From a7779ba615a0a1994c269959cb5948492032d7d1 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 18:58:50 +0000 Subject: [PATCH 1/4] Reference apps, Review B F04: a recovery lock is never presented as a final lock The light service maps the node's lockKind (igneum_getFinalityCheckpoints, 2.0.2 line) to lock_state beside every certificate it answers with; core.js reads it as one step on /light and /receipt, refuses an unknown kind and a receipt that claims final under a reported recovery lock; the pages print "recovery lock, not final" on the result, the receipt file carries lock_state, the one-file verifier prints it; the shared terms block defines the recovery lock; /oracle says recovery locks are not accepted by the Sepolia verifiers (two-thirds rule only, so every stored root passed the final rule). Node and browser negative cases added. On a node before the field nothing changes. Co-Authored-By: Claude Fable 5.1 --- site/lc/app.js | 21 ++++++++----- site/lc/core.js | 25 ++++++++++++++-- site/lc/test.html | 5 ++++ site/light.html | 1 + site/oracle.html | 2 ++ site/partials/terms.html | 1 + site/receipt.html | 1 + tools/reference-apps/light-service/serve.mjs | 23 +++++++++++--- .../light-service/verify.test.mjs | 30 ++++++++++++++++++- .../receipt/verify-receipt.src.mjs | 2 ++ 10 files changed, 96 insertions(+), 15 deletions(-) diff --git a/site/lc/app.js b/site/lc/app.js index 0ffd2eb5a..ffc6f56a8 100644 --- a/site/lc/app.js +++ b/site/lc/app.js @@ -80,12 +80,13 @@ export async function runLight(address) { const res = verifyBalance(cp, proof, deps); window.__igneumLight = { cp, proof, neg, res }; const top = res.verified - ? `
Proven balance · Devnet 3, no value
${esc(formatIgn(res.balance_wei))} IGN
-

${esc(res.balance_wei)} wei at chain block ${res.block}, under checkpoint ${res.checkpoint} (locked ${esc(ago(Number(proof.headers[proof.headers.length - 1].timestamp)))}). Verified here in ${res.ms} ms, ${res.headers} headers checked.

` + ? `
${res.lock_state === 'recovery' ? 'Proven balance under a RECOVERY LOCK, not final' : 'Proven balance'} · Devnet 3, no value
${esc(formatIgn(res.balance_wei))} IGN
+

${esc(res.balance_wei)} wei at chain block ${res.block}, under checkpoint ${res.checkpoint} (${res.lock_state === 'recovery' ? 'recovery lock' : 'locked'} ${esc(ago(Number(proof.headers[proof.headers.length - 1].timestamp)))}). Verified here in ${res.ms} ms, ${res.headers} headers checked.

+ ${res.lock_state === 'recovery' ? `

Recovery lock. The node reports this checkpoint locked under the recovery rule: more than half of the anchored weight after a full window with no lock, not the two-thirds final rule. Nothing under it is final. The state is the node's report; the certificate bytes carry none.

` : ''}
` : `
Not verified · Devnet 3, no value

${esc(res.reason)}

`; out.innerHTML = top + negativeHtml('a copy of this proof with one byte of a trie node altered', neg) + stepsHtml(res) + `

Data served by ${esc(API)} (a read service in front of a Devnet 3 node). Nothing it answered was taken on trust: the certificate, every header hash and parent link, the coinbase inclusion, the segment record's signature and the account proof were recomputed in this tab. What is trusted: that the aggregator's statement is the true execution result (every node checks it natively before paying the record; the SP1 proof behind it is verified by nodes, not in this tab yet), and the voter list with weights, which came from the node (spec 10.1).

`; - setStatus(res.verified ? 'verified' : 'refused', res.verified ? 'ok' : 'bad'); + setStatus(res.verified ? (res.lock_state === 'recovery' ? 'verified under a recovery lock, not final' : 'verified') : 'refused', res.verified ? (res.lock_state === 'recovery' ? 'warn' : 'ok') : 'bad'); return res; } @@ -110,18 +111,22 @@ export async function runReceipt(tx) { if (res.payment) { receipt.kind = 'payment receipt'; receipt.authenticates = 'inclusion of the signed transaction in a finalised block and its successful execution outcome (status and logs) through the proven segment\'s receipts commitment'; } let negPay = null; if (res.payment) { const b2 = clone(receipt); const r0 = b2.segment.receipts[Number(b2.segment.receipt_position)]; r0.status = '0x0'; negPay = verifyPaymentReceipt(b2, deps); } - window.__igneumReceipt = { receipt, neg, res }; + if (res.lock_state) receipt.lock_state = res.lock_state; + // negative case under a recovery lock: a copy claiming lock_state final must be refused + let negLock = null; + if (res.lock_state === 'recovery') { const b3 = clone(receipt); b3.lock_state = 'final'; negLock = verifyReceipt(b3, deps); } + window.__igneumReceipt = { receipt, neg, res, negLock }; const t = res.tx || {}; const when = new Date(Number(res.block_time || 0)).toISOString().replace('T', ' ').slice(0, 19) + ' UTC'; const top = res.verified - ? `
${res.payment ? 'Payment receipt · included, executed, proven and finalised' : 'Transaction inclusion receipt · included and finalised'} · Devnet 3, no value
${esc(formatIgn(t.value || '0'))} IGN
+ ? `
${res.lock_state === 'recovery' ? (res.payment ? 'Payment receipt · included, executed, proven, under a RECOVERY LOCK (not final)' : 'Transaction inclusion receipt · included, under a RECOVERY LOCK (not final)') : res.payment ? 'Payment receipt · included, executed, proven and finalised' : 'Transaction inclusion receipt · included and finalised'} · Devnet 3, no value
${esc(formatIgn(t.value || '0'))} IGN
${res.payment ? `

Outcome authenticated: ${esc(res.outcome.asset)}, ${esc(formatIgn(res.outcome.amount_wei))} IGN to ${esc(res.outcome.recipient || 'contract creation')}, executed with status success, through the receipts commitment of the proven segment ending at chain block ${esc(String(receipt.execution.chain_block))}.

` : `

This is the inclusion receipt. ${esc(res.payment_unavailable || receipt.payment_unavailable || 'the outcome is not authenticated')}${res.receipt_status === 'failed' ? ' The authenticated status is FAILED: no transfer took place.' : ''}

`}
To
${esc(t.to || 'contract creation')}
From
${esc(receipt.tx_as_reported.from)} (as the node reports it; the signature is the chain's check)
Transaction
0x${esc(receipt.tx_hash)}
Block
${esc(res.block)} at ${esc(when)}, DAA ${esc(res.block_daa)}
-
Finality
checkpoint ${res.checkpoint}, ${esc(res.certificate)}; ${res.headers} headers from the block to the checkpoint, verified here in ${res.ms} ms
+
${res.lock_state === 'recovery' ? 'Recovery lock' : 'Finality'}
${res.lock_state === 'recovery' ? 'recovery lock, not final (the node reports the checkpoint locked under the recovery rule; the certificate bytes carry no state); ' : ''}checkpoint ${res.checkpoint}, ${esc(res.certificate)}; ${res.headers} headers from the block to the checkpoint, verified here in ${res.ms} ms
${receipt.execution ? `
Executed
status ${receipt.execution.status === '0x1' ? 'success' : 'failed'}, gas ${parseInt(receipt.execution.gas_used, 16)}, ${receipt.execution.logs} log(s) ${res.payment ? '(authenticated: the receipt sits in the shard receipts trie whose root the proven segment statement commits to)' : '(as the node reports it: executed is reported, not authenticated by this receipt; a payment receipt would authenticate the outcome)'}
` : ''}
` : `
Not verified · Devnet 3, no value

${esc(res.reason)}

`; - out.innerHTML = top + negativeHtml('a copy of this receipt with one nibble of the raw transaction altered', neg) + (negPay ? negativeHtml('a copy of this payment receipt with the receipt status flipped to failed', { verified: negPay.verified && negPay.payment, reason: negPay.reason }) : '') + stepsHtml(res) + out.innerHTML = top + negativeHtml('a copy of this receipt with one nibble of the raw transaction altered', neg) + (negLock ? negativeHtml('a copy of this receipt claiming lock_state final under a certificate the node reports as a recovery lock', negLock) : '') + (negPay ? negativeHtml('a copy of this payment receipt with the receipt status flipped to failed', { verified: negPay.verified && negPay.payment, reason: negPay.reason }) : '') + stepsHtml(res) + (res.verified ? `

The file carries the raw transaction, the including block's header and merkle path, every header up to the certified checkpoint, the certificate and the voter table. Anyone re-verifies it offline with the one-file verifier: node verify-receipt.js receipt.json (verify-receipt.js, plain JavaScript, no npm, no network). A tampered file fails there the same way the copy above failed here.

` : ''); const dl = $('[data-download]'); @@ -129,7 +134,7 @@ export async function runReceipt(tx) { const blob = new Blob([JSON.stringify(receipt, null, 1)], { type: 'application/json' }); const a = document.createElement('a'); a.href = URL.createObjectURL(blob); a.download = `igneum-${res.payment ? 'payment' : 'inclusion'}-receipt-${receipt.tx_hash.slice(0, 12)}.json`; a.click(); setTimeout(() => URL.revokeObjectURL(a.href), 5000); }); - setStatus(res.verified ? 'verified' : 'refused', res.verified ? 'ok' : 'bad'); + setStatus(res.verified ? (res.lock_state === 'recovery' ? 'verified under a recovery lock, not final' : 'verified') : 'refused', res.verified ? (res.lock_state === 'recovery' ? 'warn' : 'ok') : 'bad'); return res; } diff --git a/site/lc/core.js b/site/lc/core.js index ffc07d478..824effe80 100644 --- a/site/lc/core.js +++ b/site/lc/core.js @@ -254,6 +254,21 @@ export function verifyHeaderPath(headers, blake2b, fromHash, toHash) { return headers.length; } + +// ---- the lock state (Review B F04, 8 October 2026): a recovery lock is never presented as a final lock --------------- +// The certificate bytes carry no state; the node reports it beside the checkpoint (lockKind "final" or "recovery" and +// recoveryLock on igneum_getFinalityCheckpoints, 2.0.2 line; the service maps it to lock_state; absent on nodes before the field). A recovery lock is a lock under the recovery rule (more than +// half of the anchored weight after a full window with no lock), reported by the node, not provable from the certificate. +export function lockStateOf(cp) { + const v = cp && (cp.lock_state ?? cp.lockKind ?? (cp.recoveryLock === true ? 'recovery' : cp.recoveryLock === false ? 'final' : undefined)); + if (v === undefined || v === null || v === '') return null; + if (v !== 'final' && v !== 'recovery') throw new Error(`unknown lock state "${v}" reported for checkpoint ${cp.index}; refused`); + return v; +} +export const lockStateDetail = st => st === 'recovery' + ? 'RECOVERY LOCK as the node reports it: a lock under the recovery rule, not the final rule; nothing under it is final' + : st === 'final' ? 'final lock as the node reports it' : 'no lock state reported by this node (a node before the field)'; + // ---- the balance proof ------------------------------------------------------------------------------------------ // `cp` is the /api/checkpoint body (certificate, voters, headers to the previous lock); `proof` is the /balance body: // { address, chain_id, checkpoint: {hash, index}, headers: [carrier .. checkpoint], carrier: { coinbase: , @@ -320,8 +335,9 @@ export function verifyBalance(cp, proof, deps) { if (!a.exists && BigInt(proof.account.balance) !== 0n) throw new Error('the node reports a balance for an account the trie does not hold'); return `${proof.account.accountProof.length} nodes, ${a.exists ? 'account present' : 'account absent (exclusion proof)'}`; }); + const lockState = lockStateOf(cp); step('lock state: the node\'s report beside the certificate (the certificate bytes carry none)', () => lockStateDetail(lockState)); const balance = acct.exists ? acct.balance : 0n; - return done({ verified: true, balance, balance_wei: balance.toString(), nonce: acct.nonce.toString(), block: Number(st.number), post_root: st.post_root, checkpoint: Number(cp.index), headers: proof.headers.length, aggregator: agg, certificate: cert }); + return done({ verified: true, balance, balance_wei: balance.toString(), nonce: acct.nonce.toString(), block: Number(st.number), post_root: st.post_root, checkpoint: Number(cp.index), lock_state: lockState, headers: proof.headers.length, aggregator: agg, certificate: cert }); } catch (e) { return done({ verified: false, reason: String(e.message || e) }); } @@ -344,6 +360,11 @@ export function verifyReceipt(receipt, deps) { if (strip(cp.hash) !== strip(receipt.checkpoint.hash) || receipt.chain_id !== cp.chain_id) throw new Error('the receipt names another checkpoint or chain than its certificate'); return `checkpoint ${r.index} on ${cp.chain_id}, ${r.signers} of ${r.voters} voters, ${(r.weight_fraction_total * 100).toFixed(1)}% of total weight`; }); + const lockState = step('lock state: the node\'s report beside the certificate (the certificate bytes carry none)', () => { + const st = lockStateOf(cp); + if (receipt.lock_state !== undefined && receipt.lock_state !== null && receipt.lock_state !== (st || 'final')) throw new Error(`the receipt says lock_state "${receipt.lock_state}" but its certificate is reported as ${st || 'final (no state field)'}; refused`); + return lockStateDetail(st); + }) && lockStateOf(cp); let tx = null; step('the transaction hash is keccak256 of the raw signed transaction', () => { const raw = hexToBytes(strip(receipt.raw_tx_hex)); @@ -361,7 +382,7 @@ export function verifyReceipt(receipt, deps) { if (bytesToHex(root) !== strip(receipt.headers[0].hash_merkle_root)) throw new Error('the merkle path does not reach the including block\'s hash_merkle_root'); return `leaf ${ib.leaf_index} of ${ib.leaf_count}`; }); - return done({ verified: true, tx, headers: receipt.headers.length, checkpoint: Number(cp.index), certificate: cert, block: strip(receipt.headers[0].hash), block_daa: receipt.headers[0].daa_score, block_time: receipt.headers[0].timestamp }); + return done({ verified: true, tx, headers: receipt.headers.length, checkpoint: Number(cp.index), lock_state: lockState, certificate: cert, block: strip(receipt.headers[0].hash), block_daa: receipt.headers[0].daa_score, block_time: receipt.headers[0].timestamp }); } catch (e) { return done({ verified: false, reason: String(e.message || e) }); } diff --git a/site/lc/test.html b/site/lc/test.html index 496cdb4d1..787f9f4d3 100644 --- a/site/lc/test.html +++ b/site/lc/test.html @@ -56,6 +56,8 @@ try { ['receipt names another checkpoint than its certificate', d => { d.checkpoint.hash = flipHex(d.checkpoint.hash, 60); }], ]; for (const [name, mutate] of R) { const d = clone(receipt); mutate(d); row('r', name, verifyReceipt(d, deps), false); } + { const d = clone(receipt); d.checkpoint.certificate.lock_state = 'recovery'; d.lock_state = 'final'; row('r', 'a receipt claiming lock_state final under a certificate the node reports as a recovery lock (F04)', verifyReceipt(d, deps), false); } + { const d = clone(receipt); d.checkpoint.certificate.lock_state = 'recovery'; const r = verifyReceipt(d, deps); row('r', 'a receipt under a recovery lock: verifies with lock_state recovery, never final (F04)', { ...r, verified: r.verified && r.lock_state === 'recovery' }, true); } row('r', `genuine receipt for ${tx.slice(0, 14)} (${receipt.headers.length} headers, checkpoint ${cp.index})`, verifyReceipt(receipt, deps), true); // a balance to prove let address = q.get('address'); @@ -77,6 +79,9 @@ try { ]; for (const [name, mutate] of B) { const d = clone(proof); mutate(d); row('b', name, verifyBalance(cp, d, deps), false); } { const c = clone(cp); c.certificate.aggregate_signature_hex = flipHex(c.certificate.aggregate_signature_hex, 20); row('b', 'certificate signature altered', verifyBalance(c, proof, deps), false); } + // Review B F04: a recovery lock is never presented as a final lock (the node's report beside the certificate) + { const c = clone(cp); c.lock_state = 'recovery'; const r = verifyBalance(c, proof, deps); row('b', 'under a node-reported recovery lock: verifies with lock_state recovery, never final', { ...r, verified: r.verified && r.lock_state === 'recovery' }, true); } + { const c = clone(cp); c.lock_state = 'anchored-maybe'; row('b', 'an unknown lock kind reported', verifyBalance(c, proof, deps), false); } const g = verifyBalance(cp, proof, deps); row('b', `genuine balance of ${address.slice(0, 12)} at chain block ${proof.segment.last} (${proof.headers.length} headers, checkpoint ${cp.index})`, g, true); } diff --git a/site/light.html b/site/light.html index 501f82bf9..8f6d7b813 100644 --- a/site/light.html +++ b/site/light.html @@ -293,6 +293,7 @@
Executed
A node ran it at a chain block and reports a result (status, gas, logs). On these pages an execution result is reported by the node, not authenticated, unless the page says it is.
Proven
An aggregator's segment record, carried in a block's coinbase and signed with its vote key, commits to the state root after that chain block; nodes check the statement against their own execution before paying it. The SP1 proof behind the statement is verified by nodes, not in the browser or on Sepolia.
Finalised
A certified checkpoint has the block in its past: an aggregate BLS signature by voters holding two thirds of active weight and at least 17/30 of total weight over the checkpoint, checked here against the voter table the node supplies.
+
Recovery lock
Not a fifth state and never shown as finalised. After a full weight window with no lock, the finality rule accepts a checkpoint signed by more than half of the anchored weight (the recovery rule, Review B F04). The node reports each lock's kind beside its checkpoint (lockKind: final or recovery); the certificate bytes carry none, so the kind is the node's report. These pages print a recovery lock as recovery lock, not final on the result, in the receipt file (lock_state) and in the one-file verifier, and refuse a receipt that claims final under a reported recovery lock. On a node before the field nothing is shown. Devnet 3 and the 2.0 devnet, no value.

The same four definitions sit on /light, /receipt and /oracle (one source: site/partials/terms.html). The devnet, no value.

diff --git a/site/oracle.html b/site/oracle.html index 0695c087d..aa5e899e2 100644 --- a/site/oracle.html +++ b/site/oracle.html @@ -277,6 +277,7 @@
  • The coinbase transaction under the carrier's hash_merkle_root, and the segment record parsed out of its extra data: the record's post_root for its block is stored under the certificate's index.
  • Every read: a keccak-keyed Merkle Patricia proof against the stored root, verified on chain.
  • +

    Recovery locks are not accepted by this verifier. Both Sepolia verifiers apply the two-thirds rule only: a certificate signed under the recovery rule (more than half of the anchored weight after a full window with no lock, Review B F04) carries under two thirds of the installed table and submitCertificate reverts, so every root this oracle answers passed the final rule. A recovery lock is never presented here as a final lock because it is never stored. The verifier reads weight against its installed table and nothing else; a re-installed table moves the threshold with it.

    Trust anchors and unchecked signatures, named (also returned by the contract's trust())

    The same four definitions sit on /light, /receipt and /oracle (one source: site/partials/terms.html). The devnet, no value.

    diff --git a/site/partials/terms.html b/site/partials/terms.html index f83933986..071a9c9bf 100644 --- a/site/partials/terms.html +++ b/site/partials/terms.html @@ -5,6 +5,7 @@
    Executed
    A node ran it at a chain block and reports a result (status, gas, logs). On these pages an execution result is reported by the node, not authenticated, unless the page says it is.
    Proven
    An aggregator's segment record, carried in a block's coinbase and signed with its vote key, commits to the state root after that chain block; nodes check the statement against their own execution before paying it. The SP1 proof behind the statement is verified by nodes, not in the browser or on Sepolia.
    Finalised
    A certified checkpoint has the block in its past: an aggregate BLS signature by voters holding two thirds of active weight and at least 17/30 of total weight over the checkpoint, checked here against the voter table the node supplies.
    +
    Recovery lock
    Not a fifth state and never shown as finalised. After a full weight window with no lock, the finality rule accepts a checkpoint signed by more than half of the anchored weight (the recovery rule, Review B F04). The node reports each lock's kind beside its checkpoint (lockKind: final or recovery); the certificate bytes carry none, so the kind is the node's report. These pages print a recovery lock as recovery lock, not final on the result, in the receipt file (lock_state) and in the one-file verifier, and refuse a receipt that claims final under a reported recovery lock. On a node before the field nothing is shown. Devnet 3 and the 2.0 devnet, no value.

    The same four definitions sit on /light, /receipt and /oracle (one source: site/partials/terms.html). The devnet, no value.

    diff --git a/site/receipt.html b/site/receipt.html index 5c6eb087e..7956e21b3 100644 --- a/site/receipt.html +++ b/site/receipt.html @@ -292,6 +292,7 @@
    Executed
    A node ran it at a chain block and reports a result (status, gas, logs). On these pages an execution result is reported by the node, not authenticated, unless the page says it is.
    Proven
    An aggregator's segment record, carried in a block's coinbase and signed with its vote key, commits to the state root after that chain block; nodes check the statement against their own execution before paying it. The SP1 proof behind the statement is verified by nodes, not in the browser or on Sepolia.
    Finalised
    A certified checkpoint has the block in its past: an aggregate BLS signature by voters holding two thirds of active weight and at least 17/30 of total weight over the checkpoint, checked here against the voter table the node supplies.
    +
    Recovery lock
    Not a fifth state and never shown as finalised. After a full weight window with no lock, the finality rule accepts a checkpoint signed by more than half of the anchored weight (the recovery rule, Review B F04). The node reports each lock's kind beside its checkpoint (lockKind: final or recovery); the certificate bytes carry none, so the kind is the node's report. These pages print a recovery lock as recovery lock, not final on the result, in the receipt file (lock_state) and in the one-file verifier, and refuse a receipt that claims final under a reported recovery lock. On a node before the field nothing is shown. Devnet 3 and the 2.0 devnet, no value.

    The same four definitions sit on /light, /receipt and /oracle (one source: site/partials/terms.html). The devnet, no value.

    diff --git a/tools/reference-apps/light-service/serve.mjs b/tools/reference-apps/light-service/serve.mjs index 828fbc203..426413477 100644 --- a/tools/reference-apps/light-service/serve.mjs +++ b/tools/reference-apps/light-service/serve.mjs @@ -134,6 +134,21 @@ async function headerPath(fromHash, chainNumber, cpNumber, cpHash) { } // ---- the checkpoint ----------------------------------------------------------------------------------------------- + +// Review B F04 (8 October 2026): the node reports a lock state beside each checkpoint (igneum_getFinalityCheckpoints: lockKind and recoveryLock +// per checkpoint, latestLockKind at the top); the service passes it through as lock_state so the pages and receipts show a recovery lock as a +// recovery lock, never as final. Absent on nodes before the field: the answer carries no lock_state and nothing changes. +async function withLockState(cp) { + if (!cp) return cp; + try { + const r = await exec('igneum_getFinalityCheckpoints', [{ last: 2000 }]); + const c = (r && r.checkpoints || []).find(x => Number(x.index) === Number(cp.index) && strip(x.hash) === strip(cp.hash)); + // the node lane's names (2.0.2 line, e9ab052f): lockKind "final" or "recovery" and recoveryLock per checkpoint + const v = c ? (c.lockKind ?? (c.recoveryLock === true ? 'recovery' : c.recoveryLock === false ? 'final' : undefined)) : undefined; + if (v !== undefined && v !== null) return { ...cp, lock_state: String(v) }; + } catch {} + return cp; +} async function checkpoint() { if (process.env.DATABASE_URL) { // the Devnet 3 observer's rows, read the way the site's /api/checkpoint reads them (DATABASE_URL from the box's observer env) @@ -144,12 +159,12 @@ async function checkpoint() { throw httpError(404, `no finality certificate yet on the Igneum 2.0 devnet (${CHAIN_ID_NAME}); the first lock comes when the weight window fills at DAA ${window ?? 7200}${daa !== null ? `, the chain reads DAA ${daa.toLocaleString('en-GB')} now` : ''}`); } if (cp.chain_id !== CHAIN_ID_NAME) throw httpError(409, `the stored certificate is for ${cp.chain_id}, not ${CHAIN_ID_NAME}; refused`); - return { ok: true, now: new Date().toISOString(), ...cp }; + return { ok: true, now: new Date().toISOString(), ...(await withLockState(cp)) }; } const r = await fetch(CHECKPOINT_URL, { signal: AbortSignal.timeout(15000), cache: 'no-store' }); const j = await r.json(); if (!j.ok) throw new Error('checkpoint: ' + (j.error || r.status)); - return j; + return withLockState(j); } async function chainNumberOf(hash) { const b = await exec('eth_getBlockByHash', ['0x' + strip(hash), false]); @@ -188,7 +203,7 @@ async function balance(q) { if (!rec) throw httpError(500, `the carrier's coinbase holds ${records.length} segment record(s), none for segment ${chosen.first}`); // the smallest proof: the earliest certified checkpoint at or above the carrier (the certificate used travels in the answer) let certificate = null; - if (process.env.DATABASE_URL) certificate = await earliestCheckpointAbove(neon(), chosen.carrierNumber, chainNumberOf, `${SOURCE}_live_certificates`).catch(() => null); + if (process.env.DATABASE_URL) certificate = await withLockState(await earliestCheckpointAbove(neon(), chosen.carrierNumber, chainNumberOf, `${SOURCE}_live_certificates`).catch(() => null)); let cpN = cpNumber, cpH = cpHash, cpI = cpIndex; if (certificate) { cpH = certificate.hash; cpI = Number(certificate.index); cpN = await chainNumberOf(cpH); } const headers = await headerPath(chosen.carrier, chosen.carrierNumber, cpN, cpH); @@ -240,7 +255,7 @@ async function receipt(q) { } const mustCover = paidRecord ? Math.max(chainNumber, Number(paidRecord.carrierNumber)) : chainNumber; let certificate = null; - if (process.env.DATABASE_URL) certificate = await earliestCheckpointAbove(neon(), mustCover, chainNumberOf, `${SOURCE}_live_certificates`).catch(() => null); + if (process.env.DATABASE_URL) certificate = await withLockState(await earliestCheckpointAbove(neon(), mustCover, chainNumberOf, `${SOURCE}_live_certificates`).catch(() => null)); if (certificate) { cpHash = certificate.hash; cpIndex = Number(certificate.index); } const cpNumber = await chainNumberOf(cpHash); if (chainNumber > cpNumber) throw httpError(409, `not final yet: executed at chain block ${chainNumber}, the latest certified checkpoint is chain block ${cpNumber}; try again in about ${chainNumber - cpNumber + 30} s`); diff --git a/tools/reference-apps/light-service/verify.test.mjs b/tools/reference-apps/light-service/verify.test.mjs index 6beb6c636..445545871 100644 --- a/tools/reference-apps/light-service/verify.test.mjs +++ b/tools/reference-apps/light-service/verify.test.mjs @@ -7,7 +7,7 @@ import { readFileSync } from 'node:fs'; import { blake2b } from '@noble/hashes/blake2.js'; import { keccak_256 } from '@noble/hashes/sha3.js'; import { bls12_381 } from '@noble/curves/bls12-381.js'; -import { verifyReceipt, verifyBalance, verifyPaymentReceipt } from '../../../site/lc/core.js'; +import { verifyReceipt, verifyBalance, verifyPaymentReceipt, lockStateOf } from '../../../site/lc/core.js'; const deps = { blake2b, bls: bls12_381, keccak: keccak_256 }; const here = new URL('.', import.meta.url).pathname; @@ -75,5 +75,33 @@ if (pay && pay.segment) { P('genuine payment receipt', d => {}, true); const g = verifyPaymentReceipt(pay, deps); if (g.payment) console.log(` outcome: ${g.outcome.amount_wei} wei of ${g.outcome.asset} to ${g.outcome.recipient}, ${g.outcome.logs.length} log(s), ${g.ms} ms`); } else if (pay) console.log('payment fixture has no segment data: ' + pay.payment_unavailable); +// ---- Review B F04: a recovery lock is never presented as a final lock ------------------------------------------------ +{ + const clone = x => JSON.parse(JSON.stringify(x)); + const rec = clone(receipt); rec.checkpoint.certificate.lock_state = 'recovery'; + const r1 = verifyReceipt(rec, deps); + if (!r1.verified || r1.lock_state !== 'recovery') { console.log('FAIL F04: a receipt under a node-reported recovery lock must verify with lock_state recovery, got', r1.verified, r1.lock_state, r1.reason); process.exit(1); } + console.log('ok F04: a receipt under a recovery lock verifies with lock_state recovery (never final)'); + const rec2 = clone(rec); rec2.lock_state = 'final'; + const r2 = verifyReceipt(rec2, deps); + if (r2.verified) { console.log('FAIL F04: a receipt claiming lock_state final under a recovery-lock certificate must be refused'); process.exit(1); } + console.log('ok F04: a receipt claiming final under a recovery lock is refused ::', r2.reason); + const rec3 = clone(receipt); rec3.checkpoint.certificate.lock_state = 'anchored-maybe'; + const r3 = verifyReceipt(rec3, deps); + if (r3.verified) { console.log('FAIL F04: an unknown lock state must be refused'); process.exit(1); } + console.log('ok F04: an unknown lock state is refused ::', r3.reason); + const rec4 = clone(receipt); + const r4 = verifyReceipt(rec4, deps); + if (!r4.verified || r4.lock_state !== null) { console.log('FAIL F04: no field, nothing changes (lock_state null), got', r4.lock_state); process.exit(1); } + console.log('ok F04: without the field nothing changes (lock_state null, the page renders as before)'); + if (lockStateOf({ lockKind: 'recovery' }) !== 'recovery' || lockStateOf({ recoveryLock: false }) !== 'final' || lockStateOf({}) !== null) { console.log('FAIL F04: lockStateOf shape'); process.exit(1); } + if (balance) { + const cp = clone(balance.checkpoint_certificate || load(here + '../fixtures/dn3-checkpoint.json')); cp.lock_state = 'recovery'; + const rb = verifyBalance(cp, balance, deps); + if (!rb.verified || rb.lock_state !== 'recovery') { console.log('FAIL F04: a balance under a recovery lock must verify with lock_state recovery, got', rb.verified, rb.lock_state, rb.reason); process.exit(1); } + console.log('ok F04: a balance under a recovery lock verifies with lock_state recovery (never final)'); + } +} + console.log(failed ? `FAILED ${failed}` : 'RESULT every case behaved'); process.exit(failed ? 1 : 0); diff --git a/tools/reference-apps/receipt/verify-receipt.src.mjs b/tools/reference-apps/receipt/verify-receipt.src.mjs index c79a1232a..e3da3c2a7 100644 --- a/tools/reference-apps/receipt/verify-receipt.src.mjs +++ b/tools/reference-apps/receipt/verify-receipt.src.mjs @@ -26,9 +26,11 @@ if (args.includes('--tamper')) { } const r = verifyReceipt(receipt, deps); console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (devnet, no value)`); +if (receipt.lock_state === 'recovery') console.log('RECOVERY LOCK: the node reported this checkpoint locked under the recovery rule (more than half of the anchored weight after a full window with no lock), not the final rule. Nothing in this file is final.'); console.log('What this file authenticates: that the signed transaction is included in a block that is finalised. What it does not: the execution outcome (status, gas), which is carried as the node reported it. A payment receipt, which authenticates the transfer outcome, is a different file.'); print(r); if (!r.verified) { console.log(`REFUSED: ${r.reason}`); process.exit(1); } +if (r.lock_state === 'recovery') console.log('LOCK STATE: recovery, as the node reported it; this receipt is included under a recovery lock, not a final one.'); const t = r.tx; console.log(`INCLUSION VERIFIED in ${r.ms} ms: a signed transaction of ${formatIgn(t.value)} IGN to ${t.to || 'contract creation'} (${t.value} wei) is included in block ${r.block.slice(0, 16)} at DAA ${r.block_daa} (${new Date(Number(r.block_time)).toISOString()}), finalised under checkpoint ${r.checkpoint}; ${r.headers} headers checked; ${r.certificate}.`); console.log('Reported by the node, not authenticated by this file: from ' + (receipt.tx_as_reported && receipt.tx_as_reported.from) + (receipt.execution ? `, executed with status ${receipt.execution.status === '0x1' ? 'success' : 'failed'}` : '') + '. The voter table with weights came from the node (spec 10.1). In the four words: included and finalised are authenticated, executed is reported, proven is not claimed.'); From 121465f65f3b64c3a7e8671968f18b992e3a53b5 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 19:00:18 +0000 Subject: [PATCH 2/4] Reference apps F04: the one-file verifier rebuilt on the box from the lock-state source; the oracle README names the refused recovery locks Co-Authored-By: Claude Fable 5.1 --- site/lc/verify-receipt.js | 18 ++++++++++++++++-- tools/reference-apps/oracle/README.md | 4 ++++ 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/site/lc/verify-receipt.js b/site/lc/verify-receipt.js index 72a549134..6c930420a 100644 --- a/site/lc/verify-receipt.js +++ b/site/lc/verify-receipt.js @@ -1,5 +1,5 @@ #!/usr/bin/env node -// Igneum receipt verifier (transaction inclusion receipt or payment receipt), one file, offline. Source: tools/reference-apps/receipt/verify-receipt.src.mjs and site/lc/core.js +// Igneum transaction inclusion receipt verifier, one file, offline. Source: tools/reference-apps/receipt/verify-receipt.src.mjs and site/lc/core.js // (the same checks the browser page runs), bundled with @noble/hashes 2.4.0 and @noble/curves 2.4.0 (MIT). Usage: node verify-receipt.js receipt.json [--tamper] // tools/reference-apps/receipt/verify-receipt.src.mjs @@ -5226,6 +5226,13 @@ function verifyHeaderPath(headers, blake2b2, fromHash, toHash) { if (toHash && strip(headers[headers.length - 1].hash) !== strip(toHash)) throw new Error("the last header is not the certified checkpoint"); return headers.length; } +function lockStateOf(cp) { + const v = cp && (cp.lock_state ?? cp.lockKind ?? (cp.recoveryLock === true ? "recovery" : cp.recoveryLock === false ? "final" : void 0)); + if (v === void 0 || v === null || v === "") return null; + if (v !== "final" && v !== "recovery") throw new Error(`unknown lock state "${v}" reported for checkpoint ${cp.index}; refused`); + return v; +} +var lockStateDetail = (st) => st === "recovery" ? "RECOVERY LOCK as the node reports it: a lock under the recovery rule, not the final rule; nothing under it is final" : st === "final" ? "final lock as the node reports it" : "no lock state reported by this node (a node before the field)"; function verifyReceipt(receipt2, deps2) { const { blake2b: blake2b2, bls: bls2, keccak } = deps2; const steps = []; @@ -5249,6 +5256,11 @@ function verifyReceipt(receipt2, deps2) { if (strip(cp.hash) !== strip(receipt2.checkpoint.hash) || receipt2.chain_id !== cp.chain_id) throw new Error("the receipt names another checkpoint or chain than its certificate"); return `checkpoint ${r2.index} on ${cp.chain_id}, ${r2.signers} of ${r2.voters} voters, ${(r2.weight_fraction_total * 100).toFixed(1)}% of total weight`; }); + const lockState = step("lock state: the node's report beside the certificate (the certificate bytes carry none)", () => { + const st = lockStateOf(cp); + if (receipt2.lock_state !== void 0 && receipt2.lock_state !== null && receipt2.lock_state !== (st || "final")) throw new Error(`the receipt says lock_state "${receipt2.lock_state}" but its certificate is reported as ${st || "final (no state field)"}; refused`); + return lockStateDetail(st); + }) && lockStateOf(cp); let tx = null; step("the transaction hash is keccak256 of the raw signed transaction", () => { const raw = hexToBytes3(strip(receipt2.raw_tx_hex)); @@ -5265,7 +5277,7 @@ function verifyReceipt(receipt2, deps2) { if (bytesToHex3(root) !== strip(receipt2.headers[0].hash_merkle_root)) throw new Error("the merkle path does not reach the including block's hash_merkle_root"); return `leaf ${ib.leaf_index} of ${ib.leaf_count}`; }); - return done({ verified: true, tx, headers: receipt2.headers.length, checkpoint: Number(cp.index), certificate: cert, block: strip(receipt2.headers[0].hash), block_daa: receipt2.headers[0].daa_score, block_time: receipt2.headers[0].timestamp }); + return done({ verified: true, tx, headers: receipt2.headers.length, checkpoint: Number(cp.index), lock_state: lockState, certificate: cert, block: strip(receipt2.headers[0].hash), block_daa: receipt2.headers[0].daa_score, block_time: receipt2.headers[0].timestamp }); } catch (e) { return done({ verified: false, reason: String(e.message || e) }); } @@ -5316,12 +5328,14 @@ if (args.includes("--tamper")) { } var r = verifyReceipt(receipt, deps); console.log(`TRANSACTION INCLUSION RECEIPT 0x${receipt.tx_hash} on ${receipt.chain_id} (devnet, no value)`); +if (receipt.lock_state === "recovery") console.log("RECOVERY LOCK: the node reported this checkpoint locked under the recovery rule (more than half of the anchored weight after a full window with no lock), not the final rule. Nothing in this file is final."); console.log("What this file authenticates: that the signed transaction is included in a block that is finalised. What it does not: the execution outcome (status, gas), which is carried as the node reported it. A payment receipt, which authenticates the transfer outcome, is a different file."); print(r); if (!r.verified) { console.log(`REFUSED: ${r.reason}`); process.exit(1); } +if (r.lock_state === "recovery") console.log("LOCK STATE: recovery, as the node reported it; this receipt is included under a recovery lock, not a final one."); var t = r.tx; console.log(`INCLUSION VERIFIED in ${r.ms} ms: a signed transaction of ${formatIgn(t.value)} IGN to ${t.to || "contract creation"} (${t.value} wei) is included in block ${r.block.slice(0, 16)} at DAA ${r.block_daa} (${new Date(Number(r.block_time)).toISOString()}), finalised under checkpoint ${r.checkpoint}; ${r.headers} headers checked; ${r.certificate}.`); console.log("Reported by the node, not authenticated by this file: from " + (receipt.tx_as_reported && receipt.tx_as_reported.from) + (receipt.execution ? `, executed with status ${receipt.execution.status === "0x1" ? "success" : "failed"}` : "") + ". The voter table with weights came from the node (spec 10.1). In the four words: included and finalised are authenticated, executed is reported, proven is not claimed."); diff --git a/tools/reference-apps/oracle/README.md b/tools/reference-apps/oracle/README.md index 8acd8eb60..a1cea76b2 100644 --- a/tools/reference-apps/oracle/README.md +++ b/tools/reference-apps/oracle/README.md @@ -50,3 +50,7 @@ node demo.mjs The deployer key is read from `~/.config/igneum/sepolia-deployer`. Sepolia's gas schedule is repriced (a plain transfer estimates 12,000 gas), so the numbers in `deployment.json` are what this network charges. + +## Recovery locks (Review B F04, 8 October 2026) + +Recovery locks are not accepted by this verifier: a certificate under half of the installed table's weight reverts in `submitCertificate` (both Sepolia verifiers apply the two-thirds rule only), so every stored root passed the final rule and nothing the oracle answers can read final for a recovery lock. `trust()` gains this sentence at the next redeploy; the page carries it now. From bfcd25b5796e1b8418e54735d04f41694c94f989 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 19:14:58 +0000 Subject: [PATCH 3/4] Merge build/master into reference-apps-f04, pages rebuilt Co-Authored-By: Claude Fable 5.1 --- site/acceptance.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/site/acceptance.html b/site/acceptance.html index aed67f257..60a4bbd88 100644 --- a/site/acceptance.html +++ b/site/acceptance.html @@ -368,8 +368,8 @@
    -
    Igneum 2.0 acceptance

    Test and Acceptance Standard 1.0

    Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

    Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

    APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

    Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 128 cases: 1 passed under the standard, 74 running with team evidence, 3 failed, 1 blocked, 48 not run, 1 deferred

    • 1 pass
    • 3 fail
    • 1 blocked
    • 74 running
    • 48 not run
    • 1 deferred
    The gates

    Five gates, and the freeze before them.

    A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

    G0RUNNING

    Freeze

    Release identity

    No formal run or public pass before approval.

    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred

    • GOV8 casesRUNNING
    G1RUNNING

    Baseline

    D1

    No validated hardware claim without reproduction.

    16 cases: 0 passed under the standard, 10 running with team evidence, 6 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    G2BLOCKED

    Experiments

    D2

    No improvement claim from a negative hypothesis.

    32 cases: 0 passed under the standard, 23 running with team evidence, 1 blocked, 8 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ROT8 casesRUNNING
    G3RUNNING

    Adversary

    D3

    No broad resistance claim from one weak design.

    16 cases: 0 passed under the standard, 11 running with team evidence, 5 not run, 0 deferred

    • GOV8 casesRUNNING
    • ADV8 casesRUNNING
    G4FAIL

    Coexistence

    D4

    No durability claim based on assumed chip expiry.

    24 cases: 0 passed under the standard, 12 running with team evidence, 1 failed, 11 not run, 0 deferred

    • GOV8 casesRUNNING
    • ECO8 casesFAIL
    • INC8 casesRUNNING
    G5RUNNING

    No rescue

    D5

    No no-rescue claim from a founder-supported demo.

    56 cases: 1 passed under the standard, 35 running with team evidence, 20 not run, 0 deferred

    • GOV8 casesRUNNING
    • ROT8 casesRUNNING
    • ZKP8 casesRUNNING
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • OPS8 casesRUNNING
    • UX8 casesRUNNING

    The three named gates

    FAIL

    Technical readiness

    Execution control

    No mainnet-ready claim with missing enforcement or safety.

    64 cases: 1 passed under the standard, 44 running with team evidence, 2 failed, 1 blocked, 16 not run, 0 deferred

    • GOV8 casesRUNNING
    • POW8 casesBLOCKED
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • UX8 casesRUNNING
    RUNNING

    Commercial evidence

    Execution control

    Devnet activity is insufficient.

    24 cases: 0 passed under the standard, 4 running with team evidence, 19 not run, 1 deferred

    • GOV8 casesRUNNING
    • CAP8 casesNOT RUN
    • COM8 casesNOT RUN
    FAIL

    Leadership-contender decision

    Execution control

    Supports a scoped contention assessment, not a guaranteed rank.

    128 cases: 1 passed under the standard, 74 running with team evidence, 3 failed, 1 blocked, 48 not run, 1 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ADV8 casesRUNNING
    • ROT8 casesRUNNING
    • ECO8 casesFAIL
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • OPS8 casesRUNNING
    • UX8 casesRUNNING
    • COM8 casesNOT RUN
    • LEAD8 casesNOT RUN
    01GOV

    Release identity and evidence

    Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

    RUNNING
    Owner
    Release lead + independent assurance
    Gate
    G0 / all gates G0 G1 G2 G3 G4 G5
    Fixtures
    F0 manifest; F1 source/build archives; F9 evidence vault
    Plan pages
    5, 21, 23, 25, 26, 27
    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred
    GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

    Steps

    1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
    2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
    3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

    Accept

    Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

    Evidence the case requires

    Signed F0; source-to-test map; claim inventory; unresolved-field register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    f0-manifest-20261008-b
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    This manual supplies proposed test thresholds, not source-approved protocol parameters.

    Steps

    1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
    2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
    3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

    Accept

    No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

    Evidence the case requires

    Approved profile register; timestamped holdout commitments; change log.

    Evidence record of the run

    What was run
    the profiles approved as proposed by the founder at 18:2x UK before any confirmatory run; P13 deferred
    Run by
    CI steward (a2ecfa95d3206016c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide public source and documented build instructions to three unaffiliated operators.

    Steps

    1. Build on clean declared environments without private files, tokens or founder assistance.
    2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
    3. Run reference vectors and restart a node using only documented artifacts.

    Accept

    All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

    Evidence the case requires

    Build logs; dependency lockfiles; binary comparison; operator attestations.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Enable append-only storage for run outputs and a separate analysis workspace.

    Steps

    1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
    2. Recompute one published figure from raw records on a clean machine.
    3. Modify a retained artifact deliberately and test integrity verification.

    Accept

    Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

    Evidence the case requires

    Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Create controlled defective variants on an isolated network only.

    Steps

    1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
    2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
    3. Confirm the baseline still accepts authorised valid cases.

    Accept

    Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

    Evidence the case requires

    Mutation catalogue; blinded run results; baseline controls; oracle review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

    Steps

    1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
    2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
    3. For each claimed option, require the complete associated test set rather than a demonstration.

    Accept

    Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

    Evidence the case requires

    Scope manifest; activation scan; product-copy comparison; exclusions register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

    Steps

    1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
    2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
    3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

    Accept

    No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

    Evidence the case requires

    Signed scoped reports; conflict declarations; finding/retest ledger.

    Method
    Independent specialist review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

    Steps

    1. Calculate affected test dependencies and invalidate their former PASS statuses.
    2. Regenerate public status pages from F0 and the evidence register.
    3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

    Accept

    Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

    Evidence the case requires

    Dependency impact report; regenerated status page; rejected claim examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    02GPU

    Whole-system GPU measurements

    Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

    RUNNING
    Owner
    GPU lead + three independent operators
    Gate
    G1 / G2 G1 G2
    Fixtures
    F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
    Plan pages
    6, 7, 8, 14, 18, 23
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    GPU-01Cover the declared commodity populationPriority GATEProfile P02RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Freeze the P02 cohort, supported role matrix and the final v6 configuration.

    Steps

    1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
    2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
    3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

    Accept

    All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

    Evidence the case requires

    Cohort manifest; compatibility matrix; raw results by SKU and role.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

    Steps

    1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
    2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
    3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

    Accept

    Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

    Evidence the case requires

    Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Build the baseline and window variant with identical dataset, reads and semantic workload.

    Steps

    1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
    2. Measure paired complete-system energy and accepted throughput, including host work.
    3. Repeat during proving coexistence and expose any memory or scheduling cliff.

    Accept

    Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

    Evidence the case requires

    Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use safe vendor-supported settings only; record operator permission and original settings.

    Steps

    1. Sweep approved core and memory operating points while holding workload constant.
    2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
    3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

    Accept

    Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

    Evidence the case requires

    Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

    Evidence record of the run

    What was run
    the memory-clock ladder at the lock (floor lane 1, b1b8d833)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

    Steps

    1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
    2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
    3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

    Accept

    Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

    Evidence the case requires

    Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use the same hardware against clean, delayed, lossy and intermittent links in F4.

    Steps

    1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
    2. Include reconnects, template changes, expired submissions and pool failover.
    3. Attribute loss to network, local software, validation and protocol causes.

    Accept

    Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

    Evidence the case requires

    Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Run the selected profile on actual reference machines for the P02 soak period.

    Steps

    1. Track wall power, temperatures, clocks, memory and accepted work continuously.
    2. Inject safe power interruptions, process restarts and normal competing desktop load.
    3. Check restored settings and compare late-run efficiency with the first stable period.

    Accept

    No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

    Evidence the case requires

    Seven-day time series; crash reports; settings-restoration checks; drift analysis.

    Evidence record of the run

    What was run
    the 5090 lock pass, 66 minutes at 1,300 MHz with the four-minute reserve (floor lane 1)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

    Steps

    1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
    2. Recompute joules and total cost per accepted work from the shared raw schema.
    3. Investigate divergence before accepting a pooled headline or uncertainty band.

    Accept

    Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

    Evidence the case requires

    Three signed reproduction packs; reconciliation report; final baseline table.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    03POW

    Proof-of-work correctness and coupling

    Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

    BLOCKED
    Owner
    Cryptography + GPU lead
    Gate
    G2 / technical readiness G2
    Fixtures
    F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
    Plan pages
    7, 9, 10, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 blocked, 0 not run, 0 deferred
    POW-01Match independent execution across every backendPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Implement an independently written reference evaluator, not a wrapper around the production GPU path.

    Steps

    1. Execute the P01 corpus across every family, boundary seed and supported backend.
    2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
    3. Minimise every mismatch and rerun it on clean builds.

    Accept

    Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

    Evidence the case requires

    Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

    Steps

    1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
    2. Check bounds, valid dependencies, address distribution and forbidden encodings.
    3. Compare source-level operations with optimised compiled code for removed or altered work.

    Accept

    No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

    Evidence the case requires

    Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Take the 64-register candidate and the cheapest independently proposed storage organisations.

    Steps

    1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
    2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
    3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

    Accept

    Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

    Evidence the case requires

    Liveness traces; alternative implementations; Pareto table; reviewer analysis.

    Evidence record of the run

    What was run
    the connected-state class KILLED (1.10x against the 1.25x gate; live state costs a clock-gated file nothing)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Experiment + independent hardware review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use a candidate initially matched to baseline instruction count, read count and dataset size.

    Steps

    1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
    2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
    3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

    Accept

    The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

    Evidence the case requires

    Matched workloads; GPU runs; redesigned core estimates; held-out results.

    Evidence record of the run

    What was run
    the same experiment, D2(a) closed
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Controlled experiment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04BLOCKEDEvidence none yetLast run 2026-10-08 18:13Z

    Setup

    Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

    Steps

    1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
    2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
    3. Price any valid strategy against fresh evaluation; independently review all bindings.

    Accept

    Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

    Evidence the case requires

    Attack implementations; valid/invalid controls; work-cost analysis; binding review.

    Evidence record of the run

    What was run
    the binding review: twelve reuse paths, none below the honest cost; five open questions B1 to B5
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    binding-review-2026-10-08-a05
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

    Steps

    1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
    2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
    3. Sustain the approved hostile request rate while ordinary valid traffic continues.

    Accept

    All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

    Evidence the case requires

    CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p01-partb-20261008-01
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

    Steps

    1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
    2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
    3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

    Accept

    Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

    Evidence the case requires

    Scope decision; semantic specification; vectors; simplified datapath model.

    Method
    Conditional implementation test
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

    Steps

    1. Retain their historic negative tests and realistic SRAM instruction-memory control.
    2. Inspect the release for reintroduction through renamed settings or hidden paths.
    3. Require a new written hypothesis and complete adversarial retest for any proposed return.

    Accept

    Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

    Evidence the case requires

    Decision register; binary/config scan; negative-control results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    04ADV

    Programmable specialist adversaries

    Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

    RUNNING
    Owner
    Independent hardware team
    Gate
    G3 G3
    Fixtures
    F2 reference GPUs; F6 RTL/physical models; all published families
    Plan pages
    8, 10, 12, 22, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Provide the complete published family bank and future known parameter schedule to the reviewer.

    Steps

    1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
    2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
    3. Verify its outputs against POW vectors before measuring any advantage.

    Accept

    At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

    Evidence the case requires

    Architecture reports; functional simulations; adaptation matrix; reviewer signature.

    Evidence record of the run

    What was run
    the 18-family programmable core placed and routed (9.36 pJ per lane-op, k 0.64 same-node)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent hardware study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

    Steps

    1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
    2. Include construction/update amortisation, bandwidth contention and retained state.
    3. Take the most favourable feasible point for the specialist into the complete-board model.

    Accept

    No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

    Evidence the case requires

    Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

    Evidence record of the run

    What was run
    D2(b): the stored-half hybrid, memory sharing, recomputation priced (the placed hybrid 1.93x same-node at the mean hit)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Model + adversarial implementation
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

    Steps

    1. Compare moving computation, intermediate state or fetched data to each read location.
    2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
    3. Include interconnect, host, synchronisation, idle and conversion costs.

    Accept

    The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

    Evidence the case requires

    Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

    Evidence record of the run

    What was run
    data-local execution moves nothing (2,112 bits of live state against an 80-bit read)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent system modelling
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-04Measure profitable selective participationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use all declared families plus held-out generated programs and the protocol difficulty rule.

    Steps

    1. Identify favourable execution paths and add cheap fallbacks for other periods.
    2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
    3. Evaluate revenue and costs across the full schedule, not just average program energy.

    Accept

    Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

    Evidence the case requires

    Per-program advantage distribution; policy simulator; full-period returns.

    Evidence record of the run

    What was run
    selective participation 9 percent spread across 2,000 era draws
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-05Validate physical and complete-board costsPriority GATEProfile P04RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

    Steps

    1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
    2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
    3. Compare against a calibrated existing hardware block or equivalent validation case.

    Accept

    No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

    Evidence the case requires

    Netlist/physical reports; macro assumptions; bill of materials; model calibration.

    Evidence record of the run

    What was run
    the complete GDDR7 machine 1.5x same-node, 1.8x a node ahead at the placed energy; the honest same-node bracket 1.5x to 2.1x: FAIL against P04 at R_E 1.5, served as such
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    FAIL against P04 at R_E 1.5
    Method
    Independent physical-design review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

    Steps

    1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
    2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
    3. Evaluate measurement confidence and model-parameter sensitivity separately.

    Accept

    P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

    Evidence the case requires

    Node-specific reports; factor provenance; uncertainty and sensitivity tables.

    Evidence record of the run

    What was run
    the node column: same-node and a node ahead kept separate (k 0.78 / 0.56 / 0.40 at N5 / N3 / N2)
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

    Steps

    1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
    2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
    3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

    Accept

    The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

    Evidence the case requires

    Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

    Evidence record of the run

    What was run
    the transition matrix: no row loses competitiveness, the three-year life holds, zero obsolescence credit
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

    Steps

    1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
    2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
    3. Record unresolved modelling disagreements and future technology exclusions.

    Accept

    Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

    Evidence the case requires

    Two review reports; challenge log; final envelope; unresolved-limit statement.

    Method
    Independent challenge/review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    05ROT

    Epochs, seeds and memory transitions

    Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

    RUNNING
    Owner
    Consensus + GPU leads
    Gate
    G5 / G2 G5 G2
    Fixtures
    F0 activation rules; F4 fault network; F5 historical and boundary vectors
    Plan pages
    7, 11, 19, 21
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

    Steps

    1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
    2. Restart nodes from both sides and replay the same headers.
    3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

    Accept

    All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

    Evidence the case requires

    Boundary vectors; node/miner traces; acceptance and reward matrix.

    Evidence record of the run

    What was run
    the fast-time crossings PASS on 4cdcc488 (17:29:58) and 617cb441 (17:30:44) with the cold restart
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use the retained schedule in F0, including coincident program, parameter and family changes.

    Steps

    1. Run every known family transition and all coincident-boundary combinations on production code.
    2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
    3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

    Accept

    Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

    Evidence the case requires

    Transition matrix; code-path evidence; compile timing; old-client logs.

    Evidence record of the run

    What was run
    the class v6 object crossing at its floor on 617cb441
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

    Steps

    1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
    2. Partition voters, restore them and test vote-key substitution through pools.
    3. Verify adoption and refusal behaviour of already running nodes.

    Accept

    The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

    Evidence the case requires

    Executable governance model; signed-vote corpus; coalition/partition results.

    Evidence record of the run

    What was run
    the bring-forward mechanism specified in the D5 block
    Run by
    node lane (a283f5f0d364ceef0)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

    Steps

    1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
    2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
    3. Validate inputs, parameters and proofs against independent vectors.

    Accept

    No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

    Evidence the case requires

    Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Stop checkpoint signing while mining continues, then cross seed and family boundaries.

    Steps

    1. Remove the required signing weight and observe the documented fallback or safe pause.
    2. Prevent access to any founder seed service; restart from persisted state.
    3. Restore the stated fault assumptions and verify deterministic recovery.

    Accept

    Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

    Evidence the case requires

    Fault timeline; seed/certificate history; node-state comparison; recovery log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

    Steps

    1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
    2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
    3. Measure data transfer, restart and excluded-card costs before approving progression.

    Accept

    No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

    Evidence the case requires

    Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use matched baseline and ablated variants in the lab; do not change a running public network.

    Steps

    1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
    2. Include favourable-period specialists and all retained known families.
    3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

    Accept

    Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

    Evidence the case requires

    Ablation report; decision log; complexity/cost comparison.

    Evidence record of the run

    What was run
    the family gate's coverage (38,000 eras) and the rotation prototype paused as the no-rescue control
    Run by
    lane D family gate (a07a99a3788566af2)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    lane D family gate (a07a99a3788566af2)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Freeze the complete published rule bank and known schedule for the five-year evaluation.

    Steps

    1. Allow a programmable adversary to know and survive all planned changes.
    2. Remove assumed future emergency instructions and manual retirement actions from the model.
    3. Run the required ECO scenarios and link them to independent network-transition tests.

    Accept

    Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

    Evidence the case requires

    Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    06ECO

    Five-year coexistence economics

    Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

    FAIL
    Owner
    Economics lead + independent reviewer
    Gate
    G4 G4
    Fixtures
    F6 adversarial costs; F7 scenario model; F2 operator costs
    Plan pages
    8, 13, 18, 24, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 failed, 0 not run, 0 deferred
    ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

    Steps

    1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
    2. Use actual accepted work and independently verify units and period conversions.
    3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

    Accept

    All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

    Evidence the case requires

    Versioned model; unit fixtures; independent reconciliation; input sources.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

    Steps

    1. Evaluate marginal operation separately from recovery of a new purchase.
    2. Stress resale at zero, hardware failures, financing and replacement cycles.
    3. Report break-even power price and total cost relative to the strongest feasible specialist.

    Accept

    P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

    Evidence the case requires

    Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

    Evidence record of the run

    What was run
    the existing-owner and new-entrant tests per class at three electricity prices
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use three development cases: fully funded elsewhere, source-range low and source-range high.

    Steps

    1. Evaluate private mining, public hardware sales and a hybrid business model.
    2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
    3. Re-evaluate GPU entry after the specialist fleet is already installed.

    Accept

    The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

    Evidence the case requires

    Business-model variants; sunk-cost case; full cash-flow and adaptation records.

    Evidence record of the run

    What was run
    the sunk-development case first in the coexistence model
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use independently reviewed dynamic operator policies, not fixed market shares.

    Steps

    1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
    2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
    3. Compare equilibrium and transient outcomes across independent starting conditions.

    Accept

    Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

    Evidence the case requires

    Agent policies; sensitivity seeds; market-share paths; independent model review.

    Evidence record of the run

    What was run
    miners react through a per-class supply curve (the second cut, 21:00)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

    Steps

    1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
    2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
    3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

    Accept

    No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

    Evidence the case requires

    Scenario register; full result cube; boundary plots; failed-world explanations.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

    Steps

    1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
    2. Test flat/declining fees and no external proving income; separately introduce external demand.
    3. Calculate capacity and security-provider coverage after each reward transition.

    Accept

    Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

    Evidence the case requires

    Issuance/fee ledger; scenario cash flows; funding-shortfall report.

    Evidence record of the run

    What was run
    the proving-payment resolution (the 90/10 user-funded payment)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

    Steps

    1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
    2. Include ordinary-owner replacement, resale and reloading expenses.
    3. Run alternate bounded schedules without assigning automatic chip death.

    Accept

    The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

    Evidence the case requires

    Per-step cost/retention table; alternative schedules; approval record.

    Evidence record of the run

    What was run
    the dataset schedule's commodity burden (10.0u)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

    Steps

    1. Recalculate required worlds and perturb favourable assumptions against the team.
    2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
    3. Publish the sensitivity range and state which conclusions are conditional.

    Accept

    Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

    Evidence the case requires

    Independent report; rerun outputs; model limitations; approved claim envelope.

    Method
    Independent economic review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    07EVM

    Execution and developer compatibility

    Keep familiar applications while making every difference and metering rule explicit and reproducible.

    RUNNING
    Owner
    Execution lead + independent implementer
    Gate
    Technical readiness
    Fixtures
    F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
    Plan pages
    15, 25, 34, 35, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Pin the intended execution fork, revm version and all Igneum deviations in F0.

    Steps

    1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
    2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
    3. Minimise mismatches and distinguish intended differences from implementation defects.

    Accept

    All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

    Evidence the case requires

    Fixture/version inventory; root/receipt diffs; deviation matrix.

    Evidence record of the run

    What was run
    /compatibility 20 of 20 rows PASSED on igneum-devnet-4
    Run by
    reference-apps lane (a2060899d2a27d31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Use signed transfers, contract calls and deployment transactions with boundary field values.

    Steps

    1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
    2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
    3. Check mempool admission and final consensus execution independently.

    Accept

    Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

    Evidence the case requires

    Signed corpus; admission/execution outcomes; account-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

    Steps

    1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
    2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
    3. Mutate a block producer to omit or undercharge expensive work.

    Accept

    Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

    Evidence the case requires

    Metering traces; fee fixtures; estimator errors; invalid-block rejection.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Use contracts sensitive to timestamp, height/context, randomness and ordering.

    Steps

    1. Compare the declared Igneum semantics with developers' documented expectations.
    2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
    3. Run dependency reviews for applications using these values for economic decisions.

    Accept

    Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

    Evidence the case requires

    Context-contract results; threat notes; compatibility exclusions.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

    Steps

    1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
    2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
    3. Compare expected application invariants with native execution and proved results.

    Accept

    Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

    Evidence the case requires

    Contract fixture hashes; transaction journeys; invariant and state comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

    Steps

    1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
    2. Reindex from genesis or the documented trust anchor after pruning and restart.
    3. Compare logs, receipts and balances with independently validated chain state.

    Accept

    No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

    Evidence the case requires

    RPC conformance report; reindex comparison; reconnect/edge-case logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

    Steps

    1. Measure CPU, memory, disk and proving cost against charged budgets.
    2. Saturate admission with invalid/expensive requests while valid workloads continue.
    3. Restart mid-execution and verify atomic state recovery.

    Accept

    P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

    Evidence the case requires

    Resource profiles; adversarial corpus; state recovery comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare two authorised versions and malicious, stale or unknown versions.

    Steps

    1. Cross activation with mixed clients, queued transactions and proofs from both versions.
    2. Bind each accepted proof to the correct execution semantics and program identity.
    3. Exercise a failed software distribution without altering consensus activation.

    Accept

    No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

    Evidence the case requires

    Upgrade vectors; mixed-version traces; manifest/version bindings.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    08ZKP

    Consensus-enforced proof validity

    The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

    RUNNING
    Owner
    Proving + protocol leads; independent cryptography review
    Gate
    Technical readiness / G5 G5
    Fixtures
    F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
    Plan pages
    16, 20, 24, 25, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Start from a native-correct statement and an independently verified valid proof.

    Steps

    1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
    2. Submit the genuine proof as a positive control through ordinary network paths.
    3. Inspect block acceptance and resulting reward/state on unmodified validators.

    Accept

    Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

    Evidence the case requires

    Hostile record corpus; validator decisions; before/after balances; positive controls.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use valid proofs from authorised and unauthorised programs and parameter sets.

    Steps

    1. Swap program digest, verifier version, security settings and verification key where applicable.
    2. Attempt downgrade through configuration, serialized metadata or an old node path.
    3. Test authorised boundary transitions and unsupported future identities.

    Accept

    Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

    Evidence the case requires

    Identity/parameter matrix; rejection traces; cryptographic review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

    Steps

    1. Replay each proof under another network, job, epoch, shard range or state commitment.
    2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
    3. Check duplicated and reordered records across forks and replayed sync data.

    Accept

    Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

    Evidence the case requires

    Binding matrix; public-input hashes; replay traces; reward reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use proofs that commit to authorisation and all reward-relevant fields required by F0.

    Steps

    1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
    2. Supply correct execution over malicious producer-provided consensus/reward inputs.
    3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

    Accept

    Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

    Evidence the case requires

    Mutation cases; reward derivation trace; signature/proof binding review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

    Steps

    1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
    2. Crash validators between validation and reward application, then recover.
    3. Reconcile canonical payouts against the exact F0 duplicate policy.

    Accept

    Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

    Evidence the case requires

    Concurrency schedule; canonical payment ledger; crash/recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

    Steps

    1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
    2. Alter shard ranges, roots and aggregation-program identity.
    3. Verify native execution, aggregate validity and coverage commitments independently.

    Accept

    Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

    Evidence the case requires

    Coverage corpus; aggregate/public-input verification; rejection ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

    Steps

    1. Review soundness assumptions, parameter margins and consequences of performance patches.
    2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
    3. Cross-check an independent verifier or reference path and test crash containment.

    Accept

    P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

    Evidence the case requires

    Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

    Method
    Independent cryptographic review + testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Inspect block import, sync, RPC, light verification, database restoration and fast paths.

    Steps

    1. Try bypassing validation via each path with a proof rejected by the normal path.
    2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
    3. Attempt to use proof-production status as ordering, voting or finality authority.

    Accept

    No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

    Evidence the case requires

    Path coverage report; bypass corpus; replacement run; authority checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    09CAP

    Sustained proving and delivery

    A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

    NOT RUN
    Owner
    Proving lead + independent operators
    Gate
    Technical readiness / commercial track
    Fixtures
    F3 meaningful workload catalogue; F4 network; F8 external job harness
    Plan pages
    17, 18, 24, 25
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

    Steps

    1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
    2. Record proof format, memory, energy, host and whether aggregation/compression are included.
    3. Repeat on the final release and label all configuration changes.

    Accept

    Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

    Evidence the case requires

    Historical/current manifests; proof verification; timing and memory records.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

    Steps

    1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
    2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
    3. Induce memory pressure and GPU task failure without losing wallet control.

    Accept

    Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

    Evidence the case requires

    Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

    Steps

    1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
    2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
    3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

    Accept

    No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

    Evidence the case requires

    Stage event ledger; clock calibration; end-to-end latency/cost report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

    Steps

    1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
    2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
    3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

    Accept

    P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

    Evidence the case requires

    Request/completion reconciliation; backlog series; held-out results; observer report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

    Steps

    1. Observe admission, explicit backpressure, reservations and deadline estimates.
    2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
    3. Measure recovery time and ensure ordinary users are not silently starved.

    Accept

    P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

    Evidence the case requires

    Overload timeline; admission/refund logs; backlog-drain proof.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

    Steps

    1. Measure actual completion distributions with network delay, competing load and failed attempts.
    2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
    3. Compare assignment frequency, paid completions and wasted work by tier.

    Accept

    P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

    Evidence the case requires

    Window sweep; paid-completion distribution; wasted-work and margin report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Remove input providers, assigned provers and the dominant aggregator independently and together.

    Steps

    1. Have replacement operators retrieve authenticated inputs without founder files.
    2. Retry expired assignments while preserving idempotent reward and customer outcomes.
    3. Restore providers and test late submissions racing with replacements.

    Accept

    P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

    Evidence the case requires

    Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Run the external workload using a customer-controlled verifier and independently operated workers.

    Steps

    1. Verify every delivered proof against the contracted program and input commitment.
    2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
    3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

    Accept

    P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

    Evidence the case requires

    Customer verification log; proof-format contract; settlement reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    10INC

    Rewards, incentives and selfish operators

    Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

    RUNNING
    Owner
    Protocol economics + proving leads
    Gate
    G4 / G5 G4 G5
    Fixtures
    F0 fee/reward rules; F4 adversarial operators; F7 incentive models
    Plan pages
    13, 16, 17, 18, 24, 26
    8 cases: 0 passed under the standard, 1 running with team evidence, 7 not run, 0 deferred
    INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use a deterministic short chain containing all reward types, fee paths and rounding cases.

    Steps

    1. Calculate balances, total supply changes, burns and distributions independently.
    2. Execute identical blocks natively and through the proving path.
    3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

    Accept

    Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

    Evidence the case requires

    Independent accounting ledger; balance/supply diffs; boundary vectors.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

    Steps

    1. Trace money from source to operator, protocol, developer and any burn.
    2. Compare node records, settlement records and Ember displays.
    3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

    Accept

    Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

    Evidence the case requires

    Money-flow register; UI reconciliation; rejected classifications.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Permit independent schedulers to mine, prove internally, prove externally or switch off.

    Steps

    1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
    2. Run clients that ignore the official scheduling recommendation.
    3. Measure realised operator margin, internal capacity and network progress.

    Accept

    Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

    Evidence the case requires

    Scheduler source/policies; switching traces; capacity and margin series.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

    Steps

    1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
    2. Observe hash participation, proof backlog, fees and recovery without an administrator.
    3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

    Accept

    Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

    Evidence the case requires

    Shock timeline; fee/hash/capacity paths; failure-region report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

    Steps

    1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
    2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
    3. Price attacker costs and observe honest completion under the approved abuse load.

    Accept

    F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

    Evidence the case requires

    Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

    Steps

    1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
    2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
    3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

    Accept

    Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

    Evidence the case requires

    Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use self-funded operators and related customer identities in the isolated economic model/network.

    Steps

    1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
    2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
    3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

    Accept

    No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

    Evidence the case requires

    Circular-flow tests; ownership/conflict review; net-cash reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Model control of hashing, signing, proving, aggregation and hardware supply separately.

    Steps

    1. Remove each largest operational dependency and combine correlated failures.
    2. Measure replacement cost/time and whether essential roles share hidden ownership.
    3. Compare results with the approved fault model and no-rescue exercise.

    Accept

    No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

    Evidence the case requires

    Role/ownership map; dependency removals; recovery and concentration report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    11FIN

    Consensus safety and recovery

    Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

    RUNNING
    Owner
    Consensus lead + independent formal/security review
    Gate
    G5 / technical readiness G5
    Fixtures
    F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
    Plan pages
    19, 21, 24, 25
    8 cases: 1 passed under the standard, 7 running with team evidence, 0 not run, 0 deferred
    FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

    Steps

    1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
    2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
    3. Replay from independent checkpoints and from genesis where practical.

    Accept

    Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

    Evidence the case requires

    Block/ordering corpus; root/work diffs; real-node replay logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 19:59 UK

    Setup

    Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

    Steps

    1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
    2. Delay messages and eligibility updates independently; keep total historical weights auditable.
    3. Try to form two certificates and reconnect nodes to observe accepted final history.

    Accept

    No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

    Evidence the case requires

    Signed votes; certificate attempts; voter-table snapshots; safety checker output.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    fin-boundary-20261008-02
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Recover historical expiry failures where available; use the actual current authority-transition rules.

    Steps

    1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
    2. Attempt independently renewed authority sets and conflicting checkpoint locks.
    3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

    Accept

    Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

    Evidence the case requires

    Expiry timeline; table/certificate history; historical regression tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Remove enough signing participation to invalidate the liveness assumption without forging votes.

    Steps

    1. Continue mining and execution, cross seed boundaries and monitor proof queues.
    2. Check which user-visible states advance and which remain unfinalised.
    3. Restore eligible weight and bounded message delay, then verify recovery.

    Accept

    No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

    Evidence the case requires

    Signing/mining trace; UI/RPC states; recovery roots and timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use normal transitions, pool members retaining keys and malicious substitution attempts.

    Steps

    1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
    2. Race updates across boundaries and replay old signed changes.
    3. Have a new node verify the authority chain from its declared trust anchor.

    Accept

    Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

    Evidence the case requires

    Authority-chain fixtures; substitution attacks; new-node verification log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

    Steps

    1. Use previously eligible keys to build alternative histories after their operators disappear.
    2. Present these histories to recently offline and newly joining clients.
    3. Test replayed certificates, stale anchors and compromised signer subsets.

    Accept

    Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

    Evidence the case requires

    Long-range corpus; trust-anchor policy; key-compromise review; client results.

    Evidence record of the run

    What was run
    bought and stolen keys in the simulator rows
    Run by
    finality lane (aca0f5ed924a2a99b)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Combine partitions with node crash, partial writes, restarts and proof backlog.

    Steps

    1. Reconnect networks under bounded latency and restore required honest participation.
    2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
    3. Compare all honest nodes and customer-visible receipts after recovery.

    Accept

    P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

    Evidence the case requires

    Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08RUNNINGEvidence recordLast run 8 Oct 2026, 19:38 UK

    Setup

    Use an independent model checker/scheduler and production-node scenarios from F4.

    Steps

    1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
    2. Explore bounded adversarial message schedules and minimise any counterexample.
    3. Replay model findings on real code and have an independent reviewer assess uncovered states.

    Accept

    No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

    Evidence the case requires

    Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

    Method
    Model checking + real-node testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    fin-boundary-20261008
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    12VER

    Wallets, receipts and data availability

    Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

    FAIL
    Owner
    Wallet + light-client lead; independent security review
    Gate
    Technical readiness / claimed options
    Fixtures
    F0 trust/availability model; F5 malformed roots, receipts and authority chains
    Plan pages
    20, 25, 35, 37
    8 cases: 0 passed under the standard, 5 running with team evidence, 2 failed, 1 not run, 0 deferred
    VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

    Steps

    1. Start from the approved trust anchor and verify every required link to the advertised state.
    2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
    3. Remove the bootstrap service and use another independently operated source.

    Accept

    The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

    Evidence the case requires

    Bootstrap corpus; trust-chain trace; fail-closed tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Use valid state proofs paired with wrong execution statements or stale authority histories.

    Steps

    1. Cross voter and verifier changes with offline clients returning after long intervals.
    2. Alter roots, aggregate identity and proof/public-input bindings independently.
    3. Check local verification rather than merely a server-reported verified flag.

    Accept

    All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

    Evidence the case requires

    Client verification trace; corrupted inputs; offline/upgrade results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

    Steps

    1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
    2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
    3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

    Accept

    Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

    Evidence the case requires

    Payment fixture corpus; receipt verification; merchant-facing status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

    Steps

    1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
    2. Exercise legitimate authority updates and source reorganisations under the approved model.
    3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

    Accept

    The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

    Evidence the case requires

    Oracle code/parameters; attack cases; cost report; privilege disclosure.

    Method
    Claimed-option verification
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Remove founder archival/input services and start an independent operator from the documented entry point.

    Steps

    1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
    2. Rebuild the expected state and continue validation/proving.
    3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

    Accept

    Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

    Evidence the case requires

    Download/reconstruction logs; data hashes; resource costs; dependency inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

    Steps

    1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
    2. Test retrieval from independent peers and expiry/retry policy.
    3. Restore data and check that recovery cannot alter an already verified commitment.

    Accept

    No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

    Evidence the case requires

    Withholding corpus; peer retrieval traces; availability/status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

    Steps

    1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
    2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
    3. Upgrade and recover without silently changing signing authority or exposing seed material.

    Accept

    No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

    Evidence the case requires

    Security review; canary-secret tests; signing fixtures; restore journey.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:04 UK

    Setup

    Create included-only, executed, proven, finalised, reverted, stale and paused examples.

    Steps

    1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
    2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
    3. Check statements about privacy, Ethereum security and device support.

    Accept

    No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

    Evidence the case requires

    Cross-surface screenshots/logs; state mapping; claim review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    13OPS

    Independent operation and release security

    A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

    RUNNING
    Owner
    Operations + release leads; independent operators
    Gate
    G5 G5
    Fixtures
    F4 isolated multi-operator network; F0 signed releases; F9 telemetry
    Plan pages
    21, 24, 25, 26
    8 cases: 0 passed under the standard, 3 running with team evidence, 5 not run, 0 deferred
    OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

    Steps

    1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
    2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
    3. Introduce scheduled faults and have independent operators recover using published instructions.

    Accept

    No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

    Evidence the case requires

    Operator roster/conflict checks; dependency removals; full activity/intervention log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Start nodes without the default bootstrap host and give others adversarial peer lists.

    Steps

    1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
    2. Use independent documented discovery paths and validate returned chain data.
    3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

    Accept

    No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

    Evidence the case requires

    Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

    Steps

    1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
    2. Test explicit operator acceptance and the published signing-key incident procedure.
    3. Confirm that distribution-key possession cannot independently activate new consensus rules.

    Accept

    Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

    Evidence the case requires

    Package corpus; approval/activation traces; compromised-key rehearsal.

    Evidence record of the run

    What was run
    the release manifest on igneum_getManifest (d5981514) and /release.json; the signing-key procedure owed
    Run by
    shipper (ae892a8b0f78fe31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

    Steps

    1. Crash during import, proof acceptance, reward application and snapshot generation.
    2. Restore from independently verified snapshots or re-sync through documented procedures.
    3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

    Accept

    No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

    Evidence the case requires

    Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Run hostile test jobs with secret canaries and restrictive worker permissions.

    Steps

    1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
    2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
    3. Retry on every supported isolation backend and check dependency vulnerability handling.

    Accept

    No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

    Evidence the case requires

    Sandbox penetration report; canary logs; resource limits; host-integrity checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use an authorised isolated load environment with declared resource and request-rate budgets.

    Steps

    1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
    2. Measure legitimate traffic, memory/disk growth and validator CPU use.
    3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

    Accept

    P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

    Evidence the case requires

    Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

    Steps

    1. Inject one instance of each monitored failure in the lab.
    2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
    3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

    Accept

    P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

    Evidence the case requires

    Alert matrix; detection timelines; independent runbook exercise.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use a clean previous supported version and the final candidate with independent operators.

    Steps

    1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
    2. Cross activation with mixed versions and unavailable founder distribution hosts.
    3. Re-run affected gates after changes and preserve prior failures and incident lessons.

    Accept

    No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

    Evidence the case requires

    Upgrade/replay logs; invalidation map; repeated gate signatures.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    14UX

    Ember, payouts and operator control

    Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

    RUNNING
    Owner
    Desktop product + pool leads; independent usability study
    Gate
    Operator readiness / G5 G5
    Fixtures
    F2 supported desktops; F8 user study; F4 honest/malicious pools
    Plan pages
    14, 21, 25, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

    Steps

    1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
    2. Record download/data preparation separately as well as complete end-to-end time.
    3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

    Accept

    P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

    Evidence the case requires

    Consent-based study records; task timings; failure reasons; compatibility outcomes.

    Method
    Independent observed user study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    update-return lane (a22d765a2e0355a9f)
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Run mining/proving on active desktops under contention and safe thermal stress.

    Steps

    1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
    2. Crash or restart the UI while workers run and verify ownership of background processes.
    3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

    Accept

    P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

    Evidence the case requires

    Control timings; process/settings audit; restart and safety traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use known rewards, fees, energy readings, retries and operator-entered tariffs.

    Steps

    1. Compare mining, internal proof and external proof income with authoritative ledgers.
    2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
    3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

    Accept

    P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

    Evidence the case requires

    UI/ledger comparisons; tariff fixtures; stale/negative examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use ordinary single-card balances and the actual pooling/payment path.

    Steps

    1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
    2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
    3. Reconcile displayed balances with canonical entitlement and actual settlement.

    Accept

    P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

    Evidence the case requires

    Single-card payout ledger; pool failure record; custody/authorisation review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use an honest pool and a modified pool that replaces worker identity or voting credentials.

    Steps

    1. Verify the consensus binding from performed work to the miner's retained key.
    2. Attempt substitution, replay and reassignment without the miner's authorisation.
    3. Leave the pool and verify retained voting/finality rights under F0.

    Accept

    No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

    Evidence the case requires

    Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

    Evidence record of the run

    What was run
    the pool vote-key commitment design
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Provide a pool interface with declared job-declaration support and independent miner templates.

    Steps

    1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
    2. Have a pool substitute or censor templates and test local verification/fallback.
    3. Measure payout and acceptance consequences without moving authority to the pool.

    Accept

    The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

    Evidence the case requires

    Template commitments; accepted-block evidence; malicious-pool/fallback report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

    Steps

    1. Ask independent users to identify the issue, stop safely and follow the recommended action.
    2. Test explicit update approval, version visibility and a failed/corrupt update.
    3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

    Accept

    P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

    Evidence the case requires

    Observed tasks; update traces; sanitised export tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

    Steps

    1. Compare Ember against independently optimised permissible implementations on identical work.
    2. Measure efficiency, fees, false rejection, installation and update transparency.
    3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

    Accept

    P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

    Evidence the case requires

    Matched software comparison; code/config review; fee/privilege inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    15COM

    Paid demand and sustainable delivery

    Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

    NOT RUN
    Owner
    Commercial lead + independent financial/customer reviewer
    Gate
    Commercial evidence
    Fixtures
    F8 real consenting customers; F7 full service costs; private identity proofs
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 7 not run, 1 deferred
    COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

    Steps

    1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
    2. Run paid jobs through ordinary independently operated infrastructure.
    3. Have the customer verify usefulness, correctness and its reason for choosing the service.

    Accept

    The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

    Evidence the case requires

    Redacted contract; verified jobs; settlement proof; consented customer confirmation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use the P14 multi-customer observation period and ownership/conflict checks.

    Steps

    1. Track paid purchases on distinct occasions, including refunds and stopped customers.
    2. Audit related parties, project reimbursements, token grants and circular funding.
    3. Reconcile external cash received with correctly delivered meaningful work.

    Accept

    P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

    Evidence the case requires

    Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

    Steps

    1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
    2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
    3. Repeat under the declared demand and price sensitivities.

    Accept

    P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

    Evidence the case requires

    Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

    Steps

    1. Count all accepted jobs, including failed, retried and abandoned cases.
    2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
    3. Compare offered capacity and quoted price with what was actually delivered.

    Accept

    P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

    Evidence the case requires

    Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

    Steps

    1. Obtain comparable quotes or consented measured trials at the evaluation date.
    2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
    3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

    Accept

    P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

    Evidence the case requires

    Dated comparison; workload/security match; customer decision record.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Follow all recruited customers through the P14 observation period, including churn.

    Steps

    1. Remove disclosed trial incentives before measuring repeat demand.
    2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
    3. Review whether one affiliated or subsidised buyer dominates the apparent market.

    Accept

    P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

    Evidence the case requires

    Cohort/renewal ledger; churn notes; concentration and incentive report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13DEFERREDEvidence none yetLast run 2026-10-08 18:3x UK (the founder: forget P13 for now)

    Setup

    Prepare a costed plan for development, review, infrastructure, support and incident response.

    Steps

    1. Separate committed resources from revenue dependent on adoption or token price.
    2. Stress lower income and an unexpected security/operations expense.
    3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

    Accept

    P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

    Evidence the case requires

    Budget and commitment evidence; downside plan; owner/continuity roster.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit unaffiliated developers unfamiliar with unpublished implementation details.

    Steps

    1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
    2. Record time, undocumented dependencies, workarounds and correctness issues.
    3. Retest after documentation fixes without founder-written hidden integration code.

    Accept

    P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

    Evidence the case requires

    Consented developer logs; public examples; issue closure; verified end-to-end journeys.

    Method
    Independent integration study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    16LEAD

    Comparative leadership evidence

    A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

    NOT RUN
    Owner
    Independent assessment panel + product/economics reviewers
    Gate
    Leadership-contender decision
    Fixtures
    F8 peer/customer studies; full signed technical evidence; 90-day observation
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

    Steps

    1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
    2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
    3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

    Accept

    The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

    Evidence the case requires

    Timestamped peer protocol; source/version records; comparison/exclusion rationale.

    Method
    Pre-registered comparative study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Use matched user tasks and operating conditions on the selected GPU-first networks.

    Steps

    1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
    2. Measure rejection/availability under the same network conditions; report fees separately.
    3. Use blinded analysis where possible and independent runs for decisive differences.

    Accept

    P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

    Evidence the case requires

    Matched task data; uncertainty/effect sizes; independent comparison report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    site lane (a846fd66b5403e35a)
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

    Steps

    1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
    2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
    3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

    Accept

    All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

    Evidence the case requires

    Claim-to-evidence map; signed envelope review; limitations statement.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

    Steps

    1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
    2. Report trial incentives separately and include every initial participant in retention denominators.
    3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

    Accept

    P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

    Evidence the case requires

    Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

    Steps

    1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
    2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
    3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

    Accept

    P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

    Evidence the case requires

    Control/failure-domain map; uncertainty notes; concentration/removal results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Observe the final candidate and approved compatible updates for the full P16 real-time period.

    Steps

    1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
    2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
    3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

    Accept

    P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

    Evidence the case requires

    90-day SLO ledger; independent probes; incident reports; change/retest history.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

    Steps

    1. Check every mandatory and claimed-option test, source requirement and approved threshold.
    2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
    3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

    Accept

    Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

    Evidence the case requires

    Signed assessment; full status index; dissent/limitations; approved claim wording.

    Method
    Independent final assessment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:04 UK

    Setup

    Define material-change triggers and scheduled reviews before publishing the assessment.

    Steps

    1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
    2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
    3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

    Accept

    Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

    Evidence the case requires

    Review calendar; invalidation drills; versioned public claim register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    Profiles

    The numbers each case is held to.

    17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

    P00Approved as proposed

    Frozen scope and approval

    1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
    2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
    3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P01Approved as proposed

    Correctness and negative-test depth

    1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
    2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
    3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

    Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P02Approved as proposed

    Hardware coverage and reproducibility

    1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
    2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
    3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
    4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

    Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P03Approved as proposed

    Candidate improvement and honest-card budget

    1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
    2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
    3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

    Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P04Approved as proposed

    Scoped specialist-competition target

    1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
    2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
    3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
    4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

    FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P05Approved as proposed

    Measurement and inference protocol

    1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
    2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
    3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
    4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

    Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P06Approved as proposed

    Memory and support policy

    1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
    2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
    3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P07Approved as proposed

    Proof service capacity and fairness

    1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
    2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
    3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
    4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
    5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

    Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P08Approved as proposed

    Fault assumptions and recovery

    1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
    2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
    3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
    4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

    Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P09Approved as proposed

    Security and bounded resource requirements

    1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
    2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
    3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
    4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

    Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P10Approved as proposed

    Ordinary-operator product targets

    1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
    2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
    3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
    4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
    5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

    Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P11Approved as proposed

    No-founder exercise and independence

    1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
    2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
    3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P12Approved as proposed

    Five-year coexistence envelope

    1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
    2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
    3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
    4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
    5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

    Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P13Deferred by the founder

    Maintenance continuity

    1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
    2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
    3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

    Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P14Approved as proposed

    Genuine commercial and developer proof

    1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
    2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
    3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
    4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

    Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P15Approved as proposed

    Comparative contention threshold

    1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
    2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
    3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
    4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P16Approved as proposed

    Observed durability and claim freshness

    1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
    2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
    3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
    4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    Fixtures

    What every run is built on.

    F0

    Release and assurance manifest

    Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

    F1

    Clean build environments

    Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

    F2

    Hardware and measurement lab

    Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

    F3

    Workload and oracle catalogue

    Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

    F4

    Authorised fault network

    Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

    F5

    Negative and regression corpus

    Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

    F6

    Specialist implementation pack

    Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

    F7

    Economic and incentive models

    Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

    F8

    User/customer/peer studies

    Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

    F9

    Evidence and status vault

    Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

    What a full pass means

    Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

    Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

    Rules in force

    • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
    • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
    • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
    • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

    Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

    Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

    - +
    Igneum 2.0 acceptance

    Test and Acceptance Standard 1.0

    Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

    Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

    APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

    Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 128 cases: 1 passed under the standard, 74 running with team evidence, 3 failed, 1 blocked, 48 not run, 1 deferred

    • 1 pass
    • 3 fail
    • 1 blocked
    • 74 running
    • 48 not run
    • 1 deferred
    The gates

    Five gates, and the freeze before them.

    A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

    G0RUNNING

    Freeze

    Release identity

    No formal run or public pass before approval.

    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred

    • GOV8 casesRUNNING
    G1RUNNING

    Baseline

    D1

    No validated hardware claim without reproduction.

    16 cases: 0 passed under the standard, 10 running with team evidence, 6 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    G2BLOCKED

    Experiments

    D2

    No improvement claim from a negative hypothesis.

    32 cases: 0 passed under the standard, 23 running with team evidence, 1 blocked, 8 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ROT8 casesRUNNING
    G3RUNNING

    Adversary

    D3

    No broad resistance claim from one weak design.

    16 cases: 0 passed under the standard, 11 running with team evidence, 5 not run, 0 deferred

    • GOV8 casesRUNNING
    • ADV8 casesRUNNING
    G4FAIL

    Coexistence

    D4

    No durability claim based on assumed chip expiry.

    24 cases: 0 passed under the standard, 12 running with team evidence, 1 failed, 11 not run, 0 deferred

    • GOV8 casesRUNNING
    • ECO8 casesFAIL
    • INC8 casesRUNNING
    G5RUNNING

    No rescue

    D5

    No no-rescue claim from a founder-supported demo.

    56 cases: 1 passed under the standard, 35 running with team evidence, 20 not run, 0 deferred

    • GOV8 casesRUNNING
    • ROT8 casesRUNNING
    • ZKP8 casesRUNNING
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • OPS8 casesRUNNING
    • UX8 casesRUNNING

    The three named gates

    FAIL

    Technical readiness

    Execution control

    No mainnet-ready claim with missing enforcement or safety.

    64 cases: 1 passed under the standard, 44 running with team evidence, 2 failed, 1 blocked, 16 not run, 0 deferred

    • GOV8 casesRUNNING
    • POW8 casesBLOCKED
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • UX8 casesRUNNING
    RUNNING

    Commercial evidence

    Execution control

    Devnet activity is insufficient.

    24 cases: 0 passed under the standard, 4 running with team evidence, 19 not run, 1 deferred

    • GOV8 casesRUNNING
    • CAP8 casesNOT RUN
    • COM8 casesNOT RUN
    FAIL

    Leadership-contender decision

    Execution control

    Supports a scoped contention assessment, not a guaranteed rank.

    128 cases: 1 passed under the standard, 74 running with team evidence, 3 failed, 1 blocked, 48 not run, 1 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ADV8 casesRUNNING
    • ROT8 casesRUNNING
    • ECO8 casesFAIL
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • OPS8 casesRUNNING
    • UX8 casesRUNNING
    • COM8 casesNOT RUN
    • LEAD8 casesNOT RUN
    01GOV

    Release identity and evidence

    Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

    RUNNING
    Owner
    Release lead + independent assurance
    Gate
    G0 / all gates G0 G1 G2 G3 G4 G5
    Fixtures
    F0 manifest; F1 source/build archives; F9 evidence vault
    Plan pages
    5, 21, 23, 25, 26, 27
    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred
    GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

    Steps

    1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
    2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
    3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

    Accept

    Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

    Evidence the case requires

    Signed F0; source-to-test map; claim inventory; unresolved-field register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    f0-manifest-20261008-b
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    This manual supplies proposed test thresholds, not source-approved protocol parameters.

    Steps

    1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
    2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
    3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

    Accept

    No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

    Evidence the case requires

    Approved profile register; timestamped holdout commitments; change log.

    Evidence record of the run

    What was run
    the profiles approved as proposed by the founder at 18:2x UK before any confirmatory run; P13 deferred
    Run by
    CI steward (a2ecfa95d3206016c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide public source and documented build instructions to three unaffiliated operators.

    Steps

    1. Build on clean declared environments without private files, tokens or founder assistance.
    2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
    3. Run reference vectors and restart a node using only documented artifacts.

    Accept

    All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

    Evidence the case requires

    Build logs; dependency lockfiles; binary comparison; operator attestations.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Enable append-only storage for run outputs and a separate analysis workspace.

    Steps

    1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
    2. Recompute one published figure from raw records on a clean machine.
    3. Modify a retained artifact deliberately and test integrity verification.

    Accept

    Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

    Evidence the case requires

    Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Create controlled defective variants on an isolated network only.

    Steps

    1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
    2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
    3. Confirm the baseline still accepts authorised valid cases.

    Accept

    Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

    Evidence the case requires

    Mutation catalogue; blinded run results; baseline controls; oracle review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

    Steps

    1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
    2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
    3. For each claimed option, require the complete associated test set rather than a demonstration.

    Accept

    Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

    Evidence the case requires

    Scope manifest; activation scan; product-copy comparison; exclusions register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

    Steps

    1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
    2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
    3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

    Accept

    No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

    Evidence the case requires

    Signed scoped reports; conflict declarations; finding/retest ledger.

    Method
    Independent specialist review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

    Steps

    1. Calculate affected test dependencies and invalidate their former PASS statuses.
    2. Regenerate public status pages from F0 and the evidence register.
    3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

    Accept

    Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

    Evidence the case requires

    Dependency impact report; regenerated status page; rejected claim examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    02GPU

    Whole-system GPU measurements

    Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

    RUNNING
    Owner
    GPU lead + three independent operators
    Gate
    G1 / G2 G1 G2
    Fixtures
    F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
    Plan pages
    6, 7, 8, 14, 18, 23
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    GPU-01Cover the declared commodity populationPriority GATEProfile P02RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Freeze the P02 cohort, supported role matrix and the final v6 configuration.

    Steps

    1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
    2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
    3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

    Accept

    All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

    Evidence the case requires

    Cohort manifest; compatibility matrix; raw results by SKU and role.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

    Steps

    1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
    2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
    3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

    Accept

    Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

    Evidence the case requires

    Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Build the baseline and window variant with identical dataset, reads and semantic workload.

    Steps

    1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
    2. Measure paired complete-system energy and accepted throughput, including host work.
    3. Repeat during proving coexistence and expose any memory or scheduling cliff.

    Accept

    Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

    Evidence the case requires

    Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use safe vendor-supported settings only; record operator permission and original settings.

    Steps

    1. Sweep approved core and memory operating points while holding workload constant.
    2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
    3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

    Accept

    Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

    Evidence the case requires

    Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

    Evidence record of the run

    What was run
    the memory-clock ladder at the lock (floor lane 1, b1b8d833)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

    Steps

    1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
    2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
    3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

    Accept

    Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

    Evidence the case requires

    Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use the same hardware against clean, delayed, lossy and intermittent links in F4.

    Steps

    1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
    2. Include reconnects, template changes, expired submissions and pool failover.
    3. Attribute loss to network, local software, validation and protocol causes.

    Accept

    Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

    Evidence the case requires

    Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Run the selected profile on actual reference machines for the P02 soak period.

    Steps

    1. Track wall power, temperatures, clocks, memory and accepted work continuously.
    2. Inject safe power interruptions, process restarts and normal competing desktop load.
    3. Check restored settings and compare late-run efficiency with the first stable period.

    Accept

    No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

    Evidence the case requires

    Seven-day time series; crash reports; settings-restoration checks; drift analysis.

    Evidence record of the run

    What was run
    the 5090 lock pass, 66 minutes at 1,300 MHz with the four-minute reserve (floor lane 1)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

    Steps

    1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
    2. Recompute joules and total cost per accepted work from the shared raw schema.
    3. Investigate divergence before accepting a pooled headline or uncertainty band.

    Accept

    Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

    Evidence the case requires

    Three signed reproduction packs; reconciliation report; final baseline table.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    03POW

    Proof-of-work correctness and coupling

    Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

    BLOCKED
    Owner
    Cryptography + GPU lead
    Gate
    G2 / technical readiness G2
    Fixtures
    F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
    Plan pages
    7, 9, 10, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 blocked, 0 not run, 0 deferred
    POW-01Match independent execution across every backendPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Implement an independently written reference evaluator, not a wrapper around the production GPU path.

    Steps

    1. Execute the P01 corpus across every family, boundary seed and supported backend.
    2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
    3. Minimise every mismatch and rerun it on clean builds.

    Accept

    Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

    Evidence the case requires

    Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

    Steps

    1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
    2. Check bounds, valid dependencies, address distribution and forbidden encodings.
    3. Compare source-level operations with optimised compiled code for removed or altered work.

    Accept

    No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

    Evidence the case requires

    Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Take the 64-register candidate and the cheapest independently proposed storage organisations.

    Steps

    1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
    2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
    3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

    Accept

    Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

    Evidence the case requires

    Liveness traces; alternative implementations; Pareto table; reviewer analysis.

    Evidence record of the run

    What was run
    the connected-state class KILLED (1.10x against the 1.25x gate; live state costs a clock-gated file nothing)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Experiment + independent hardware review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use a candidate initially matched to baseline instruction count, read count and dataset size.

    Steps

    1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
    2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
    3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

    Accept

    The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

    Evidence the case requires

    Matched workloads; GPU runs; redesigned core estimates; held-out results.

    Evidence record of the run

    What was run
    the same experiment, D2(a) closed
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Controlled experiment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04BLOCKEDEvidence none yetLast run 2026-10-08 18:13Z

    Setup

    Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

    Steps

    1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
    2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
    3. Price any valid strategy against fresh evaluation; independently review all bindings.

    Accept

    Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

    Evidence the case requires

    Attack implementations; valid/invalid controls; work-cost analysis; binding review.

    Evidence record of the run

    What was run
    the binding review: twelve reuse paths, none below the honest cost; five open questions B1 to B5
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    binding-review-2026-10-08-a05
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

    Steps

    1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
    2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
    3. Sustain the approved hostile request rate while ordinary valid traffic continues.

    Accept

    All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

    Evidence the case requires

    CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p01-partb-20261008-01
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

    Steps

    1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
    2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
    3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

    Accept

    Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

    Evidence the case requires

    Scope decision; semantic specification; vectors; simplified datapath model.

    Method
    Conditional implementation test
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

    Steps

    1. Retain their historic negative tests and realistic SRAM instruction-memory control.
    2. Inspect the release for reintroduction through renamed settings or hidden paths.
    3. Require a new written hypothesis and complete adversarial retest for any proposed return.

    Accept

    Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

    Evidence the case requires

    Decision register; binary/config scan; negative-control results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    04ADV

    Programmable specialist adversaries

    Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

    RUNNING
    Owner
    Independent hardware team
    Gate
    G3 G3
    Fixtures
    F2 reference GPUs; F6 RTL/physical models; all published families
    Plan pages
    8, 10, 12, 22, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Provide the complete published family bank and future known parameter schedule to the reviewer.

    Steps

    1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
    2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
    3. Verify its outputs against POW vectors before measuring any advantage.

    Accept

    At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

    Evidence the case requires

    Architecture reports; functional simulations; adaptation matrix; reviewer signature.

    Evidence record of the run

    What was run
    the 18-family programmable core placed and routed (9.36 pJ per lane-op, k 0.64 same-node)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent hardware study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

    Steps

    1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
    2. Include construction/update amortisation, bandwidth contention and retained state.
    3. Take the most favourable feasible point for the specialist into the complete-board model.

    Accept

    No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

    Evidence the case requires

    Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

    Evidence record of the run

    What was run
    D2(b): the stored-half hybrid, memory sharing, recomputation priced (the placed hybrid 1.93x same-node at the mean hit)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Model + adversarial implementation
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

    Steps

    1. Compare moving computation, intermediate state or fetched data to each read location.
    2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
    3. Include interconnect, host, synchronisation, idle and conversion costs.

    Accept

    The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

    Evidence the case requires

    Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

    Evidence record of the run

    What was run
    data-local execution moves nothing (2,112 bits of live state against an 80-bit read)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent system modelling
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-04Measure profitable selective participationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use all declared families plus held-out generated programs and the protocol difficulty rule.

    Steps

    1. Identify favourable execution paths and add cheap fallbacks for other periods.
    2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
    3. Evaluate revenue and costs across the full schedule, not just average program energy.

    Accept

    Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

    Evidence the case requires

    Per-program advantage distribution; policy simulator; full-period returns.

    Evidence record of the run

    What was run
    selective participation 9 percent spread across 2,000 era draws
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-05Validate physical and complete-board costsPriority GATEProfile P04RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

    Steps

    1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
    2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
    3. Compare against a calibrated existing hardware block or equivalent validation case.

    Accept

    No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

    Evidence the case requires

    Netlist/physical reports; macro assumptions; bill of materials; model calibration.

    Evidence record of the run

    What was run
    the complete GDDR7 machine 1.5x same-node, 1.8x a node ahead at the placed energy; the honest same-node bracket 1.5x to 2.1x: FAIL against P04 at R_E 1.5, served as such
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    FAIL against P04 at R_E 1.5
    Method
    Independent physical-design review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

    Steps

    1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
    2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
    3. Evaluate measurement confidence and model-parameter sensitivity separately.

    Accept

    P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

    Evidence the case requires

    Node-specific reports; factor provenance; uncertainty and sensitivity tables.

    Evidence record of the run

    What was run
    the node column: same-node and a node ahead kept separate (k 0.78 / 0.56 / 0.40 at N5 / N3 / N2)
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

    Steps

    1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
    2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
    3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

    Accept

    The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

    Evidence the case requires

    Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

    Evidence record of the run

    What was run
    the transition matrix: no row loses competitiveness, the three-year life holds, zero obsolescence credit
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

    Steps

    1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
    2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
    3. Record unresolved modelling disagreements and future technology exclusions.

    Accept

    Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

    Evidence the case requires

    Two review reports; challenge log; final envelope; unresolved-limit statement.

    Method
    Independent challenge/review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    05ROT

    Epochs, seeds and memory transitions

    Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

    RUNNING
    Owner
    Consensus + GPU leads
    Gate
    G5 / G2 G5 G2
    Fixtures
    F0 activation rules; F4 fault network; F5 historical and boundary vectors
    Plan pages
    7, 11, 19, 21
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

    Steps

    1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
    2. Restart nodes from both sides and replay the same headers.
    3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

    Accept

    All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

    Evidence the case requires

    Boundary vectors; node/miner traces; acceptance and reward matrix.

    Evidence record of the run

    What was run
    the fast-time crossings PASS on 4cdcc488 (17:29:58) and 617cb441 (17:30:44) with the cold restart
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use the retained schedule in F0, including coincident program, parameter and family changes.

    Steps

    1. Run every known family transition and all coincident-boundary combinations on production code.
    2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
    3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

    Accept

    Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

    Evidence the case requires

    Transition matrix; code-path evidence; compile timing; old-client logs.

    Evidence record of the run

    What was run
    the class v6 object crossing at its floor on 617cb441
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

    Steps

    1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
    2. Partition voters, restore them and test vote-key substitution through pools.
    3. Verify adoption and refusal behaviour of already running nodes.

    Accept

    The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

    Evidence the case requires

    Executable governance model; signed-vote corpus; coalition/partition results.

    Evidence record of the run

    What was run
    the bring-forward mechanism specified in the D5 block
    Run by
    node lane (a283f5f0d364ceef0)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

    Steps

    1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
    2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
    3. Validate inputs, parameters and proofs against independent vectors.

    Accept

    No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

    Evidence the case requires

    Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Stop checkpoint signing while mining continues, then cross seed and family boundaries.

    Steps

    1. Remove the required signing weight and observe the documented fallback or safe pause.
    2. Prevent access to any founder seed service; restart from persisted state.
    3. Restore the stated fault assumptions and verify deterministic recovery.

    Accept

    Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

    Evidence the case requires

    Fault timeline; seed/certificate history; node-state comparison; recovery log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

    Steps

    1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
    2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
    3. Measure data transfer, restart and excluded-card costs before approving progression.

    Accept

    No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

    Evidence the case requires

    Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use matched baseline and ablated variants in the lab; do not change a running public network.

    Steps

    1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
    2. Include favourable-period specialists and all retained known families.
    3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

    Accept

    Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

    Evidence the case requires

    Ablation report; decision log; complexity/cost comparison.

    Evidence record of the run

    What was run
    the family gate's coverage (38,000 eras) and the rotation prototype paused as the no-rescue control
    Run by
    lane D family gate (a07a99a3788566af2)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    lane D family gate (a07a99a3788566af2)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Freeze the complete published rule bank and known schedule for the five-year evaluation.

    Steps

    1. Allow a programmable adversary to know and survive all planned changes.
    2. Remove assumed future emergency instructions and manual retirement actions from the model.
    3. Run the required ECO scenarios and link them to independent network-transition tests.

    Accept

    Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

    Evidence the case requires

    Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    06ECO

    Five-year coexistence economics

    Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

    FAIL
    Owner
    Economics lead + independent reviewer
    Gate
    G4 G4
    Fixtures
    F6 adversarial costs; F7 scenario model; F2 operator costs
    Plan pages
    8, 13, 18, 24, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 failed, 0 not run, 0 deferred
    ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

    Steps

    1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
    2. Use actual accepted work and independently verify units and period conversions.
    3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

    Accept

    All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

    Evidence the case requires

    Versioned model; unit fixtures; independent reconciliation; input sources.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

    Steps

    1. Evaluate marginal operation separately from recovery of a new purchase.
    2. Stress resale at zero, hardware failures, financing and replacement cycles.
    3. Report break-even power price and total cost relative to the strongest feasible specialist.

    Accept

    P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

    Evidence the case requires

    Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

    Evidence record of the run

    What was run
    the existing-owner and new-entrant tests per class at three electricity prices
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use three development cases: fully funded elsewhere, source-range low and source-range high.

    Steps

    1. Evaluate private mining, public hardware sales and a hybrid business model.
    2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
    3. Re-evaluate GPU entry after the specialist fleet is already installed.

    Accept

    The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

    Evidence the case requires

    Business-model variants; sunk-cost case; full cash-flow and adaptation records.

    Evidence record of the run

    What was run
    the sunk-development case first in the coexistence model
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use independently reviewed dynamic operator policies, not fixed market shares.

    Steps

    1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
    2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
    3. Compare equilibrium and transient outcomes across independent starting conditions.

    Accept

    Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

    Evidence the case requires

    Agent policies; sensitivity seeds; market-share paths; independent model review.

    Evidence record of the run

    What was run
    miners react through a per-class supply curve (the second cut, 21:00)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

    Steps

    1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
    2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
    3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

    Accept

    No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

    Evidence the case requires

    Scenario register; full result cube; boundary plots; failed-world explanations.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

    Steps

    1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
    2. Test flat/declining fees and no external proving income; separately introduce external demand.
    3. Calculate capacity and security-provider coverage after each reward transition.

    Accept

    Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

    Evidence the case requires

    Issuance/fee ledger; scenario cash flows; funding-shortfall report.

    Evidence record of the run

    What was run
    the proving-payment resolution (the 90/10 user-funded payment)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

    Steps

    1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
    2. Include ordinary-owner replacement, resale and reloading expenses.
    3. Run alternate bounded schedules without assigning automatic chip death.

    Accept

    The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

    Evidence the case requires

    Per-step cost/retention table; alternative schedules; approval record.

    Evidence record of the run

    What was run
    the dataset schedule's commodity burden (10.0u)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

    Steps

    1. Recalculate required worlds and perturb favourable assumptions against the team.
    2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
    3. Publish the sensitivity range and state which conclusions are conditional.

    Accept

    Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

    Evidence the case requires

    Independent report; rerun outputs; model limitations; approved claim envelope.

    Method
    Independent economic review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    07EVM

    Execution and developer compatibility

    Keep familiar applications while making every difference and metering rule explicit and reproducible.

    RUNNING
    Owner
    Execution lead + independent implementer
    Gate
    Technical readiness
    Fixtures
    F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
    Plan pages
    15, 25, 34, 35, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Pin the intended execution fork, revm version and all Igneum deviations in F0.

    Steps

    1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
    2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
    3. Minimise mismatches and distinguish intended differences from implementation defects.

    Accept

    All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

    Evidence the case requires

    Fixture/version inventory; root/receipt diffs; deviation matrix.

    Evidence record of the run

    What was run
    /compatibility 20 of 20 rows PASSED on igneum-devnet-4
    Run by
    reference-apps lane (a2060899d2a27d31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use signed transfers, contract calls and deployment transactions with boundary field values.

    Steps

    1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
    2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
    3. Check mempool admission and final consensus execution independently.

    Accept

    Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

    Evidence the case requires

    Signed corpus; admission/execution outcomes; account-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

    Steps

    1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
    2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
    3. Mutate a block producer to omit or undercharge expensive work.

    Accept

    Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

    Evidence the case requires

    Metering traces; fee fixtures; estimator errors; invalid-block rejection.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use contracts sensitive to timestamp, height/context, randomness and ordering.

    Steps

    1. Compare the declared Igneum semantics with developers' documented expectations.
    2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
    3. Run dependency reviews for applications using these values for economic decisions.

    Accept

    Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

    Evidence the case requires

    Context-contract results; threat notes; compatibility exclusions.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

    Steps

    1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
    2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
    3. Compare expected application invariants with native execution and proved results.

    Accept

    Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

    Evidence the case requires

    Contract fixture hashes; transaction journeys; invariant and state comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

    Steps

    1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
    2. Reindex from genesis or the documented trust anchor after pruning and restart.
    3. Compare logs, receipts and balances with independently validated chain state.

    Accept

    No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

    Evidence the case requires

    RPC conformance report; reindex comparison; reconnect/edge-case logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

    Steps

    1. Measure CPU, memory, disk and proving cost against charged budgets.
    2. Saturate admission with invalid/expensive requests while valid workloads continue.
    3. Restart mid-execution and verify atomic state recovery.

    Accept

    P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

    Evidence the case requires

    Resource profiles; adversarial corpus; state recovery comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare two authorised versions and malicious, stale or unknown versions.

    Steps

    1. Cross activation with mixed clients, queued transactions and proofs from both versions.
    2. Bind each accepted proof to the correct execution semantics and program identity.
    3. Exercise a failed software distribution without altering consensus activation.

    Accept

    No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

    Evidence the case requires

    Upgrade vectors; mixed-version traces; manifest/version bindings.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    08ZKP

    Consensus-enforced proof validity

    The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

    RUNNING
    Owner
    Proving + protocol leads; independent cryptography review
    Gate
    Technical readiness / G5 G5
    Fixtures
    F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
    Plan pages
    16, 20, 24, 25, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Start from a native-correct statement and an independently verified valid proof.

    Steps

    1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
    2. Submit the genuine proof as a positive control through ordinary network paths.
    3. Inspect block acceptance and resulting reward/state on unmodified validators.

    Accept

    Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

    Evidence the case requires

    Hostile record corpus; validator decisions; before/after balances; positive controls.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use valid proofs from authorised and unauthorised programs and parameter sets.

    Steps

    1. Swap program digest, verifier version, security settings and verification key where applicable.
    2. Attempt downgrade through configuration, serialized metadata or an old node path.
    3. Test authorised boundary transitions and unsupported future identities.

    Accept

    Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

    Evidence the case requires

    Identity/parameter matrix; rejection traces; cryptographic review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

    Steps

    1. Replay each proof under another network, job, epoch, shard range or state commitment.
    2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
    3. Check duplicated and reordered records across forks and replayed sync data.

    Accept

    Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

    Evidence the case requires

    Binding matrix; public-input hashes; replay traces; reward reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use proofs that commit to authorisation and all reward-relevant fields required by F0.

    Steps

    1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
    2. Supply correct execution over malicious producer-provided consensus/reward inputs.
    3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

    Accept

    Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

    Evidence the case requires

    Mutation cases; reward derivation trace; signature/proof binding review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

    Steps

    1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
    2. Crash validators between validation and reward application, then recover.
    3. Reconcile canonical payouts against the exact F0 duplicate policy.

    Accept

    Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

    Evidence the case requires

    Concurrency schedule; canonical payment ledger; crash/recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

    Steps

    1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
    2. Alter shard ranges, roots and aggregation-program identity.
    3. Verify native execution, aggregate validity and coverage commitments independently.

    Accept

    Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

    Evidence the case requires

    Coverage corpus; aggregate/public-input verification; rejection ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

    Steps

    1. Review soundness assumptions, parameter margins and consequences of performance patches.
    2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
    3. Cross-check an independent verifier or reference path and test crash containment.

    Accept

    P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

    Evidence the case requires

    Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

    Method
    Independent cryptographic review + testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Inspect block import, sync, RPC, light verification, database restoration and fast paths.

    Steps

    1. Try bypassing validation via each path with a proof rejected by the normal path.
    2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
    3. Attempt to use proof-production status as ordering, voting or finality authority.

    Accept

    No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

    Evidence the case requires

    Path coverage report; bypass corpus; replacement run; authority checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    09CAP

    Sustained proving and delivery

    A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

    NOT RUN
    Owner
    Proving lead + independent operators
    Gate
    Technical readiness / commercial track
    Fixtures
    F3 meaningful workload catalogue; F4 network; F8 external job harness
    Plan pages
    17, 18, 24, 25
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

    Steps

    1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
    2. Record proof format, memory, energy, host and whether aggregation/compression are included.
    3. Repeat on the final release and label all configuration changes.

    Accept

    Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

    Evidence the case requires

    Historical/current manifests; proof verification; timing and memory records.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

    Steps

    1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
    2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
    3. Induce memory pressure and GPU task failure without losing wallet control.

    Accept

    Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

    Evidence the case requires

    Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

    Steps

    1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
    2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
    3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

    Accept

    No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

    Evidence the case requires

    Stage event ledger; clock calibration; end-to-end latency/cost report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

    Steps

    1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
    2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
    3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

    Accept

    P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

    Evidence the case requires

    Request/completion reconciliation; backlog series; held-out results; observer report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

    Steps

    1. Observe admission, explicit backpressure, reservations and deadline estimates.
    2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
    3. Measure recovery time and ensure ordinary users are not silently starved.

    Accept

    P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

    Evidence the case requires

    Overload timeline; admission/refund logs; backlog-drain proof.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

    Steps

    1. Measure actual completion distributions with network delay, competing load and failed attempts.
    2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
    3. Compare assignment frequency, paid completions and wasted work by tier.

    Accept

    P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

    Evidence the case requires

    Window sweep; paid-completion distribution; wasted-work and margin report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Remove input providers, assigned provers and the dominant aggregator independently and together.

    Steps

    1. Have replacement operators retrieve authenticated inputs without founder files.
    2. Retry expired assignments while preserving idempotent reward and customer outcomes.
    3. Restore providers and test late submissions racing with replacements.

    Accept

    P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

    Evidence the case requires

    Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Run the external workload using a customer-controlled verifier and independently operated workers.

    Steps

    1. Verify every delivered proof against the contracted program and input commitment.
    2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
    3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

    Accept

    P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

    Evidence the case requires

    Customer verification log; proof-format contract; settlement reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    10INC

    Rewards, incentives and selfish operators

    Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

    RUNNING
    Owner
    Protocol economics + proving leads
    Gate
    G4 / G5 G4 G5
    Fixtures
    F0 fee/reward rules; F4 adversarial operators; F7 incentive models
    Plan pages
    13, 16, 17, 18, 24, 26
    8 cases: 0 passed under the standard, 1 running with team evidence, 7 not run, 0 deferred
    INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use a deterministic short chain containing all reward types, fee paths and rounding cases.

    Steps

    1. Calculate balances, total supply changes, burns and distributions independently.
    2. Execute identical blocks natively and through the proving path.
    3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

    Accept

    Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

    Evidence the case requires

    Independent accounting ledger; balance/supply diffs; boundary vectors.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

    Steps

    1. Trace money from source to operator, protocol, developer and any burn.
    2. Compare node records, settlement records and Ember displays.
    3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

    Accept

    Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

    Evidence the case requires

    Money-flow register; UI reconciliation; rejected classifications.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Permit independent schedulers to mine, prove internally, prove externally or switch off.

    Steps

    1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
    2. Run clients that ignore the official scheduling recommendation.
    3. Measure realised operator margin, internal capacity and network progress.

    Accept

    Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

    Evidence the case requires

    Scheduler source/policies; switching traces; capacity and margin series.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

    Steps

    1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
    2. Observe hash participation, proof backlog, fees and recovery without an administrator.
    3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

    Accept

    Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

    Evidence the case requires

    Shock timeline; fee/hash/capacity paths; failure-region report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

    Steps

    1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
    2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
    3. Price attacker costs and observe honest completion under the approved abuse load.

    Accept

    F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

    Evidence the case requires

    Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

    Steps

    1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
    2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
    3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

    Accept

    Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

    Evidence the case requires

    Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use self-funded operators and related customer identities in the isolated economic model/network.

    Steps

    1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
    2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
    3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

    Accept

    No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

    Evidence the case requires

    Circular-flow tests; ownership/conflict review; net-cash reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Model control of hashing, signing, proving, aggregation and hardware supply separately.

    Steps

    1. Remove each largest operational dependency and combine correlated failures.
    2. Measure replacement cost/time and whether essential roles share hidden ownership.
    3. Compare results with the approved fault model and no-rescue exercise.

    Accept

    No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

    Evidence the case requires

    Role/ownership map; dependency removals; recovery and concentration report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    11FIN

    Consensus safety and recovery

    Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

    RUNNING
    Owner
    Consensus lead + independent formal/security review
    Gate
    G5 / technical readiness G5
    Fixtures
    F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
    Plan pages
    19, 21, 24, 25
    8 cases: 1 passed under the standard, 7 running with team evidence, 0 not run, 0 deferred
    FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

    Steps

    1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
    2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
    3. Replay from independent checkpoints and from genesis where practical.

    Accept

    Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

    Evidence the case requires

    Block/ordering corpus; root/work diffs; real-node replay logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 19:59 UK

    Setup

    Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

    Steps

    1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
    2. Delay messages and eligibility updates independently; keep total historical weights auditable.
    3. Try to form two certificates and reconnect nodes to observe accepted final history.

    Accept

    No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

    Evidence the case requires

    Signed votes; certificate attempts; voter-table snapshots; safety checker output.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    fin-boundary-20261008-02
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Recover historical expiry failures where available; use the actual current authority-transition rules.

    Steps

    1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
    2. Attempt independently renewed authority sets and conflicting checkpoint locks.
    3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

    Accept

    Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

    Evidence the case requires

    Expiry timeline; table/certificate history; historical regression tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Remove enough signing participation to invalidate the liveness assumption without forging votes.

    Steps

    1. Continue mining and execution, cross seed boundaries and monitor proof queues.
    2. Check which user-visible states advance and which remain unfinalised.
    3. Restore eligible weight and bounded message delay, then verify recovery.

    Accept

    No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

    Evidence the case requires

    Signing/mining trace; UI/RPC states; recovery roots and timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use normal transitions, pool members retaining keys and malicious substitution attempts.

    Steps

    1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
    2. Race updates across boundaries and replay old signed changes.
    3. Have a new node verify the authority chain from its declared trust anchor.

    Accept

    Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

    Evidence the case requires

    Authority-chain fixtures; substitution attacks; new-node verification log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

    Steps

    1. Use previously eligible keys to build alternative histories after their operators disappear.
    2. Present these histories to recently offline and newly joining clients.
    3. Test replayed certificates, stale anchors and compromised signer subsets.

    Accept

    Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

    Evidence the case requires

    Long-range corpus; trust-anchor policy; key-compromise review; client results.

    Evidence record of the run

    What was run
    bought and stolen keys in the simulator rows
    Run by
    finality lane (aca0f5ed924a2a99b)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Combine partitions with node crash, partial writes, restarts and proof backlog.

    Steps

    1. Reconnect networks under bounded latency and restore required honest participation.
    2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
    3. Compare all honest nodes and customer-visible receipts after recovery.

    Accept

    P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

    Evidence the case requires

    Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08RUNNINGEvidence recordLast run 8 Oct 2026, 19:38 UK

    Setup

    Use an independent model checker/scheduler and production-node scenarios from F4.

    Steps

    1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
    2. Explore bounded adversarial message schedules and minimise any counterexample.
    3. Replay model findings on real code and have an independent reviewer assess uncovered states.

    Accept

    No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

    Evidence the case requires

    Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

    Method
    Model checking + real-node testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    fin-boundary-20261008
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    12VER

    Wallets, receipts and data availability

    Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

    FAIL
    Owner
    Wallet + light-client lead; independent security review
    Gate
    Technical readiness / claimed options
    Fixtures
    F0 trust/availability model; F5 malformed roots, receipts and authority chains
    Plan pages
    20, 25, 35, 37
    8 cases: 0 passed under the standard, 5 running with team evidence, 2 failed, 1 not run, 0 deferred
    VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

    Steps

    1. Start from the approved trust anchor and verify every required link to the advertised state.
    2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
    3. Remove the bootstrap service and use another independently operated source.

    Accept

    The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

    Evidence the case requires

    Bootstrap corpus; trust-chain trace; fail-closed tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use valid state proofs paired with wrong execution statements or stale authority histories.

    Steps

    1. Cross voter and verifier changes with offline clients returning after long intervals.
    2. Alter roots, aggregate identity and proof/public-input bindings independently.
    3. Check local verification rather than merely a server-reported verified flag.

    Accept

    All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

    Evidence the case requires

    Client verification trace; corrupted inputs; offline/upgrade results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

    Steps

    1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
    2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
    3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

    Accept

    Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

    Evidence the case requires

    Payment fixture corpus; receipt verification; merchant-facing status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

    Steps

    1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
    2. Exercise legitimate authority updates and source reorganisations under the approved model.
    3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

    Accept

    The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

    Evidence the case requires

    Oracle code/parameters; attack cases; cost report; privilege disclosure.

    Method
    Claimed-option verification
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Remove founder archival/input services and start an independent operator from the documented entry point.

    Steps

    1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
    2. Rebuild the expected state and continue validation/proving.
    3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

    Accept

    Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

    Evidence the case requires

    Download/reconstruction logs; data hashes; resource costs; dependency inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

    Steps

    1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
    2. Test retrieval from independent peers and expiry/retry policy.
    3. Restore data and check that recovery cannot alter an already verified commitment.

    Accept

    No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

    Evidence the case requires

    Withholding corpus; peer retrieval traces; availability/status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

    Steps

    1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
    2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
    3. Upgrade and recover without silently changing signing authority or exposing seed material.

    Accept

    No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

    Evidence the case requires

    Security review; canary-secret tests; signing fixtures; restore journey.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Create included-only, executed, proven, finalised, reverted, stale and paused examples.

    Steps

    1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
    2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
    3. Check statements about privacy, Ethereum security and device support.

    Accept

    No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

    Evidence the case requires

    Cross-surface screenshots/logs; state mapping; claim review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1746-ver
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    13OPS

    Independent operation and release security

    A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

    RUNNING
    Owner
    Operations + release leads; independent operators
    Gate
    G5 G5
    Fixtures
    F4 isolated multi-operator network; F0 signed releases; F9 telemetry
    Plan pages
    21, 24, 25, 26
    8 cases: 0 passed under the standard, 3 running with team evidence, 5 not run, 0 deferred
    OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

    Steps

    1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
    2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
    3. Introduce scheduled faults and have independent operators recover using published instructions.

    Accept

    No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

    Evidence the case requires

    Operator roster/conflict checks; dependency removals; full activity/intervention log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Start nodes without the default bootstrap host and give others adversarial peer lists.

    Steps

    1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
    2. Use independent documented discovery paths and validate returned chain data.
    3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

    Accept

    No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

    Evidence the case requires

    Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

    Steps

    1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
    2. Test explicit operator acceptance and the published signing-key incident procedure.
    3. Confirm that distribution-key possession cannot independently activate new consensus rules.

    Accept

    Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

    Evidence the case requires

    Package corpus; approval/activation traces; compromised-key rehearsal.

    Evidence record of the run

    What was run
    the release manifest on igneum_getManifest (d5981514) and /release.json; the signing-key procedure owed
    Run by
    shipper (ae892a8b0f78fe31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

    Steps

    1. Crash during import, proof acceptance, reward application and snapshot generation.
    2. Restore from independently verified snapshots or re-sync through documented procedures.
    3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

    Accept

    No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

    Evidence the case requires

    Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Run hostile test jobs with secret canaries and restrictive worker permissions.

    Steps

    1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
    2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
    3. Retry on every supported isolation backend and check dependency vulnerability handling.

    Accept

    No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

    Evidence the case requires

    Sandbox penetration report; canary logs; resource limits; host-integrity checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use an authorised isolated load environment with declared resource and request-rate budgets.

    Steps

    1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
    2. Measure legitimate traffic, memory/disk growth and validator CPU use.
    3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

    Accept

    P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

    Evidence the case requires

    Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

    Steps

    1. Inject one instance of each monitored failure in the lab.
    2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
    3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

    Accept

    P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

    Evidence the case requires

    Alert matrix; detection timelines; independent runbook exercise.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use a clean previous supported version and the final candidate with independent operators.

    Steps

    1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
    2. Cross activation with mixed versions and unavailable founder distribution hosts.
    3. Re-run affected gates after changes and preserve prior failures and incident lessons.

    Accept

    No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

    Evidence the case requires

    Upgrade/replay logs; invalidation map; repeated gate signatures.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    14UX

    Ember, payouts and operator control

    Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

    RUNNING
    Owner
    Desktop product + pool leads; independent usability study
    Gate
    Operator readiness / G5 G5
    Fixtures
    F2 supported desktops; F8 user study; F4 honest/malicious pools
    Plan pages
    14, 21, 25, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

    Steps

    1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
    2. Record download/data preparation separately as well as complete end-to-end time.
    3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

    Accept

    P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

    Evidence the case requires

    Consent-based study records; task timings; failure reasons; compatibility outcomes.

    Method
    Independent observed user study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    update-return lane (a22d765a2e0355a9f)
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Run mining/proving on active desktops under contention and safe thermal stress.

    Steps

    1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
    2. Crash or restart the UI while workers run and verify ownership of background processes.
    3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

    Accept

    P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

    Evidence the case requires

    Control timings; process/settings audit; restart and safety traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use known rewards, fees, energy readings, retries and operator-entered tariffs.

    Steps

    1. Compare mining, internal proof and external proof income with authoritative ledgers.
    2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
    3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

    Accept

    P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

    Evidence the case requires

    UI/ledger comparisons; tariff fixtures; stale/negative examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use ordinary single-card balances and the actual pooling/payment path.

    Steps

    1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
    2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
    3. Reconcile displayed balances with canonical entitlement and actual settlement.

    Accept

    P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

    Evidence the case requires

    Single-card payout ledger; pool failure record; custody/authorisation review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use an honest pool and a modified pool that replaces worker identity or voting credentials.

    Steps

    1. Verify the consensus binding from performed work to the miner's retained key.
    2. Attempt substitution, replay and reassignment without the miner's authorisation.
    3. Leave the pool and verify retained voting/finality rights under F0.

    Accept

    No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

    Evidence the case requires

    Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

    Evidence record of the run

    What was run
    the pool vote-key commitment design
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Provide a pool interface with declared job-declaration support and independent miner templates.

    Steps

    1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
    2. Have a pool substitute or censor templates and test local verification/fallback.
    3. Measure payout and acceptance consequences without moving authority to the pool.

    Accept

    The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

    Evidence the case requires

    Template commitments; accepted-block evidence; malicious-pool/fallback report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

    Steps

    1. Ask independent users to identify the issue, stop safely and follow the recommended action.
    2. Test explicit update approval, version visibility and a failed/corrupt update.
    3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

    Accept

    P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

    Evidence the case requires

    Observed tasks; update traces; sanitised export tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

    Steps

    1. Compare Ember against independently optimised permissible implementations on identical work.
    2. Measure efficiency, fees, false rejection, installation and update transparency.
    3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

    Accept

    P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

    Evidence the case requires

    Matched software comparison; code/config review; fee/privilege inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    15COM

    Paid demand and sustainable delivery

    Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

    NOT RUN
    Owner
    Commercial lead + independent financial/customer reviewer
    Gate
    Commercial evidence
    Fixtures
    F8 real consenting customers; F7 full service costs; private identity proofs
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 7 not run, 1 deferred
    COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

    Steps

    1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
    2. Run paid jobs through ordinary independently operated infrastructure.
    3. Have the customer verify usefulness, correctness and its reason for choosing the service.

    Accept

    The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

    Evidence the case requires

    Redacted contract; verified jobs; settlement proof; consented customer confirmation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use the P14 multi-customer observation period and ownership/conflict checks.

    Steps

    1. Track paid purchases on distinct occasions, including refunds and stopped customers.
    2. Audit related parties, project reimbursements, token grants and circular funding.
    3. Reconcile external cash received with correctly delivered meaningful work.

    Accept

    P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

    Evidence the case requires

    Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

    Steps

    1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
    2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
    3. Repeat under the declared demand and price sensitivities.

    Accept

    P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

    Evidence the case requires

    Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

    Steps

    1. Count all accepted jobs, including failed, retried and abandoned cases.
    2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
    3. Compare offered capacity and quoted price with what was actually delivered.

    Accept

    P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

    Evidence the case requires

    Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

    Steps

    1. Obtain comparable quotes or consented measured trials at the evaluation date.
    2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
    3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

    Accept

    P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

    Evidence the case requires

    Dated comparison; workload/security match; customer decision record.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Follow all recruited customers through the P14 observation period, including churn.

    Steps

    1. Remove disclosed trial incentives before measuring repeat demand.
    2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
    3. Review whether one affiliated or subsidised buyer dominates the apparent market.

    Accept

    P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

    Evidence the case requires

    Cohort/renewal ledger; churn notes; concentration and incentive report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13DEFERREDEvidence none yetLast run 2026-10-08 18:3x UK (the founder: forget P13 for now)

    Setup

    Prepare a costed plan for development, review, infrastructure, support and incident response.

    Steps

    1. Separate committed resources from revenue dependent on adoption or token price.
    2. Stress lower income and an unexpected security/operations expense.
    3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

    Accept

    P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

    Evidence the case requires

    Budget and commitment evidence; downside plan; owner/continuity roster.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit unaffiliated developers unfamiliar with unpublished implementation details.

    Steps

    1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
    2. Record time, undocumented dependencies, workarounds and correctness issues.
    3. Retest after documentation fixes without founder-written hidden integration code.

    Accept

    P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

    Evidence the case requires

    Consented developer logs; public examples; issue closure; verified end-to-end journeys.

    Method
    Independent integration study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    16LEAD

    Comparative leadership evidence

    A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

    NOT RUN
    Owner
    Independent assessment panel + product/economics reviewers
    Gate
    Leadership-contender decision
    Fixtures
    F8 peer/customer studies; full signed technical evidence; 90-day observation
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

    Steps

    1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
    2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
    3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

    Accept

    The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

    Evidence the case requires

    Timestamped peer protocol; source/version records; comparison/exclusion rationale.

    Method
    Pre-registered comparative study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Use matched user tasks and operating conditions on the selected GPU-first networks.

    Steps

    1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
    2. Measure rejection/availability under the same network conditions; report fees separately.
    3. Use blinded analysis where possible and independent runs for decisive differences.

    Accept

    P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

    Evidence the case requires

    Matched task data; uncertainty/effect sizes; independent comparison report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    site lane (a846fd66b5403e35a)
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

    Steps

    1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
    2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
    3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

    Accept

    All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

    Evidence the case requires

    Claim-to-evidence map; signed envelope review; limitations statement.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

    Steps

    1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
    2. Report trial incentives separately and include every initial participant in retention denominators.
    3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

    Accept

    P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

    Evidence the case requires

    Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

    Steps

    1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
    2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
    3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

    Accept

    P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

    Evidence the case requires

    Control/failure-domain map; uncertainty notes; concentration/removal results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Observe the final candidate and approved compatible updates for the full P16 real-time period.

    Steps

    1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
    2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
    3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

    Accept

    P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

    Evidence the case requires

    90-day SLO ledger; independent probes; incident reports; change/retest history.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

    Steps

    1. Check every mandatory and claimed-option test, source requirement and approved threshold.
    2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
    3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

    Accept

    Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

    Evidence the case requires

    Signed assessment; full status index; dissent/limitations; approved claim wording.

    Method
    Independent final assessment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:13 UK

    Setup

    Define material-change triggers and scheduled reviews before publishing the assessment.

    Steps

    1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
    2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
    3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

    Accept

    Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

    Evidence the case requires

    Review calendar; invalidation drills; versioned public claim register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    Profiles

    The numbers each case is held to.

    17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

    P00Approved as proposed

    Frozen scope and approval

    1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
    2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
    3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P01Approved as proposed

    Correctness and negative-test depth

    1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
    2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
    3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

    Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P02Approved as proposed

    Hardware coverage and reproducibility

    1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
    2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
    3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
    4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

    Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P03Approved as proposed

    Candidate improvement and honest-card budget

    1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
    2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
    3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

    Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P04Approved as proposed

    Scoped specialist-competition target

    1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
    2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
    3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
    4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

    FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P05Approved as proposed

    Measurement and inference protocol

    1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
    2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
    3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
    4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

    Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P06Approved as proposed

    Memory and support policy

    1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
    2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
    3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P07Approved as proposed

    Proof service capacity and fairness

    1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
    2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
    3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
    4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
    5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

    Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P08Approved as proposed

    Fault assumptions and recovery

    1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
    2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
    3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
    4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

    Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P09Approved as proposed

    Security and bounded resource requirements

    1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
    2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
    3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
    4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

    Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P10Approved as proposed

    Ordinary-operator product targets

    1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
    2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
    3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
    4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
    5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

    Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P11Approved as proposed

    No-founder exercise and independence

    1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
    2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
    3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P12Approved as proposed

    Five-year coexistence envelope

    1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
    2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
    3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
    4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
    5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

    Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P13Deferred by the founder

    Maintenance continuity

    1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
    2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
    3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

    Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P14Approved as proposed

    Genuine commercial and developer proof

    1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
    2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
    3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
    4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

    Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P15Approved as proposed

    Comparative contention threshold

    1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
    2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
    3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
    4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P16Approved as proposed

    Observed durability and claim freshness

    1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
    2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
    3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
    4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    Fixtures

    What every run is built on.

    F0

    Release and assurance manifest

    Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

    F1

    Clean build environments

    Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

    F2

    Hardware and measurement lab

    Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

    F3

    Workload and oracle catalogue

    Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

    F4

    Authorised fault network

    Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

    F5

    Negative and regression corpus

    Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

    F6

    Specialist implementation pack

    Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

    F7

    Economic and incentive models

    Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

    F8

    User/customer/peer studies

    Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

    F9

    Evidence and status vault

    Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

    What a full pass means

    Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

    Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

    Rules in force

    • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
    • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
    • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
    • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

    Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

    Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

    + +
    Igneum 2.0 acceptance

    Test and Acceptance Standard 1.0

    Every case of the standard, shown as it is run, in the standard’s own words. A checklist, never a completion score: a gate passes only when every case it depends on has passed.

    Basis IGNEUM_2.0_Plan.pdf, 37 pages, 8 October 2026. The standard runs to 73 pages. Registry dated 8 October 2026.

    APPROVED AS PROPOSED 8 OCTOBER 2026P13 DEFERRED

    Test and Acceptance Standard 1.0: APPROVED AS PROPOSED by the founder, 8 October 2026; P13 (maintenance continuity) DEFERRED; 128 cases: 1 passed under the standard, 73 running with team evidence, 4 failed, 1 blocked, 48 not run, 1 deferred

    • 1 pass
    • 4 fail
    • 1 blocked
    • 73 running
    • 48 not run
    • 1 deferred
    The gates

    Five gates, and the freeze before them.

    A gate reads NOT RUN until every case it depends on has run, RUNNING while any is running, BLOCKED if any is blocked, FAIL if any fails, and PASS only when every case passes. No gate is weighted into an average.

    G0RUNNING

    Freeze

    Release identity

    No formal run or public pass before approval.

    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred

    • GOV8 casesRUNNING
    G1RUNNING

    Baseline

    D1

    No validated hardware claim without reproduction.

    16 cases: 0 passed under the standard, 10 running with team evidence, 6 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    G2BLOCKED

    Experiments

    D2

    No improvement claim from a negative hypothesis.

    32 cases: 0 passed under the standard, 23 running with team evidence, 1 blocked, 8 not run, 0 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ROT8 casesRUNNING
    G3RUNNING

    Adversary

    D3

    No broad resistance claim from one weak design.

    16 cases: 0 passed under the standard, 11 running with team evidence, 5 not run, 0 deferred

    • GOV8 casesRUNNING
    • ADV8 casesRUNNING
    G4FAIL

    Coexistence

    D4

    No durability claim based on assumed chip expiry.

    24 cases: 0 passed under the standard, 12 running with team evidence, 1 failed, 11 not run, 0 deferred

    • GOV8 casesRUNNING
    • ECO8 casesFAIL
    • INC8 casesRUNNING
    G5RUNNING

    No rescue

    D5

    No no-rescue claim from a founder-supported demo.

    56 cases: 1 passed under the standard, 35 running with team evidence, 20 not run, 0 deferred

    • GOV8 casesRUNNING
    • ROT8 casesRUNNING
    • ZKP8 casesRUNNING
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • OPS8 casesRUNNING
    • UX8 casesRUNNING

    The three named gates

    FAIL

    Technical readiness

    Execution control

    No mainnet-ready claim with missing enforcement or safety.

    64 cases: 1 passed under the standard, 43 running with team evidence, 3 failed, 1 blocked, 16 not run, 0 deferred

    • GOV8 casesRUNNING
    • POW8 casesBLOCKED
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • UX8 casesRUNNING
    RUNNING

    Commercial evidence

    Execution control

    Devnet activity is insufficient.

    24 cases: 0 passed under the standard, 4 running with team evidence, 19 not run, 1 deferred

    • GOV8 casesRUNNING
    • CAP8 casesNOT RUN
    • COM8 casesNOT RUN
    FAIL

    Leadership-contender decision

    Execution control

    Supports a scoped contention assessment, not a guaranteed rank.

    128 cases: 1 passed under the standard, 73 running with team evidence, 4 failed, 1 blocked, 48 not run, 1 deferred

    • GOV8 casesRUNNING
    • GPU8 casesRUNNING
    • POW8 casesBLOCKED
    • ADV8 casesRUNNING
    • ROT8 casesRUNNING
    • ECO8 casesFAIL
    • EVM8 casesRUNNING
    • ZKP8 casesRUNNING
    • CAP8 casesNOT RUN
    • INC8 casesRUNNING
    • FIN8 casesRUNNING
    • VER8 casesFAIL
    • OPS8 casesRUNNING
    • UX8 casesRUNNING
    • COM8 casesNOT RUN
    • LEAD8 casesNOT RUN
    01GOV

    Release identity and evidence

    Prevent a favourable result from being attached to the wrong code, assumptions or public claim.

    RUNNING
    Owner
    Release lead + independent assurance
    Gate
    G0 / all gates G0 G1 G2 G3 G4 G5
    Fixtures
    F0 manifest; F1 source/build archives; F9 evidence vault
    Plan pages
    5, 21, 23, 25, 26, 27
    8 cases: 0 passed under the standard, 4 running with team evidence, 4 not run, 0 deferred
    GOV-01Freeze the release and its claimsPriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Candidate source, binaries, public documentation and the 2.0 plan are available; no run is yet accepted.

    Steps

    1. Record exact commits, binary hashes, dependencies, genesis/network identity, mining class, datasets, execution fork, verifier IDs and fee rules in F0.
    2. Map every promised capability and plan requirement to a test ID; distinguish supported mining, proving and wallet combinations.
    3. Sign the manifest with protocol, product and independent review owners before confirmatory runs.

    Accept

    Every material rule and claim has an unambiguous version and test. Conflicts or unknown activation rules produce BLOCKED, not an inferred default. Changes create a new manifest and invalidate affected results.

    Evidence the case requires

    Signed F0; source-to-test map; claim inventory; unresolved-field register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    f0-manifest-20261008-b
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-02Approve thresholds before resultsPriority BLOCKERProfile P00RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    This manual supplies proposed test thresholds, not source-approved protocol parameters.

    Steps

    1. Approve or replace every P-profile before confirmatory testing; give each change a rationale and independent approver.
    2. Register hardware cohorts, mandatory economic worlds, customer workloads, peer dimensions and exclusion rules.
    3. Lock the profile hash and hold out seeds/workloads from the developers doing optimisation.

    Accept

    No decision-critical field is TBD. Numeric limits are frozen, commercially meaningful and not chosen from observed results. A weakened limit after failure requires a new protocol, full affected rerun and explicit claim downgrade review.

    Evidence the case requires

    Approved profile register; timestamped holdout commitments; change log.

    Evidence record of the run

    What was run
    the profiles approved as proposed by the founder at 18:2x UK before any confirmatory run; P13 deferred
    Run by
    CI steward (a2ecfa95d3206016c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-03Reproduce builds outside the founding teamPriority BLOCKERProfile P00, P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide public source and documented build instructions to three unaffiliated operators.

    Steps

    1. Build on clean declared environments without private files, tokens or founder assistance.
    2. Compare reproducible payload hashes; isolate signatures, notarisation and permitted non-deterministic wrappers.
    3. Run reference vectors and restart a node using only documented artifacts.

    Accept

    All independent builds reproduce the same consensus payload or an independently explained, pre-approved wrapper difference; reference outputs match exactly. Missing private prerequisites block release.

    Evidence the case requires

    Build logs; dependency lockfiles; binary comparison; operator attestations.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    18
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-04Preserve raw and negative evidencePriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Enable append-only storage for run outputs and a separate analysis workspace.

    Steps

    1. Capture failed, aborted and successful runs with timestamps, seeds and environment hashes.
    2. Recompute one published figure from raw records on a clean machine.
    3. Modify a retained artifact deliberately and test integrity verification.

    Accept

    Every headline can be regenerated; tampering is detected; exclusions have pre-registered reasons. Failed or missing runs remain visible and are never replaced silently by a successful retry.

    Evidence the case requires

    Artifact manifest; hashes; reproduction script; exclusion ledger; negative-run archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-05Prove the test oracle detects broken behaviourPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Create controlled defective variants on an isolated network only.

    Steps

    1. Disable proof verification, change one reward, accept an expired authority set and alter one hash output in separate mutants.
    2. Run the corresponding ZKP, INC, FIN and POW tests without telling the runner which mutant is active.
    3. Confirm the baseline still accepts authorised valid cases.

    Accept

    Every deliberately introduced fault is caught by its mapped test; valid controls pass. Any undetected critical mutant blocks acceptance of that test family until the oracle is repaired.

    Evidence the case requires

    Mutation catalogue; blinded run results; baseline controls; oracle review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-06Enforce scope and optional-feature disciplinePriority BLOCKERProfile P00RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Inventory FP32 experiments, receipts/oracles and all retained or excluded mining levers.

    Steps

    1. Mark each capability CORE, CLAIMED-OPTIONAL or EXCLUDED before release testing.
    2. For excluded code, check binaries, protocol activation and product copy for accidental enablement or implied availability.
    3. For each claimed option, require the complete associated test set rather than a demonstration.

    Accept

    Every core and claimed-option obligation passes. Excluded items are shown as EXCLUDED, never PASS and never counted as achievements. Removing a failed core requirement prevents an all-2.0-pass claim.

    Evidence the case requires

    Scope manifest; activation scan; product-copy comparison; exclusions register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    19
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-07Independent review and finding closurePriority BLOCKERProfile P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Nominate reviewers with declared conflicts and scopes covering cryptography, consensus and hardware.

    Steps

    1. Provide pinned code, raw data, adversarial models and prior failures, including negative results.
    2. Track each finding to remediation and an independent retest; do not use the author as sole approver.
    3. Have reviewers state unreviewed surfaces and model limitations in their signed conclusions.

    Accept

    No unresolved critical or high-severity finding affects the claimed release. A finite review is described by scope, not as proof of universal security. Independent reproduction and review are both evidenced.

    Evidence the case requires

    Signed scoped reports; conflict declarations; finding/retest ledger.

    Method
    Independent specialist review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    GOV-08Invalidate stale evidence and control public statusPriority BLOCKERProfile P00NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Create a simulated post-test change to a verifier, mining class, dataset and fee rule.

    Steps

    1. Calculate affected test dependencies and invalidate their former PASS statuses.
    2. Regenerate public status pages from F0 and the evidence register.
    3. Attempt to publish a rank-one, guaranteed-profit or automatic-chip-death claim without the required evidence.

    Accept

    Affected gates return to NOT RUN or BLOCKED. Public claims retain version, limits and date; unsupported claims are withheld. No stale result remains attached to a different release.

    Evidence the case requires

    Dependency impact report; regenerated status page; rejected claim examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    CI steward (a2ecfa95d3206016c)
    Design status
    NOT RUN
    Standard page
    20
    Plan pages
    5, 21, 23, 25, 26, 27
    02GPU

    Whole-system GPU measurements

    Close the pending measurements and evaluate the actual configuration, including costs hidden by kernel-only results.

    RUNNING
    Owner
    GPU lead + three independent operators
    Gate
    G1 / G2 G1 G2
    Fixtures
    F2 retail-hardware cohort; F3 paired benchmark workloads; F9 calibrated evidence
    Plan pages
    6, 7, 8, 14, 18, 23
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    GPU-01Cover the declared commodity populationPriority GATEProfile P02RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Freeze the P02 cohort, supported role matrix and the final v6 configuration.

    Steps

    1. Inventory physical SKU, usable memory, driver, operating system, firmware, cooling and acquisition channel.
    2. Run mining on every supported cohort cell and proving on every separately advertised prover cell.
    3. Include lower-memory, used-generation and all advertised vendor cases; retain unsupported results separately.

    Accept

    All declared cells are tested, with no after-the-fact removal of weak cards. At least the P02 minimum coverage is met. Mining-only support is never reported as proof-generation support.

    Evidence the case requires

    Cohort manifest; compatibility matrix; raw results by SKU and role.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-02Reproduce Ember clock-lock savingsPriority GATEProfile P02, P03RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Use paired stock and tuned runs on the same board, host, workload and ambient conditions.

    Steps

    1. Warm to stability; randomise stock/tuned order and run P02 repeated sessions.
    2. Measure accepted work, calibrated wall energy, device telemetry and rejected work.
    3. Calculate paired energy and rate changes with run-level uncertainty, retaining failed tuning attempts.

    Accept

    Tuning preserves correctness and meets approved P03 operating limits. The historical 34-41% saving and under-2% rate-loss statement is reproduced only for qualifying configurations; otherwise that claim is corrected. Existing savings are not counted twice.

    Evidence the case requires

    Raw power/time series; paired analysis; tuning settings; claim-by-SKU table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-03Measure the real 64-register GPU costPriority GATEProfile P02, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Build the baseline and window variant with identical dataset, reads and semantic workload.

    Steps

    1. Inspect compiled register allocation, spills, occupancy and memory traffic on each supported backend.
    2. Measure paired complete-system energy and accepted throughput, including host work.
    3. Repeat during proving coexistence and expose any memory or scheduling cliff.

    Accept

    Any production window meets P03 budgets for every mandatory SKU; no hidden spills or correctness changes. Zero GPU cost is claimed only where measurement supports it within uncertainty. Results feed the redesigned adversary, not an old core estimate.

    Evidence the case requires

    Compiler reports; allocation traces; paired energy/rate data; coexistence runs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    21
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-04Find the memory-clock operating ladderPriority BLOCKERProfile P01, P02RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use safe vendor-supported settings only; record operator permission and original settings.

    Steps

    1. Sweep approved core and memory operating points while holding workload constant.
    2. Measure error rate, accepted throughput, wall energy and thermal equilibrium.
    3. Repeat the selected knee after reboot and restore defaults after a failed or interrupted tuning session.

    Accept

    Selected profiles are stable, reproducible and not dependent on unsafe clocks. Every accepted hash remains correct; saved settings restore predictably. Tuning failure leaves a working safe configuration.

    Evidence the case requires

    Clock ladder; safe bounds; thermal/error logs; reboot and rollback record.

    Evidence record of the run

    What was run
    the memory-clock ladder at the lock (floor lane 1, b1b8d833)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-05Test dataset fit and support-horizon costsPriority BLOCKERProfile P01, P02, P06RUNNINGEvidence recordLast run 8 Oct 2026, 19:41 UK

    Setup

    Test 5.5, 8.5 and 11.5 GiB only as source-proposed candidates; F0 determines activated sizes.

    Steps

    1. Measure allocation plus driver, display, prover and OS headroom on the 8 GB and other cohort tiers.
    2. Run near-full-memory, fragmentation, restart and next-epoch construction scenarios.
    3. Compare time-sharing/eviction with concurrent mining/proving, including reload cost.

    Accept

    Every advertised combination completes without OOM or silent corruption. Unsupported future sizes are identified before activation. GPU exclusions and lost proving capacity appear in ECO evaluation; retirement of a tier is not a success metric.

    Evidence the case requires

    Memory budget per SKU; OOM traces; support horizon; concurrency cost table.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    hash-lane-20261008-batch1
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-06Measure accepted work under ordinary connectivityPriority GATEProfile P02, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use the same hardware against clean, delayed, lossy and intermittent links in F4.

    Steps

    1. Measure kernel rate and accepted work separately under home and datacentre link profiles.
    2. Include reconnects, template changes, expired submissions and pool failover.
    3. Attribute loss to network, local software, validation and protocol causes.

    Accept

    Results use accepted work, never kernel rate alone. Ordinary-link incremental rejection stays within P10; all losses remain priced in ECO. Unreachable links may pause but must not claim paid work.

    Evidence the case requires

    Per-submission ledger; network trace; rejection reasons; accepted-work comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    22
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-07Survive sustained thermal and power operationPriority BLOCKERProfile P01, P02, P10RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Run the selected profile on actual reference machines for the P02 soak period.

    Steps

    1. Track wall power, temperatures, clocks, memory and accepted work continuously.
    2. Inject safe power interruptions, process restarts and normal competing desktop load.
    3. Check restored settings and compare late-run efficiency with the first stable period.

    Accept

    No invalid work or unsafe persistent settings; P02/P10 stability limits hold. Thermal throttling, crashes and recovery time remain in throughput and energy denominators. A crash-free short benchmark cannot substitute for the soak.

    Evidence the case requires

    Seven-day time series; crash reports; settings-restoration checks; drift analysis.

    Evidence record of the run

    What was run
    the 5090 lock pass, 66 minutes at 1,300 MHz with the four-minute reserve (floor lane 1)
    Run by
    hash lane (a690540514aa453d7)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    GPU-08Reproduce the full baseline independentlyPriority GATEProfile P02NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Three unaffiliated operators receive F0, F2 and F3, including the final miner/prover build.

    Steps

    1. Repeat identical-SKU paired runs with documented meter calibration and environment differences.
    2. Recompute joules and total cost per accepted work from the shared raw schema.
    3. Investigate divergence before accepting a pooled headline or uncertainty band.

    Accept

    Reproductions meet P02 tolerance and exact correctness. No unexplained divergence or selectively missing low-end cell remains. Report manufactured GPU measurements separately from modelled specialist estimates.

    Evidence the case requires

    Three signed reproduction packs; reconciliation report; final baseline table.

    Method
    Independent reproduction
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    23
    Plan pages
    6, 7, 8, 14, 18, 23
    03POW

    Proof-of-work correctness and coupling

    Find semantic disagreements and structural shortcuts before treating a harder-looking program as a stronger defence.

    BLOCKED
    Owner
    Cryptography + GPU lead
    Gate
    G2 / technical readiness G2
    Fixtures
    F0 rule set; F3 independent CPU/GPU oracles; F5 mutation corpus
    Plan pages
    7, 9, 10, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 blocked, 0 not run, 0 deferred
    POW-01Match independent execution across every backendPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Implement an independently written reference evaluator, not a wrapper around the production GPU path.

    Steps

    1. Execute the P01 corpus across every family, boundary seed and supported backend.
    2. Exercise zero, maximum, sign, shift, rotate, overflow and unaligned-address cases allowed by the spec.
    3. Minimise every mismatch and rerun it on clean builds.

    Accept

    Bit-for-bit agreement for all valid cases and identical rejection for invalid cases. One unexplained mismatch is a blocker. Large sample counts are evidence of testing, not proof that unseen disagreements cannot exist.

    Evidence the case requires

    Reference implementation review; seeds/vectors; backend matrix; mismatch archive.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-02Validate generated programs and index foldingPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use the frozen grammar, opcode semantics and index-fold rule; include boundary and malformed programs.

    Steps

    1. Enumerate small constrained programs and fuzz the full generator at P01 depth.
    2. Check bounds, valid dependencies, address distribution and forbidden encodings.
    3. Compare source-level operations with optimised compiled code for removed or altered work.

    Accept

    No accepted program violates semantics, termination or memory bounds. Distribution claims have predeclared tests and effect-size limits; passing randomness checks is not treated as a cryptographic proof.

    Evidence the case requires

    Generator/fuzzer logs; reduced counterexamples; disassembly comparison; index tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-03Test whether live state is unavoidablePriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Take the 64-register candidate and the cheapest independently proposed storage organisations.

    Steps

    1. Trace value liveness across dependent reads and final output, distinguishing distinct information from duplicated values.
    2. Try banking, compression, recomputation, fewer ports and time-multiplexed contexts.
    3. Quantify the best complete-system cost/throughput trade-off rather than the reference register count.

    Accept

    Production selection is supported by measured or physically modelled penalties after these alternatives. G2 requires the P03 improvement; an attractive source-level register count alone does not pass.

    Evidence the case requires

    Liveness traces; alternative implementations; Pareto table; reviewer analysis.

    Evidence record of the run

    What was run
    the connected-state class KILLED (1.10x against the 1.25x gate; live state costs a clock-gated file nothing)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Experiment + independent hardware review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    24
    Plan pages
    7, 9, 10, 23
    POW-04Evaluate connected-resource restructuringPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use a candidate initially matched to baseline instruction count, read count and dataset size.

    Steps

    1. Connect state, addresses, arithmetic and lane communication according to the written hypothesis.
    2. Measure GPU cost and allow the specialist reviewer to redesign the entire core.
    3. Repeat on held-out program seeds and compare the worst supported adversary, not only the original design.

    Accept

    The selected upgrade meets P03 and improves the adversarial result outside declared uncertainty. A negative experiment remains a negative outcome; adopting a different design requires a new frozen comparison.

    Evidence the case requires

    Matched workloads; GPU runs; redesigned core estimates; held-out results.

    Evidence record of the run

    What was run
    the same experiment, D2(a) closed
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Controlled experiment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-05Prevent amortised cheap winning attemptsPriority BLOCKERProfile P01, P04BLOCKEDEvidence none yetLast run 2026-10-08 18:13Z

    Setup

    Prepare valid templates, nonces, intermediate-state captures and independent acceptance checks.

    Steps

    1. Vary nonce, payout identity, transactions, roots and other committed fields after expensive work.
    2. Try replay, precomputation, shared prefixes, partial evaluation and many cheap suffix candidates.
    3. Price any valid strategy against fresh evaluation; independently review all bindings.

    Accept

    Invalid modifications are rejected. Any valid cost-saving strategy is incorporated into ADV and must still meet P04/ECO gates. No unresolved shortcut is hidden behind passing reference vectors.

    Evidence the case requires

    Attack implementations; valid/invalid controls; work-cost analysis; binding review.

    Evidence record of the run

    What was run
    the binding review: twelve reuse paths, none below the honest cost; five open questions B1 to B5
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    binding-review-2026-10-08-a05
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-06Bound verifier work and malformed-input costPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Use ordinary CPU validators with a manifest-defined resource budget and untrusted submissions.

    Steps

    1. Submit shortest/longest programs, malformed encodings and adversarial memory references.
    2. Measure verification time, peak memory and work amplification across valid and invalid inputs.
    3. Sustain the approved hostile request rate while ordinary valid traffic continues.

    Accept

    All semantics remain correct and P09 resource budgets hold. Invalid traffic cannot cause unbounded allocation, crashes or disproportionate free work. Rate limits must not replace consensus validation.

    Evidence the case requires

    CPU profiles; adversarial corpus; allocation traces; valid-traffic latency.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p01-partb-20261008-01
    Design status
    NOT RUN
    Standard page
    25
    Plan pages
    7, 9, 10, 23
    POW-07Constrain any mixed-resource or FP32 branchPriority BLOCKERProfile P00, P01, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    If this branch is excluded, verify that it is unreachable and not claimed; if included, use a separate frozen candidate.

    Steps

    1. Specify exact rounding, fusion, special values and backend behaviour before compiling.
    2. Differentially test all supported architectures and allow numerical-domain simplification in the specialist model.
    3. Include verifier cost and candidate energy in P03/P04, not just arithmetic-unit area.

    Accept

    Included branches achieve exact agreed semantics and all hardware budgets. An excluded branch earns no performance credit. No approximate operation or unspecified compiler choice enters consensus.

    Evidence the case requires

    Scope decision; semantic specification; vectors; simplified datapath model.

    Method
    Conditional implementation test
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    POW-08Keep rejected mechanisms out of the shipped claimPriority GATEProfile P00, P03RUNNINGEvidence none yetLast run 8 Oct 2026, 20:10 UK

    Setup

    Inventory long programs, select trees, SM gating, wider reads, sealed classes, random epoch lengths, per-tier scoring and VRF draws.

    Steps

    1. Retain their historic negative tests and realistic SRAM instruction-memory control.
    2. Inspect the release for reintroduction through renamed settings or hidden paths.
    3. Require a new written hypothesis and complete adversarial retest for any proposed return.

    Accept

    Excluded levers remain excluded unless separately approved and retested. Flip-flop instruction-memory area is never presented as the cost of a realistic SRAM implementation.

    Evidence the case requires

    Decision register; binary/config scan; negative-control results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    p02-fleet-pods-20261008-01
    Design status
    NOT RUN
    Standard page
    26
    Plan pages
    7, 9, 10, 23
    04ADV

    Programmable specialist adversaries

    Give the opponent permission to adapt, share resources and remain operational; test cost rather than imagined chip death.

    RUNNING
    Owner
    Independent hardware team
    Gate
    G3 G3
    Fixtures
    F2 reference GPUs; F6 RTL/physical models; all published families
    Plan pages
    8, 10, 12, 22, 23
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ADV-01Build a multi-family programmable opponentPriority GATEProfile P01, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Provide the complete published family bank and future known parameter schedule to the reviewer.

    Steps

    1. Design one programmable architecture that supports all retained families, including firmware and emulation paths.
    2. Optimise clocks, lanes, ports and pipelines without requiring a graphics-card layout.
    3. Verify its outputs against POW vectors before measuring any advantage.

    Accept

    At least the P04 design diversity is evaluated; every estimated competitive design is functionally validated. Inability of one narrow design to adapt is not evidence that all chips expire.

    Evidence the case requires

    Architecture reports; functional simulations; adaptation matrix; reviewer signature.

    Evidence record of the run

    What was run
    the 18-family programmable core placed and routed (9.36 pJ per lane-op, k 0.64 same-node)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent hardware study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-02Price shared, reduced and reconstructed memoryPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Allow multiple engines to share a dataset and to store selected fractions rather than a complete per-engine copy.

    Steps

    1. Sweep sharing factors, memory fractions, caches and recomputation depth across many simultaneous hashes.
    2. Include construction/update amortisation, bandwidth contention and retained state.
    3. Take the most favourable feasible point for the specialist into the complete-board model.

    Accept

    No omitted feasible trade-off materially lowers the accepted cost estimate. Any winning alternative is included in P04 and ECO; capacity alone is not accepted as an energy bound.

    Evidence the case requires

    Sweep definitions; energy/bandwidth data; best-feasible envelope; excluded-design reasons.

    Evidence record of the run

    What was run
    D2(b): the stored-half hybrid, memory sharing, recomputation priced (the placed hybrid 1.93x same-node at the mean hit)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Model + adversarial implementation
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-03Attack with data-local and hybrid executionPriority GATEProfile P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Permit distributed memories, state migration and companion CPU/GPU/FPGA components.

    Steps

    1. Compare moving computation, intermediate state or fetched data to each read location.
    2. Test specialised mining alongside outsourced proof generation rather than assuming one physical GPU does both.
    3. Include interconnect, host, synchronisation, idle and conversion costs.

    Accept

    The cheapest feasible combined system is included in the adversarial envelope and economic model. A worker identity or account is never treated as proof of a single physical device.

    Evidence the case requires

    Hybrid architecture diagrams; traffic traces; system cost and energy ledger.

    Evidence record of the run

    What was run
    data-local execution moves nothing (2,112 bits of live state against an 80-bit read)
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Independent system modelling
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    27
    Plan pages
    8, 10, 12, 22, 23
    ADV-04Measure profitable selective participationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use all declared families plus held-out generated programs and the protocol difficulty rule.

    Steps

    1. Identify favourable execution paths and add cheap fallbacks for other periods.
    2. Simulate entry/exit around profitable periods, including idle time, compilation and re-entry costs.
    3. Evaluate revenue and costs across the full schedule, not just average program energy.

    Accept

    Intermittent specialists meet P04/ECO limits when evaluated on full-period economics. A weak tail cannot be concealed by a favourable mean; known valid shortcuts must be priced.

    Evidence the case requires

    Per-program advantage distribution; policy simulator; full-period returns.

    Evidence record of the run

    What was run
    selective participation 9 percent spread across 2,000 era draws
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-05Validate physical and complete-board costsPriority GATEProfile P04RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use feasible process/library assumptions and documented component boundaries; no fabricated foundry access.

    Steps

    1. Model SRAM macros, ports, wiring, clocking, memory PHYs, external memory, host and power conversion.
    2. Run place-and-route where available; mark unmodelled items as uncertainty rather than zero.
    3. Compare against a calibrated existing hardware block or equivalent validation case.

    Accept

    No decision-critical cost is omitted. Physically unvalidated or proprietary estimates are labelled and independently bounded; synthesis alone cannot earn a manufactured-chip claim.

    Evidence the case requires

    Netlist/physical reports; macro assumptions; bill of materials; model calibration.

    Evidence record of the run

    What was run
    the complete GDDR7 machine 1.5x same-node, 1.8x a node ahead at the placed energy; the honest same-node bracket 1.5x to 2.1x: FAIL against P04 at R_E 1.5, served as such
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    FAIL against P04 at R_E 1.5
    Method
    Independent physical-design review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-06Separate process advantage from specialisationPriority GATEProfile P04, P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Evaluate same-node, one-node-ahead and two-node-ahead scenarios with explicit technology definitions.

    Steps

    1. Use independently justified process factors, voltages, memory and packaging assumptions for each design.
    2. Allow reusable IP and modular revisions; credit GPU improvement consistently.
    3. Evaluate measurement confidence and model-parameter sensitivity separately.

    Accept

    P04 primary limits hold for all competitive-reference cells; two-node futures are reported and pass the predeclared economic stress envelope. A model range is never labelled a statistical confidence interval without justification.

    Evidence the case requires

    Node-specific reports; factor provenance; uncertainty and sensitivity tables.

    Evidence record of the run

    What was run
    the node column: same-node and a node ahead kept separate (k 0.78 / 0.56 / 0.40 at N5 / N3 / N2)
    Run by
    k lane (a3c9601a6d4686fe1)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    k lane (a3c9601a6d4686fe1)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    28
    Plan pages
    8, 10, 12, 22, 23
    ADV-07Evaluate lifetime without forced obsolescencePriority GATEProfile P04, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Assume multi-year productive survival and known schedule support before testing optional retirement penalties.

    Steps

    1. Price firmware, emulation, memory expansion, companion hardware and incremental redesign.
    2. Include 1-, 3- and 5-year productive lifetimes plus idle/resale possibilities.
    3. Grant a retirement credit only if all feasible cheaper adaptations lose competitiveness.

    Accept

    The primary case does not require chip death or a fresh full development bill per family. Every retirement credit has a documented adaptation comparison; incompatible and unprofitable are reported separately.

    Evidence the case requires

    Lifetime/adaptation ledger; revision costs; feasible-alternative analysis.

    Evidence record of the run

    What was run
    the transition matrix: no row loses competitiveness, the three-year life holds, zero obsolescence credit
    Run by
    adversary lane (a1a9876a88f5a72fc)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    ADV-08Independently challenge the best-cost envelopePriority GATEProfile P04NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Publish the non-sensitive model and negative results; commission an unaffiliated second hardware reviewer.

    Steps

    1. Reward cheaper valid designs and reproduced shortcuts, not confirmation of the preferred number.
    2. Re-run P04 with the strongest submitted feasible design, including a low-cost funded-development case.
    3. Record unresolved modelling disagreements and future technology exclusions.

    Accept

    Both reviews accept the scoped envelope or all material disagreements are resolved transparently. Passing supports only evaluated designs and conditions, never a universal bound on all future silicon.

    Evidence the case requires

    Two review reports; challenge log; final envelope; unresolved-limit statement.

    Method
    Independent challenge/review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    adversary lane (a1a9876a88f5a72fc)
    Design status
    NOT RUN
    Standard page
    29
    Plan pages
    8, 10, 12, 22, 23
    05ROT

    Epochs, seeds and memory transitions

    Transitions must agree across nodes and remain usable during failures; crossing a boundary is not a chip-retirement test.

    RUNNING
    Owner
    Consensus + GPU leads
    Gate
    G5 / G2 G5 G2
    Fixtures
    F0 activation rules; F4 fault network; F5 historical and boundary vectors
    Plan pages
    7, 11, 19, 21
    8 cases: 0 passed under the standard, 6 running with team evidence, 2 not run, 0 deferred
    ROT-01Agree across every hourly boundaryPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use real nodes, CPU/GPU miners and independent clocks around successive program boundaries.

    Steps

    1. Submit valid work immediately before, at and after the activation boundary under clock skew and delayed delivery.
    2. Restart nodes from both sides and replay the same headers.
    3. Compare selected seed, program, validity, rewards and local wall-clock dependence.

    Accept

    All honest nodes derive identical consensus outcomes from the frozen rule. Late work is handled exactly as specified; no wall-clock ambiguity or cross-backend split occurs.

    Evidence the case requires

    Boundary vectors; node/miner traces; acceptance and reward matrix.

    Evidence record of the run

    What was run
    the fast-time crossings PASS on 4cdcc488 (17:29:58) and 617cb441 (17:30:44) with the cold restart
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-02Cross weekly and family boundaries togetherPriority BLOCKERProfile P01, P03, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use the retained schedule in F0, including coincident program, parameter and family changes.

    Steps

    1. Run every known family transition and all coincident-boundary combinations on production code.
    2. Interrupt downloads, compilation and restart during activation; include mixed old/new clients.
    3. Repeat selected cases under real elapsed time and the remainder under disclosed accelerated time.

    Accept

    Deterministic activation, documented old-client behaviour and no unsafe fallback. Compilation/setup costs satisfy P03; accelerated runs are not reported as years of operating history.

    Evidence the case requires

    Transition matrix; code-path evidence; compile timing; old-client logs.

    Evidence record of the run

    What was run
    the class v6 object crossing at its floor on 617cb441
    Run by
    fast-time lane (a8be71a0db962911c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-03Test miner-voted bring-forward governancePriority BLOCKERProfile P00, P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze eligibility, threshold, windows and activation semantics before testing; do not invent a no-veto rule.

    Steps

    1. Attempt threshold-minus-one, threshold, conflicting proposals, duplicate votes and coalition withholding.
    2. Partition voters, restore them and test vote-key substitution through pools.
    3. Verify adoption and refusal behaviour of already running nodes.

    Accept

    The actual mechanism enforces F0, with authenticated voting and no conflicting activation. Any coalition capable of blocking or manipulating changes is disclosed; labels such as no veto do not override arithmetic.

    Evidence the case requires

    Executable governance model; signed-vote corpus; coalition/partition results.

    Evidence record of the run

    What was run
    the bring-forward mechanism specified in the D5 block
    Run by
    node lane (a283f5f0d364ceef0)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    30
    Plan pages
    7, 11, 19, 21
    ROT-04Resist seed selection and faster evaluatorsPriority BLOCKERProfile P00, P01, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Provide the specified seed pipeline and delay proof implementation plus independently parameterised fast-adversary models.

    Steps

    1. Try withholding candidate seeds, grinding alternatives, replaying delay proofs and biased checkpoint selection.
    2. Vary adversarial speed advantage and outage duration; trace influence on program choice.
    3. Validate inputs, parameters and proofs against independent vectors.

    Accept

    No invalid seed or proof is accepted; selection advantage stays within the approved threat-model bound. Missing bounds block this gate. A delay mechanism is not credited as generic ASIC resistance.

    Evidence the case requires

    Seed/grinding simulations; speed sensitivity; proof vectors; threat-model signoff.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-05Continue or pause correctly when finality stopsPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Stop checkpoint signing while mining continues, then cross seed and family boundaries.

    Steps

    1. Remove the required signing weight and observe the documented fallback or safe pause.
    2. Prevent access to any founder seed service; restart from persisted state.
    3. Restore the stated fault assumptions and verify deterministic recovery.

    Accept

    Mining/seed behaviour matches F0 without manufacturing certificates or reinterpreting finality. Safety holds during the outage; liveness is required only after its stated assumptions return.

    Evidence the case requires

    Fault timeline; seed/certificate history; node-state comparison; recovery log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-06Activate datasets without hidden exclusionsPriority BLOCKERProfile P01, P06RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Freeze memory sizes, support horizon and sync/update procedure; test all advertised roles.

    Steps

    1. Construct the next dataset while current work remains active; test slow disks, low free memory and interruption.
    2. Try stale-state/dataset submissions and maliciously expensive state growth where coupling exists.
    3. Measure data transfer, restart and excluded-card costs before approving progression.

    Accept

    No invalid stale work is accepted, no supported card silently fails, and P06 is met. Hardware retirement and sync burden are included in the economic decision, not treated as automatic chip protection.

    Evidence the case requires

    Dataset hashes; memory/update traces; stale-work tests; exclusion decision.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    31
    Plan pages
    7, 11, 19, 21
    ROT-07Ablate redundant rotation layersPriority GATEProfile P03, P04RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use matched baseline and ablated variants in the lab; do not change a running public network.

    Steps

    1. Remove each weekly/family component independently and measure adversarial cost, GPU setup and verifier complexity.
    2. Include favourable-period specialists and all retained known families.
    3. Keep a layer only with a distinct, independently supported benefit or a documented non-resistance purpose.

    Accept

    Every retained layer has explicit justification and full boundary coverage. Redundant complexity is removed or its rationale recorded; the security model does not double-count the same versatility cost.

    Evidence the case requires

    Ablation report; decision log; complexity/cost comparison.

    Evidence record of the run

    What was run
    the family gate's coverage (38,000 eras) and the rotation prototype paused as the no-rescue control
    Run by
    lane D family gate (a07a99a3788566af2)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    lane D family gate (a07a99a3788566af2)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    ROT-08Pass the no-new-rules counterfactualPriority GATEProfile P04, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Freeze the complete published rule bank and known schedule for the five-year evaluation.

    Steps

    1. Allow a programmable adversary to know and survive all planned changes.
    2. Remove assumed future emergency instructions and manual retirement actions from the model.
    3. Run the required ECO scenarios and link them to independent network-transition tests.

    Accept

    Competitiveness survives the approved envelope without future rescue assumptions. Any result that needs unannounced changes fails this claim; ordinary bug maintenance is distinguished from anti-chip intervention.

    Evidence the case requires

    Frozen-rule model; scenario results; excluded-rescue audit; G5 evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    32
    Plan pages
    7, 11, 19, 21
    06ECO

    Five-year coexistence economics

    Test the world after specialised hardware exists, including new entrants and an already-funded competitor.

    FAIL
    Owner
    Economics lead + independent reviewer
    Gate
    G4 G4
    Fixtures
    F6 adversarial costs; F7 scenario model; F2 operator costs
    Plan pages
    8, 13, 18, 24, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 failed, 0 not run, 0 deferred
    ECO-01Reconcile complete cost per accepted workPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Use benchmark outputs, current-source cost inputs recorded at execution time and separate reference scenarios.

    Steps

    1. Calculate hardware annualisation, electricity, host, cooling/hosting, failures, fees, downtime and residual value.
    2. Use actual accepted work and independently verify units and period conversions.
    3. Cross-check formulas using hand-worked fixtures, edge cases and a second implementation.

    Accept

    All material costs and rejected-work effects appear once; model totals reconcile to raw inputs. No GPU upgrade is free, development cost is not double-counted, and burn is not mislabelled operator income.

    Evidence the case requires

    Versioned model; unit fixtures; independent reconciliation; input sources.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-02Separate existing-owner and new-entrant viabilityPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use both installed hardware and purchasable replacement hardware in every mandatory cohort.

    Steps

    1. Evaluate marginal operation separately from recovery of a new purchase.
    2. Stress resale at zero, hardware failures, financing and replacement cycles.
    3. Report break-even power price and total cost relative to the strongest feasible specialist.

    Accept

    P12 competitiveness conditions hold for the predeclared cohorts in required sustainable worlds. Existing-owner profitability cannot substitute for viable new entry; cards outside the envelope remain visible.

    Evidence the case requires

    Owner/entrant curves; price-date records; break-even tables; cohort outcomes.

    Evidence record of the run

    What was run
    the existing-owner and new-entrant tests per class at three electricity prices
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-03Let the specialist keep its sunk developmentPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use three development cases: fully funded elsewhere, source-range low and source-range high.

    Steps

    1. Evaluate private mining, public hardware sales and a hybrid business model.
    2. Allow shared IP, incremental revisions, multi-year survival and resale where justified.
    3. Re-evaluate GPU entry after the specialist fleet is already installed.

    Accept

    The coexistence claim does not depend on recovering the original chip research bill. Required P12 cases meet the approved envelope even at zero incremental development cost; failures cannot be hidden by the $23M/$340M source thresholds.

    Evidence the case requires

    Business-model variants; sunk-cost case; full cash-flow and adaptation records.

    Evidence record of the run

    What was run
    the sunk-development case first in the coexistence model
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    33
    Plan pages
    8, 13, 18, 24, 26
    ECO-04Model entry, exit and difficulty responsePriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use independently reviewed dynamic operator policies, not fixed market shares.

    Steps

    1. Let agents buy, sell, switch off, re-enter and choose tasks based on declared costs and expected income.
    2. Apply the actual difficulty/reward rules and test optimistic and adversarial liquidity/capital availability.
    3. Compare equilibrium and transient outcomes across independent starting conditions.

    Accept

    Mandatory worlds satisfy P12 without an imposed GPU share or artificial specialist capacity limit. Concentration, oscillations and excluded regions are reported; model behaviour matches unit and conservation checks.

    Evidence the case requires

    Agent policies; sensitivity seeds; market-share paths; independent model review.

    Evidence record of the run

    What was run
    miners react through a per-class supply curve (the second cut, 21:00)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-05Stress success, contraction and cheap electricityPriority GATEProfile P12FAILEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Freeze mandatory scenarios before results: revenue bands, tariff range, lifetimes and demand states.

    Steps

    1. Run the P12 factorial grid plus adversarial combinations selected by the independent reviewer.
    2. Test a large successful network as well as weak-revenue and heterogeneous-tariff cases.
    3. Distinguish feasible sustained-entry worlds from collapse scenarios with no rational profitable operator.

    Accept

    No small-network or token-appreciation assumption props up the primary claim. Required viable worlds pass the envelope; collapse worlds show honest contraction and safety, not fabricated profits. Failure regions are explicit.

    Evidence the case requires

    Scenario register; full result cube; boundary plots; failed-world explanations.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-06Fund security and proving as issuance fallsPriority GATEProfile P12RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use the frozen supply, halving, fee, burn and reward rules rather than source prose assumptions.

    Steps

    1. Reconcile revenue reaching miners, internal provers, developers and burns over the full horizon.
    2. Test flat/declining fees and no external proving income; separately introduce external demand.
    3. Calculate capacity and security-provider coverage after each reward transition.

    Accept

    Recurring compensation is explicit and internally consistent; mandatory sustainable scenarios meet P12. Burned amounts are never counted as payments, and external operator income is not assumed to fund internal work automatically.

    Evidence the case requires

    Issuance/fee ledger; scenario cash flows; funding-shortfall report.

    Evidence record of the run

    What was run
    the proving-payment resolution (the 90/10 user-funded payment)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    34
    Plan pages
    8, 13, 18, 24, 26
    ECO-07Price memory growth and honest-card displacementPriority GATEProfile P06, P12RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Use GPU-05 and ROT-06 costs with the cheapest specialist adaptation.

    Steps

    1. For each dataset increment, compare specialist cost increases with excluded cards and lost proving capacity.
    2. Include ordinary-owner replacement, resale and reloading expenses.
    3. Run alternate bounded schedules without assigning automatic chip death.

    Accept

    The retained schedule meets P06/P12 and has an evidence-backed net competitiveness benefit. A schedule that mainly harms accessible GPUs fails; excluded tiers and mitigations are documented before activation.

    Evidence the case requires

    Per-step cost/retention table; alternative schedules; approval record.

    Evidence record of the run

    What was run
    the dataset schedule's commodity burden (10.0u)
    Run by
    research lane (ad6a2bd47d4a46105)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    ECO-08Reproduce and adversarially audit the modelPriority GATEProfile P12RUNNINGEvidence recordLast run 8 Oct 2026, 19:39 UK

    Setup

    Give an independent economist or qualified analyst the code, inputs and frozen success criteria.

    Steps

    1. Recalculate required worlds and perturb favourable assumptions against the team.
    2. Check dependence on discounts, utilisation, capital limits, artificial prices and future upgrades.
    3. Publish the sensitivity range and state which conclusions are conditional.

    Accept

    Material results reproduce, required scenarios pass and no unacknowledged assumption dominates the claim. The model supports a bounded coexistence conclusion, not a percentage probability that no chip will appear.

    Evidence the case requires

    Independent report; rerun outputs; model limitations; approved claim envelope.

    Method
    Independent economic review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Run
    eco05-20261008-01
    Design status
    NOT RUN
    Standard page
    35
    Plan pages
    8, 13, 18, 24, 26
    07EVM

    Execution and developer compatibility

    Keep familiar applications while making every difference and metering rule explicit and reproducible.

    RUNNING
    Owner
    Execution lead + independent implementer
    Gate
    Technical readiness
    Fixtures
    F0 execution-fork semantics; F5 transactions/contracts; F4 multi-node network
    Plan pages
    15, 25, 34, 35, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    EVM-01Match the selected EVM semanticsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Pin the intended execution fork, revm version and all Igneum deviations in F0.

    Steps

    1. Run the applicable upstream execution/state fixtures plus independently written deviation tests.
    2. Execute identical blocks on multiple nodes and compare roots, receipts, logs, gas and failure outcomes.
    3. Minimise mismatches and distinguish intended differences from implementation defects.

    Accept

    All applicable vectors match; every deviation has a documented test and developer consequence. No claim of universal Ethereum equivalence or Ethereum settlement security is inferred.

    Evidence the case requires

    Fixture/version inventory; root/receipt diffs; deviation matrix.

    Evidence record of the run

    What was run
    /compatibility 20 of 20 rows PASSED on igneum-devnet-4
    Run by
    reference-apps lane (a2060899d2a27d31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-02Preserve transaction binding and replay protectionPriority BLOCKERProfile P01RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use signed transfers, contract calls and deployment transactions with boundary field values.

    Steps

    1. Alter chain identity, nonce, signature, fee caps and recipient after signing.
    2. Replay across nodes, forks and distinct test networks; resubmit around reorganisation.
    3. Check mempool admission and final consensus execution independently.

    Accept

    Unauthorised, wrong-network or duplicate spends are rejected according to F0. Valid replacements follow the declared rule; mempool filtering alone is not evidence of consensus enforcement.

    Evidence the case requires

    Signed corpus; admission/execution outcomes; account-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-03Test two-dimensional fees and proving limitsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Freeze fee dimensions, estimator rules, abort behaviour and refund policy.

    Steps

    1. Run workloads near and beyond execution and proving budgets, including state-heavy pathological cases.
    2. Compare estimated fees with charged fees and validate rollback/receipt status on abort.
    3. Mutate a block producer to omit or undercharge expensive work.

    Accept

    Deterministic metering, charged amounts and aborted state agree across nodes and proofs. Resource bounds hold; fee estimates meet P09 for accepted supported cases. Undercharged invalid blocks cannot bypass consensus.

    Evidence the case requires

    Metering traces; fee fixtures; estimator errors; invalid-block rejection.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    36
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-04Exercise block context and randomness assumptionsPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use contracts sensitive to timestamp, height/context, randomness and ordering.

    Steps

    1. Compare the declared Igneum semantics with developers' documented expectations.
    2. Test boundary transitions, miner-influenced inputs and adversarial ordering in the isolated network.
    3. Run dependency reviews for applications using these values for economic decisions.

    Accept

    Semantics match F0 and differences are surfaced in compatibility documentation. No source of miner influence is marketed as unbiased randomness; incompatible applications are not included in the compatibility claim.

    Evidence the case requires

    Context-contract results; threat notes; compatibility exclusions.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-05Run representative contract integration journeysPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Use versioned transfer/token, NFT, multisignature, exchange and upgrade-pattern fixtures where supported.

    Steps

    1. Deploy, initialise, transact, revert and upgrade each contract using ordinary tooling.
    2. Exercise events, logs, balances, storage and call traces across node restart/reorganisation.
    3. Compare expected application invariants with native execution and proved results.

    Accept

    Supported journeys preserve their stated invariants; all deviations are documented. Example deployment success alone cannot stand in for application-level correctness or financial audit.

    Evidence the case requires

    Contract fixture hashes; transaction journeys; invariant and state comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-06Validate wallets, RPC and indexersPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:13 UK

    Setup

    Pin supported RPC methods and response semantics; use normal developer clients and an independent indexer.

    Steps

    1. Test fee estimation, pending/final states, subscriptions, pagination and reconnects.
    2. Reindex from genesis or the documented trust anchor after pruning and restart.
    3. Compare logs, receipts and balances with independently validated chain state.

    Accept

    No missing/duplicate canonical records; unsupported methods are explicit. UI states distinguish included, executed, proven and finalised. Malformed RPC input cannot crash validators or leak secrets.

    Evidence the case requires

    RPC conformance report; reindex comparison; reconnect/edge-case logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1744-evm
    Design status
    NOT RUN
    Standard page
    37
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-07Handle execution denial-of-service workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Create bounded pathological bytecode, calls, state growth, storage and precompile inputs.

    Steps

    1. Measure CPU, memory, disk and proving cost against charged budgets.
    2. Saturate admission with invalid/expensive requests while valid workloads continue.
    3. Restart mid-execution and verify atomic state recovery.

    Accept

    P09 limits hold with no unbounded free work or divergent rollback. State remains consistent after crash; availability under overload follows the declared admission policy, not silent dropping of accepted transactions.

    Evidence the case requires

    Resource profiles; adversarial corpus; state recovery comparisons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    EVM-08Verify controlled execution and verifier upgradesPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare two authorised versions and malicious, stale or unknown versions.

    Steps

    1. Cross activation with mixed clients, queued transactions and proofs from both versions.
    2. Bind each accepted proof to the correct execution semantics and program identity.
    3. Exercise a failed software distribution without altering consensus activation.

    Accept

    No unknown or wrong-version execution is accepted. Pre/post-boundary handling is deterministic and documented; software delivery cannot silently redefine transaction semantics or proof acceptance.

    Evidence the case requires

    Upgrade vectors; mixed-version traces; manifest/version bindings.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    38
    Plan pages
    15, 25, 34, 35, 36, 37
    08ZKP

    Consensus-enforced proof validity

    The validator, not merely the official producer, must reject unauthorised or invalid proof records and rewards.

    RUNNING
    Owner
    Proving + protocol leads; independent cryptography review
    Gate
    Technical readiness / G5 G5
    Fixtures
    F0 pinned programs/verifiers; F5 valid and hostile proof corpus; unmodified validators
    Plan pages
    16, 20, 24, 25, 36, 37
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    ZKP-01Reject missing and invalid proofsPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Start from a native-correct statement and an independently verified valid proof.

    Steps

    1. Submit the statement with no proof, truncated bytes, random bytes and targeted proof mutations using a modified producer.
    2. Submit the genuine proof as a positive control through ordinary network paths.
    3. Inspect block acceptance and resulting reward/state on unmodified validators.

    Accept

    Every invalid proof record is rejected and earns no reward; valid controls succeed. A producer-side filter is not sufficient. Record rejection semantics exactly as defined by F0.

    Evidence the case requires

    Hostile record corpus; validator decisions; before/after balances; positive controls.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-02Bind program, verifier and security parametersPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use valid proofs from authorised and unauthorised programs and parameter sets.

    Steps

    1. Swap program digest, verifier version, security settings and verification key where applicable.
    2. Attempt downgrade through configuration, serialized metadata or an old node path.
    3. Test authorised boundary transitions and unsupported future identities.

    Accept

    Only explicitly authorised combinations are accepted in the correct epoch. No implicit trust in producer-supplied metadata or lower-security fallback; all accepted settings have scoped soundness review.

    Evidence the case requires

    Identity/parameter matrix; rejection traces; cryptographic review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-03Bind network, epoch, job and state rootsPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Prepare valid proofs for distinct chains, epochs, jobs and initial/final states.

    Steps

    1. Replay each proof under another network, job, epoch, shard range or state commitment.
    2. Alter public inputs while retaining the proof and test valid-but-wrong-context statements.
    3. Check duplicated and reordered records across forks and replayed sync data.

    Accept

    Every misbound proof is rejected; valid authorised replays follow only explicitly allowed semantics and never create extra rewards. Native reexecution cannot conceal missing proof-context binding.

    Evidence the case requires

    Binding matrix; public-input hashes; replay traces; reward reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    39
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-04Prevent reward and payout substitutionPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use proofs that commit to authorisation and all reward-relevant fields required by F0.

    Steps

    1. Alter payout key, amount, beneficiary, source work or fee allocation independently.
    2. Supply correct execution over malicious producer-provided consensus/reward inputs.
    3. Compare consensus-derived rewards with the proved/publicly authenticated derivation.

    Accept

    Unauthorised payout changes and incorrect consensus inputs are rejected; no statement accepted merely because execution over supplied inputs is internally correct. Legitimate authorisations are preserved.

    Evidence the case requires

    Mutation cases; reward derivation trace; signature/proof binding review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-05Make proof payment idempotent across racesPriority BLOCKERProfile P01RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Use competing provers submitting valid results for the same work and simulate retries/reorganisations.

    Steps

    1. Submit simultaneous duplicates, reordered receipts and repeated messages after disconnects.
    2. Crash validators between validation and reward application, then recover.
    3. Reconcile canonical payouts against the exact F0 duplicate policy.

    Accept

    Only the authorised total payment is made; no double payout, lost accepted entitlement or fork-retained balance. Transactions and payout records recover atomically.

    Evidence the case requires

    Concurrency schedule; canonical payment ledger; crash/recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-06Verify aggregation coverage and completenessPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Build valid multi-shard workloads plus omitted, duplicated, overlapping and misordered shard sets.

    Steps

    1. Attempt an aggregate with a correct outer proof but wrong coverage/public-input construction.
    2. Alter shard ranges, roots and aggregation-program identity.
    3. Verify native execution, aggregate validity and coverage commitments independently.

    Accept

    Only complete, correctly ordered authorised coverage is accepted. No valid proof of the wrong computation becomes an accepted chain result; aggregation failures do not fabricate successful delivery.

    Evidence the case requires

    Coverage corpus; aggregate/public-input verification; rejection ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    40
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-07Review soundness and verifier resource limitsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide proof-system code, parameters, patches and the pinned verification path to an independent specialist.

    Steps

    1. Review soundness assumptions, parameter margins and consequences of performance patches.
    2. Fuzz deserialization and adversarial proofs; measure verification CPU and memory under load.
    3. Cross-check an independent verifier or reference path and test crash containment.

    Accept

    P09 review and resource requirements pass with no unresolved critical/high finding. Random proof rejection counts are not described as evidence of a particular cryptographic security level.

    Evidence the case requires

    Scoped soundness review; parameter sheet; fuzzer corpus; verifier profiles.

    Method
    Independent cryptographic review + testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    ZKP-08Preserve authority and audit all acceptance pathsPriority BLOCKERProfile P01, P07, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 20:03 UK

    Setup

    Inspect block import, sync, RPC, light verification, database restoration and fast paths.

    Steps

    1. Try bypassing validation via each path with a proof rejected by the normal path.
    2. Remove the dominant prover/aggregator and have independent replacements process available inputs.
    3. Attempt to use proof-production status as ordering, voting or finality authority.

    Accept

    No bypass accepts invalid work; proofs alone confer no unauthorised consensus control. Replacement and pause behaviour meet F0/P07/P08 without privileged keys or a trusted aggregator shortcut.

    Evidence the case requires

    Path coverage report; bypass corpus; replacement run; authority checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    enforced-proving-20261008-01
    Design status
    NOT RUN
    Standard page
    41
    Plan pages
    16, 20, 24, 25, 36, 37
    09CAP

    Sustained proving and delivery

    A correct fast shard is only one stage; capacity, latency, payment and retries must work together.

    NOT RUN
    Owner
    Proving lead + independent operators
    Gate
    Technical readiness / commercial track
    Fixtures
    F3 meaningful workload catalogue; F4 network; F8 external job harness
    Plan pages
    17, 18, 24, 25
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    CAP-01Reproduce the historical consumer-shard resultPriority GATEProfile P02, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Recover the exact source-era workload/build if available; keep it separate from the release-candidate workload.

    Steps

    1. Attempt independent reproduction of the 4,717,439-cycle workload and reported 3060/4060/4070 results.
    2. Record proof format, memory, energy, host and whether aggregation/compression are included.
    3. Repeat on the final release and label all configuration changes.

    Accept

    Historical figures are either reproduced within P02 tolerance or corrected/labelled non-reproduced. Release acceptance uses the current complete workload, never an unmatched historical time or a smaller substituted shard.

    Evidence the case requires

    Historical/current manifests; proof verification; timing and memory records.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-02Prove on the actual mining configurationPriority BLOCKERProfile P01, P06, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use final dataset sizes, registers, clocks, drivers and proof pipeline on every advertised proving tier.

    Steps

    1. Run mining alone, proving alone, concurrent execution and supported time-sharing.
    2. Measure wall energy, memory headroom, reloads, proof latency and forgone accepted mining work.
    3. Induce memory pressure and GPU task failure without losing wallet control.

    Accept

    Every advertised mode completes correctly and meets P06/P07. Net output includes opportunity cost; unsupported concurrency is not claimed. Mining-only vendor support remains separately labelled.

    Evidence the case requires

    Four-mode results; OOM/failure logs; memory and opportunity-cost ledger.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-03Measure the entire request-to-payment pathPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Assign a unique job ID and immutable timestamps to every stage of F3/F8 jobs.

    Steps

    1. Record request, input availability, assignment, execution, shard proof, aggregation, verification, delivery and payment.
    2. Compare monotonic elapsed time with any protocol/DAA clock and document their relationship.
    3. Reconcile failed, censored, retried and abandoned jobs with the original request denominator.

    Accept

    No hidden stage or missing job; latency distributions and cost cover the complete path. Delivery, finality and payment are reported separately; protocol seconds are not silently relabelled wall-clock seconds.

    Evidence the case requires

    Stage event ledger; clock calibration; end-to-end latency/cost report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    42
    Plan pages
    17, 18, 24, 25
    CAP-04Sustain meaningful load without queue growthPriority GATEProfile P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Freeze W: payload mix, input sizes, execution work and per-hour demand; prohibit tiny-workload substitution.

    Steps

    1. Run 72 hours at W and a separate 24 hours at 1.2W on the declared fleet.
    2. Measure arrival/completion counts, backlog trend, oldest-job age, deadlines and all retries.
    3. Use held-out workloads and an independent observer to detect discarded or delayed requests.

    Accept

    P07 completion, tail-latency and bounded-backlog criteria hold. Capacity is stated for the tested W/fleet, not as universal TPS. A queue that grows indefinitely or shrinks through silent loss fails.

    Evidence the case requires

    Request/completion reconciliation; backlog series; held-out results; observer report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-05Overload and recover without false acceptancePriority BLOCKERProfile P01, P07NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Start at W and inject 2W for 15 minutes with valid and invalid jobs, then return to W.

    Steps

    1. Observe admission, explicit backpressure, reservations and deadline estimates.
    2. Track accepted jobs to valid completion or the pre-agreed failure/refund outcome.
    3. Measure recovery time and ensure ordinary users are not silently starved.

    Accept

    P07 overload policy and recovery limits hold; no accepted job vanishes or earns an invalid reward. Rejected demand is reported separately from delivery success, preventing denominator manipulation.

    Evidence the case requires

    Overload timeline; admission/refund logs; backlog-drain proof.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-06Calibrate assignment windows to paid completionPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use a heterogeneous proving fleet, including the slowest advertised consumer tier.

    Steps

    1. Measure actual completion distributions with network delay, competing load and failed attempts.
    2. Test the chosen exclusive window, open claiming and faster challengers after expiry.
    3. Compare assignment frequency, paid completions and wasted work by tier.

    Accept

    P07 fairness and wasted-work limits hold for advertised tiers. A provisional 10-DAA-second window is not treated as approved. Fair assignment counts alone cannot pass; payment outcomes and operator margins matter.

    Evidence the case requires

    Window sweep; paid-completion distribution; wasted-work and margin report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    43
    Plan pages
    17, 18, 24, 25
    CAP-07Reassign work when inputs or providers disappearPriority BLOCKERProfile P01, P07, P08NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Remove input providers, assigned provers and the dominant aggregator independently and together.

    Steps

    1. Have replacement operators retrieve authenticated inputs without founder files.
    2. Retry expired assignments while preserving idempotent reward and customer outcomes.
    3. Restore providers and test late submissions racing with replacements.

    Accept

    P07/P08 replacement deadlines hold when availability assumptions permit. Otherwise a truthful bounded pause/refund occurs; no fake proof, double payment or hidden privileged input source is used.

    Evidence the case requires

    Failure schedule; input hashes; reassignment and payout ledger; recovery trace.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    CAP-08Deliver customer-verifiable output at scalePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Run the external workload using a customer-controlled verifier and independently operated workers.

    Steps

    1. Verify every delivered proof against the contracted program and input commitment.
    2. Reject wrong-format, stale and partial deliveries; test customer retry and delivery failure.
    3. Reconcile delivery, acceptance, payment and refund records without exposing private inputs publicly.

    Accept

    P07 delivery performance and exact validity hold. Payment depends on the contracted correct result; a valid proof for the wrong job is not a successful delivery.

    Evidence the case requires

    Customer verification log; proof-format contract; settlement reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fleet lane (ac055d60427caab99)
    Design status
    NOT RUN
    Standard page
    44
    Plan pages
    17, 18, 24, 25
    10INC

    Rewards, incentives and selfish operators

    Assume operators optimise their own returns. Do not depend on the official client choosing a less profitable task.

    RUNNING
    Owner
    Protocol economics + proving leads
    Gate
    G4 / G5 G4 G5
    Fixtures
    F0 fee/reward rules; F4 adversarial operators; F7 incentive models
    Plan pages
    13, 16, 17, 18, 24, 26
    8 cases: 0 passed under the standard, 1 running with team evidence, 7 not run, 0 deferred
    INC-01Reconcile issuance, fees, burns and recipientsPriority BLOCKERProfile P01, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use a deterministic short chain containing all reward types, fee paths and rounding cases.

    Steps

    1. Calculate balances, total supply changes, burns and distributions independently.
    2. Execute identical blocks natively and through the proving path.
    3. Test zero, minimum, maximum and transition-boundary values plus malformed producer accounting.

    Accept

    Conservation and recipient rules match F0 exactly; no inflation, rounding leakage or duplicate reward. Fee-table and prose discrepancies are resolved before the run, not guessed by the tester.

    Evidence the case requires

    Independent accounting ledger; balance/supply diffs; boundary vectors.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-02Keep revenue streams and claims separatePriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Prepare jobs and blocks producing mining income, internal proof rewards and external payments.

    Steps

    1. Trace money from source to operator, protocol, developer and any burn.
    2. Compare node records, settlement records and Ember displays.
    3. Attempt to classify testnet rewards, reimbursed purchases or token appreciation as external customer revenue.

    Accept

    Every stream reconciles and is labelled correctly. No double-counted revenue or fabricated protocol demand; mining subsidy and external service income remain distinct in dashboards and ECO.

    Evidence the case requires

    Money-flow register; UI reconciliation; rejected classifications.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-03Let a modified client choose the most profitable taskPriority GATEProfile P07, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Permit independent schedulers to mine, prove internally, prove externally or switch off.

    Steps

    1. Publish common costs and vary relative task rewards, memory pressure and switching costs.
    2. Run clients that ignore the official scheduling recommendation.
    3. Measure realised operator margin, internal capacity and network progress.

    Accept

    Required P12 sustainable worlds maintain paid essential capacity without compelled altruism. Profitability and availability are based on realised outcomes, including switching and wasted work.

    Evidence the case requires

    Scheduler source/policies; switching traces; capacity and margin series.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    45
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-04Survive external-demand spikes and token declinesPriority GATEProfile P07, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use F7 scenarios with 10x external job offers and token-denominated mining-income shocks.

    Steps

    1. Allow miners/provers to switch freely under the declared reward and difficulty rules.
    2. Observe hash participation, proof backlog, fees and recovery without an administrator.
    3. Repeat with external demand dropping to zero and with a dominant operator withdrawn.

    Accept

    Mandatory viable worlds meet P07/P12; stressed nonviable worlds fail or pause safely with truthful status. No emergency rule, fabricated demand or unofficial subsidy is inserted to force a pass.

    Evidence the case requires

    Shock timeline; fee/hash/capacity paths; failure-region report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-05Contain job reservation and identity-splitting abusePriority BLOCKERProfile P01, P07, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Freeze the actual assignment/payment mechanism; do not assume unimplemented collateral or identity controls.

    Steps

    1. Create many worker identities, reserve jobs, withhold proofs and submit late results.
    2. Attempt free option-taking, duplicate work rewards and displacement of honest assignments.
    3. Price attacker costs and observe honest completion under the approved abuse load.

    Accept

    F0 rules and P07 service limits hold under the declared adversary. Identity splitting does not create unauthorised rewards or control; any unmitigated starvation path blocks the permissionless-service claim.

    Evidence the case requires

    Attack clients; assignment trace; cost-to-disrupt analysis; honest-user outcomes.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-06Test difficulty and timestamp manipulationPriority BLOCKERProfile P01, P08, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use the actual adjustment algorithm and consensus timestamp rule with independent miners.

    Steps

    1. Inject large hashrate arrivals/departures, periodic selective mining and boundary-timed bursts.
    2. Try allowed and invalid timestamp skew, withheld blocks and replayed work.
    3. Observe block intervals, reward allocation and recovery after hashrate stabilises.

    Accept

    Invalid inputs are rejected; valid adversarial strategies remain within F0/P08 bounds and are priced in ECO. No unexplained reward amplification, permanent stall or conflicting accepted work.

    Evidence the case requires

    Difficulty trace; timestamp corpus; revenue analysis; independent rule review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    46
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-07Resist self-dealing fees and fake proving demandPriority BLOCKERProfile P01, P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use self-funded operators and related customer identities in the isolated economic model/network.

    Steps

    1. Cycle funds through jobs, tips, developer shares and rebates to seek net reward extraction.
    2. Attempt to inflate external-demand metrics without genuine unrelated customer expenditure.
    3. Reconcile all counterparties and net cash contribution rather than gross transaction volume.

    Accept

    No unauthorised subsidy extraction or metric inflation passes. Related-party volume is disclosed/excluded from P14; net external cash and legitimate protocol incentives are reported separately.

    Evidence the case requires

    Circular-flow tests; ownership/conflict review; net-cash reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    enforced-proving lane (a6e8f84588b809d62)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    INC-08Quantify provider and supplier failure concentrationPriority GATEProfile P08, P11, P12NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Model control of hashing, signing, proving, aggregation and hardware supply separately.

    Steps

    1. Remove each largest operational dependency and combine correlated failures.
    2. Measure replacement cost/time and whether essential roles share hidden ownership.
    3. Compare results with the approved fault model and no-rescue exercise.

    Accept

    No hidden single dependency defeats the claimed independence; within-tolerance withdrawals recover under P08/P11. Hardware supply concentration is disclosed without equating vendor sales to operator voting control.

    Evidence the case requires

    Role/ownership map; dependency removals; recovery and concentration report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    research lane (ad6a2bd47d4a46105)
    Design status
    NOT RUN
    Standard page
    47
    Plan pages
    13, 16, 17, 18, 24, 26
    11FIN

    Consensus safety and recovery

    Test safety under the stated fault bounds. Demand liveness only when synchrony and participation assumptions actually hold.

    RUNNING
    Owner
    Consensus lead + independent formal/security review
    Gate
    G5 / technical readiness G5
    Fixtures
    F0 exact fault model; F4 real-node partitions; F5 certificates and historical failures
    Plan pages
    19, 21, 24, 25
    8 cases: 1 passed under the standard, 7 running with team evidence, 0 not run, 0 deferred
    FIN-01Agree on ordering, work and executed statePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use real fork-choice/DAG handling and independent miners, not only a simplified simulator.

    Steps

    1. Generate concurrent branches, delayed blocks, duplicates and invalid work with deterministic seeds.
    2. Compare selected ordering, accumulated work, transaction execution and state roots after delivery converges.
    3. Replay from independent checkpoints and from genesis where practical.

    Accept

    Honest nodes converge under F0 assumptions with exact roots and rewards. No duplicated work accounting or undocumented ordering dependence; simulator-only success cannot substitute.

    Evidence the case requires

    Block/ordering corpus; root/work diffs; real-node replay logs.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-02Attack finality with split honest populationsPriority BLOCKERProfile P01, P08PASSEvidence recordLast run 8 Oct 2026, 19:59 UK

    Setup

    Use the source-discussed 40/40/20 weight split, plus threshold-boundary splits under F0.

    Steps

    1. Let the 20% adversarial group sign conflicting histories while honest groups are partitioned.
    2. Delay messages and eligibility updates independently; keep total historical weights auditable.
    3. Try to form two certificates and reconnect nodes to observe accepted final history.

    Accept

    No conflicting final certificates are accepted within the declared fault bound. A safe pause is valid when quorum is unavailable; making progress on both sides is not required.

    Evidence the case requires

    Signed votes; certificate attempts; voter-table snapshots; safety checker output.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    fin-boundary-20261008-02
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-03Cross authority expiry in a long partitionPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Recover historical expiry failures where available; use the actual current authority-transition rules.

    Steps

    1. Partition for 31, 35, 60 and 90 logical days and around every retention/expiry boundary.
    2. Attempt independently renewed authority sets and conflicting checkpoint locks.
    3. Repeat selected boundary cases on real nodes with accelerated timers explicitly labelled.

    Accept

    Authority continuity remains authenticated and no conflicting final history appears within F0 assumptions. A timeout is not accepted as proof absent voters ceased to exist. Compressed time is not multi-month field evidence.

    Evidence the case requires

    Expiry timeline; table/certificate history; historical regression tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    48
    Plan pages
    19, 21, 24, 25
    FIN-04Stop signing while mining continuesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Remove enough signing participation to invalidate the liveness assumption without forging votes.

    Steps

    1. Continue mining and execution, cross seed boundaries and monitor proof queues.
    2. Check which user-visible states advance and which remain unfinalised.
    3. Restore eligible weight and bounded message delay, then verify recovery.

    Accept

    No false finality or fabricated authority. Behaviour matches F0 during the pause and P08 after assumptions return; unfinished transactions are not displayed as irreversible.

    Evidence the case requires

    Signing/mining trace; UI/RPC states; recovery roots and timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-05Authenticate voter-set changes and pooled keysPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use normal transitions, pool members retaining keys and malicious substitution attempts.

    Steps

    1. Alter voter weights, membership proofs, miner/pool identity bindings and prior-certificate links.
    2. Race updates across boundaries and replay old signed changes.
    3. Have a new node verify the authority chain from its declared trust anchor.

    Accept

    Only correctly authenticated changes are accepted; weights cannot be double-counted or redirected by a pool. All honest nodes agree on the active authority set for each certified point.

    Evidence the case requires

    Authority-chain fixtures; substitution attacks; new-node verification log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-06Analyse old-key compromise and long-range historiesPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Freeze assumptions about key erasure, retained weights, trust anchors and offline recovery.

    Steps

    1. Use previously eligible keys to build alternative histories after their operators disappear.
    2. Present these histories to recently offline and newly joining clients.
    3. Test replayed certificates, stale anchors and compromised signer subsets.

    Accept

    Acceptance matches the explicit security model with no hidden trusted recovery step. Any reliance on a recent trusted anchor is disclosed and tested; hashpower assumptions cannot replace old-key analysis.

    Evidence the case requires

    Long-range corpus; trust-anchor policy; key-compromise review; client results.

    Evidence record of the run

    What was run
    bought and stolen keys in the simulator rows
    Run by
    finality lane (aca0f5ed924a2a99b)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    49
    Plan pages
    19, 21, 24, 25
    FIN-07Recover deterministically after reconnection and crashPriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Combine partitions with node crash, partial writes, restarts and proof backlog.

    Steps

    1. Reconnect networks under bounded latency and restore required honest participation.
    2. Verify fork choice, unfinalised reorganisation, finality, reward rollback and proof reassignments.
    3. Compare all honest nodes and customer-visible receipts after recovery.

    Accept

    P08 recovery holds without reversing a previously valid final guarantee. Only permitted unfinalised state is reorganised; no duplicate rewards or inconsistent receipt statuses survive.

    Evidence the case requires

    Recovery timelines; roots/certificates; payout rollback; customer-state reconciliation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    finality lane (aca0f5ed924a2a99b)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    FIN-08Combine boundaries, faults and adversarial schedulingPriority BLOCKERProfile P01, P08RUNNINGEvidence recordLast run 8 Oct 2026, 19:38 UK

    Setup

    Use an independent model checker/scheduler and production-node scenarios from F4.

    Steps

    1. Combine epoch changes, authority transitions, mining churn, data delays and prover/aggregator loss.
    2. Explore bounded adversarial message schedules and minimise any counterexample.
    3. Replay model findings on real code and have an independent reviewer assess uncovered states.

    Accept

    No unresolved safety failure; liveness claims hold only within declared assumptions and P08. Model bounds and untested schedules are published, not described as proof over every possible execution.

    Evidence the case requires

    Model/spec artifacts; schedule corpus; replay evidence; independent assessment.

    Method
    Model checking + real-node testing
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    fast-time lane (a8be71a0db962911c)
    Run
    fin-boundary-20261008
    Design status
    NOT RUN
    Standard page
    50
    Plan pages
    19, 21, 24, 25
    12VER

    Wallets, receipts and data availability

    Verify the exact property shown to the user. An inclusion proof, execution proof and finality certificate are not interchangeable.

    FAIL
    Owner
    Wallet + light-client lead; independent security review
    Gate
    Technical readiness / claimed options
    Fixtures
    F0 trust/availability model; F5 malformed roots, receipts and authority chains
    Plan pages
    20, 25, 35, 37
    8 cases: 0 passed under the standard, 4 running with team evidence, 3 failed, 1 not run, 0 deferred
    VER-01Authenticate light-client bootstrapPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Give a clean client malicious RPC responses, fabricated voter tables and valid-looking signatures.

    Steps

    1. Start from the approved trust anchor and verify every required link to the advertised state.
    2. Substitute otherwise well-formed but unauthorised keys, weights and checkpoints.
    3. Remove the bootstrap service and use another independently operated source.

    Accept

    The client rejects unauthorised authority and discloses any trust anchor. Signatures over a node-supplied table do not by themselves pass; missing authentication never silently degrades to trusted RPC.

    Evidence the case requires

    Bootstrap corpus; trust-chain trace; fail-closed tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-02Verify evolving authority and execution statementsPriority BLOCKERProfile P01, P09FAILEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Use valid state proofs paired with wrong execution statements or stale authority histories.

    Steps

    1. Cross voter and verifier changes with offline clients returning after long intervals.
    2. Alter roots, aggregate identity and proof/public-input bindings independently.
    3. Check local verification rather than merely a server-reported verified flag.

    Accept

    All advertised proof checks occur locally or the remaining trust is explicitly disclosed. Wrong roots and unauthenticated authority are rejected; unsupported verification paths are not claimed.

    Evidence the case requires

    Client verification trace; corrupted inputs; offline/upgrade results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-03Prove successful payment rather than inclusionPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Create successful, reverted, wrong-asset, wrong-recipient and wrong-amount transfers.

    Steps

    1. Generate receipts for included transactions, including failures and replaced/unfinalised transactions.
    2. Verify execution status plus asset, recipient, amount and canonical-state/receipt commitment.
    3. Replay the receipt on another chain and after an allowed unfinalised reorganisation.

    Accept

    Only the actual successful, correctly bound transfer is labelled payment proof. Inclusion-only receipts are labelled as such; no node-reported success flag substitutes for authenticated outcome.

    Evidence the case requires

    Payment fixture corpus; receipt verification; merchant-facing status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    51
    Plan pages
    20, 25, 35, 37
    VER-04Bound cross-chain oracle trust and replayPriority BLOCKERProfile P00, P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    For a claimed oracle, freeze destination verifier, authority updates, accepted proof types and replay policy.

    Steps

    1. Try deployer-substituted keys, stale certificates, unchecked signatures and wrong source/destination identities.
    2. Exercise legitimate authority updates and source reorganisations under the approved model.
    3. Measure gas/cost with realistic header sets and test disabled/unavailable verification.

    Accept

    The oracle enforces its declared trust model and fails closed. Deployer privileges and unavailable guarantees are explicit; no trustless-bridge claim exceeds the checks performed. Excluded oracle scope earns no pass credit.

    Evidence the case requires

    Oracle code/parameters; attack cases; cost report; privilege disclosure.

    Method
    Claimed-option verification
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-05Reconstruct required state without founder storagePriority BLOCKERProfile P01, P08, P09FAILEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Remove founder archival/input services and start an independent operator from the documented entry point.

    Steps

    1. Fetch authenticated blocks, state/proof inputs and any required witnesses from permitted peers.
    2. Rebuild the expected state and continue validation/proving.
    3. Measure bandwidth, disk, time and retention requirements against advertised operator budgets.

    Accept

    Required data can be obtained and verified within the declared availability model. Hidden archives or unpublished files block independence. A valid execution proof alone does not satisfy this test.

    Evidence the case requires

    Download/reconstruction logs; data hashes; resource costs; dependency inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-06Detect withholding, corruption and stale dataPriority BLOCKERProfile P01, P08, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Serve valid commitments with missing data, corrupted chunks, stale witnesses and conflicting peer replies.

    Steps

    1. Attempt to make a validator or light client accept an unavailable or incorrect state under F0.
    2. Test retrieval from independent peers and expiry/retry policy.
    3. Restore data and check that recovery cannot alter an already verified commitment.

    Accept

    No unjustified available/verified status; safety and admission rules match F0. Recovery is bounded where assumptions permit, and unavailable-data states remain visible instead of hidden behind proofs.

    Evidence the case requires

    Withholding corpus; peer retrieval traces; availability/status checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    52
    Plan pages
    20, 25, 35, 37
    VER-07Protect wallet keys, signing and recoveryPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use test-only keys, encrypted backups and clean replacement devices; no real user funds.

    Steps

    1. Attempt secret access from proving jobs, logs, crash dumps, clipboard and telemetry paths.
    2. Verify transaction destination/amount before signing; test backup/restore and wrong-password handling.
    3. Upgrade and recover without silently changing signing authority or exposing seed material.

    Accept

    No unintended secret disclosure or unauthorised signature. Supported recovery restores the correct keys and accounts; users receive explicit risk/backup information. Logs are sanitised without hiding security evidence.

    Evidence the case requires

    Security review; canary-secret tests; signing fixtures; restore journey.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    VER-08Keep every user-facing state truthfulPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 8 Oct 2026, 20:15 UK

    Setup

    Create included-only, executed, proven, finalised, reverted, stale and paused examples.

    Steps

    1. Compare explorer, wallet, receipt, RPC and customer API labels against authenticated evidence.
    2. Interrupt finality and proof services and observe refresh/reconnect behaviour.
    3. Check statements about privacy, Ethereum security and device support.

    Accept

    No stronger state is implied than verified; stale data is marked and failures are actionable. EVM compatibility is not labelled Ethereum security, and ZK technology is not automatically labelled transaction privacy.

    Evidence the case requires

    Cross-surface screenshots/logs; state mapping; claim review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    reference-apps lane (a2060899d2a27d31c)
    Run
    ra-20261008T1915-ver
    Design status
    NOT RUN
    Standard page
    53
    Plan pages
    20, 25, 35, 37
    13OPS

    Independent operation and release security

    A permissionless specification must remain operational without privileged infrastructure or unsafe automatic updates.

    RUNNING
    Owner
    Operations + release leads; independent operators
    Gate
    G5 G5
    Fixtures
    F4 isolated multi-operator network; F0 signed releases; F9 telemetry
    Plan pages
    21, 24, 25, 26
    8 cases: 0 passed under the standard, 3 running with team evidence, 5 not run, 0 deferred
    OPS-01Run the complete no-founder exercisePriority BLOCKERProfile P07, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use the P11 independent network, adequate honest participation and enough non-founder capacity for W.

    Steps

    1. Remove founder miners, provers, aggregators, RPC, DNS/bootstrap dependencies and private support access.
    2. Run the full P11 period while crossing real and separately labelled accelerated boundaries.
    3. Introduce scheduled faults and have independent operators recover using published instructions.

    Accept

    No founder action, secret file, privileged key or emergency anti-chip rule is needed. P07/P08 outcomes hold within assumptions; any intervention is recorded as a failed no-rescue run, not erased.

    Evidence the case requires

    Operator roster/conflict checks; dependency removals; full activity/intervention log.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-02Diversify bootstrap and resist peer isolationPriority BLOCKERProfile P01, P08, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Start nodes without the default bootstrap host and give others adversarial peer lists.

    Steps

    1. Attempt eclipse through peer concentration, stale discovery, poisoned DNS and repeated identities in an isolated lab.
    2. Use independent documented discovery paths and validate returned chain data.
    3. Measure synchronisation, peer diversity and recovery after benign connectivity returns.

    Accept

    No unauthenticated history is trusted; bootstrap has no hidden single-provider requirement. Isolation is detected/contained according to F0 and recovery meets P08 when assumptions return.

    Evidence the case requires

    Peer/discovery traces; eclipse scenarios; startup and recovery evidence.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-03Separate update distribution from consensus authorityPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use test signing keys and clean desktop/node installations with valid, stale and malicious packages.

    Steps

    1. Offer signed updates with unexpected consensus rules, downgraded binaries and corrupted payloads.
    2. Test explicit operator acceptance and the published signing-key incident procedure.
    3. Confirm that distribution-key possession cannot independently activate new consensus rules.

    Accept

    Tampering/unauthorised rollback is rejected; updates do not silently transfer authority. Approved acceptance and activation are separate. No test touches production signing material.

    Evidence the case requires

    Package corpus; approval/activation traces; compromised-key rehearsal.

    Evidence record of the run

    What was run
    the release manifest on igneum_getManifest (d5981514) and /release.json; the signing-key procedure owed
    Run by
    shipper (ae892a8b0f78fe31c)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    54
    Plan pages
    21, 24, 25, 26
    OPS-04Recover nodes from crash and storage damagePriority BLOCKERProfile P01, P08RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use production database/snapshot paths with controlled interrupted writes and corrupted test storage.

    Steps

    1. Crash during import, proof acceptance, reward application and snapshot generation.
    2. Restore from independently verified snapshots or re-sync through documented procedures.
    3. Compare roots, certificates, balances and processed-job IDs with an unaffected node.

    Accept

    No corrupt snapshot is trusted, no duplicate payout and no loss of authenticated final state. Recovery meets P08 where data is available; ambiguous corruption fails closed and is actionable.

    Evidence the case requires

    Crash schedule; snapshot hashes; root/balance diffs; recovery timing.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    node lane (a283f5f0d364ceef0)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-05Isolate untrusted proving workloadsPriority BLOCKERProfile P01, P09NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Run hostile test jobs with secret canaries and restrictive worker permissions.

    Steps

    1. Attempt filesystem escape, process spawning, resource exhaustion, network access and key-store reads.
    2. Crash workers and inspect host, wallet and node availability plus dump/log contents.
    3. Retry on every supported isolation backend and check dependency vulnerability handling.

    Accept

    No secret leakage or unauthorised host action; P09 resource containment holds. Worker failure does not compromise validator/wallet authority; unsupported isolation is not marketed as safe execution.

    Evidence the case requires

    Sandbox penetration report; canary logs; resource limits; host-integrity checks.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-06Contain malicious network and API trafficPriority BLOCKERProfile P01, P09RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use an authorised isolated load environment with declared resource and request-rate budgets.

    Steps

    1. Send malformed headers, proofs, oversized messages, floods and invalid peer sequences.
    2. Measure legitimate traffic, memory/disk growth and validator CPU use.
    3. Test limit resets, peer reconnect and graceful degradation without disabling validation.

    Accept

    P09 abuse budgets hold; no unbounded allocation, persistent crash or invalid acceptance. Backpressure is visible and honest users retain the specified service at admitted load.

    Evidence the case requires

    Load/corpus manifests; resource series; valid-traffic metrics; incident traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    55
    Plan pages
    21, 24, 25, 26
    OPS-07Detect failures with usable evidence and runbooksPriority GATEProfile P09, P10NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Define alerts for invalid acceptance, conflicting finality, backlog, data loss, payout mismatch and stale status.

    Steps

    1. Inject one instance of each monitored failure in the lab.
    2. Have an unaffiliated operator diagnose it using only emitted evidence and published instructions.
    3. Test redaction, metric freshness and duplicate-alert suppression without suppressing serious failures.

    Accept

    P10 alert/detection limits hold; every blocker produces actionable evidence. Monitoring does not leak secrets or mislabel intentional safe pauses as successful finality.

    Evidence the case requires

    Alert matrix; detection timelines; independent runbook exercise.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    OPS-08Repeat independent operation across releasesPriority BLOCKERProfile P00, P08, P11NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use a clean previous supported version and the final candidate with independent operators.

    Steps

    1. Perform documented rolling upgrade, rollback of non-consensus software where allowed and resynchronisation.
    2. Cross activation with mixed versions and unavailable founder distribution hosts.
    3. Re-run affected gates after changes and preserve prior failures and incident lessons.

    Accept

    No undocumented privileged migration or automatic consensus rewrite. All affected evidence is refreshed; P11 no-rescue results remain tied to the final release, not an earlier build.

    Evidence the case requires

    Upgrade/replay logs; invalidation map; repeated gate signatures.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    build-server lane (a352e49ff4613df86)
    Design status
    NOT RUN
    Standard page
    56
    Plan pages
    21, 24, 25, 26
    14UX

    Ember, payouts and operator control

    Successful participation must be practical for ordinary owners without hidden custody or loss of consensus authority.

    RUNNING
    Owner
    Desktop product + pool leads; independent usability study
    Gate
    Operator readiness / G5 G5
    Fixtures
    F2 supported desktops; F8 user study; F4 honest/malicious pools
    Plan pages
    14, 21, 25, 26
    8 cases: 0 passed under the standard, 7 running with team evidence, 1 not run, 0 deferred
    UX-01Onboard ordinary owners on native desktop appsPriority GATEProfile P10NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit the P10 first-time user cohort across Windows and macOS using supported physical hardware.

    Steps

    1. Observe install, hardware detection, safety explanation and first accepted work without staff intervention.
    2. Record download/data preparation separately as well as complete end-to-end time.
    3. Test unsupported hardware and insufficient memory messaging rather than forcing a failed start.

    Accept

    P10 completion/time targets hold with no unsafe default or concealed prerequisite. The product is tested as the actual desktop app, not only a browser preview.

    Evidence the case requires

    Consent-based study records; task timings; failure reasons; compatibility outcomes.

    Method
    Independent observed user study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    update-return lane (a22d765a2e0355a9f)
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-02Make pause, stop and safe tuning reliablePriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Run mining/proving on active desktops under contention and safe thermal stress.

    Steps

    1. Use pause, stop, power limit, task selection and emergency local shutdown controls.
    2. Crash or restart the UI while workers run and verify ownership of background processes.
    3. Restore the original hardware settings and test power-saving/low-battery behaviour where supported.

    Accept

    P10 control latency and safe-state requirements hold. Stopping does not strand an uncontrolled process; tuning never depends on unsafe settings or silent privilege escalation.

    Evidence the case requires

    Control timings; process/settings audit; restart and safety traces.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-03Show net earnings and compatibility honestlyPriority BLOCKERProfile P01, P10, P12RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use known rewards, fees, energy readings, retries and operator-entered tariffs.

    Steps

    1. Compare mining, internal proof and external proof income with authoritative ledgers.
    2. Show gross/net estimates, measurement boundaries, tariff assumptions and payout status.
    3. Test stale data, losses, negative margins and mining-only versus proving-compatible devices.

    Accept

    P10 reconciliation limits hold and uncertainty is visible. No guaranteed profits, fabricated fiat price or inferred proving support; provisional earnings are not shown as settled payments.

    Evidence the case requires

    UI/ledger comparisons; tariff fixtures; stale/negative examples.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    57
    Plan pages
    14, 21, 25, 26
    UX-04Pay small operators without hidden custodyPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Use ordinary single-card balances and the actual pooling/payment path.

    Steps

    1. Earn, request/receive payment, disconnect and reconnect; include low balances, fees and a pool outage.
    2. Attempt redirection, delayed accounting and withdrawal of another user's entitlement.
    3. Reconcile displayed balances with canonical entitlement and actual settlement.

    Accept

    P10 payout limits hold for the declared small-operator case. No unauthorised custody, redirection or unexplained loss; thresholds and fees are disclosed rather than masked by larger test balances.

    Evidence the case requires

    Single-card payout ledger; pool failure record; custody/authorisation review.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-05Keep voting keys with the miner through poolingPriority BLOCKERProfile P01, P09RUNNINGEvidence recordLast run 2026-10-08 18:3x UK

    Setup

    Use an honest pool and a modified pool that replaces worker identity or voting credentials.

    Steps

    1. Verify the consensus binding from performed work to the miner's retained key.
    2. Attempt substitution, replay and reassignment without the miner's authorisation.
    3. Leave the pool and verify retained voting/finality rights under F0.

    Accept

    No silent transfer of governance/finality authority. If the protocol cannot establish retained keys, this requirement fails; a pool-protocol name or user-interface promise does not pass.

    Evidence the case requires

    Work/key binding vectors; malicious-pool attempts; leave-pool authority check.

    Evidence record of the run

    What was run
    the pool vote-key commitment design
    Run by
    pool design seat (a3832b1c3b274b310)
    Under the standard
    no: team-run before the standard's procedure; the status is RUNNING until the case is re-run under its steps with the profile's numbers and an independent run where the profile asks one
    Pass or fail today
    not judged under the standard yet
    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    pool design seat (a3832b1c3b274b310)
    Run
    team-2026-10-08
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-06Verify actual miner-selected work templatesPriority BLOCKERProfile P01, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Provide a pool interface with declared job-declaration support and independent miner templates.

    Steps

    1. Submit miner-selected valid transaction templates and verify what is actually hashed and accepted.
    2. Have a pool substitute or censor templates and test local verification/fallback.
    3. Measure payout and acceptance consequences without moving authority to the pool.

    Accept

    The advertised selection control exists in accepted work, not only configuration. Undisclosed substitution is detected; supported independent operation remains practical under P10.

    Evidence the case requires

    Template commitments; accepted-block evidence; malicious-pool/fallback report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    58
    Plan pages
    14, 21, 25, 26
    UX-07Expose actionable failures and safe updatesPriority BLOCKERProfile P09, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:51 UK

    Setup

    Create failed proofs, memory pressure, expired jobs, missing payouts and available software updates.

    Steps

    1. Ask independent users to identify the issue, stop safely and follow the recommended action.
    2. Test explicit update approval, version visibility and a failed/corrupt update.
    3. Confirm diagnostic exports remove keys and private inputs while retaining useful evidence.

    Accept

    P10 task-success requirements hold; no silent update or false success state. Recovery instructions work on supported desktops and secret canaries never enter exported logs.

    Evidence the case requires

    Observed tasks; update traces; sanitised export tests.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    shipper (ae892a8b0f78fe31c)
    Run
    201-ef0f2ed8-2826f37e
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    UX-08Publish competitive accessible softwarePriority GATEProfile P02, P10RUNNINGEvidence none yetLast run 8 Oct 2026, 19:28 UK

    Setup

    Provide open documented builds, tuning parameters and known fee conditions for all supported platforms.

    Steps

    1. Compare Ember against independently optimised permissible implementations on identical work.
    2. Measure efficiency, fees, false rejection, installation and update transparency.
    3. Scan for hidden developer fees, hardware whitelists, per-address privilege or undisclosed remote controls.

    Accept

    P10 relative-efficiency limits hold and all fees/privileges are explicit. No self-reported device tier earns consensus advantage. A superior external implementation triggers investigation, not selective exclusion.

    Evidence the case requires

    Matched software comparison; code/config review; fee/privilege inventory.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    hash lane (a690540514aa453d7)
    Run
    200-417c4a57-b2
    Design status
    NOT RUN
    Standard page
    59
    Plan pages
    14, 21, 25, 26
    15COM

    Paid demand and sustainable delivery

    Devnet payouts and subsidised pilots demonstrate mechanics, not independent willingness to pay.

    NOT RUN
    Owner
    Commercial lead + independent financial/customer reviewer
    Gate
    Commercial evidence
    Fixtures
    F8 real consenting customers; F7 full service costs; private identity proofs
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 7 not run, 1 deferred
    COM-01Deliver a genuine contracted proof pilotPriority GATEProfile P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Select one real external customer with a meaningful fixed workload and no required migration to Igneum.

    Steps

    1. Agree program, inputs, proof format, deadline, price, failure/refund policy and verification method.
    2. Run paid jobs through ordinary independently operated infrastructure.
    3. Have the customer verify usefulness, correctness and its reason for choosing the service.

    Accept

    The pilot satisfies its actual contract and settles genuine external payment. Trial subsidies are disclosed and cannot satisfy the repeat-demand gate; no invented customer or testimonial.

    Evidence the case requires

    Redacted contract; verified jobs; settlement proof; consented customer confirmation.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-02Establish independent repeat purchasingPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use the P14 multi-customer observation period and ownership/conflict checks.

    Steps

    1. Track paid purchases on distinct occasions, including refunds and stopped customers.
    2. Audit related parties, project reimbursements, token grants and circular funding.
    3. Reconcile external cash received with correctly delivered meaningful work.

    Accept

    P14 buyer, duration and volume minima are met without reimbursement or related-party substitution. Repeat orders are separate buying decisions, not a single payment split into many jobs.

    Evidence the case requires

    Anonymised buyer ledger; repeat-order dates; conflict review; net receipts.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-03Demonstrate service and operator marginsPriority GATEProfile P12, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Allocate all delivery costs, including aggregation, retries, hardware, power, host, network and support.

    Steps

    1. Calculate gross contribution and fully loaded unit costs for each contracted workload.
    2. Reconcile a representative operator's realised earnings against metered costs and opportunity cost.
    3. Repeat under the declared demand and price sensitivities.

    Accept

    P14 contribution targets hold and at least the required operator cohort has positive realised contribution. Excluded overhead is visible; token appreciation or unpriced founder labour cannot silently create profitability.

    Evidence the case requires

    Unit-economics ledger; metered operator sample; allocation rules; sensitivity report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    60
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-04Meet the customer service guaranteePriority BLOCKERProfile P01, P07, P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Observe actual delivery deadlines, validity, failure handling and support over the contracted period.

    Steps

    1. Count all accepted jobs, including failed, retried and abandoned cases.
    2. Have the customer independently verify results and invoke one authorised refund/failure exercise.
    3. Compare offered capacity and quoted price with what was actually delivered.

    Accept

    P07 and contracted obligations hold; validity has zero accepted exceptions. Failure terms are honoured, and demand beyond capacity is explicitly refused rather than quietly omitted from metrics.

    Evidence the case requires

    Customer-verifier records; SLO report; refunds; promised-versus-delivered comparison.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-05Compare against the buyer's real alternativePriority GATEProfile P14, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Identify a credible alternative supplier or in-house option for the same workload, proof format and security.

    Steps

    1. Obtain comparable quotes or consented measured trials at the evaluation date.
    2. Include integration, verification, deadlines and all operational costs, not only proof-generation time.
    3. Document the customer's actual trade-off without inventing unavailable comparator evidence.

    Accept

    P15 commercial comparison is satisfied with like-for-like scope and a evidenced purchase reason. Missing alternative data remains MISSING; it is not scored as an Igneum win.

    Evidence the case requires

    Dated comparison; workload/security match; customer decision record.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-06Retain buyers after the pilot and subsidy periodPriority GATEProfile P14NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Follow all recruited customers through the P14 observation period, including churn.

    Steps

    1. Remove disclosed trial incentives before measuring repeat demand.
    2. Track renewal, expansion, cancellation reasons, unresolved incidents and buyer concentration.
    3. Review whether one affiliated or subsidised buyer dominates the apparent market.

    Accept

    P14 repeat/concentration conditions hold with honest denominator and churn reporting. Paying demand survives beyond a demonstration; unsatisfied or departed buyers are not removed retrospectively.

    Evidence the case requires

    Cohort/renewal ledger; churn notes; concentration and incentive report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    61
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-07Fund maintenance without assumed appreciationPriority GATEProfile P13DEFERREDEvidence none yetLast run 2026-10-08 18:3x UK (the founder: forget P13 for now)

    Setup

    Prepare a costed plan for development, review, infrastructure, support and incident response.

    Steps

    1. Separate committed resources from revenue dependent on adoption or token price.
    2. Stress lower income and an unexpected security/operations expense.
    3. Verify responsible owners and continuity arrangements without changing fair-launch promises.

    Accept

    P13 committed-runway requirement holds and downside responses are documented. No uncommitted financing, rising token price or burn accounting is presented as available maintenance funding.

    Evidence the case requires

    Budget and commitment evidence; downside plan; owner/continuity roster.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    COM-08Let independent developers build useful integrationsPriority GATEProfile P09, P14NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Recruit unaffiliated developers unfamiliar with unpublished implementation details.

    Steps

    1. Use public docs to deploy a supported application or integrate an external proof request and verification flow.
    2. Record time, undocumented dependencies, workarounds and correctness issues.
    3. Retest after documentation fixes without founder-written hidden integration code.

    Accept

    P14 developer-task minimum passes on the final release; all required public instructions exist. Successful bytecode deployment alone does not count as a working application or service integration.

    Evidence the case requires

    Consented developer logs; public examples; issue closure; verified end-to-end journeys.

    Method
    Independent integration study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    62
    Plan pages
    4, 17, 18, 24, 26, 27, 31, 32, 33
    16LEAD

    Comparative leadership evidence

    A serious contention claim requires comparative outcomes and real adoption evidence, not just an internally green test dashboard.

    NOT RUN
    Owner
    Independent assessment panel + product/economics reviewers
    Gate
    Leadership-contender decision
    Fixtures
    F8 peer/customer studies; full signed technical evidence; 90-day observation
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    8 cases: 0 passed under the standard, 0 running with team evidence, 8 not run, 0 deferred
    LEAD-01Register a fair contemporary comparisonPriority GATEProfile P15NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Choose at least the P15 peer coverage and an evaluation date before collecting confirmatory results.

    Steps

    1. Include the plan's Ravencoin, Ergo and Firo reference set where comparable, then check for other relevant current options.
    2. Freeze versions, supported hardware, methods, noninferiority margins and commercial alternatives.
    3. Publish exclusions and prohibit cross-algorithm raw-hashrate comparisons.

    Accept

    The protocol covers material alternatives fairly and is signed independently. A missing or non-comparable feature is not scored zero; no arbitrary universal rank is inferred from selected metrics.

    Evidence the case requires

    Timestamped peer protocol; source/version records; comparison/exclusion rationale.

    Method
    Pre-registered comparative study
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-02Demonstrate comparable operator advantagesPriority GATEProfile P02, P10, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Use matched user tasks and operating conditions on the selected GPU-first networks.

    Steps

    1. Measure install-to-first-accepted-work, software overhead versus each network's tuned baseline, payout friction and retained control.
    2. Measure rejection/availability under the same network conditions; report fees separately.
    3. Use blinded analysis where possible and independent runs for decisive differences.

    Accept

    P15 noninferiority and superiority requirements hold on meaningful comparable dimensions. No raw hashes from different algorithms are compared, and transient token price is not labelled engineering superiority.

    Evidence the case requires

    Matched task data; uncertainty/effect sizes; independent comparison report.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    site lane (a846fd66b5403e35a)
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-03Substantiate the specialist-coexistence claimPriority GATEProfile P04, P12, P15NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Assemble G1-G4 plus frozen rules and all surviving-adversary assumptions.

    Steps

    1. Have independent reviewers trace each public competitiveness statement to its narrowest evidence.
    2. Separate measured GPUs, modelled silicon and economic scenarios in all summaries.
    3. Evaluate residual uncertainty, excluded technologies and the no-new-rules counterfactual.

    Accept

    All claimed envelopes meet P04/P12 without unsupported universal bounds. Reviewers agree the evidence supports scoped commodity competitiveness even when chips remain compatible; an exact chip-arrival probability is not inferred.

    Evidence the case requires

    Claim-to-evidence map; signed envelope review; limitations statement.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    63
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-04Observe ordinary-operator retention and marginsPriority GATEProfile P12, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Recruit the P16 independent cohort before observing results; use privacy-preserving evidence.

    Steps

    1. Follow participation, realised margin, hardware changes, failures and reasons for leaving for 90 days.
    2. Report trial incentives separately and include every initial participant in retention denominators.
    3. Compare behaviour with matched alternatives where feasible; disclose absence of an actual downturn.

    Accept

    P16 retention/margin minima hold with verified independence and no removal of churned users. Simulated downturns cannot be called observed bear-market retention; historical claims stay limited to the period measured.

    Evidence the case requires

    Pseudonymous cohort ledger; margin/retention calculations; departure reasons.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-05Measure control and dependency concentrationPriority GATEProfile P11, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Audit operational control of mining, voting, proving, aggregation, hosting and software distribution separately.

    Steps

    1. Use opt-in attestations, observed dependencies and independent corroboration; disclose uncertain common ownership.
    2. Compare concentration and provider-removal outcomes to the approved security and availability assumptions.
    3. Check that pooled payments do not hide authority concentration and hardware vendors are not equated with operators.

    Accept

    P11/P16 concentration requirements hold within disclosed uncertainty; unidentified control cannot be counted as independent. No single removable dependency is falsely marketed as decentralised operation.

    Evidence the case requires

    Control/failure-domain map; uncertainty notes; concentration/removal results.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-06Complete the reliability observation windowPriority BLOCKERProfile P01, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Observe the final candidate and approved compatible updates for the full P16 real-time period.

    Steps

    1. Measure promised service availability, invalid acceptance, finality safety, payouts and incident impact.
    2. Reconcile external probes, customer records and operator logs, including maintenance and exclusions.
    3. Repeat affected critical tests after every material change; reset observation where comparability breaks.

    Accept

    P16 availability and safety criteria hold on live observation; no hidden downtime or compressed-time substitution. This supports the recorded window only, not multi-year operational maturity.

    Evidence the case requires

    90-day SLO ledger; independent probes; incident reports; change/retest history.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    64
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-07Issue an independent contender assessmentPriority GATEProfile P00, P15, P16NOT RUNEvidence none yetLast run 2026-10-08 18:3x UK

    Setup

    Provide the full evidence packet, commercial results, comparative study and unresolved-limit register to the panel.

    Steps

    1. Check every mandatory and claimed-option test, source requirement and approved threshold.
    2. Require separate signoffs for hardware/economics, security/operations and customer/operator evidence.
    3. Document dissent and challenge any inference that passing an internal checklist proves number-one rank.

    Accept

    Every required gate is PASS with no unresolved material challenge, critical/high defect or missing comparator/customer evidence. The panel supports a credible leadership-contender conclusion within scope, not a guaranteed rank.

    Evidence the case requires

    Signed assessment; full status index; dissent/limitations; approved claim wording.

    Method
    Independent final assessment
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    LEAD-08Keep leadership claims valid after releasePriority GATEProfile P00, P16NOT RUNEvidence none yetLast run 8 Oct 2026, 20:15 UK

    Setup

    Define material-change triggers and scheduled reviews before publishing the assessment.

    Steps

    1. Refresh competitor, hardware-cost, demand and security evidence at the P16 cadence.
    2. Test a newly credible specialist, lost customer, major outage and verifier change against invalidation rules.
    3. Withdraw or narrow stale claims promptly while publishing the new evidence status.

    Accept

    Claims remain dated, scoped and revisable; material contrary evidence reopens the appropriate gate. The network may remain usable while a leadership claim is suspended. No permanent self-awarded certification.

    Evidence the case requires

    Review calendar; invalidation drills; versioned public claim register.

    Method
    Automated + independent review
    Cadence
    Release candidate; repeat after relevant changes
    Owner
    main / the founder
    Design status
    NOT RUN
    Standard page
    65
    Plan pages
    4, 22, 25, 27, 31, 32, 33
    Profiles

    The numbers each case is held to.

    17 profiles, P00 to P16. A profile is frozen before the confirmatory run; weakening a target after a failure creates a different claim.

    P00Approved as proposed

    Frozen scope and approval

    1. Approve the release manifest, supported roles, numerical profiles, mandatory scenarios, trust/fault model, workload W, adapters and claims before confirmatory tests. Unknown values are BLOCKED, not defaults.
    2. Core safety and authentication invariants admit no waiver. Proposed performance or commercial targets may be replaced only before the confirmatory run, with an independent rationale and a versioned public scope.
    3. After a failure, weakening a target creates a different claim and requires a new assessment. Preserve all failed runs; do not average a blocker away.

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P01Approved as proposed

    Correctness and negative-test depth

    1. Zero observed invalid acceptance, unauthorised signature, conflicting finality within assumptions, duplicated reward or unexplained cross-backend state/hash disagreement.
    2. Minimum proposed campaign: 1,000,000 full-hash vectors per supported backend across all families, plus at least 10,000 malformed/boundary cases per relevant parser or binding class. Include exhaustive small-domain cases and historical regressions.
    3. All prescribed critical mutants must be detected. This sampling target is not a bound on cryptographic failure probability and does not replace independent reasoning about soundness or safety.

    Cited by 69 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P02Approved as proposed

    Hardware coverage and reproducibility

    1. At least 12 physical retail configurations: at least 3 NVIDIA, 3 AMD and 2 Apple configurations, at least two discrete-GPU generations, an advertised 8 GB mining tier and 12 GB proving tiers where claimed. Record usable, not nominal, memory.
    2. Declare a competitive core of at least 6 configurations spanning every advertised vendor and at least two discrete generations before optimisation. The wider cohort remains mandatory for access and economic tests; it cannot be silently dropped.
    3. Use 5 paired 30-minute steady-state runs per primary cell after at least 15 minutes of warm-up and a stable temperature trend. Calibrated wall meter uncertainty must be at most 2%. Run a 7-day soak on representative low/mid/high tiers.
    4. Three unaffiliated operators participate; every competitive-core cell is reproduced by at least two. Identical-SKU energy/accepted-work results must agree within 5% after declared environment corrections; unexplained variance blocks the headline.

    Cited by 12 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P03Approved as proposed

    Candidate improvement and honest-card budget

    1. For production candidate changes, per mandatory GPU cell: no more than 5% increase in joules per accepted work and no more than 2% decrease in accepted throughput versus the paired tuned baseline. Absolute safety limits always apply.
    2. G2 requires at least a 10% reduction in the strongest evaluated specialist advantage after redesign, outside the declared measurement/model uncertainty, while meeting those budgets. A failed experiment is not a successful upgrade.
    3. Existing clock-lock savings belong in the baseline. Long programs cannot pass by adding enough equally costly work to both devices to improve a ratio while materially worsening honest operation.

    Cited by 8 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P04Approved as proposed

    Scoped specialist-competition target

    1. Define R_E as GPU wall joules per accepted work divided by the lowest credible complete-system specialist joules for that same work. The proposed target is R_E at most 1.5 for every competitive-core cell at the same node and one node ahead.
    2. Evaluate at least three materially distinct specialist architectures, with one programmable multi-family design, and a second independent reviewer. Include shared/reduced memory, hybrid execution, selective participation and realistic power/host costs.
    3. Publish two-node-ahead and modular/reused-IP stress cases; they must satisfy the predeclared P12 economic envelope. No universal ceiling for unknown future hardware is claimed. Report model bounds separately from statistical confidence.
    4. A lower-bound specialist estimate, not a convenient average or a deliberately constrained reference architecture, drives the conservative comparison. Undefined or unbounded decision-critical assumptions make the result BLOCKED.

    FAIL R_E target at most 1.5 at the same node and one node ahead; today's placed bracket 1.5x to 2.1x: FAIL

    Cited by 14 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P05Approved as proposed

    Measurement and inference protocol

    1. Pre-register primary metrics, cohorts, holdout seeds, run order, exclusions and analysis before confirmation. Keep tuning/training runs separate from holdout runs.
    2. Use independent runs/operators as measurement units. Report point estimates, two-sided 95% measurement intervals and absolute sample counts; handle time-series dependence with a declared block or run-level method.
    3. Apply conservative uncertainty to pass decisions. A confidence interval around measured GPU energy does not capture unknown ASIC architectures; model parameter ranges and expert judgement must be reported as such.
    4. Never compare raw hashes per second across different algorithms. Do not transform a five-year scenario sweep into a probability of chip arrival or a guarantee of future profitability.

    Cited by 0 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P06Approved as proposed

    Memory and support policy

    1. All advertised role/configuration combinations must finish without OOM, corruption or unsafe fallback. Publish a component memory budget, including display/OS, driver, miner, prover, aggregation and epoch construction.
    2. Proposed support horizon: at least 24 months of known schedule compatibility for the advertised entry tier, unless a narrower horizon is prominently approved before sale or launch. Removal changes the claim and must pass ECO-07.
    3. Treat 5.5 / 8.5 / 11.5 GiB as source candidates, not imposed final rules. Simultaneous operation, eviction and time-sharing are distinct advertised modes with separately measured cost.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P07Approved as proposed

    Proof service capacity and fairness

    1. Freeze W as a meaningful workload mix, input sizes, proof format, fleet and requests/hour. Primary proposed target: 72 hours at W, plus 24 hours at 1.2W; at least 99.5% accepted jobs delivered valid within the contracted deadline.
    2. Default delivery targets for the declared internal reference workload: p95 at most 60 seconds and p99 at most 120 seconds from input-ready assignment through verified delivery. Also publish request-to-delivery including input wait; no claim may omit that delay.
    3. Request-to-delivery p99 must meet the separately approved customer deadline. Payment p99 must be at most 10 minutes after verified payable eligibility, with chain finality time reported separately. These defaults do not override a stricter contract.
    4. No statistically supported positive backlog drift at steady load, no silent drops; after 2W for 15 minutes, drain excess backlog within 30 minutes of return to W. Report rejected demand and accepted-job success separately.
    5. Proposed advertised-tier fairness: at least 90% timely valid assigned completions are paid under the approved rules; avoidable duplicate/retry work is at most 10% of total work. Reassignment policy must bound abandonment without promising every assignment a reward.

    Cited by 15 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P08Approved as proposed

    Fault assumptions and recovery

    1. F0 must state the exact safety threshold, quorum and authority-transition rule; the synchrony/participation assumptions for liveness; trusted inputs; and clock/expiry semantics. This manual supplies no substitute consensus rule.
    2. Exercise threshold-minus/at/plus cases, the 40/40/20 partition fixture, signing outages and 31/35/60/90 logical-day expiry cases. Preserve safety when liveness assumptions fail; do not demand finality from an unavailable quorum.
    3. After assumptions and input availability are restored: service replacement within 10 minutes and deterministic network convergence within 30 minutes on the reference topology. Different certified bounds must be approved beforehand.
    4. Accelerated-time simulation and real elapsed operation are separate evidence classes. Recovery may not reverse a guarantee previously represented as final.

    Cited by 25 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P09Approved as proposed

    Security and bounded resource requirements

    1. Zero unresolved critical or high-severity security findings on the claimed release. Independent scopes must cover consensus, proof soundness/parameters, implementation bypasses, wallet/isolation and relevant operational controls.
    2. Review the intended proof-system security level and assumptions explicitly; do not infer a security-bit claim from random rejection tests. Version every verifier, program and parameter set.
    3. Freeze maximum valid/invalid verification time, memory, disk and admission rates for ordinary validator hardware. At rated valid load plus the approved hostile load, no unbounded growth, invalid acceptance or unrecoverable process failure.
    4. For supported wallet fee-estimation cases, proposed absolute error at most 5% versus the specified charge when inputs are unchanged; deterministic fee-cap handling and explicit uncertainty otherwise. Customer contracts remain separately binding.

    Cited by 30 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P10Approved as proposed

    Ordinary-operator product targets

    1. At least 30 unaffiliated first-time study participants across supported Windows/macOS combinations. At least 90% install, configure safely and submit accepted work without staff help; p90 active setup at most 15 minutes. Publish complete download/dataset time separately.
    2. Pause/stop acknowledgement within 2 seconds, safe worker stop within 5 seconds where no documented atomic operation prevents it, and reliable restoration of original tuning settings. No hidden custody or silent update.
    3. Net-energy/fee displays reconcile within 5% under the declared measurement boundary. Incremental rejected-work loss on the normal home-link profile is at most 2 percentage points over the matched datacentre profile.
    4. Open miner efficiency is within 5% of the best independently tuned permitted implementation on identical work. For the declared single-card payout case, p95 payable-to-payment at most 24 hours and total payout friction at most 2% of earned value.
    5. Critical alerts are emitted within 60 seconds of detectable evidence. At least 90% of study users can identify the injected failure and follow the published safe action. No control target excuses a security failure.

    Cited by 11 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P11Approved as proposed

    No-founder exercise and independence

    1. At least 10 verified unaffiliated operators, three independently administered network/hosting domains and sufficient honest weight/capacity to satisfy F0 and W after founders are removed.
    2. Run at least 30 real elapsed days without founder mining, proving, aggregation, bootstrap, required RPC, private files or privileged interventions. Cross all known logical transitions separately without calling accelerated time real history.
    3. Document control by role and common dependencies; uncertain identities are not counted as independent. Within-assumption withdrawals must satisfy P08; losing more than the assumed quorum may cause a visible safe pause.

    Cited by 4 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P12Approved as proposed

    Five-year coexistence envelope

    1. Freeze a sourced revenue reference R and mandatory worlds before results. Sweep 0.25R, R, 4R and 10R; electricity at $0.03/$0.10/$0.25/$0.40 per kWh; 1/3/5-year productive life; zero/$20M/$75M development; private mining and hardware sales; no/normal/spiking external demand.
    2. Those values are proposed stress inputs, not current prices or forecasts. Declare which worlds have enough funded demand for rational ongoing service before running; retain collapse worlds as explicit safety/exit tests, not profitable successes.
    3. Proposed matched-tariff new-entry target in every mandatory sustainable world: median GPU/specialist total cost per accepted work at most 1.5, 90th percentile at most 1.75, and no advertised competitive-core cell above 2.0. Publish every cell, including heterogeneous tariffs.
    4. At least three purchasable GPU configurations across at least two advertised vendors must have positive modelled new-entry economics; at least 75% of the entry cohort must have positive marginal operating economics in those worlds. Report model uncertainty and failure regions.
    5. Do not impose GPU market share, specialist production limits, token appreciation, full research-cost recovery or automatic chip death to force the result. Any such condition must become an explicit limitation rather than a hidden assumption.

    Cited by 24 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P13Deferred by the founder

    Maintenance continuity

    1. Before a readiness claim, document at least 12 months of committed maintenance resources at the approved operating scope. Include engineering, security review, infrastructure, support and incident response.
    2. Use independently reviewable commitments and downside budgets. Uncommitted future sales, rising token prices, burned fees or assumed fundraising are not available resources.
    3. This is a proposed governance test, not a directive to change the supply cap, issuance allocation or fair-launch design.

    Cited by 1 case. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P14Approved as proposed

    Genuine commercial and developer proof

    1. At least three unrelated paying buyer organisations, each making at least three separate purchase decisions across at least 30 days; at least 1,000 meaningful verified external jobs in aggregate. Split invoices do not create independent demand.
    2. No project reimbursement, circular funding or undisclosed related party counts. Report customer concentration and churn; proposed maximum largest-buyer share is 70% of qualifying revenue.
    3. At least 20% aggregate contribution margin after directly attributable delivery costs, retries, refunds and support; publish fully loaded economics separately. At least 75% of sampled eligible operators have positive realised contribution on the declared workload.
    4. At least five unaffiliated developers complete a useful supported application or proof-service integration using public documentation. Customer confirmation and raw commercial evidence may remain confidential to the reviewer.

    Cited by 10 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P15Approved as proposed

    Comparative contention threshold

    1. Pre-register at least three relevant operating GPU-first peers, plus a real proving alternative for customer comparisons. Verify current versions at execution time. The source reference set is a starting point, not a claim about current rankings.
    2. Require at least three meaningful comparable dimensions with no material inferiority beyond a pre-agreed 10% margin against the best valid comparator, and at least two independently evidenced advantages against at least two peers.
    3. Advantages must be either a greater-than-10% measured improvement outside uncertainty or a directly tested control/capability difference with demonstrated user value. Non-comparable or missing data is not a win.
    4. A panel with hardware/economics, security/operations and customer/operator expertise must support the scoped contender conclusion. Passing these judgement-based thresholds does not certify a universal number-one ranking.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    P16Approved as proposed

    Observed durability and claim freshness

    1. At least 90 real elapsed days on the final compatible release family, at least 30 independently verified operators, and transparent eligibility/churn denominators. Material uncomparable changes reset affected observations.
    2. Proposed outcomes: at least 60% day-90 operator retention and at least 75% of eligible observed operators with positive measured marginal operation over the period. Report incentives and electricity assumptions; do not claim a downturn was observed if it was not.
    3. At least 99.9% availability for the declared customer service during eligible operating conditions, with all-in availability also reported; zero accepted invalid proofs or conflicting finality within F0 assumptions. Do not remove real incidents as maintenance to force a pass.
    4. Run fault injection on isolated infrastructure, not unsuspecting customers. Publish planned test windows separately. Reassess claims at least quarterly and immediately after material hardware, protocol, economics or security changes.

    Cited by 5 cases. The profile’s own line in the registry: PROPOSED, REQUIRES APPROVAL.

    Fixtures

    What every run is built on.

    F0

    Release and assurance manifest

    Exact commits, binaries, genesis/network ID, mining class, dataset schedule, EVM fork/deviations, program/verifier IDs, fees, supply, quorum/fault rules, trust anchors, activation and supported roles.

    F1

    Clean build environments

    Pinned toolchains, dependency locks, clean OS images and documented signing/notarisation boundaries. No production secrets or private founder files.

    F2

    Hardware and measurement lab

    Approved physical GPU cohort, calibrated wall meters, stable thermal conditions, driver/OS images and realistic home/datacentre link conditions.

    F3

    Workload and oracle catalogue

    Fixed full-hash and EVM/proving jobs, independent reference implementations, real customer-sized payloads, held-out seeds and complete expected results.

    F4

    Authorised fault network

    Independent nodes/operators; controllable latency, loss, clocks, partitions, storage faults and role withdrawals. Actual consensus paths plus separately labelled simulators.

    F5

    Negative and regression corpus

    Malformed transactions/proofs, wrong roots/IDs, duplicate payments, bad authority tables, historical failures and deliberately faulty code mutants.

    F6

    Specialist implementation pack

    Functionally checked architectures, RTL/physical estimates where feasible, memory and board assumptions, cost inputs, adaptation paths and uncertainty ranges.

    F7

    Economic and incentive models

    Independently reproducible costs, entry/exit/difficulty policies, scenario grid, operator opportunity costs and money-flow conservation fixtures.

    F8

    User/customer/peer studies

    Consenting unaffiliated users, contracted meaningful workloads, private ownership checks, dated competitor methods and independent analysis.

    F9

    Evidence and status vault

    Immutable run IDs, raw logs, hashes, analysis code, exclusions, defects, reviewers, signatures, privacy controls and public redacted summaries.

    What a full pass means

    Independent passage of all mandatory and claimed-option gates, including commercial and comparative observation, can support a scoped leadership-contender assessment. It does not prove a universal rank or eliminate unknown future hardware risks.

    Test design, not executed evidence. All numeric additions are proposed, not source-approved protocol rules. Optional claimed features require their tests; excluded features earn no pass credit.

    Rules in force

    • P03: a candidate change pays at most 5 percent of joules per accepted work and loses at most 2 percent of accepted throughput against the paired tuned baseline (replaces the 10 percent budget from 18:2x UK)
    • P04: R_E at most 1.5 for every competitive-core cell at the same node and one node ahead against the lowest credible complete-system specialist; today's placed bracket (1.5x to 2.1x same-node) is a FAIL to work against and is served as such
    • P12: the matched-tariff median at most 1.5, p90 at most 1.75, no core cell above 2.0
    • P02: twelve retail configurations, three unaffiliated operators, the seven-day soak define D1's reproduction

    Never served: guaranteed chip death, a universal ASIC-efficiency ceiling, chip-arrival probabilities, guaranteed profits, Ethereum security by compatibility, privacy from ZK, a numerical rank.

    Source: docs/plans/igneum-2.0-test-registry.json, version 1.0, dated 8 October 2026, plan sha256 418b3b9f68f96a41. This copy was written when the page was built; the page checks the registry on the public git host every 60 seconds.

    +