finality-guarantees.md: the two-thirds anchored test never lapses (6.2 item 1, after the node lane's harness finding acd9d067); the even split's jitter fact (7 item 4); the harness pass line per variant (6.7)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
534d7020d6
commit
2e5f1c6036
1 changed files with 3 additions and 3 deletions
|
|
@ -90,7 +90,7 @@ The expiry clause of Q5 is exactly a timeout alone. Rule v4 removes it and adds
|
|||
|
||||
Rule v4 replaces Q5's expiry with the following, active for checkpoints at or above `finality_v4_activation_daa`:
|
||||
|
||||
1. **The anchored table never expires by time.** `T_f` is the sliding table at `C_f`, the highest certified checkpoint on the selected chain of `C_i`, with the strips and successions known at `C_i` applied. It stands until a certificate that passes it replaces it. A certificate for `i` locks only if its signers hold at least two thirds of `T_f` at `T_f`'s weights, in addition to Q3, **for as long as `daa(C_i) < daa(C_f) + 2,592,000`** (one weight window, as under v3), and
|
||||
1. **The anchored table never expires by time.** `T_f` is the sliding table at `C_f`, the highest certified checkpoint on the selected chain of `C_i`, with the strips and successions known at `C_i` applied. It stands until a certificate that passes it replaces it. A certificate for `i` locks if its signers hold at least two thirds of `T_f` at `T_f`'s weights, in addition to Q3, **at any time**: the two-thirds anchored test never lapses, under either variant (the node line's acd9d067 of 8 October 2026 reads it so; an earlier reading that refused everything past one window under the pause-only variant was a fault, found by the harness: the heal could not resume). Item 2 adds a second way to pass once a window has elapsed; it replaces nothing. And
|
||||
2. **The majority-continuity recovery.** Once `daa(C_i) >= daa(C_f) + 2,592,000` with no certificate formed between `C_f` and `C_i` on this chain, a certificate for `i` locks when its signers hold at least two thirds of the sliding table `T(i)` (Q3, both tests) AND **strictly more than half** of `T_f` at `T_f`'s weights (`2 x signed_f > total_f`), AND
|
||||
3. `C_f` is an ancestor of `C_i` on the selected chain (the certificate names a chain through the last certified history; a certificate for a chain that misses any lock the node holds is a conflict under 3.11.4, as before).
|
||||
4. A lock under item 2 is a **recovery lock**: it re-anchors `T_f` at `C_i` (so the next certificate needs two thirds again), it is carried, verified and followed exactly like any other certificate (C3, C4, F1, the certificate-driven reorg of 3.5), and the node reports `finality_reason` `recovered` with the index and the signed share of the old `T_f` for one window after it, then `active`.
|
||||
|
|
@ -127,14 +127,14 @@ The alternative the founder can choose by deleting item 2 is the **indefinite pa
|
|||
|
||||
### 6.7 The node change
|
||||
|
||||
One function and one switch, for the node lane; nothing here lands on any network until the founder sets the height. `frozen_table` (the Q5 row of 3.10) keeps its reference and loses its drop; `evaluate` and `ingest_off_chain` test `floor_met(frozen_signed, frozen.total)` while `daa(C_i) < daa(C_f) + weight_window` and `continuity_met(frozen_signed, frozen.total)` (`2 x signed > total`, a pure function with its own inclusive-boundary unit test) after, provided no lock exists between; a lock that passed by `continuity_met` is stamped `recovered` in the record and `getFinalityCheckpoints` reports `finality_reason` `recovered` with `anchored_index` and `anchored_signed_share` for one window. Switch `finality_v4_activation_daa` (never on every network until set; the digest arm entered only when set, so a binary carrying the field peers with one that does not, the rule of every switch since 0.3.20). Unit tests, known-failed first: the M3 shape (A at 60 percent and B at 40 percent lock together, B leaves, A alone must not lock under v4 pause ever and must lock under v4 recovery only once the last lock is one window old; under v3 it locks at the window, the known-failed line); and a 50/50 shape that never locks under either v4. The fast-time harness row is `tools/finality-attacks/v3.mjs split50` extended past the window (`SPLIT` above 120 DAA at 60x), where v3 must conflict and v4 must not.
|
||||
One function and one switch, for the node lane; nothing here lands on any network until the founder sets the height. `frozen_table` (the Q5 row of 3.10) keeps its reference and loses its drop; `evaluate` and `ingest_off_chain` test `floor_met(frozen_signed, frozen.total)` while `daa(C_i) < daa(C_f) + weight_window` and `continuity_met(frozen_signed, frozen.total)` (`2 x signed > total`, a pure function with its own inclusive-boundary unit test) after, provided no lock exists between; a lock that passed by `continuity_met` is stamped `recovered` in the record and `getFinalityCheckpoints` reports `finality_reason` `recovered` with `anchored_index` and `anchored_signed_share` for one window. Switch `finality_v4_activation_daa` (never on every network until set; the digest arm entered only when set, so a binary carrying the field peers with one that does not, the rule of every switch since 0.3.20). Unit tests, known-failed first: the M3 shape (A at 60 percent and B at 40 percent lock together, B leaves, A alone must not lock under v4 pause ever and must lock under v4 recovery only once the last lock is one window old; under v3 it locks at the window, the known-failed line); and a 50/50 shape that never locks under either v4. The fast-time harness row is `tools/finality-attacks/v3.mjs split50` extended past the window (`SPLIT` above 120 DAA at 60x), where v3 must conflict and v4 must not; the pass line per variant: pause-only, no lock on either side during the split, locking resumed after the heal (a heal window of at least one weight window after the reconnect), 0 conflicting certificates, 0 disagreeing locks; recovery, at most one side locks during the split (the side above half of the anchored table by weight, which block-count jitter decides in a 3/3 split), 0 conflicting certificates, 0 disagreeing locks, every node on the recovering side's chain after the heal. Measured on the 2.0.0 node line on 8 October 2026 (the node lane's rows in `sim/results_v2.md`, "Rule v4").
|
||||
|
||||
## 7. What is NOT guaranteed
|
||||
|
||||
1. **At or above one third of equivocating weight** two valid certificates can exist at one index; the rule reports and does not resolve (3.11.4).
|
||||
2. **A recovery lock** is bounded as 6.5 states, not by one third: a month-long partition plus an equivocator outweighing the split's imbalance can produce two recovery locks after `C_f`. The history through `C_f` is never touched.
|
||||
3. **A loss of half or more of the last certified table at once** has no in-protocol exit: finality pauses until the weight returns, hands over or is stripped, or an operator configures a trusted certificate on the chain through the last lock (F5 with 6.6's check). The chain runs on proof of work meanwhile.
|
||||
4. **An exactly even partition** (each side exactly half of `T_f`) pauses until the heal. Half is not more than half.
|
||||
4. **An exactly even partition** (each side exactly half of `T_f`) pauses until the heal. Half is not more than half. A split that is even by key count or by hashrate is rarely even by weight (block-count jitter: the three-node harness's 3/3 split put 51.26 percent of the anchored table on one side), so under the recovery one side, and only one, recovers whenever the shares differ at all; the exactly-even case is the limit, not the common one.
|
||||
5. **The first month** (3.8): no certificate until the window is full; proof of work guidance applies.
|
||||
6. **Body availability and execution correctness**: a certificate is a statement about a header chain by voters who validated it; availability and pruning are F3 and section 2, execution is section 7's proofs. The "proven" word of section 9 is a different claim from "finalised".
|
||||
7. **Everything the model excludes** (2.5): no DAG, the 2.2 percent outage guess, the cert reading, no VRF noise, no cost of keys. The young-window form of the sliding bound (`W / R` of a side's DAA time) is a devnet fact, not a mainnet one.
|
||||
|
|
|
|||
Loading…
Reference in a new issue