools/ci/proof-rule-bypass-check.sh --self-test run "the test map merges structurally at a landing: master's cells plus the branch's, minus what the branch removed and master left (self-test)" python3 tools/ci/test-map-merge.py --self-test + run "rule 33: a release entry publishes only with a PASS fresh-install canary record for its sha (the record check and the publish guard, self-tests)" bash -c 'bash tools/ci/canary-check.sh --self-test >/dev/null && bash packaging/ota/publish-manifest.sh --self-test-canary-guard >/dev/null' + run "the guest input format moves with the pinned guests: the elf manifest's guest_input_format equals the source constant where the field exists, a format bump without a guest change is refused at the merge (self-test, then the tree)" bash -c 'bash tools/ci/guest-format-check.sh --self-test >/dev/null && bash tools/ci/guest-format-check.sh --tree .' run "the REV suite is generated from Review B's findings and dispatch and matches them (self-test, then the tree)" bash tools/ci/review-suite-check.sh + run "F03 (Review B): every component's own pin equals packaging/release-manifest.json where a release branch carries one (self-test, then the tree)" bash -c 'bash tools/ci/release-manifest-check.sh --self-test >/dev/null && bash tools/ci/release-manifest-check.sh' run "the public ledger (docs/ledger-public.md) is what docs/fud-ledger.md generates: one row per item, no commit ids, times or team names (self-test first)" bash -c 'node tools/ledger/export-public.mjs --self-test && node tools/ledger/export-public.mjs --check' run "the ledger page reads both entry heading forms (M1 and AP-F8-1) so no in-house pass row is dropped from /ledger (known-failed first)" node tools/ledger-page.mjs --self-test run "every workflow job carries timeout-minutes (site 15, changes 10, pow 60, sims 45; the hung-job class of 7 October 2026)" bash tools/ci/workflow-timeouts-check.sh --self-test diff --git a/tools/ci/release-manifest-check.sh b/tools/ci/release-manifest-check.sh new file mode 100755 index 000000000..bfde43f9e --- /dev/null +++ b/tools/ci/release-manifest-check.sh @@ -0,0 +1,104 @@ +#!/usr/bin/env bash +# F03 (Review B, 8 October 2026): one release manifest (packaging/release-manifest.json) pins node, generator, dataset policy, +# acceptance rule, host ABI, miner app, pool, proof guests, verifying keys and activation; every component's own pin must equal it: +# 1. packaging/windows/node-source.pin == manifest.node.sha +# 2. the node fork's packaging/pow-freeze.txt carries manifest.generator.fingerprint (the fork at , when given) +# 3. proving/igneum-prove/elf/manifest.json's elf and vk sha256s == manifest.proof_guests, and the files on disk hash to them +# 4. the pool's vendored node checkout (pool/../vendor/igneum-node, when present) is at manifest.node.sha +# tools/ci/release-manifest-check.sh [--tree ] [] exit 0 when every pin agrees, 1 with every disagreement named +# tools/ci/release-manifest-check.sh --self-test +set -euo pipefail +HERE="$(cd "$(dirname "$0")" && pwd -P)"; ME="$HERE/$(basename "$0")" +check() { # [] ; prints "red ..." lines + local tree="$1" fork="${2:-}" rc=0 + python3 - "$tree" "$fork" <<'PY' || rc=1 +import json, sys, os, hashlib, subprocess +tree, fork = sys.argv[1], sys.argv[2]; red = [] +m = json.load(open(os.path.join(tree, 'packaging/release-manifest.json'))) +pin = os.path.join(tree, 'packaging/windows/node-source.pin') +if os.path.exists(pin): + p = open(pin).read().split()[0] if open(pin).read().split() else '' + if not (p.startswith(m['node']['sha']) or m['node']['sha'].startswith(p)): red.append(f"red node-source.pin reads {p}, the manifest pins node {m['node']['sha']}") +else: red.append('red packaging/windows/node-source.pin is missing') +pm_path = os.path.join(tree, 'proving/igneum-prove/elf/manifest.json') +if os.path.exists(pm_path): + pm = json.load(open(pm_path)) + for g in ('shard', 'aggregator'): + for k in ('elf_sha256', 'vk_sha256'): + if pm[g][k] != m['proof_guests'][g][k]: red.append(f"red proof guest {g} {k}: the proving manifest reads {pm[g][k][:18]}, the release manifest {m['proof_guests'][g][k][:18]}") + for fk, sk in (('elf', 'elf_sha256'), ('vk', 'vk_sha256')): + fp = os.path.join(tree, 'proving/igneum-prove/elf', pm[g][fk]) + if os.path.exists(fp): + h = '0x' + hashlib.sha256(open(fp, 'rb').read()).hexdigest() + if h != m['proof_guests'][g][sk]: red.append(f"red proof guest {g} {fk} on disk hashes to {h[:18]}, the release manifest pins {m['proof_guests'][g][sk][:18]}") +else: red.append('red proving/igneum-prove/elf/manifest.json is missing') +# provenance (V6-10, the proving lane's class, 8 October 2026): a proving manifest that names its source_commit must name a commit +# the tree's HEAD contains; a manifest pinned from a commit this tree never carried (the 5 October manifest had no provenance at all) +# is red. A manifest without source_commit is a note, not a red, until igneum-prove-pin writes one everywhere. +if os.path.exists(pm_path) and os.path.isdir(os.path.join(tree, '.git')) or os.path.exists(pm_path) and os.path.isfile(os.path.join(tree, '.git')): + sc = pm.get('source_commit') + if sc: + r = subprocess.run(['git', '-C', tree, 'merge-base', '--is-ancestor', sc, 'HEAD'], capture_output=True, text=True) + if r.returncode != 0: red.append(f"red proving manifest source_commit {sc[:12]} is not an ancestor of this tree's HEAD (pinned from a commit this branch never carried)") + else: print('release-manifest: note: the proving manifest names no source_commit (pre-provenance pin)') +if fork: + fz = os.path.join(fork, 'packaging/pow-freeze.txt') + if os.path.exists(fz): + if m['generator']['fingerprint'] not in open(fz).read(): red.append(f"red the fork's packaging/pow-freeze.txt does not carry the manifest's generator fingerprint {m['generator']['fingerprint'][:16]}") + else: red.append(f'red {fz} is missing') + try: + head = subprocess.run(['git', '-C', fork, 'rev-parse', 'HEAD'], capture_output=True, text=True).stdout.strip() + if head and not head.startswith(m['node']['sha']): red.append(f"red the fork checkout is at {head[:8]}, the manifest pins node {m['node']['sha']}") + except Exception: pass +vend = os.path.join(tree, 'vendor/igneum-node') +if os.path.isdir(vend): + head = subprocess.run(['git', '-C', vend, 'rev-parse', 'HEAD'], capture_output=True, text=True).stdout.strip() + if head and not head.startswith(m['node']['sha']): red.append(f"red the pool's vendored node checkout is at {head[:8]}, the manifest pins node {m['node']['sha']} (the shadow_reps seam closes by a build against the pinned node)") + nodeas = os.path.join(tree, 'pool/src/node.rs') + if os.path.exists(nodeas) and 'struct EpochSeeds' in open(nodeas).read(): red.append('red pool/src/node.rs redefines EpochSeeds; it must import kaspa_pow::igneum::EpochSeeds') +# V6-12 (R1 p. 213, the master): the signed manifest binds lockfile hashes, kernel and host binaries, supported devices and drivers, the prover +# server patch, memory thresholds and tuner identity; a manifest without the block reads BLOCKED on INT-07, never a pass of it +v = m.get('v6_12') or {} +for k in ('lockfile_sha256', 'kernel_binaries', 'host_binaries', 'supported_devices', 'supported_drivers', 'prover_server_patch', 'memory_thresholds', 'tuner_identity', 'signature'): + if k not in v: print(f'note V6-12 field {k} is not in the manifest (INT-07 reads BLOCKED until it is)') +for r in red: print(r) +sys.exit(1 if red else 0) +PY + return $rc +} +if [ "${1:-}" = --self-test ]; then + d=$(mktemp -d); trap 'rm -rf "$d"' EXIT; fails=0 + mk() { local t="$d/$1"; mkdir -p "$t/packaging/windows" "$t/proving/igneum-prove/elf" "$t/pool/src"; printf 'elf' > "$t/proving/igneum-prove/elf/a.elf"; printf 'vk' > "$t/proving/igneum-prove/elf/a.vk" + local es="0x$(printf 'elf' | shasum -a 256 | cut -d' ' -f1)" vs="0x$(printf 'vk' | shasum -a 256 | cut -d' ' -f1)" + printf '{"shard":{"elf":"a.elf","elf_sha256":"%s","vk":"a.vk","vk_sha256":"%s"},"aggregator":{"elf":"a.elf","elf_sha256":"%s","vk":"a.vk","vk_sha256":"%s"}}\n' "$es" "$vs" "$es" "$vs" > "$t/proving/igneum-prove/elf/manifest.json" + printf '{"node":{"sha":"%s"},"generator":{"fingerprint":"ffff0000"},"proof_guests":{"shard":{"elf_sha256":"%s","vk_sha256":"%s"},"aggregator":{"elf_sha256":"%s","vk_sha256":"%s"}}}\n' "$2" "$es" "$vs" "$es" "$vs" > "$t/packaging/release-manifest.json" + printf '%s\n' "$3" > "$t/packaging/windows/node-source.pin"; printf 'use kaspa_pow::igneum::EpochSeeds;\n' > "$t/pool/src/node.rs"; } + mk agree abcd1234 abcd1234; mk pinoff abcd1234 ffff1234 + bash "$ME" --tree "$d/agree" >/dev/null 2>&1 || { echo "self-test failed: agreeing pins were refused: $(bash "$ME" --tree "$d/agree" 2>&1)"; fails=1; } + out=$(bash "$ME" --tree "$d/pinoff" 2>&1) && { echo "self-test failed: a node-source pin off the manifest passed"; fails=1; }; case "$out" in *"node-source.pin reads ffff1234"*) ;; *) echo "self-test failed: the pin was not named: $out"; fails=1 ;; esac + printf 'elf2' > "$d/agree/proving/igneum-prove/elf/a.elf"; out=$(bash "$ME" --tree "$d/agree" 2>&1) && { echo "self-test failed: a guest file that hashes off the manifest passed"; fails=1; }; case "$out" in *"on disk hashes to"*) ;; *) echo "self-test failed: the hash drift was not named: $out"; fails=1 ;; esac + printf 'elf' > "$d/agree/proving/igneum-prove/elf/a.elf"; mkdir -p "$d/fork/packaging"; printf '# f\nffff0000 c1 v5 2026\n' > "$d/fork/packaging/pow-freeze.txt" + bash "$ME" --tree "$d/agree" "$d/fork" >/dev/null 2>&1 || { echo "self-test failed: a fork carrying the fingerprint was refused: $(bash "$ME" --tree "$d/agree" "$d/fork" 2>&1)"; fails=1; } + printf '# f\n00000000 c1 v5 2026\n' > "$d/fork/packaging/pow-freeze.txt"; out=$(bash "$ME" --tree "$d/agree" "$d/fork" 2>&1) && { echo "self-test failed: a fork without the fingerprint passed"; fails=1; } + printf 'pub struct EpochSeeds {}\n' > "$d/agree/pool/src/node.rs"; mkdir -p "$d/agree/vendor/igneum-node" && ( cd "$d/agree/vendor/igneum-node" && git init -q && git -c user.name=t -c user.email=t@t commit -q --allow-empty -m x ) >/dev/null 2>&1 + out=$(bash "$ME" --tree "$d/agree" 2>&1) && { echo "self-test failed: a redefined EpochSeeds and an unpinned vendored node passed"; fails=1; }; case "$out" in *"redefines EpochSeeds"*) ;; *) echo "self-test failed: the seam was not named: $out"; fails=1 ;; esac + # provenance: a git tree whose proving manifest names a source_commit HEAD contains passes; one naming a commit HEAD never carried is red + mk prov abcd1234 abcd1234; ( cd "$d/prov" && git init -q && git add -A && git -c user.name=t -c user.email=t@t commit -q -m x ) >/dev/null 2>&1; sc=$(git -C "$d/prov" rev-parse HEAD) + python3 - "$d/prov/proving/igneum-prove/elf/manifest.json" "$sc" <<'PY2' +import json,sys; p=sys.argv[1]; d=json.load(open(p)); d['source_commit']=sys.argv[2]; json.dump(d,open(p,'w')) +PY2 + bash "$ME" --tree "$d/prov" >/dev/null 2>&1 || { echo "self-test failed: a manifest whose source_commit HEAD contains was refused: $(bash "$ME" --tree "$d/prov" 2>&1)"; fails=1; } + python3 - "$d/prov/proving/igneum-prove/elf/manifest.json" <<'PY2' +import json,sys; p=sys.argv[1]; d=json.load(open(p)); d['source_commit']='0'*40; json.dump(d,open(p,'w')) +PY2 + out=$(bash "$ME" --tree "$d/prov" 2>&1) && { echo "self-test failed: a manifest pinned from a commit the tree never carried passed"; fails=1; }; case "$out" in *"not an ancestor"*) ;; *) echo "self-test failed: the provenance red was not named: $out"; fails=1 ;; esac + [ "$fails" = 0 ] && echo "self-test passed: agreeing pins pass; a node-source pin, a guest file's hash, a fork freeze file, the pool's vendored node checkout, a redefined EpochSeeds or a proving manifest pinned from a commit the tree never carried is red and named" + exit $fails +fi +TREE="$(git rev-parse --show-toplevel 2>/dev/null || pwd)"; FORK="" +while [ $# -gt 0 ]; do case "$1" in --tree) TREE="$2"; shift 2 ;; *) FORK="$1"; shift ;; esac; done +[ -f "$TREE/packaging/release-manifest.json" ] || { echo "release-manifest: no packaging/release-manifest.json on this tree: not a release branch, nothing to pin"; exit 0; } +rc=0; out=$(check "$TREE" "$FORK") || rc=1 +printf '%s\n' "$out" | sed -n 's/^red /release-manifest: RED: /p; s/^note /release-manifest: /p' | grep . || true +[ "$rc" = 0 ] && echo "release-manifest: every component's own pin equals packaging/release-manifest.json" +exit $rc diff --git a/tools/ci/review-suite.mjs b/tools/ci/review-suite.mjs index 41c86bf9b..06f27ec00 100644 --- a/tools/ci/review-suite.mjs +++ b/tools/ci/review-suite.mjs @@ -36,7 +36,7 @@ function suite(findings, dispatchMd, prefix, sourceNote, master) { } function merge(reg, s) { // replace the suite of the same code, keeping live fields of cases that already exist const old = (reg.suites || []).find((x) => x.code === s.code); const live = new Map((old?.tests || []).map((t) => [t.id, t])); - for (const t of s.tests) { const o = live.get(t.id); if (o) for (const k of ['run_status', 'run_id', 'evidence_path', 'updated', 'evidence_record', 'in_progress_since', 'deferral_note', 'approvals']) if (k in o) t[k] = o[k]; } + for (const t of s.tests) { const o = live.get(t.id); if (o) for (const k of ['run_status', 'run_id', 'evidence_path', 'updated', 'evidence_record', 'evidence_records', 'blocked_on', 'method_recorded', 'in_progress_since', 'deferral_note', 'approvals']) if (k in o) t[k] = o[k]; } reg.suites = [...(reg.suites || []).filter((x) => x.code !== s.code), s]; return reg; } if (args.includes('--self-test')) { @@ -49,9 +49,9 @@ if (args.includes('--self-test')) { if (!(s.tests[0].title === 'r one' && s.tests[0].accept === 'r one')) { console.log('self-test failed: the title and accept are not the regression line verbatim'); fails = 1; } if (!(s.tests[0].owner_lane === 'lane x, lane y' && s.tests[2].owner_lane === 'lane z')) { console.log(`self-test failed: owners not read from the dispatch table: ${s.tests.map((t) => t.owner_lane)}`); fails = 1; } if (!(s.tests[0].finding === 'R2-F01' && s.tests[0].priority === 'P0' && s.tests[0].run_status === 'NOT RUN' && s.tests[0].method.includes('Automated'))) { console.log('self-test failed: finding, priority, NOT RUN or method missing'); fails = 1; } - const reg = { suites: [{ code: 'GOV', tests: [] }, { code: 'REV', tests: [{ id: 'R2-F01-R01', run_status: 'NOT RUN', in_progress_since: 't', run_id: 'r9' }] }] }; + const reg = { suites: [{ code: 'GOV', tests: [] }, { code: 'REV', tests: [{ id: 'R2-F01-R01', run_status: 'NOT RUN', in_progress_since: 't', evidence_records: { 'c:x': { decision: 'PASS' } }, run_id: 'r9' }] }] }; const m = merge(JSON.parse(JSON.stringify(reg)), s); const rev = m.suites.find((x) => x.code === 'REV'); - if (!(m.suites.length === 2 && rev.tests.length === 3 && rev.tests[0].in_progress_since === 't' && rev.tests[0].run_id === 'r9' && rev.tests[1].run_status === 'NOT RUN')) { console.log('self-test failed: a regenerated suite did not keep the existing case\'s live fields or dropped another suite'); fails = 1; } + if (!(m.suites.length === 2 && rev.tests.length === 3 && rev.tests[0].in_progress_since === 't' && rev.tests[0].evidence_records?.['c:x']?.decision === 'PASS' && rev.tests[0].run_id === 'r9' && rev.tests[1].run_status === 'NOT RUN')) { console.log('self-test failed: a regenerated suite did not keep the existing case\'s live fields or dropped another suite'); fails = 1; } const map = { cells: { c1: { cases: ['R2-F01-R01'] } }, not_run: { 'REV-F02-1': 'old' } }; const n = mapReasons(map, s); if (!(n === 2 && !('R2-F01-R01' in map.not_run) && /lane z/.test(map.not_run['REV-F02-1']) && /lane x/.test(map.not_run['REV-F01-2']))) { console.log(`self-test failed: the map's NOT RUN reasons: ${JSON.stringify(map.not_run)} n=${n}`); fails = 1; } if (!fails) console.log('self-test passed: one case per required regression with the id --, the line verbatim as title and accept, the owner from the dispatch table, finding and priority carried, NOT RUN; regenerating keeps live fields and the other suites; every unmapped case gets a NOT RUN reason naming its owner lane in the map, a mapped one loses it'); diff --git a/tools/ci/route-spill-check.sh b/tools/ci/route-spill-check.sh index fedfd5854..0675f5937 100755 --- a/tools/ci/route-spill-check.sh +++ b/tools/ci/route-spill-check.sh @@ -36,8 +36,9 @@ BS_ROUTE_STATE_1="free=1 slots=2 load1=80" BS_ROUTE_STATE_2="free=3 slots=3 load BS_ROUTE_STATE_1="free=2 slots=2 load1=70" BS_ROUTE_STATE_2="free=3 slots=3 load1=5" expect "load 70 stays on build-1 (the line is 80)" build 1 0 # the ssh path itself under the hook's shell (/bin/bash is 3.2 on the Mac; the pool lane found `BS_SSH_OPTS[@]: unbound variable` # at the first unpinned route, 7 Oct 2026): a host file pointing at a port nothing answers on must read "down" in a few seconds, -# not die on an unset array -printf 'build@127.0.0.1\n' > "$t/hosts" +# not die on an unset array. Port 1 in the ssh URI form (8 Oct 2026, the workers-page lane): on a build box sshd answers on +# 127.0.0.1:22 and a forwarded agent logs in, so the bare address read "free=..." there and the gate was red only off the Mac +printf 'ssh://build@127.0.0.1:1\n' > "$t/hosts" out=$(IGNEUM_BUILD_KEY="$t/no-such-key" /bin/bash -c '. infra/build-server/lib.sh; bs_box_state 1' 2>&1 || true) if [ "$out" = down ]; then echo "route-spill: the ssh probe under /bin/bash $(/bin/bash -c 'echo $BASH_VERSION') reads an unreachable box as down" else echo "route-spill: the ssh probe under /bin/bash failed: '$out' (expected 'down')" >&2; fail=1; fi diff --git a/tools/ci/site-nav-check.mjs b/tools/ci/site-nav-check.mjs index b6481ef38..77d17ea98 100644 --- a/tools/ci/site-nav-check.mjs +++ b/tools/ci/site-nav-check.mjs @@ -15,7 +15,7 @@ const here = dirname(fileURLToPath(import.meta.url)); const GROUPS = { mine: ['/miner', '/download', '/app', '/wallet', '/miners', '/tuning', '/dev-fee', '/metamask'], network: ['/live', '/explorer', '/evidence', '/light', '/receipt', '/oracle'], - learn: ['/litepaper', '/income', '/economics', '/scorecard', '/audit', '/docs', '/ledger', '/claims', '/randomx', '/provenance', '/acceptance'], + learn: ['/litepaper', '/income', '/economics', '/scorecard', '/prize', '/audit', '/docs', '/ledger', '/claims', '/randomx', '/provenance', '/acceptance'], build: ['/build', '/faucet', '/swap', '/grants', '/compatibility'], // the builder programme (8 October 2026): the developer entry page, the Devnet 3 faucet, the swap, the grants }; const ROUTES = Object.values(GROUPS).flat(); diff --git a/tools/ci/test-map.json b/tools/ci/test-map.json index dca147e97..7789806b7 100644 --- a/tools/ci/test-map.json +++ b/tools/ci/test-map.json @@ -225,8 +225,8 @@ } }, "bench:pc1-packs": { - "command": "tools/ca3-v4-amend/pc1-ca4-packs.ps1 on PC 1 (RTX 5090, the signed-jobs channel, --cards-off, the Power Helper lock at 1,300 MHz, nvidia-smi at 1 Hz, 250 x 2^24 per row, the kit's CUDA worker --bench)", - "box_class": "PC 1 bench", + "command": "tools/ca3-v4-amend/pc1-ca4-packs.ps1 on the project's own rig (RTX 5090, the signed-jobs channel, --cards-off, the Power Helper lock at 1,300 MHz, nvidia-smi at 1 Hz, 250 x 2^24 per row, the kit's CUDA worker --bench)", + "box_class": "the project's own rig bench", "fixtures": [ "F0", "F1" @@ -245,8 +245,8 @@ } }, "bench:pc1-amd": { - "command": "tools/ca3-v4-amend/pc1-amd-cardin-bench.ps1 on PC 1 (RX 7600, OpenCL, gfx1102, 30 dispatches of 2^24 per size, rate only)", - "box_class": "PC 1 bench", + "command": "tools/ca3-v4-amend/pc1-amd-cardin-bench.ps1 on the project's own rig (RX 7600, OpenCL, gfx1102, 30 dispatches of 2^24 per size, rate only)", + "box_class": "the project's own rig bench", "fixtures": [ "F0", "F1" @@ -422,7 +422,7 @@ "VER-08" ], "coverage": { - "VER-03": "partial: a payment receipt is labelled payment only when the receipt is proven against the segment statement's receipts commitment under the finality certificate, inclusion-only receipts read inclusion, a tampered receipt and a flipped status fail; run on the Devnet 3 fixtures, the 2.0 devnet re-run waits for its first paid segment whose last block carries a transaction", + "VER-03": "partial: a payment receipt is labelled payment only when the receipt is proven against the segment statement's receipts commitment under the finality certificate, inclusion-only receipts read inclusion, a tampered receipt and a flipped status fail; run on the the earlier devnet fixtures, the 2.0 devnet re-run waits for its first paid segment whose last block carries a transaction", "VER-04": "partial: the oracle's trust() names the deployer-installed table and the unchecked aggregator signature, a second hash at a stored certificate index is refused, a root claim at an unknown index is refused, another chain id is refused (tools/reference-apps/oracle/test.mjs on Sepolia); Review B F04: the Sepolia verifiers apply the two-thirds rule only, carry no lock-kind field, and an under-threshold (recovery-rule) certificate fails closed in submitCertificate, so no stored root is a recovery lock (the DEX lane's docs/bridge/light-client-bridge.md paragraph); the claimed-option review of the trust model is the reviewer's", "VER-05": "partial: the public node and the reference reader on build-1 executed the 2.0 devnet from genesis with no snapshot (unit ExecStart without --igneum-exec-snapshot), and the pages fetch headers, certificates, coinbase bodies and account proofs from the public read RPC only; the archive and availability model beyond the 2,048-block state ring is the OPS no-founder exercise", "VER-06": "partial: the read service never serves a certificate from another network, a withheld header in the path and a corrupted proof node are detected, stale data prints its lock age beside every balance, and a client told no certificate never falls back to a trusted RPC balance; detection on the fault network F4 is not run", @@ -576,8 +576,8 @@ } }, "bench:amd-intel-energy": { - "command": "the AMD-and-Intel energy lane jobs on the signed-jobs channel: run-ae-pc2-b580-energy-20261008 (PC 2, Arc B580, the class v6 kit worker --memprobe and --bench-pack on hl-v6-foldrw and hl-v6-all, Level Zero energy counter) and run-ae-pc1-7600-energy-20261008 (PC 1, RX 7600, the same with ADLX watts at stock, plimit -30, gmax -500 + plimit -30); scripts in docs/analysis/class-v6/amd-intel-energy/", - "box_class": "PC 1 and PC 2 bench (OpenCL)", + "command": "the AMD-and-Intel energy lane jobs on the signed-jobs channel: run-ae-pc2-b580-energy-20261008 (PC 2, Arc B580, the class v6 kit worker --memprobe and --bench-pack on hl-v6-foldrw and hl-v6-all, Level Zero energy counter) and run-ae-pc1-7600-energy-20261008 (the project's own rig, RX 7600, the same with ADLX watts at stock, plimit -30, gmax -500 + plimit -30); scripts in docs/analysis/class-v6/amd-intel-energy/", + "box_class": "the project's own rig and PC 2 bench (OpenCL)", "fixtures": [ "F0", "F1" @@ -588,19 +588,140 @@ "coverage": { "GPU-03": "partial: the 64-register window on AMD and Intel, rate per unit of work (RX 7600 0 percent, Arc B580 -0.3 percent, kernel throughput, quiet) with the B580 fingerprints equal on both packs and the offline RDNA allocation (160 VGPRs, no spill); energy owed (the 7600 job queued, the B580 counter unsupported unelevated); team-run, not under the standard's paired protocol or a wall meter" } + }, + "adversary:mf-placed": { + "command": "cd tools/chip-model/mf && make flow- power- (inside openroad/orfs:latest on a rented CPU host; never the Mac); python3 flow/collect.py results; python3 flow/board.py ; python3 flow/hash.py results power", + "box_class": "rented CPU host (Vast, 48 to 72 cores) on the ORFS image", + "fixtures": [ + "F0", + "F1" + ], + "cases": [ + "ADV-01", + "ADV-03", + "ADV-07", + "ADV-08", + "POW-03", + "POW-04", + "ADV-05" + ], + "coverage": { + "ADV-01": "the mf core (18 families, SRAM window and imem macros, operand isolation, 5-phase port) placed and routed on ASAP7 with SPEF and a gate-level VCD; k per family and per draw; outputs checked against the RTL simulation's checksums per tag, not yet against the POW vectors (owed)", + "ADV-03": "the data-local, hybrid and companion-host rows of multi-family-adversary.md sections 11, 13 and 14 (bit counts closed-form; the hop and wire energies claimed)", + "ADV-07": "the lifetime table and the six-row transition matrix (sections 7 and 14) on the placed rows; the 32-lane genesis comparator placed on adv-g", + "ADV-08": "the best-cost envelope on the complete machine (section 6) and the SRAM-die ticket reconciliation with lane B (section 15); the unaffiliated second reviewer is not this lane's", + "POW-03": "partial: the live state held in an SRAM macro per 8 lanes with a time-multiplexed single port and operand isolation, the complete-system cost in section 6; the liveness trace itself is the connected-state lane's tool", + "POW-04": "partial: the 64-register window's cost on the macro core (sections 4 and 5, agreeing with the k lane's gated-flop row within 5 percent); the restructured candidate's GPU cost is the invention lane's", + "ADV-05": "partial: the SRAM macros, ports, wiring, clocking and the complete-board terms are modelled in sections 2.3, 5 and 6 with the unmodelled items carried as uncertainty; the calibration against an existing hardware block is the k lane's bare-lane row beside it, owed as a named comparison" + } + }, + "adversary:d2b": { + "command": "cd tools/chip-model/mf && python3 flow/d2b.py results N5 1 && python3 flow/d2b.py results N3 1 (on a build box under lease pool or a rented host; reads results/table.csv)", + "box_class": "any box (a one-minute Python model on the placed rows)", + "fixtures": [ + "F0" + ], + "cases": [ + "ADV-02", + "ADV-04" + ], + "coverage": { + "ADV-02": "memory sharing, partial stores at the measured window-layer hit rates (and hit 0.50 with layer 8 off), recomputation and the set-up amortisation on the complete board (section 13); the formal memory model's terms (section 16)", + "ADV-04": "selective participation over 2,000 era draws under the layer 1 band with two reserve families live per epoch, the specialist's revenue against its ratio gain (section 13); downtime and re-entry priced as the DAA window's lag, not simulated against the difficulty rule itself (owed)" + } + }, + "pc:install-update": { + "command": "signed jobs and relay runs on the project's own rig (ae432dc7) and PC 2 (1ccfe586): the installer over the running app (rule 14: installed versions, the process set, the first upload), the OTA path (update-now, the update-return read-back line), and the no-click resume after the install (relay run mining-on-after-200.ps1)", + "box_class": "PC (the two Windows PCs; nothing on the Mac)", + "fixtures": [ + "F2" + ], + "cases": [ + "UX-01", + "UX-07", + "OPS-03" + ], + "coverage": { + "UX-01": "team-run evidence only (the two PCs taking the Windows entry through the app's own update path with no click and mining on every card); the P10 study is NOT RUN until unaffiliated participants are recruited", + "UX-07": "partial: the install classes (the payload's stop step, the detached installer under a job, the installer refusing a wrong-version name, a stale install flag) and the no-click resume; the recovery-instruction and canary rows are the shipper's", + "OPS-03": "partial: the update path's read-back and the signed manifest's verify on the PC (a tampered or rolled-back payload is refused by the engine's manifest check); authority separation is the shipper's review" + } + }, + "harness:release-manifest": { + "command": "bash tools/ci/release-manifest-check.sh (self-test, then the tree; the pins, the proof guests' hashes on disk, the fork freeze, the pool's vendored node, the proving manifest's source_commit provenance) and bash tools/ci/build-from-manifest.sh --box N on the release tree (kaspad with igneum-pow, igneum-miner, igneum-pool, igneum-app, igneum-prove-host from packaging/release-manifest.json with the node vendored at the manifest's sha)", + "box_class": "gate", + "fixtures": [ + "F0" + ], + "cases": [ + "R2-F03-R01" + ], + "coverage": { + "R2-F03-R01": "full for the components the tree builds (node, miner, pool, app, prove-host from one manifest, no unpublished vendor tree); the GPU workers are the kit's cross-build and read under the shipper's kit-isa line, not this cell" + } + }, + "harness:same-work": { + "command": "tools/ci/p01-vectors.py --job-context --phase 1|2|3 per reader (CUDA, OpenCL, Metal workers), igneum-miner --recheck-vectors (node), igneum-pow hash-bound (CPU reference), the pool's member-side re-check; docs/plans/igneum-2.0-same-work-test.md", + "box_class": "release (the readers on their pods and boxes)", + "fixtures": [ + "F0" + ], + "cases": [ + "R2-F03-R02", + "R2-F03-R03" + ], + "coverage": { + "R2-F03-R02": "partial until every reader has run: bit-for-bit agreement per nonce across node, CPU reference, CUDA, OpenCL, Metal and pool on one job context", + "R2-F03-R03": "partial: the day-boundary transition in phase 2 (the one transition every live network crosses hourly at 60x); a class rotation is the same test on a research object until a v6 floor is set" + } + }, + "canary:fresh-install": { + "command": "the rule 33 fresh-install canary on a release tip (the founder, 8 October 2026): install from the published artefact on a non-AVX-512 box with an empty datadir, sync genesis to tip, five minutes mining with zero refusals and an accepted block, one shard claimed, proved and paid or queued, a bounded quit, every line read back; the record tools/ci/canary/.json (one file per sha, an artefacts list: fleet, windows, mac, hive) read by tools/ci/canary-check.sh [--artefact kind], which publish-manifest.sh and publish-public.sh refuse without", + "box_class": "release (a non-AVX-512 box with an empty datadir)", + "fixtures": [ + "F0" + ], + "cases": [ + "INT-07" + ], + "coverage": { + "INT-07": "partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's" + } + }, + "review:k-lane-shadow-k": { + "command": "floor lane 2's placed and routed cores on ASAP7 in tools/chip-model/rtl (the rows in docs/analysis/class-v6/floor/shadow-k.md); the register landing 50ff1611f recorded ADV-06 against it before the recorder existed", + "box_class": "none", + "fixtures": [], + "cases": [ + "ADV-06" + ], + "coverage": { + "ADV-06": "partial: the placed gated cores and the adversary's forms are modelled in shadow-k.md; the independent review remains" + } + }, + "kit:class-v6-fingerprints": { + "command": "KITS_BOX_SCRIPT=kits-v6-on-box.sh tools/class-v5/kits-remote.sh --box 1 (the kit zip with its emulation check), then the kit's workers on every platform: the box's CPU emulation (--check, 96 of 96 vector lanes), the fleet's CUDA 4090 (--check and --bench at 2^24, base nonce 0), the Mac's Metal (proto-metal/packbench.swift --pack) and Apple OpenCL (proto-opencl/host.c --pack --bench-pack), PC 1's RTX 5090 and RX 7600 (tools/class-v5/pc1-v6-bench.ps1), PC 2's Arc B580 (tools/class-v5/arc-v6-bench.ps1); the fingerprint of the 2^24 outputs at base nonce 0 equal on every platform for the all pack and for its known-failed partner, the two distinct", + "box_class": "build box + pods + Mac + PC 1 + PC 2", + "fixtures": [ + "F0", + "F2" + ], + "cases": [ + "R2-F03-R02" + ], + "coverage": { + "R2-F03-R02": "partial: the worker half (CPU reference, CUDA, Metal, OpenCL) on the same program packs; the node's and the pool's accepted work on the same job context are the CI steward's and the pool lane's cells; PASS only when every listed platform reads one fingerprint and the node and pool halves are green" + } } }, "not_run": { "GOV-02": "the approval is recorded in the registry's approval field; the automated half (thresholds frozen before any run_status) is the gate rule landing by 21:00", "GOV-04": "the evidence vault F9 (raw and negative evidence preserved) is the gate rule landing by 21:00: a PASS must carry its evidence file", "GOV-08": "the stale-evidence rule (evidence older than the manifest sha reads NOT RUN) is the gate rule landing by 21:00", - "GPU-04": "the memory-clock ladder has no harness tonight: PC 1 mines nothing under the Devnet 3 off order", + "GPU-04": "the memory-clock ladder has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order", "GPU-06": "accepted work under ordinary connectivity needs the fault network F4", - "GPU-07": "the sustained thermal and power soak has no harness tonight: PC 1 mines nothing under the Devnet 3 off order", + "GPU-07": "the sustained thermal and power soak has no harness tonight: the project's own rig mines nothing under the the earlier devnet off order", "POW-05": "amortised cheap winning attempts are the attack lanes' grind and era harnesses (tools/attack/f7-era, f9-grind), not in the release matrix; their rows come from those lanes", - "ADV-04": "selective participation needs the economic model F7 and a live chain window", - "ADV-06": "process-advantage separation is the adversary lanes' chip study", - "ADV-07": "lifetime rows are the adversary lanes' models", "ROT-03": "miner-voted bring-forward needs a vote harness on the fault network F4", "ROT-04": "seed-selection resistance is the census harness (the class v6 invention lane), not yet in the matrix", "EVM-01": "no EVM conformance-vector harness is mapped tonight; the exec suite does not run the reference test vectors", @@ -687,7 +808,6 @@ "INT-04": "INT-04 (R1 integration gate): the gate's harness is the owner lane's (pool lane (a1c484c48a62948c2)); not yet named in the map", "INT-05": "INT-05 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map", "INT-06": "INT-06 (R1 integration gate): the gate's harness is the owner lane's (node lane (a283f5f0d364ceef0)); not yet named in the map", - "INT-07": "INT-07 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", "INT-08": "INT-08 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", "INT-09": "INT-09 (R1 integration gate): the gate's harness is the owner lane's (app lane); not yet named in the map", "INT-10": "INT-10 (R1 integration gate): the gate's harness is the owner lane's (CI steward with the hash lane (a690540514aa453d7) and the worker lane (a9e87343f008e0edd)); not yet named in the map", @@ -706,9 +826,6 @@ "R2-F02-R01": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", "R2-F02-R02": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", "R2-F02-R03": "R2-F02 (P0, the external review): the regression's harness is the owner lane's (proving lane, CI steward); not yet named in the map", - "R2-F03-R01": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", - "R2-F03-R02": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", - "R2-F03-R03": "R2-F03 (P0, the external review): the regression's harness is the owner lane's (CI steward, hash lane (ProgramClass::V6 on freeze), pool lane); not yet named in the map", "R2-F04-R01": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", "R2-F04-R02": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", "R2-F04-R03": "R2-F04 (P0, the external review): the regression's harness is the owner lane's (node lane, reference apps, site (explorer)); not yet named in the map", diff --git a/tools/ci/test-record.mjs b/tools/ci/test-record.mjs index 8c16570c9..d292cae29 100644 --- a/tools/ci/test-record.mjs +++ b/tools/ci/test-record.mjs @@ -106,7 +106,10 @@ function record(reg, map, batch) { claim_impact: cell.claim_impact || batch.claim_impact || '', reviewer: cell.reviewer || batch.reviewer || '', at: now, ...(missing.length ? { blocked_on: missing, reason: `INT-17: missing ${missing.join(', ')}; never PASS without them` } : {}) }; c.evidence_records[cell.cell] = c.evidence_record; - const decs = Object.values(c.evidence_records).map((r) => r.decision); + // a lifted legacy 'record' entry that carries only a no-harness reason (no run) is not a run: it never counts in the combined + // decision and is dropped once a real cell lands (8 October 2026, 21:5x UK: R2-F03-R01 read NOT RUN on master beside its PASS cell) + for (const [k, r] of Object.entries(c.evidence_records)) if (k !== cell.cell && !r.run_id && !r.evidence && r.reason) delete c.evidence_records[k]; + const decs = Object.values(c.evidence_records).filter((r) => r.run_id || r.evidence || r.decision === 'BLOCKED').map((r) => r.decision); const combined = decs.includes('FAIL') ? 'FAIL' : decs.includes('BLOCKED') ? 'BLOCKED' : decs.every((d) => d === 'PASS') ? 'PASS' : 'NOT RUN'; c.run_status = combined; c.run_id = batch.run_id; c.updated = now; c.evidence_path = [...new Set(Object.values(c.evidence_records).map((r) => r.evidence).filter(Boolean))].join('; '); @@ -151,6 +154,10 @@ if (args.includes('--self-test')) { if (!badMethod) { console.log('self-test failed: a batch with no method was accepted (methods are never conflated)'); fails = 1; } const regO = { cases: [{ id: 'O1', method: 'Automated', accept: 'a', run_status: 'RUNNING', updated: 't', evidence_record: { cell: 'suite:x' } }, { id: 'O2', method: 'Automated', accept: 'b', run_status: 'DEFERRED' }] }; normalize(regO); if (!(regO.cases[0].run_status === 'NOT RUN' && regO.cases[0].in_progress_since === 't' && regO.cases[0].evidence_record.method === 'native' && regO.cases[1].run_status === 'NOT RUN' && /deferred/.test(regO.cases[1].deferral_note))) { console.log(`self-test failed: normalize: ${JSON.stringify(regO)}`); fails = 1; } + // a lifted reason-only record beside a real cell: the row reads the cell's decision and the placeholder is gone + const regL = { cases: [{ id: 'L1', method: 'Automated', accept: 'a', run_status: 'NOT RUN', evidence_records: { record: { decision: 'NOT RUN', reason: 'no harness yet', at: 't' } } }] }; + record(regL, { cells: { lc: { command: 'x', box_class: 'b', fixtures: [], cases: ['L1'] } }, not_run: {} }, { run_id: 'rl', manifest_sha: 'abc', method: 'native', cells: [{ cell: 'lc', status: 'PASS', evidence: '/e/l.log' }] }); + if (!(regL.cases[0].run_status === 'PASS' && !('record' in regL.cases[0].evidence_records))) { console.log(`self-test failed: a lifted reason-only record kept a PASS cell at NOT RUN or survived beside it: ${JSON.stringify(regL.cases[0].evidence_records)}`); fails = 1; } record(reg, map, { run_id: 'r1p', manifest_sha: 'abc', method: 'native', cells: [{ cell: 'pow', status: 'PASS', evidence: '/e/pow.log' }] }); if (acceptSnapshot(reg) !== before) { console.log('self-test failed: a record changed an accept text'); fails = 1; } if (!(touched.length === 1 && reg.cases[0].run_status === 'PASS' && reg.cases[0].run_id === 'r1p' && reg.cases[0].evidence_record.manifest_sha === 'abc' && reg.cases[0].evidence_path === '/e/pow.log' && reg.cases[0].updated)) { console.log(`self-test failed: the run was not written to the mapped case's live fields: ${JSON.stringify(reg.cases[0])}`); fails = 1; } diff --git a/tools/class-v5/arc-v6-bench.ps1 b/tools/class-v5/arc-v6-bench.ps1 new file mode 100644 index 000000000..a7d67b375 --- /dev/null +++ b/tools/class-v5/arc-v6-bench.ps1 @@ -0,0 +1,103 @@ +# Class v6 kit (8 October 2026, the coordinator's order): the arc job of the v5 script with the class v6 packs: hl-v6-foldrw (the +# known-failed partner; expected fingerprint 6ce3dc344a613500, the Mac's Metal and Apple OpenCL reading) and hl-v6-all (the +# all-together pack, id 9d40978601a7df2a; with the second zip its OpenCL text is the window's real text and the expected +# fingerprint is the CUDA reference e8f4f3289c6ee1fc; the first zip's stub refused it, that refusal line being that run's record). +# Kit fetch job fetch-class-v6-kit-20261008-g6 = the third zip packs-class-v6-20261008T194045Z.zip (735e1411...), generator 6 packs; the +# earlier dir fetch-class-v6-kit-20261008 holds zip 2 (generator 5) and stays as the generator 5 record's kit. +# Class v5 kit bench on the Intel Arc B580 (7 October 2026, 23:5x UK, main's word: the B580 is the eGPU of the second PC, +# so the Intel fingerprint runs there through the hash lane's job queue as a lock-free, non-elevated, quiet job, never beside +# an install or a build; the page names no PC): tools/class-v5/pc1-amd-v5-bench.ps1 with the device +# match on the Intel OpenCL platform (Arc / B580) instead of gfx1201; everything else identical (the v5-dn3-epoch0 pack, +# the v4-genesis control, RESULT lines, SUMMARY {json}). Expected fingerprint 6ce3dc344a613500. +# Class v5 kit bench on PC 1's RX 9070 XT (7 October 2026, docs/design/class-v5-stored-state.md section 13, "the kit: +# OpenCL (AMD)"): the kit's igneum-worker-opencl.exe (THIS tree's proto-opencl/host.c with the class v5 leaf upload: +# igneum_build(ds, cache, leaves, nLeaves, nItems), the leaves of leaves.bin checked against the pack's FNV-1a 64 first) +# runs --bench-pack on the first class v5 pack, proto-cuda/packs-ca3-v5/v5-dn3-epoch0 (program id e5a4ac5978462156, 11 +# leaves under state root 7e37a9fb..., cache FNV 7334fa46e5d972eb), on the gfx1201 device. Expected: the self-test +# PASS line (cache head, last line and FNV; dataset head, word [268435455] and 64 samples; 96 of 96 vector lanes) and the +# fingerprint of the 2^24 outputs at base nonce 0 equal to the Metal reading, 6ce3dc344a613500 (the M5 Max, 7 October +# 2026, 18:07:09Z). The v4-genesis control pack runs after it so the run has a known class v4 row beside the v5 row. +# Beside the miners (a correctness and fingerprint gate; the rate row is labelled loaded when the card mines): no card is +# switched, nothing is posted to the installed app, nothing is built on the PC. Published by the Counter ASIC coordinator +# only (the PC 1 queue is its); the kit is fetch job $kitId. Every result line starts with RESULT; SUMMARY {json} ends it. +# Post-review packs (8 October 2026, 20:4x UK, the third kit zip packs-class-v6-20261008T194045Z.zip, sha256 735e1411...): the packs are +# generator 6 (class v6; ids hl-v6-all 4de7b836cc40a4ea, hl-v6-foldrw d7eba30115d26dd4) and the expected fingerprints are the +# Mac's Metal and Apple OpenCL reading of them (all pack e8f4f3289c6ee1fc, partner 6ce3dc344a613500); the generator 5 zips' values +# (59e6708e46f1e87c and 5a6ad122a71a888f) belong to the superseded packs and no longer match by construction. +$ErrorActionPreference = 'Continue' +$jobName = 'arc-v6-bench' +$kitId = $env:IGNEUM_V5_KIT_ID; if (-not $kitId) { $kitId = 'fetch-class-v6-kit-20261008-g6' } # a fresh dir for the generator 6 zip: a fetch into the old dir left zip 2's files in place (PC 2, 20:17 UK) +$expected = '6ce3dc344a613500' +$started = Get-Date +function Stamp { (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') } +function Summary([string] $status, [hashtable] $extra) { + $o = [ordered]@{ job = $jobName; status = $status; duration_s = [int]((Get-Date) - $started).TotalSeconds; finished_at = (Stamp) } + foreach ($k in $extra.Keys) { $o[$k] = $extra[$k] } + 'SUMMARY ' + ($o | ConvertTo-Json -Compress -Depth 4) +} +"RESULT start $(Stamp) job=$jobName machine=$env:COMPUTERNAME app_version=$env:IGNEUM_APP_VERSION expected_fingerprint=$expected" +$jobs = Split-Path $env:IGNEUM_JOB_DIR +$kit = Join-Path $jobs $kitId +if (-not (Test-Path $kit)) { "RESULT error kit missing at $kit (the fetch job $kitId runs first; republish it after any app update)"; Summary 'failed' @{ error = 'kit missing' }; exit 2 } +$exe = Join-Path $kit 'bin\windows\igneum-worker-opencl.exe' +$packs = Join-Path $kit 'packs' +if (-not (Test-Path $exe)) { "RESULT error worker missing at $exe"; Summary 'failed' @{ error = 'worker missing' }; exit 2 } +"RESULT worker kit $exe sha256 $((Get-FileHash -Algorithm SHA256 $exe).Hash.ToLower()) bytes $((Get-Item $exe).Length)" +foreach ($pk in @('hl-v6-foldrw', 'hl-v6-all')) { + $d = Join-Path $packs $pk + if (-not (Test-Path (Join-Path $d 'kernel_bound.cl'))) { "RESULT error pack $pk missing at $d"; Summary 'failed' @{ error = "pack $pk missing" }; exit 2 } + "RESULT pack $pk kernel_bound.cl sha256 $((Get-FileHash -Algorithm SHA256 (Join-Path $d 'kernel_bound.cl')).Hash.ToLower()) program.h sha256 $((Get-FileHash -Algorithm SHA256 (Join-Path $d 'program.h')).Hash.ToLower())" +} +# the class v6 kit's packs each carry their own leaves.bin (the class v5 script checked one pack by name; the 18:01 UK run on +# PC 1 stopped on that name before the device list) +foreach ($lp in @('hl-v6-foldrw', 'hl-v6-all')) { + $leaves = Join-Path $packs ($lp + '\leaves.bin') + if (-not (Test-Path $leaves)) { "RESULT error leaves.bin missing at $leaves (a class v5 pack without its leaves builds nothing)"; Summary 'failed' @{ error = 'leaves missing'; pack = $lp }; exit 2 } + "RESULT leaves $lp $((Get-Item $leaves).Length) bytes sha256 $((Get-FileHash -Algorithm SHA256 $leaves).Hash.ToLower())" +} +# the OpenCL device index of the 9070 XT (the installed worker's list when present: the app's own indices) +$inst = @("$env:LOCALAPPDATA\Programs\Igneum Miner", "$env:ProgramFiles\Igneum Miner") | Where-Object { Test-Path (Join-Path $_ 'igneum-app.exe') } | Select-Object -First 1 +$listExe = $exe +if ($inst -and (Test-Path (Join-Path $inst 'igneum-worker-opencl.exe'))) { $listExe = Join-Path $inst 'igneum-worker-opencl.exe' } +$list = @(& $listExe --list 2>&1 | ForEach-Object { "$_" }) +$list | ForEach-Object { "RESULT list $_" } +$dev = $null +foreach ($l in $list) { if ($l -match '^\s*\[(\d+)\].*(Intel|Arc|B580)' -and $l -notmatch 'dup') { $dev = [int]$Matches[1]; break } } +if ($null -eq $dev) { "RESULT error no Intel Arc device in --list (the B580 is off the bus or has no OpenCL runtime: the Intel v5 row stays OWED)"; Summary 'failed' @{ error = 'no intel arc' }; exit 2 } +"RESULT device $dev Intel Arc (list from $listExe)" +function Workers { @(Get-CimInstance Win32_Process -Filter "Name = 'igneum-worker-opencl.exe' OR Name = 'igneum-worker-cuda.exe'" -ErrorAction SilentlyContinue | ForEach-Object { "$($_.Name):$($_.ProcessId):[$($_.CommandLine -replace '\s+', ' ')]" }) } +$w = @(Workers) +$loaded = ($w | Where-Object { $_ -match "igneum-worker-opencl.*--device\s+$dev(\s|$)" }).Count -gt 0 +"RESULT workers_before $(Stamp) $($w -join ' ')" +$state = if ($loaded) { 'loaded' } else { 'quiet' } +"RESULT context card_state=$state (a fingerprint gate: the load changes the rate row, never the bytes)" +$rows = @{} +$fpOk = $false +foreach ($pk in @('hl-v6-foldrw', 'hl-v6-all')) { + $d = Join-Path $packs $pk + $t0 = Get-Date + "RESULT bench $pk start $(Stamp) cmd=igneum-worker-opencl.exe --bench-pack --pack $d --device $dev --batch-log2 24 --batches 5" + $out = @(& $exe --bench-pack --pack $d --device $dev --batch-log2 24 --batches 5 2>&1 | ForEach-Object { "$_" }) + $code = $LASTEXITCODE + $secs = [int]((Get-Date) - $t0).TotalSeconds + # the whole stdout, line by line (the 09:36 UK run kept one line per pack and lost the host's exchange, kernel, + # rotate-fold and build-log lines, which the diagnosis needed) + foreach ($l in $out) { "RESULT bench $pk out $l" } + $res = $out | Where-Object { $_ -match '^RESULT ' } | Select-Object -Last 1 + $fp = ''; $mhs = ''; $check = '' + if ($res -match 'fingerprint=([0-9a-f]{16})') { $fp = $Matches[1] } + if ($res -match 'mhs=([0-9.]+)') { $mhs = $Matches[1] } + if ($res -match 'check=(\w+)') { $check = $Matches[1] } + $rows[$pk] = [ordered]@{ exit = $code; seconds = $secs; fingerprint = $fp; mhs = $mhs; check = $check; card_state = $state } + if ($pk -eq 'hl-v6-foldrw') { + $fpOk = ($fp -eq $expected -and $check -eq 'PASS') + "RESULT partner fingerprint=$fp expected=$expected match=$fpOk check=$check mhs=$mhs card_state=$state exit=$code seconds=$secs $(Stamp)" + } else { + # the all pack: with the window's OpenCL text (the second zip) a fingerprint, expected the CUDA reference e8f4f3289c6ee1fc + $allOk = ($fp -eq 'e8f4f3289c6ee1fc' -and $check -eq 'PASS') + "RESULT all-pack fingerprint=$fp expected=e8f4f3289c6ee1fc match=$allOk check=$check mhs=$mhs card_state=$state exit=$code seconds=$secs $(Stamp)" + } +} +"RESULT workers_after $(Stamp) $((@(Workers)) -join ' ')" +Summary $(if ($fpOk) { 'done' } else { 'failed' }) @{ expected = $expected; partner = $rows['hl-v6-foldrw']; all_pack = $rows['hl-v6-all']; device = $dev; kit = $kitId } +exit $(if ($fpOk) { 0 } else { 1 }) diff --git a/tools/class-v5/kits-remote.sh b/tools/class-v5/kits-remote.sh index 15c43d55c..e355bd5ab 100755 --- a/tools/class-v5/kits-remote.sh +++ b/tools/class-v5/kits-remote.sh @@ -13,9 +13,9 @@ # # Takes one of the box's build slots through infra/build-server/remote-run.sh (bs_remote_run), box 1 by default (the # build-server lane's word of 7 October 2026, 19:4x BST: the kit builds on build-1 explicitly). The work itself is -# tools/class-v5/kits-on-box.sh, a script file run by path on the box (the inline-rm rule of 21:33 BST); when the +# tools/class-v5/kits-on-box.sh (or KITS_BOX_SCRIPT=kits-v6-on-box.sh for the class v6 kit), a script file run by path on the box (the inline-rm rule of 21:33 BST); when the # build-server lane's lease tool is in place, the same file goes through `/srv/builds/_bin/lease pool -- bash -# tools/class-v5/kits-on-box.sh ...` with the label "v5 kit". +# tools/class-v5/${KITS_BOX_SCRIPT:-kits-on-box.sh} ...` with the label "v5 kit". set -euo pipefail HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" BS_TOOL=class-v5-kits @@ -34,9 +34,9 @@ ZIP="/srv/artefacts/packs/packs-ca3-v5-$STAMP.zip" bs_toolchain_check bs_sync_sources bs_log "sources at $WT (commit $BS_SHA on $BS_BRANCH); building the class v5 kits on box $BOX" -# the body runs from a script FILE at the worktree's mirror checkout (tools/class-v5/kits-on-box.sh, carried by the commit), never +# the body runs from a script FILE at the worktree's mirror checkout (tools/class-v5/${KITS_BOX_SCRIPT:-kits-on-box.sh}, carried by the commit), never # an inline string: main's rule of 7 October 2026, 21:33 BST (no rm, find -delete or truncation inside a bash -c string) -CMD="cd '$WT' && bash tools/class-v5/kits-on-box.sh '$STAMP' '$SKIP_EMU'" +CMD="cd '$WT' && bash tools/class-v5/${KITS_BOX_SCRIPT:-kits-on-box.sh} '$STAMP' '$SKIP_EMU'" set +e BR_KIND=build BR_COMMAND="class v5 kits (packfile-test, emu --check v5, Linux and Windows workers, kit zip)" BR_TARGET="x86_64-linux+windows" BR_ARTEFACTS="" \ bs_remote_run "$WT" "$BS_WT class-v5 kits" "$CMD" 2>&1 | tee "/tmp/v5-kits-$STAMP.log" | grep -E '^(STEP|FAIL|KIT|BIN|LOGS|check PASS|self-test|packfile-test|emu:| v5|build-remote: RESULT)' diff --git a/tools/class-v5/kits-v6-on-box.sh b/tools/class-v5/kits-v6-on-box.sh new file mode 100755 index 000000000..845cdbd5c --- /dev/null +++ b/tools/class-v5/kits-v6-on-box.sh @@ -0,0 +1,98 @@ +#!/usr/bin/env bash +# The class v5 kit build as it runs ON igneum-build-1 (called by tools/class-v5/kits-remote.sh through the build-server +# library's remote runner, from the worktree's mirror checkout, so this file travels with the commit). A script file by +# path, never an inline string: main's rule of 7 October 2026, 21:33 BST (no rm, find -delete or truncation inside a +# `bash -c` string; tools/ci/inline-rm-check.sh). What it does, in order: the pack loader test with the class v5 cases, +# the Linux and Windows builds of the two one-click workers, the CPU emulation's --check on the class v5 pack, then the +# kit zip at /srv/artefacts/packs/packs-ca3-v5-.zip with SHA256SUMS. Logs land in /srv/builds/_log/v5-class/kits-. +# bash tools/class-v5/kits-on-box.sh (cwd = the worktree root on the box) +set -u +STAMP="${1:?stamp}"; SKIP_EMU="${2:-0}" +ZIP="/srv/artefacts/packs/packs-class-v6-$STAMP.zip" +LOGDIR="/srv/builds/_log/v5-class/kits-$STAMP" +T=$(mktemp -d /tmp/v5-kits.XXXXXX); S=$T/stage; mkdir -p "$S/bin/linux" "$S/bin/windows" "$S/src" "$S/packs" "$S/tools" "$LOGDIR" +rc=0 +step() { echo "STEP $1 $(date -u +%H:%M:%SZ)"; } +fail() { echo "FAIL $1"; rc=1; } +finish() { cp "$T"/*.log "$LOGDIR"/ 2>/dev/null; echo "LOGS $LOGDIR"; rm -rf "$T"; } +# class v6 (8 October 2026, the coordinator's order): the all-together pack and its known-failed partner come from the hash +# lane's tgz files on build-1 (V6_ALL and V6_PARTNER, default hl-v6-all and hl-v6-foldrw), extracted beside the stage; +# the emulation check runs pack A = the all pack against pack B = the partner, and the two ids must differ +V6_ALL="${V6_ALL:-hl-v6-all}"; V6_PARTNER="${V6_PARTNER:-hl-v6-foldrw}" +PK=$T/v6packs; mkdir -p "$PK" +for p in "$V6_ALL" "$V6_PARTNER"; do tar -xzf "/srv/artefacts/packs/$p.tgz" -C "$PK" 2>/dev/null || { echo "FAIL no pack tgz /srv/artefacts/packs/$p.tgz"; exit 1; }; done +rm -rf "$PK"/._* "$PK"/*/._* 2>/dev/null +V5="$PK/$V6_ALL"; V6P="$PK/$V6_PARTNER" +echo "PACKS $V6_ALL id $(grep -oE 'IGNEUM_PROGRAM_ID 0x[0-9a-f]+' "$V5/program.h" | awk '{print $2}') | $V6_PARTNER id $(grep -oE 'IGNEUM_PROGRAM_ID 0x[0-9a-f]+' "$V6P/program.h" | awk '{print $2}')" +[ "$(grep -oE 'IGNEUM_PROGRAM_ID 0x[0-9a-f]+' "$V5/program.h")" != "$(grep -oE 'IGNEUM_PROGRAM_ID 0x[0-9a-f]+' "$V6P/program.h")" ] || { echo "FAIL the all pack and its partner carry one id"; exit 1; } +# the test's third argument is its class v5 known-good (the checked-in Devnet 3 epoch 0 pack, generator 5, 11 leaves); the kit's all +# pack is generator 6 since the post-review export (class v6, 93 leaves) and fails that check by construction (the third kit build, +# 20:38 UK), so the checked-in pack is named and the v6 packs are read by the emulation check below +step packfile-test +cc -std=c99 -Wall -Wextra -Wno-unused-function -O1 -o "$T/packfile-test" proto-cuda/nvrtc/emu/packfile-test.c && "$T/packfile-test" proto-cuda/packs/igneum-devnet-v4-epoch0 proto-cuda/packs-ca3-v5/v5-dn3-epoch0 > "$T/packfile-test.log" 2>&1 || fail "packfile-test ($(tail -1 "$T/packfile-test.log"))" +grep -E '^(FAIL| v5 pack)' "$T/packfile-test.log"; grep -c '^ok' "$T/packfile-test.log" | sed 's/^/packfile-test ok lines /' +step linux-opencl-worker +gcc -std=c99 -O2 -Wall -Wextra -Wno-stringop-truncation -Wno-format-truncation -DIGNEUM_CL_DYNAMIC -DCL_TARGET_OPENCL_VERSION=120 -I proto-cuda/packs/igneum-devnet-v4-epoch0 -DIGNEUM_KERNEL_PATH='"kernel_bound.cl"' -o "$S/bin/linux/igneum-worker-opencl" proto-opencl/host.c -ldl -lpthread 2> "$T/cl-linux.log" || { fail "linux opencl worker"; head -20 "$T/cl-linux.log"; } +step linux-cuda-worker +g++ -std=c++17 -O2 -Wall -Wextra -I proto-cuda/nvrtc -I /usr/local/cuda/include -o "$S/bin/linux/igneum-worker-cuda" proto-cuda/nvrtc/worker.cpp -ldl -lpthread 2> "$T/cuda-linux.log" || { fail "linux cuda worker"; head -20 "$T/cuda-linux.log"; } +step windows-cuda-worker +x86_64-w64-mingw32-g++ -std=c++17 -O2 -Wall -Wextra -static -I proto-cuda/nvrtc -I /usr/local/cuda/include -o "$S/bin/windows/igneum-worker-cuda.exe" proto-cuda/nvrtc/worker.cpp 2> "$T/cuda-win.log" && x86_64-w64-mingw32-strip "$S/bin/windows/igneum-worker-cuda.exe" || { fail "windows cuda worker"; head -20 "$T/cuda-win.log"; } +step windows-opencl-worker +# the Khronos CL headers alone (never -I /usr/include: that puts glibc's stdint.h ahead of mingw's) +mkdir -p "$T/inc" && cp -r /usr/include/CL "$T/inc/" +x86_64-w64-mingw32-gcc -std=c99 -O2 -Wall -Wextra -Wno-stringop-truncation -Wno-format-truncation -static -DIGNEUM_CL_DYNAMIC -DCL_TARGET_OPENCL_VERSION=120 -I "$T/inc" -I proto-cuda/packs/igneum-devnet-v4-epoch0 -DIGNEUM_KERNEL_PATH='"kernel_bound.cl"' -o "$S/bin/windows/igneum-worker-opencl.exe" proto-opencl/host.c 2> "$T/cl-win.log" && x86_64-w64-mingw32-strip "$S/bin/windows/igneum-worker-opencl.exe" || { fail "windows opencl worker"; head -20 "$T/cl-win.log"; } +if [ "$SKIP_EMU" = 0 ]; then + step emu-check-v5 + # the CPU emulation (proto-cuda/nvrtc/emu/test.sh's build) with pack A = the class v5 pack and pack B = the v4 control + E=$T/emu; mkdir -p "$E" + emu_kernel() { { echo '#include '; echo '#include '; echo "namespace $2 {"; sed -E 's/([A-Za-z_0-9]+)<<<([^,]+), ([^>]+)>>>\(/emu_launch(\1, \2, \3, /' "$1/$3.cu"; echo "}"; } > "$E/$3_$2.cpp"; g++ -std=c++17 -O2 -w -I proto-cuda/emu -I "$1" -c "$E/$3_$2.cpp" -o "$E/$3_$2.o"; } + emu_kernel "$V5" emu_pack_a kernel && emu_kernel "$V5" emu_pack_a kernel_bound && emu_kernel "$V6P" emu_pack_b kernel && emu_kernel "$V6P" emu_pack_b kernel_bound \ + && g++ -std=c++17 -O2 -Wall -Wextra -DIGNEUM_EMU -I proto-cuda/nvrtc -I /usr/local/cuda/include -c proto-cuda/nvrtc/worker.cpp -o "$E/worker.o" \ + && g++ -std=c++17 -O2 -Wall -Wextra -DIGNEUM_EMU -DIGNEUM_EMU_TWO_PACKS -I proto-cuda/nvrtc -I proto-cuda/emu -I /usr/local/cuda/include -c proto-cuda/nvrtc/emu/emu_backend.cpp -o "$E/emu_backend.o" \ + && g++ -std=c++17 -O2 -w -I proto-cuda/emu -c proto-cuda/emu/shim.cpp -o "$E/shim.o" \ + && g++ -o "$E/igneum-worker-cuda-emu" "$E"/*.o -pthread 2> "$T/emu-build.log" || { fail "emu build"; head -30 "$T/emu-build.log"; } + if [ -x "$E/igneum-worker-cuda-emu" ]; then + ( IGNEUM_EMU_PACK="$V5" IGNEUM_EMU_PACK2="$V6P" timeout 1500 nice -n 10 "$E/igneum-worker-cuda-emu" --check --pack "$V5" > "$T/emu-check.log" 2>&1 ) || fail "emu --check on the class v5 pack (rc $?)" + grep -E '^check PASS|self-test|FAIL|error' "$T/emu-check.log" | cut -c1-400 + fi +fi +if [ "$rc" != 0 ]; then echo "KIT not written: a step failed (rc $rc)"; finish; exit 1; fi +step stage +for p in "$V6_ALL" "$V6_PARTNER"; do mkdir -p "$S/packs/$p"; cp "$PK/$p"/* "$S/packs/$p/"; done +cp proto-cuda/nvrtc/worker.cpp proto-cuda/nvrtc/packfile.h proto-cuda/nvrtc/cuda_api.h proto-opencl/host.c proto-opencl/cl_dynamic.h proto-newpow/class-v5/bench.cu proto-newpow/class-v5/run.sh proto-metal/packbench.swift "$S/src/" +cp tools/class-v5/fleet-cuda-v5-bench.sh tools/class-v5/pc1-amd-v5-bench.ps1 "$S/tools/" +cat > "$S/README.txt" <<'R' +packs-class-v6: the class v6 kit (Igneum, 8 October 2026; docs/design/class-v5-stored-state.md section 0, the class v6 row): the all-together pack and its known-failed partner +packs/v5-dn3-epoch0 the first class v5 pack: Devnet 3 epoch 0, program id e5a4ac5978462156, 11 state leaves (leaves.bin, 704 B) under + state root 7e37a9fb19b154d32daf5bf30a50d339a75029fbc9eec9ea20e95439dba5a311, cache FNV-1a 64 7334fa46e5d972eb + expected fingerprint of the 2^24 outputs at base nonce 0: 82b19cbde8557ea5 (Metal, M5 Max, 18:07:09Z) on every platform +packs/v5-genesis the string-seed class v5 pack over the devnet's 93 leaves; packs/v4-genesis the class v4 control (sub-version 3) +bin/linux igneum-worker-cuda (NVRTC, libcuda + libnvrtc.so.12 at run time), igneum-worker-opencl (libOpenCL.so.1 at run time) +bin/windows igneum-worker-cuda.exe (nvcuda.dll + nvrtc64 at run time), igneum-worker-opencl.exe (OpenCL.dll at run time) +Every worker reads a class v5 pack's leaves.bin, checks it against the pack's IGNEUM_STATE_LEAVES_FNV64, uploads it for igneum_build and +frees it after the build; a pack without its leaves builds nothing. Self-test: cache head, last line and FNV; dataset head, last word and +64 samples; 96 vector lanes. Bench: igneum-worker-cuda --bench --pack packs/v5-dn3-epoch0 --batch-log2 24 (fleet-cuda-v5-bench.sh); +igneum-worker-opencl --bench-pack --pack packs/v5-dn3-epoch0 --batch-log2 24 --device (pc1-amd-v5-bench.ps1); src/bench.cu with nvcc. +Intel: not measured tonight (7 October 2026); no Arc B580 sits on PC 1 or PC 2 and the only Arc path needs a driver click, which no PC job +may raise; the card's holder and a click-free driver path are owed. The OpenCL worker takes the Intel device by index the same way. +R +( cd "$S" && find . -type f ! -name SHA256SUMS | sort | xargs sha256sum > SHA256SUMS ) +mkdir -p /srv/artefacts/packs +python3 - "$S" "$ZIP" <<'PY' +import os, sys, zipfile +stage, out = sys.argv[1], sys.argv[2] +with zipfile.ZipFile(out, 'w', zipfile.ZIP_DEFLATED) as z: + for dp, dn, fn in os.walk(stage): + dn.sort() + for f in sorted(fn): + p = os.path.join(dp, f); rel = os.path.relpath(p, stage) + zi = zipfile.ZipInfo(rel, date_time=(2026, 10, 7, 0, 0, 0)); zi.compress_type = zipfile.ZIP_DEFLATED + zi.external_attr = (0o755 if rel.startswith('bin/') or rel.endswith('.sh') else 0o644) << 16 + with open(p, 'rb') as fh: z.writestr(zi, fh.read()) +PY +sha256sum "$ZIP" | cut -c1-64 > "$ZIP.sha256" +echo "KIT $ZIP bytes $(stat -c %s "$ZIP") files $(python3 -c "import zipfile,sys; print(len(zipfile.ZipFile(sys.argv[1]).namelist()))" "$ZIP")" +echo "KIT sha256 $(cat "$ZIP.sha256")" +for b in "$S"/bin/linux/* "$S"/bin/windows/*; do echo "BIN $(basename "$(dirname "$b")")/$(basename "$b") $(stat -c %s "$b") bytes sha256 $(sha256sum "$b" | cut -c1-64)"; done +finish +exit 0 diff --git a/tools/class-v5/pc1-v6-bench.ps1 b/tools/class-v5/pc1-v6-bench.ps1 new file mode 100644 index 000000000..84f8349cd --- /dev/null +++ b/tools/class-v5/pc1-v6-bench.ps1 @@ -0,0 +1,95 @@ +# Class v6 kit (8 October 2026, the coordinator's order): the amd job of the v5 script with the class v6 packs: hl-v6-foldrw (the +# known-failed partner; expected fingerprint 6ce3dc344a613500, the Mac's Metal and Apple OpenCL reading) and hl-v6-all (the +# all-together pack, id 9d40978601a7df2a; with the second zip its OpenCL text is the window's real text and the expected +# fingerprint is the CUDA reference e8f4f3289c6ee1fc; the first zip's stub refused it, that refusal line being that run's record). +# Kit fetch job fetch-class-v6-kit-20261008 = the second zip (packs-class-v6-.zip named in the job's publish line). +# Class v5 kit bench on PC 1's RX 9070 XT (7 October 2026, docs/design/class-v5-stored-state.md section 13, "the kit: +# OpenCL (AMD)"): the kit's igneum-worker-opencl.exe (THIS tree's proto-opencl/host.c with the class v5 leaf upload: +# igneum_build(ds, cache, leaves, nLeaves, nItems), the leaves of leaves.bin checked against the pack's FNV-1a 64 first) +# runs --bench-pack on the first class v5 pack, proto-cuda/packs-ca3-v5/v5-dn3-epoch0 (program id e5a4ac5978462156, 11 +# leaves under state root 7e37a9fb..., cache FNV 7334fa46e5d972eb), on the gfx1201 device. Expected: the self-test +# PASS line (cache head, last line and FNV; dataset head, word [268435455] and 64 samples; 96 of 96 vector lanes) and the +# fingerprint of the 2^24 outputs at base nonce 0 equal to the Metal reading, 6ce3dc344a613500 (the M5 Max, 7 October +# 2026, 18:07:09Z). The v4-genesis control pack runs after it so the run has a known class v4 row beside the v5 row. +# Beside the miners (a correctness and fingerprint gate; the rate row is labelled loaded when the card mines): no card is +# switched, nothing is posted to the installed app, nothing is built on the PC. Published by the Counter ASIC coordinator +# only (the PC 1 queue is its); the kit is fetch job $kitId. Every result line starts with RESULT; SUMMARY {json} ends it. +# Post-review packs (8 October 2026, 20:4x UK, the third kit zip packs-class-v6-20261008T194045Z.zip, sha256 735e1411...): the packs are +# generator 6 (class v6; ids hl-v6-all 4de7b836cc40a4ea, hl-v6-foldrw d7eba30115d26dd4) and the expected fingerprints are the +# Mac's Metal and Apple OpenCL reading of them (all pack e8f4f3289c6ee1fc, partner 6ce3dc344a613500); the generator 5 zips' values +# (59e6708e46f1e87c and 5a6ad122a71a888f) belong to the superseded packs and no longer match by construction. +$ErrorActionPreference = 'Continue' +$jobName = 'pc1-v6-bench' +$kitId = $env:IGNEUM_V5_KIT_ID; if (-not $kitId) { $kitId = 'fetch-class-v6-kit-20261008' } +$expected = '6ce3dc344a613500' +$started = Get-Date +function Stamp { (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') } +function Summary([string] $status, [hashtable] $extra) { + $o = [ordered]@{ job = $jobName; status = $status; duration_s = [int]((Get-Date) - $started).TotalSeconds; finished_at = (Stamp) } + foreach ($k in $extra.Keys) { $o[$k] = $extra[$k] } + 'SUMMARY ' + ($o | ConvertTo-Json -Compress -Depth 4) +} +"RESULT start $(Stamp) job=$jobName machine=$env:COMPUTERNAME app_version=$env:IGNEUM_APP_VERSION expected_fingerprint=$expected" +$jobs = Split-Path $env:IGNEUM_JOB_DIR +$kit = Join-Path $jobs $kitId +if (-not (Test-Path $kit)) { "RESULT error kit missing at $kit (the fetch job $kitId runs first; republish it after any app update)"; Summary 'failed' @{ error = 'kit missing' }; exit 2 } +$exe = Join-Path $kit 'bin\windows\igneum-worker-opencl.exe' +$packs = Join-Path $kit 'packs' +if (-not (Test-Path $exe)) { "RESULT error worker missing at $exe"; Summary 'failed' @{ error = 'worker missing' }; exit 2 } +"RESULT worker kit $exe sha256 $((Get-FileHash -Algorithm SHA256 $exe).Hash.ToLower()) bytes $((Get-Item $exe).Length)" +foreach ($pk in @('hl-v6-foldrw', 'hl-v6-all')) { + $d = Join-Path $packs $pk + if (-not (Test-Path (Join-Path $d 'kernel_bound.cl'))) { "RESULT error pack $pk missing at $d"; Summary 'failed' @{ error = "pack $pk missing" }; exit 2 } + "RESULT pack $pk kernel_bound.cl sha256 $((Get-FileHash -Algorithm SHA256 (Join-Path $d 'kernel_bound.cl')).Hash.ToLower()) program.h sha256 $((Get-FileHash -Algorithm SHA256 (Join-Path $d 'program.h')).Hash.ToLower())" +} +# the class v6 kit's packs each carry their own leaves.bin (the class v5 script checked one pack by name; the 18:01 UK run on +# PC 1 stopped on that name before the device list) +foreach ($lp in @('hl-v6-foldrw', 'hl-v6-all')) { + $leaves = Join-Path $packs ($lp + '\leaves.bin') + if (-not (Test-Path $leaves)) { "RESULT error leaves.bin missing at $leaves (a class v5 pack without its leaves builds nothing)"; Summary 'failed' @{ error = 'leaves missing'; pack = $lp }; exit 2 } + "RESULT leaves $lp $((Get-Item $leaves).Length) bytes sha256 $((Get-FileHash -Algorithm SHA256 $leaves).Hash.ToLower())" +} +# the OpenCL device index of the 9070 XT (the installed worker's list when present: the app's own indices) +$inst = @("$env:LOCALAPPDATA\Programs\Igneum Miner", "$env:ProgramFiles\Igneum Miner") | Where-Object { Test-Path (Join-Path $_ 'igneum-app.exe') } | Select-Object -First 1 +$listExe = $exe +if ($inst -and (Test-Path (Join-Path $inst 'igneum-worker-opencl.exe'))) { $listExe = Join-Path $inst 'igneum-worker-opencl.exe' } +$list = @(& $listExe --list 2>&1 | ForEach-Object { "$_" }) +$list | ForEach-Object { "RESULT list $_" } +$dev = $null +foreach ($l in $list) { if ($l -match '^\s*\[(\d+)\].*gfx1102' -and $l -notmatch 'dup') { $dev = [int]$Matches[1]; break } } +if ($null -eq $dev) { "RESULT error no gfx1102 device in --list (the RX 7600 is off the bus: the AMD class v6 row stays OWED)"; Summary 'failed' @{ error = 'no gfx1102' }; exit 2 } +"RESULT device $dev gfx1102 (list from $listExe)" +function Workers { @(Get-CimInstance Win32_Process -Filter "Name = 'igneum-worker-opencl.exe' OR Name = 'igneum-worker-cuda.exe'" -ErrorAction SilentlyContinue | ForEach-Object { "$($_.Name):$($_.ProcessId):[$($_.CommandLine -replace '\s+', ' ')]" }) } +$w = @(Workers) +$loaded = ($w | Where-Object { $_ -match "igneum-worker-opencl.*--device\s+$dev(\s|$)" }).Count -gt 0 +"RESULT workers_before $(Stamp) $($w -join ' ')" +$state = if ($loaded) { 'loaded' } else { 'quiet' } +"RESULT context card_state=$state (a fingerprint gate: the load changes the rate row, never the bytes)" +$rows = @{} +$fpOk = $false +foreach ($pk in @('hl-v6-foldrw', 'hl-v6-all')) { + $d = Join-Path $packs $pk + $t0 = Get-Date + "RESULT bench $pk start $(Stamp) cmd=igneum-worker-opencl.exe --bench-pack --pack $d --device $dev --batch-log2 24 --batches 5" + $out = @(& $exe --bench-pack --pack $d --device $dev --batch-log2 24 --batches 5 2>&1 | ForEach-Object { "$_" }) + $code = $LASTEXITCODE + $secs = [int]((Get-Date) - $t0).TotalSeconds + foreach ($l in $out) { if ($l -match '^(pack |class v5|RESULT |FAIL|error|warm-up)') { "RESULT bench $pk out $l" } } + $res = $out | Where-Object { $_ -match '^RESULT ' } | Select-Object -Last 1 + $fp = ''; $mhs = ''; $check = '' + if ($res -match 'fingerprint=([0-9a-f]{16})') { $fp = $Matches[1] } + if ($res -match 'mhs=([0-9.]+)') { $mhs = $Matches[1] } + if ($res -match 'check=(\w+)') { $check = $Matches[1] } + $rows[$pk] = [ordered]@{ exit = $code; seconds = $secs; fingerprint = $fp; mhs = $mhs; check = $check; card_state = $state } + if ($pk -eq 'hl-v6-foldrw') { + $fpOk = ($fp -eq $expected -and $check -eq 'PASS') + "RESULT partner fingerprint=$fp expected=$expected match=$fpOk check=$check mhs=$mhs card_state=$state exit=$code seconds=$secs $(Stamp)" + } else { + # the all pack: with the window's OpenCL text (the second zip) a fingerprint, expected the CUDA reference e8f4f3289c6ee1fc + $allOk = ($fp -eq 'e8f4f3289c6ee1fc' -and $check -eq 'PASS') + "RESULT all-pack fingerprint=$fp expected=e8f4f3289c6ee1fc match=$allOk check=$check mhs=$mhs card_state=$state exit=$code seconds=$secs $(Stamp)" + } +} +"RESULT workers_after $(Stamp) $((@(Workers)) -join ' ')" +Summary $(if ($fpOk) { 'done' } else { 'failed' }) @{ expected = $expected; partner = $rows['hl-v6-foldrw']; all_pack = $rows['hl-v6-all']; device = $dev; kit = $kitId } +exit $(if ($fpOk) { 0 } else { 1 }) diff --git a/tools/fleet/box-dn3.sh b/tools/fleet/box-dn3.sh new file mode 100644 index 000000000..040d97805 --- /dev/null +++ b/tools/fleet/box-dn3.sh @@ -0,0 +1,77 @@ +#!/usr/bin/env bash +# A Devnet 3 box (7 October 2026, the founder's clock: a fresh chain from genesis on 0.3.22, network igneum-devnet-3, every activation at 0, +# NO override file). Modelled on box-dn2.sh. The node runs with NET_ARGS (default "--devnet --devnet-suffix=3": own handshake magic, +# own data directory $F/$APPDIR; a live-devnet or Devnet 2 peer refuses it at the handshake), peered with SEED (comma list); one miner on +# card 0 with the box's vote key; PROVER=1 adds the segment prover loop (CHAIN_NAME igneum-devnet-3). NODE_BIN names the igneumd. +# FRESH=1 wipes $F/$APPDIR (a new genesis); UNSYNCED=1 adds --enable-unsynced-mining (the genesis boxes: a fresh chain's nodes start +# unsynced and must mine anyway). RPC_PORT, P2P_PORT, EVM_PORT: other ports on a box whose live node holds 26610/26611/26790 +# (a standing box running a second node for Devnet 3: 36610/36611/36790). Nothing here touches the live devnet's node or miner. +set -uo pipefail +mkdir -p /root/fleet/pids; echo $$ > /root/fleet/pids/loop.pid # 15:3xZ 8 Oct 2026: kills by pid file only (main): loop.pid, node.pid, miner.pid under /root/fleet/pids +F=/root/fleet; OUT=$F/out; mkdir -p $F/in $OUT $F/$APPDIR $F/mine/packs; exec >> $OUT/dn3.log 2>&1 +stamp() { date -u +%Y-%m-%dT%H:%M:%SZ; } +LABEL="${LABEL:-dn3}"; WALLET="${WALLET:-0x1919191919191919191919191919191919191919}"; SEED="${SEED:-}"; NODE_BIN="${NODE_BIN:-$F/in/igneumd-0322}" +APPDIR="${APPDIR:-dn3}"; PACK="${PACK:-dn3}"; CHAIN_NAME="${CHAIN_NAME:-igneum-devnet-3}" # 15:4xZ 8 Oct 2026: devnet-4 takes APPDIR=dn4 PACK=dn4 CHAIN_NAME=igneum-devnet-4 NET_ARGS="--devnet --devnet-suffix=4" +PROVER="${PROVER:-0}"; UNSYNCED="${UNSYNCED:-}"; RPC_PORT="${RPC_PORT:-26610}"; P2P_PORT="${P2P_PORT:-26611}"; EVM_PORT="${EVM_PORT:-26790}"; JSON_PORT="${JSON_PORT:-$((RPC_PORT+2080))}"; MINE="${MINE:-1}" +NET_ARGS="${NET_ARGS:---devnet --devnet-suffix=3}"; P2P_LISTEN="${P2P_LISTEN:-0.0.0.0:$P2P_PORT}"; MINER_ONLY="${MINER_ONLY:-0}"; ANNOUNCE="${ANNOUNCE:-}"; export -n MINER_ONLY # 21:3xZ 7 Oct 2026: never in the loop's environment (the puller restarts from it; MINER_ONLY=1 there would leave the node down at the next move) # MINER_ONLY=1: the node stays, only the miner loop restarts (with --announce ip:port when ANNOUNCE is set: the peer directory) +JSONF="--rpclisten-json=127.0.0.1:$JSON_PORT"; case " $NET_ARGS ${EXTRA_ARGS:-} " in *rpclisten-json*) JSONF="";; esac # 13:3xZ 8 Oct: the pool boxes already carry it in NET_ARGS (dn3-pool-b: "cannot be used multiple times") +MINER_BIN="${MINER_BIN:-$F/in/igneum-miner-0322}" # the 0.3.22 miner (sub-version 3 draw); the hive package's 0.3.20 miner is the live devnet's and never mines Devnet 3 (16:5xZ: every block BlockInvalid) +[ -x "$NODE_BIN" ] || { echo "RESULT dn3_failed $(stamp) no node binary at $NODE_BIN"; exit 2; } +[ "${MINE:-1}" = 1 ] && { [ -x "$MINER_BIN" ] || { echo "RESULT dn3_failed $(stamp) no 0.3.22 miner at $MINER_BIN"; exit 2; }; } +# the pack-id gate (main through the shipper, 7 Oct 2026 17:0xZ): BEFORE the miner starts, the worker's pack and the node's engine must come +# from the same igneum-pow pin. Tonight's shape (the shipper, 17:05Z): BY CONSTRUCTION, the pack the worker hashes is EXPORTED on this box by the +# paired 0.3.22 miner (MINER_BIN's sha equals PAIR_MINER_SHA16, default 07246920fd9fe895 = igneum-pow 017e7037, the node's pin), never a copied kit; +# a different miner sha or a pre-shipped pack directory is UNREADABLE and holds the miner. The id-equality read over RPC (a785001687d8688a against +# the kit's id) replaces it from the next cut when the node lane names the method (NODE_ID_CMD / PACK_ID_CMD). +pack_gate() { + local msha want; msha=$(sha256sum "$MINER_BIN" | cut -c1-16); want="${PAIR_MINER_SHA16:-07246920fd9fe895 c29f33bbbd284a12 dfdc6883aa79a76f fb147dd1754cbfc0 cfa9f5ca382e0efc} $(cat $F/in/pair-miners.txt 2>/dev/null | tr '\n' ' ')" # 8 Oct 2026 09:4xZ: the list is also a FILE the puller appends every move's miner sha to (the 10:05 move: 18 miners refused for a sha only in a hand-edited default) # the two paired 0.3.22 miners (hands / node-lane builds, both igneum-pow 017e7037) + if [ -n "${NODE_ID_CMD:-}" ] && [ -n "${PACK_ID_CMD:-}" ]; then + local pid nid; pid=$(eval "$PACK_ID_CMD" 2>/dev/null); nid=$(eval "$NODE_ID_CMD" 2>/dev/null) + [ -n "$pid" ] && [ -n "$nid" ] || { echo "RESULT dn3_pack_gate $(stamp) UNREADABLE pack_id=${pid:-none} node_id=${nid:-none}"; return 1; } + [ "$pid" = "$nid" ] || { echo "RESULT dn3_pack_gate $(stamp) REFUSED pack_id=$pid node_id=$nid"; return 1; } + echo "RESULT dn3_pack_gate $(stamp) PASS by id pack_id=$pid node_id=$nid"; return 0 + fi + case " $want " in *" $msha "*) ;; *) echo "RESULT dn3_pack_gate $(stamp) UNREADABLE miner=$msha is not a paired miner ($want); a pre-shipped kit or another miner"; return 1;; esac + [ -e $F/mine/packs/$PACK ] && { echo "RESULT dn3_pack_gate $(stamp) UNREADABLE packs/$PACK already present before this export (a copied kit?)"; return 1; } + echo "RESULT dn3_pack_gate $(stamp) PASS by construction (miner $msha = pair, pack exported here by it, generator v4 sub-version 3)"; return 0 +} +echo "RESULT dn3_start $(stamp) label=$LABEL node=$(sha256sum $NODE_BIN | cut -c1-16) miner=$(sha256sum $MINER_BIN 2>/dev/null | cut -c1-16) seed=${SEED:-none} prover=$PROVER mine=$MINE net=\"$NET_ARGS\" ports=$RPC_PORT/$P2P_PORT/$EVM_PORT" +command -v curl >/dev/null || { apt-get update -qq >/dev/null 2>&1; apt-get install -y -qq curl ca-certificates python3 >/dev/null 2>&1; } +if [ ! -x /opt/igneum/pkg/bin/igneum-miner ]; then + read -r PKG_PATH PKG_SHA PKG_VER <<< "$(curl -fsSL -m 30 https://dl.igneum.network/dl/public/igneum-downloads.json | python3 -c 'import sys,json; d=json.load(sys.stdin)["files"]["miner-hive"]; print(d["path"], d["sha256"], d["version"])')" + curl -fsSL -o $F/pkg.tgz "https://dl.igneum.network$PKG_PATH" && echo "$PKG_SHA $F/pkg.tgz" | sha256sum -c - >/dev/null && mkdir -p /opt/igneum/pkg && tar -C /opt/igneum/pkg --strip-components=1 -xzf $F/pkg.tgz || { echo "RESULT dn3_failed package"; exit 2; } +fi +B=/opt/igneum/pkg/bin +# the Devnet 3 node and its miner only (anchored on the dn3 appdir and this RPC port), never the live node beside it +# kills by pid file only (founder 8 Oct 2026, by construction: pkill and killall are shimmed to exit 97 on every box) +pidkill() { local P; P=$(cat "$F/pids/$1.pid" 2>/dev/null); [ -n "$P" ] && kill -0 "$P" 2>/dev/null && { kill -TERM "$P" 2>/dev/null; sleep 2; kill -0 "$P" 2>/dev/null && kill -9 "$P" 2>/dev/null; }; return 0; } +[ "$MINER_ONLY" = 1 ] || pidkill node; pidkill miner; sleep 2 +[ "${FRESH:-0}" = 1 ] && { rm -rf $F/$APPDIR; mkdir -p $F/$APPDIR; [ -s $F/$APPDIR-node.log ] && mv $F/$APPDIR-node.log $F/$APPDIR-node.prev.log; echo "RESULT dn3_fresh $(stamp) appdir wiped for the genesis"; } +PEER=""; for sd in ${SEED//,/ }; do PEER="$PEER --addpeer=$sd"; done +UNS=""; [ "$UNSYNCED" = 1 ] && UNS="--enable-unsynced-mining" +if [ "$MINER_ONLY" != 1 ]; then +echo "=== dn3 node start $(stamp) $(sha256sum $NODE_BIN | cut -c1-16)" >> $F/$APPDIR-node.log +IGNEUM_PROOF_PROGRAM_IDS="${PROGRAM_IDS:-}" IGNEUM_PROOF_VERIFIER="${HOST_VERIFIER:-}" setsid nohup $NODE_BIN $NET_ARGS --appdir=$F/$APPDIR --rpclisten=0.0.0.0:$RPC_PORT --evm-rpclisten=127.0.0.1:$EVM_PORT $JSONF --listen=$P2P_LISTEN $PEER $UNS --unsaferpc --nodnsseed --disable-upnp --nologfiles --yes > $F/$APPDIR-node.log 2>&1 & + echo $! > $F/pids/node.pid +sleep 10 +echo "RESULT dn3_node $(stamp) pid=$(pgrep -f '[/]root/fleet/in/igneumd-[0-9a-f]+ .* --appdir=/root/fleet/$APPDIR ' | head -1) version=$(grep -oE 'igneumd/[0-9]+\.[0-9]+\.[0-9]+-[0-9a-f]+' $F/$APPDIR-node.log | tail -1) digest=$(grep -o 'digest: [0-9a-f]*' $F/$APPDIR-node.log | tail -1 | awk '{print substr($2,1,16)}') network=$(grep -oiE 'igneum-devnet-[0-9][^ ,]*' $F/$APPDIR-node.log | head -1) genesis=$(grep -oiE 'genesis[^\n]{0,120}' $F/$APPDIR-node.log | grep -oE '[0-9a-f]{64}' | head -1 | cut -c1-16)" +for i in $(seq 1 30); do w="$($B/igneum-miner watch 1 grpc://127.0.0.1:$RPC_PORT 2>/dev/null | grep -o 'blocks=[0-9]*.*synced=[a-z]*' | tail -1)"; [ -n "$w" ] && break; sleep 5; done +echo "RESULT dn3_watch $(stamp) $(printf '%s' "$w" | sed -E 's/difficulty=[0-9.]* sink=[0-9a-f]* //')" +fi +rm -rf $F/mine/packs/$PACK.prev; [ -e $F/mine/packs/$PACK ] && mv $F/mine/packs/$PACK $F/mine/packs/$PACK.prev # the previous run's export, moved aside so the gate sees a clean slot +if [ "$MINE" = 1 ] && ! pack_gate; then echo "RESULT dn3_miner_refused $(stamp) the pack-id gate refused the place; node runs, miner off"; MINE=0; fi +if [ "$MINE" = 1 ]; then + cd $F/mine && rm -rf packs/$PACK && $MINER_BIN export-pack grpc://127.0.0.1:$RPC_PORT packs/$PACK > $OUT/dn3-export-pack.log 2>&1 + ( echo $BASHPID > $F/pids/miner-loop.pid; while :; do $MINER_BIN mine grpc://127.0.0.1:$RPC_PORT 1 100000000 "$LABEL" --exec-rpc http://127.0.0.1:$EVM_PORT --worker $WORKER_BIN --worker-args "--device 0 --pack packs/$PACK" --prepare-packs packs/$PACK-prepare --exit-on-seed-change ${ANNOUNCE:+--announce $ANNOUNCE} --evm-address "$WALLET" --payout-label "$LABEL" --status-secs 30 >> $OUT/dn3-miner.log 2>&1 & echo $! > $F/pids/miner.pid; wait $(cat $F/pids/miner.pid); sleep 5; done ) /dev/null 2>&1 & + echo "RESULT dn3_miner_started $(stamp) miner=$(sha256sum $MINER_BIN | cut -c1-16) announce=${ANNOUNCE:-none}" + # the engine's program id as the paired miner prints it ("class v4 program id <16 hex>", the node lane 17:0xZ): a785001687d8688a on sub-version 3, + # 1a4230699a6b9c60 is the 0.3.20 kit (known-failed); logged as the gate's id line, refused on the known-failed value + # the worker form prints no id (the node lane, main.rs 1471): a second one-thread CPU miner beside the worker for 20 s prints "class v4 program id <16 hex>" + timeout 60 $MINER_BIN mine grpc://127.0.0.1:$RPC_PORT 1 20 idread --engine igneum-pow --no-vote --stall-secs 0 > $OUT/dn3-idread.log 2>&1 > $OUT/dn3-prover-launch.log 2>&1 & + echo "RESULT dn3_prover_started $(stamp)" +fi diff --git a/tools/fleet/box-ember.sh b/tools/fleet/box-ember.sh index e278c4497..db5f1bfae 100755 --- a/tools/fleet/box-ember.sh +++ b/tools/fleet/box-ember.sh @@ -1,4 +1,5 @@ #!/usr/bin/env bash +. /root/fleet/in/pidkill.sh # kills by pid only (founder 8 Oct 2026) # Ember Tune's two-knob ladder on a rented NVIDIA card (docs/plans/ember-tune.md, branch ember-tune): the miner runs # throughout; the power ladder 100, 90, 80, 70, 60, 50% of the default limit at the unlocked clock (clamped at the # card's reported minimum), then the clock ladder 90, 80, 70, 60% of the maximum graphics clock at the power the @@ -15,7 +16,7 @@ stamp() { date -u +%Y-%m-%dT%H:%M:%SZ; } say() { echo "$(stamp) $*"; } q() { nvidia-smi --query-gpu="$1" --format=csv,noheader,nounits -i 0 2>/dev/null | head -1 | tr -d ' '; } NAME="$(q name)"; DRV="$(q driver_version)"; PDEF="$(q power.default_limit)"; PMIN="$(q power.min_limit)"; PMAX="$(q power.max_limit)"; CMAX="$(q clocks.max.graphics)" -pkill -x sp1-gpu-server 2>/dev/null; rm -f /tmp/sp1-cuda-*.sock +. /root/fleet/in/pidkill.sh; kill_sock_owner 'sp1-cuda-[0-9]*\.sock' echo "RESULT start $(stamp) card=$NAME driver=$DRV power_default_w=$PDEF min_w=$PMIN max_w=$PMAX clock_max_mhz=$CMAX" # can we set anything? nvidia-smi -i 0 -pl "$PDEF" >/dev/null 2>&1 && PL_OK=1 || PL_OK=0 @@ -27,7 +28,7 @@ rm -rf packs/devnet; $B/igneum-miner export-pack grpc://127.0.0.1:26610 packs/de nohup $B/igneum-miner mine grpc://127.0.0.1:26610 1 100000000 "$LABEL" --worker $B/igneum-worker-cuda --worker-args "--device 0 --pack packs/devnet" \ --prepare-packs packs/prepare --exit-on-seed-change --evm-address "$WALLET" --payout-label "$LABEL" --status-secs 10 > $OUT/ember-miner.log 2>&1 & MPID=$!; cd $F -cleanup() { nvidia-smi -i 0 -rgc >/dev/null 2>&1; [ "$PL_OK" = 1 ] && nvidia-smi -i 0 -pl "$PDEF" >/dev/null 2>&1; kill $MPID 2>/dev/null; pkill -f '[/]opt/igneum/pkg/bin/igneum-worker-cuda' 2>/dev/null; } +cleanup() { nvidia-smi -i 0 -rgc >/dev/null 2>&1; [ "$PL_OK" = 1 ] && nvidia-smi -i 0 -pl "$PDEF" >/dev/null 2>&1; kill_children $MPID; kill $MPID 2>/dev/null; } trap cleanup EXIT say "miner warming 90 s"; sleep 90 STEPS=$OUT/ember-steps.jsonl; : > $STEPS @@ -38,7 +39,7 @@ step() { #