Merge review-b-landing-l 94bed472 into master (gate: green on 94bed472, recorded by tools/ci/pre-push.sh; landed on the box mirror under the exception declared by main: main's ruling, 7 Oct 2026 19:5x UK: the GitHub account is suspended, lanes land on the box mirror's master, the box gate stamp is the verdict; GitHub gets the fast-forward when it answers)

This commit is contained in:
igneum-labs 2026-10-08 19:04:43 +00:00
commit 2f7cb99200
13 changed files with 5027 additions and 0 deletions

View file

@ -0,0 +1,28 @@
# External review B (8 October 2026, 19:44 UK): dispatch
The second external review read the six packs sent on 8 October (algorithm, v6 freeze tree, proving, Ember, node and DAG, mining workers and pool). Its verdict: real progress, not yet one demonstrated release; fix correctness and integration first, then make honest operation cheaper. Fourteen findings, forty-four regression requirements. The review, its structured findings and its reproduction pack sit beside this file. Nothing in it changes the 2.0 objective, the four properties or the five deliverables; every finding maps onto the Test and Acceptance Standard as a new suite, REV, whose cases are the reviewer's regressions verbatim.
Rule for every lane: a finding closes only when its regression runs green on the pinned release and the record carries the evidence file. "Fixed by construction" is a claim until the regression says so.
| Finding | Priority | Owner | Default action | Clock (UK) | Blocks |
|---|---|---|---|---|---|
| F01 proof-verdict cache omits the statement | P0 | proving lane, node lane | cache the verified facts (kind, program identity, public-values digest, format version) and compare the carried statement and the permitted identities on every lookup; invalid bytes and wrong-context refusals cached apart; no zero pinned id; known-failed test first, then a two-node cache-history test | fix sha 21:30; rides node 2.0.2 | value-bearing release |
| F02 proof rule fails open | P0 | proving lane, CI steward | test bypass compiled out of release builds (CI check); missing oracle or pinned keys after activation = not ready, never pass; pending bytes retry, invalid reject | with F01, 21:30 | value-bearing release |
| F03 one release manifest | P0 | CI steward, hash lane (ProgramClass::V6 on freeze), pool lane | one manifest pinning node, generator, dataset policy, acceptance, host ABI, miner app, pool, guests, keys, activation; pool and every worker built against it in CI (rule 24 extends to the pool); the EpochSeeds shadow_reps seam closed; the cross-backend same-work test (node, CPU reference, CUDA, Metal, OpenCL, pool) before, during and after a transition | manifest 23:00; cross-backend test with the freeze object | D1 |
| F04 recovery lock weaker than final | P0 | node lane, reference apps, site (explorer) | the 20:00 default (recovery) stands with the reviewer's condition: a recovery lock is never presented as a final lock; the checkpoint carries the state, the explorer, receipts, the light client and the oracle show it; the native 40/40/20 case runs on real nodes past the window; the pause-only alternative gets the backfill test | state flag 22:00; native case tomorrow | D5, public finality claim |
| F05 reg64 address mixer has an exact incremental form | P1 | hash lane, adversary lane, floor lane 3 | implement the prefix-tree form natively, prove equivalence across every source register with real instruction updates, then full-kernel equivalence and power on the rented cards; the chip model prices prefix caching, never an assumed 63-read cost per load; no new mixing work added in answer | native equivalence 22:30; chip rows 23:30 | P04 bracket, freeze |
| F06 acceptance and census do not cover the final execution | P1 | hash lane, research lane D | the freeze object's acceptance evaluates the actual 64-register schedule (reg64 liveness wired into canonical acceptance, not a side check); the full live-dataset census on unseen seeds and the complete pack runs on the frozen object; rw2 stays a rejected control; a failed rule never exhausts generation silently | acceptance wiring 23:00; live census overnight, a D1 gate before the object is called frozen | D1 |
| F07 one per-device scheduler | P1 | app lane, fleet lane | explicit modes: simultaneous (measured headroom only), time-share (dataset evicted, memory confirmed free, prover runs, dataset rebuilt), mining-only; one per-device coordinator across mining, proving, aggregation, benchmark and next-epoch preparation; admission counts transfer, startup, aggregation, rebuild and the payment deadline | modes in 2.0.2 (the 16 GB time-share copy already planned); mine-evict-prove-rebuild test 01:00 | consumer proving income claim |
| F08 proving pipeline hides expired work | P1 | proving lane, fleet lane, site (ops page) | outcome ledger for every eligible job: completed, active, expired, cancelled; deadline misses and useful proof throughput published, not queue depth; failure attributed by cause; the two-hour declared-load hold rerun on the pinned release | ledger 23:00; two-hour hold on node 2.0.2 | D4, consumer proving claim |
| F09 economic table and the failed specialist | P1 | research lane, floor lane 3, coordinator | every pass or fail cell generated from the declared inequality and its inputs (the USD 18 M against 40 to 80 M cell is wrong as displayed); condition (g) adds the hybrid operator who owns companion GPUs or buys proofs; the N2 SRAM die stays the open failed case until an independent physical-design read prices it | regenerated table in the 21:00 landing; hybrid row 22:00 | property 2 claim |
| F10 CUDA readback: port the OpenCL select pass | P2 | worker lane (new) | a separate selection pass with sentinels, exact comparison and overflow fallback, then asynchronous overlap; publish kernel throughput and end-to-end accepted work per wall joule as two numbers | equivalence 23:30; measured rows 01:00 | nothing (byte-preserving) |
| F11 Ember search and identity | P2 | Ember lane (new) | objective-aware bounded two-sided search, rebase on goal change; workload fingerprint (backend, dataset geometry, compiler, schedule, concurrent proving) invalidates certification while keeping hints; paired A/B/A, soak, rejected-work check; mining-only, proving-only, hybrid profiles under the device scheduler | search 23:00; identity 01:00 | nothing |
| F12 pool payout durability | P1 | pool lane (new) | durable idempotent intent and the exact signed transaction before broadcast; balance reserved atomically; states prepared, broadcast, mined, finalised, reorged, replaced; reconcile by intent after timeout or restart; crash tests around every durable step | 01:00 | pool launch |
| F13 pool admission bounds | P1 | pool lane (new) | frame size enforced while reading; bounded write queues; one membership per session (re-authorise replaces atomically); nonce dedup after validation with in-flight handling; slow-reader and invalid-share flood tests | 01:00 | pool launch |
| F14 lab fleet control is not the public trust model | P1 | app lane, relay lane | two builds from 2.0.2: the public miner (no remote execution, auto-update a choice at install and honoured, an urgent manifest may pause and notify, never install over "off") and the lab build for our own fleet (remote jobs on, separate signing root); a compromised update key cannot reach the wallet or activate a consensus change | split in 2.0.2, 23:00 | public client, retained operator control |
Decisions for the founder (defaults apply at the clock unless he names otherwise):
1. F04: keep recovery (labelled, never called final) rather than pause-only. Default: keep recovery with the label. Clock 22:00.
2. F14: the public miner ships without remote execution; our fleet runs the lab build. Default: yes. Clock 20:30.
3. F06: if the live-dataset census on the frozen object is not green by 00:30, the object is "frozen pending D1 census" and the register says so; the freeze is not called complete. Default: yes.

View file

@ -0,0 +1,671 @@
{
"date": "2026-10-08",
"status": "SOURCE REVIEW; NOT A COMPLETED ACCEPTANCE AUDIT",
"findings": [
{
"id": "F01",
"title": "Proof-verdict cache omits the statement being verified",
"priority": "P0 - public/value-bearing release blocker",
"evidence_status": "SOURCE + ISOLATED CONTROL-FLOW REPRODUCTION",
"body": "\nThe native cold verifier checks both the pinned program and the hash of the proof's public values against the carried statement. That is good. However, `ProofPool::verdict_for` returns a cached success keyed only by `proof_hash`, checking only the accepted program ID. It does not compare the carried statement on that path. It also returns cached errors without distinguishing intrinsically invalid proof bytes from an otherwise valid proof queried in the wrong context.\n\nThe isolated model reproduces: a wrong statement is refused with a cold cache; the same wrong statement is accepted after that proof was cached against its correct statement. Querying the wrong statement first can poison the later correct lookup. The zero-ID cache wildcard can also bypass a nonempty accepted-ID list if such an entry has been populated. Host configuration controls that second case's reachability.\n\nThis is NOT an SP1 forgery. It is a failure to bind a cached verification result to its use. `check_record` still checks native execution and signatures, so this finding does not show arbitrary execution roots becoming valid. But proof payment and block-validity decisions consume the cache. Warm/cold or order-dependent decisions are unacceptable there. A malicious block producer need not use the honest producer's template-selection code. Full native reproduction is required to establish exact network impact.\n\nFix: cache immutable verified facts (proof kind, actual verifier/program identity, public-values digest, proof format/security version) and compare the required statement and current permitted IDs on EVERY lookup. Alternatively, key by all relevant context. Do not use zero as an accepted pinned ID. Distinguish context-specific refusal from invalid bytes. The relay-time cache population must store the identity actually verified, not merely a configured host label. Bound cache size and in-flight verification.\n",
"source_ranges": [
{
"path": "node/igneum/exec/src/proving.rs",
"start": 1046,
"end": 1102
},
{
"path": "node/igneum/exec/src/proving.rs",
"start": 1358,
"end": 1379
},
{
"path": "node/igneum/exec/src/nativeverify.rs",
"start": 151,
"end": 177
},
{
"path": "node/igneum/exec/src/proving.rs",
"start": 471,
"end": 489
}
],
"required_regressions": [
"Valid proof A, warm cache, carried statement B: refuse exactly as a cold node does.",
"Run valid/invalid contexts in both orders, concurrently and across cache eviction/restart.",
"Change payout, network, kind, program ID and activation context; no accepted misbinding.",
"A native two-node test must agree on block validity and payouts despite different cache histories."
]
},
{
"id": "F02",
"title": "Proof-rule infrastructure can fail open",
"priority": "P0 - release configuration blocker",
"evidence_status": "STATIC SOURCE",
"body": "\n`check_carried_proofs` has a production-compiled environment bypass (`IGNEUM_TEST_SKIP_PROOF_RULE=1`) and returns success when the oracle is absent. The comments explicitly describe these as harness/unit-test accommodations. This is not evidence an unauthenticated peer can set the environment, nor evidence the normal daemon omits its oracle. It is a configuration failure mode that contradicts mandatory enforcement if accidentally activated.\n\nAfter the rule activates, missing verifier infrastructure should stop startup or validation safely, not silently disable the rule. Restrict deliberately unsafe test switches to test-only builds. Distinguish pending proof bytes (retry) from invalid proof (reject) and unavailable trusted verifier (not accepted).\n",
"source_ranges": [
{
"path": "node/consensus/src/pipeline/body_processor/body_validation_in_context.rs",
"start": 28,
"end": 79
}
],
"required_regressions": [
"Release build cannot activate test bypass.",
"Missing oracle or pinned keys prevents service readiness after enforcement activation.",
"Missing proof bytes retry without incorrectly marking a valid block permanently invalid."
]
},
{
"id": "F03",
"title": "The bundle contains a v6 candidate, not a demonstrated integrated v6 release",
"priority": "P0 - freeze/integration blocker",
"evidence_status": "STATIC SOURCE + ARCHIVE PROVENANCE",
"body": "\nThe v6 freeze contains real candidate flags, a 64-register schedule, address mixing, fold/reweight experiments and non-power-of-two dataset geometry. It is materially newer than the earlier V2/V3/V4-only review. Nevertheless the canonical `ProgramClass` enum in this snapshot ends at V5. The freeze README itself says the D1 object cut and spec re-cut are subsequent work. The node bundle is from a different release branch. Generated packs and relevant vendor/build context are omitted.\n\nThere is a concrete seam: the node's `EpochSeeds` struct requires `shadow_reps`, but the pool constructs that type without the field or a struct-update expression. Those exact files cannot be compiled together as written. This was identified statically, not by running Cargo. It does not establish that another deployed pool or vendor revision has the mismatch.\n\nFix: produce one release manifest that pins node, generator, dataset policy, acceptance, host ABI, miner app, pool, proof guests/keys and activation. Build the pool and all supported workers against it in CI. Include executable packs and their authenticated identity. Never combine measurements from different candidates into a single v6 claim.\n",
"source_ranges": [
{
"path": "v6/igneum-v6-freeze-tree/README-FREEZE.txt",
"start": 1,
"end": 1
},
{
"path": "pow/src/generator.rs",
"start": 249,
"end": 277
},
{
"path": "pow/src/generator.rs",
"start": 939,
"end": 954
},
{
"path": "node/consensus/pow/src/igneum.rs",
"start": 72,
"end": 95
},
{
"path": "mining/pool/src/node.rs",
"start": 47,
"end": 71
}
],
"required_regressions": [
"Clean build from one manifest, including the pool and workers, with no unpublished vendor tree.",
"Same job context produces identical accepted work in node, CPU reference, CUDA, Metal, OpenCL and pool.",
"Cross every scheduled transition with old/new client behavior documented and identical rule identities."
]
},
{
"id": "F04",
"title": "Finality v4 recovery deliberately has a weaker safety boundary",
"priority": "P0 - finality guarantee decision",
"evidence_status": "SOURCE + SOURCE-REPORTED SIMULATION + PURE PREDICATE REPRODUCTION",
"body": "\nThe older unconditional table-expiry problem has been addressed: the v4 anchored table does not simply disappear. However, after a full window without a lock, the recovery branch accepts strictly more than half of the anchored weight. The supplied guarantee document openly reports conflicting recovery locks in a prolonged partition when an equivocator both mines and signs on both sides. The 40/40/20 case is explicitly included.\n\nThe isolated predicate confirms two sides each holding 60 of the original 100 pass the recovery threshold after the window, although neither passes the two-thirds threshold before it. This alone is not a full protocol exploit: sliding tables, ancestry, dust eligibility and signed certificates also matter. The team's simulation record supplies additional evidence. The same document says its real-node line at the snapshot is the known-failed v3 case and the v4 line still awaits the node change.\n\nDo not call normal finality and recovery finality the same irreversible guarantee. Prefer a reviewed authority-transition/recovery rule retaining the claimed safety assumptions; otherwise restrict and label the recovery state and dependent wallet/bridge actions explicitly. A timeout does not prove that a missing authority is permanently gone.\n\nThe pure pause-only predicate refuses every post-window checkpoint, even with 100% anchored signatures. This is not proof of permanent network liveness failure: historical-checkpoint backfill may re-anchor first. The reported immediate-heal simulations must be reproduced against the actual implementation, including that path.\n",
"source_ranges": [
{
"path": "node/consensus/src/processes/finality.rs",
"start": 1111,
"end": 1128
},
{
"path": "node/consensus/src/processes/finality.rs",
"start": 2610,
"end": 2642
},
{
"path": "dag/igneum-node-dag/spec/docs/spec/finality-guarantees.md",
"start": 111,
"end": 136
},
{
"path": "dag/igneum-node-dag/spec/docs/spec/finality-guarantees.md",
"start": 184,
"end": 197
}
],
"required_regressions": [
"Native multi-node 40/40/20 partition, equivocation and dust-valid mining on both sides past the window.",
"Proof that the chosen recovery guarantee matches the public finality claim; two valid contradictory certificates are a hard failure for strong finality.",
"Pause-only resume with historical backfill, missing historical data and all old keys returning.",
"Wallet, receipt and oracle consumers distinguish any weaker recovery state."
]
},
{
"id": "F05",
"title": "reg64 address coupling has an exact incremental alternative",
"priority": "P1 - adversarial hardware evaluation",
"evidence_status": "EXACT ALGEBRA + 33,024 RANDOMIZED/EDGE COMPARISONS",
"body": "\nThe full-chain window computes a rotate-XOR fold over the 63 registers other than the source, then XORs the source. This connects every register syntactically, but it does not force a physical implementation to reread and fold all 63 on each load.\n\nDefine a[k] = ROL32(r[k], 63-k), S = XOR of all a[k], and P_s = XOR of a[k] for k < s. Then the exact source expression is:\n\n address_source(s) = r[s] XOR ROR32(P_s, 1) XOR S XOR P_s XOR a[s]\n\nA prefix-XOR tree supports point updates and prefix queries in logarithmic time. The included model checked 33,024 comparisons, including 4,096 state updates, without a mismatch. The algebra follows by distributing the rotation across XOR: values before the excluded source have one fewer subsequent rotation; values after it retain their original exponent.\n\nThis is NOT evidence that the full hash is cheap, that the necessary 64-register state is compressible to one word, or that the extra index state is free. Cached prefix state, port bandwidth and update costs must all be priced. The GPU compiler may already remove some redundant work. It is a concrete alternative the adversarial designer must be allowed, and potentially a byte-preserving implementation experiment for both sides.\n\nDo not respond by adding unmeasured nonlinear work. First implement the cheapest alternatives, remeasure GPU cost, then compare complete hardware designs. A one-register perturbation test cannot establish a minimum circuit or storage cost.\n",
"source_ranges": [
{
"path": "pow/src/verify.rs",
"start": 674,
"end": 692
},
{
"path": "pow/src/generator.rs",
"start": 258,
"end": 277
}
],
"required_regressions": [
"Native reference-vs-incremental expression equivalence across all source registers and real instruction updates.",
"Full-kernel output equivalence, registers, spills, wall power and accepted throughput across target GPUs.",
"Adversary physical design includes prefix caching/recomputation cost; no assumed full 63-read cost on every load."
]
},
{
"id": "F06",
"title": "The v6 acceptance and census gates are not complete for the final execution",
"priority": "P1 - freeze blocker",
"evidence_status": "STATIC SOURCE + SOURCE-REPORTED RESULTS",
"body": "\nThe new code explicitly executes the V4 shadow in its acceptance interpreter, includes repeated-source and index-concentration checks, and contains a regression test for shadow agreement. That improves on the older review. The v6 comments nevertheless say reg64's draw/acceptance are the underlying class's, while the liveness check is a separate research check not wired into canonical acceptance. Its sampling checks influence, not a formal unavoidable-state lower bound.\n\nThe census is similarly candid: rw2 fails its F8 line; fold plus rw1 is stronger on the reported controls; reg64/all results are based on the full tracing path with closed-form data, and the live-dataset point remains owed. These source results must not be promoted into an unconditional full-v6 pass.\n\nFreeze one agreed acceptance rule for the actual scheduled 64-register execution, and specify safe deterministic fallback behavior when a candidate fails. Re-run known-bad seeds, unseen seeds, real datasets, bound headers/nonces, the combined intended width/geometry and all family transitions. Retain rw2 as a rejected control unless new evidence changes the decision.\n",
"source_ranges": [
{
"path": "pow/src/accept.rs",
"start": 114,
"end": 119
},
{
"path": "pow/src/accept.rs",
"start": 625,
"end": 637
},
{
"path": "pow/src/accept.rs",
"start": 867,
"end": 871
},
{
"path": "pow/src/generator.rs",
"start": 258,
"end": 264
},
{
"path": "v6/igneum-v6-freeze-tree/docs/analysis/class-v6/census-packs.md",
"start": 8,
"end": 22
},
{
"path": "v6/igneum-v6-freeze-tree/docs/analysis/class-v6/census-packs.md",
"start": 40,
"end": 49
}
],
"required_regressions": [
"Acceptance/reference/emitter evaluate the same activated schedule.",
"Full live-dataset census on unseen seeds and the complete v6 pack.",
"A failed experimental rule does not silently exhaust generation or bypass the intended resource requirement."
]
},
{
"id": "F07",
"title": "VRAM admission and proving deadlines need one operator-level scheduler",
"priority": "P1 - miner economics and reliability",
"evidence_status": "SOURCE-REPORTED HARDWARE RESULTS + STATIC INTEGRATION REVIEW",
"body": "\nThe coexistence records report successful standalone compressed proofs: 13.2 seconds on a 3060 12 GB and 8.2 seconds on a 4060 8 GB after correcting the packaged prover server. They also report that both fail when run beside the 5.5 GiB dataset miner, with device allocation failures while mining continues. These are team measurements, not measurements made for this review. The registered reg64 rows use a different kit configuration and must not be combined with ds55 rows as one benchmark.\n\nThe right product path is explicit modes: simultaneous execution only on tested configurations with headroom; time-sharing on smaller cards with actual dataset eviction/release and confirmed memory availability; mining-only where a complete paid proof job cannot fit. Merely pausing kernel dispatch does not establish that GPU allocations were released.\n\nUse per-device identity and a memory reservation/lease state machine across miner, prover, aggregation, benchmark and next-epoch preparation. Include time to evict/rebuild datasets, WSL process startup, aggregation and payment deadlines in job admission. Do not market an isolated successful shard as proof that the card can finish the economically relevant segment.\n",
"source_ranges": [
{
"path": "v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexist-rows.md",
"start": 17,
"end": 37
},
{
"path": "v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexist-rows.md",
"start": 60,
"end": 86
}
],
"required_regressions": [
"Same final v6 configuration: mine -> evict -> prove -> aggregate -> submit -> rebuild -> resume; no leaked reservations.",
"OOM, process crash and stale work recover without losing wallet state or silently consuming power.",
"16 GB+ simultaneous mode only after measured peak plus next-epoch headroom; smaller-card modes labelled separately."
]
},
{
"id": "F08",
"title": "The proving pipeline reports waste and deadline censoring, not sustained capacity",
"priority": "P1 - proving product gate",
"evidence_status": "SOURCE-REPORTED OPERATIONAL DATA; NOT INDEPENDENTLY REPLAYED",
"body": "\nThe supplied pipeline report says the requested two-hour declared-load window does not exist in its record. It describes a class-v5 transition stall/partition and 93 paid segments in the paid interval, not a successful end-to-end hold at 150 transactions per second. Its 3060 tier completed zero paid segments over 313 claims. This does not prove a 3060 can never prove profitably: the same report says its completed submissions occurred after the stall, and the standalone fixture succeeds. It does show the claimed consumer-paid-work experience is not established by this run.\n\nA particularly important measurement issue: the worklist stays around 600 entries because entries expire at a deadline whether proved or not. Therefore bounded queue length does not establish sufficient proving capacity. The report itself discloses this mechanism.\n\nAdd lifecycle accounting: eligible work = completed + active + expired + explicitly cancelled, with definitions preventing double-counting. Publish deadline misses and useful accepted proof throughput, not just queue depth. Attribute failure to protocol partition, packaging, proving, assignment race, aggregation or submission. The source reports 70 wasted card-hours versus roughly 4 paid, dominated by the chain incident, so it would be wrong to call that all a prover-speed failure.\n\nPrioritise feasible job sizing and deadlines, resumable verified shards/checkpoints, early cancellation of obsolete claims, and bounded assignment protection. Protection must prevent slow or malicious claimants from monopolising work; do not simply promise no competing completion can ever occur. Run the two-hour workload test on the pinned release, then a longer independent soak.\n",
"source_ranges": [
{
"path": "proving/igneum-proving/docs/analysis/proving-pipeline-2026-10-08.md",
"start": 7,
"end": 16
},
{
"path": "proving/igneum-proving/docs/analysis/proving-pipeline-2026-10-08.md",
"start": 35,
"end": 84
},
{
"path": "proving/igneum-proving/docs/analysis/proving-pipeline-2026-10-08.md",
"start": 86,
"end": 121
}
],
"required_regressions": [
"Report every eligible job outcome, including expired work; a bounded list cannot hide losses.",
"Consumer tiers complete and receive payment for declared jobs before claims about income.",
"Sustained real workload across class transitions, with restart/retry and no publisher intervention."
]
},
{
"id": "F09",
"title": "The economic model explicitly retains a failed specialist case",
"priority": "P1 - founding claim not yet earned",
"evidence_status": "SOURCE-REPORTED MODEL + DISPLAYED-ARITHMETIC CHECK",
"body": "\nThe coexistence model states that the desired competitiveness statement does not hold for its modeled N2 SRAM die after development is sunk, and that the remaining deterrent is the investment decision. That is not proof the proposed die is manufacturable at the stated cost or throughput. It is also not evidence that the fundamental gate has passed.\n\nThere are at least two items to repair before using the model as certification. Its condition (c) requires fleet cost to exceed a year's mining revenue but labels USD 18M against USD 40-80M a pass; those displayed numbers do not satisfy that inequality. The table or criterion may be mistaken. Condition (g) also treats proving income as a business the specialised supplier cannot enter because its hash engine cannot prove. A company can own companion GPUs or buy proofs; the single-device limitation does not exclude the operator.\n\nReproduce the model from raw inputs, price the SRAM/recomputation design at physical board boundaries, include uncertainty and independent hardware critique, and test a hybrid operator. Treat unknown feasibility as unknown, not either a proven attack or an automatic pass. No retirement credit without a demonstrated adaptation penalty.\n",
"source_ranges": [
{
"path": "v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexistence-model.md",
"start": 299,
"end": 321
}
],
"required_regressions": [
"Generate all pass/fail cells directly from the declared inequalities and inputs.",
"Independent feasibility and cost evaluation of the strongest modeled SRAM/hybrid opponent.",
"GPU owners and entrants remain viable under the approved scenario envelope without assuming chip absence or death."
]
},
{
"id": "F10",
"title": "CUDA production readback has an existing OpenCL optimization to borrow",
"priority": "P2 - byte-preserving performance experiment",
"evidence_status": "STATIC SOURCE; SPEEDUP NOT MEASURED",
"body": "\nThe CUDA serving loop synchronises and copies one 64-bit result per nonce to the CPU, then scans it while holding its GPU mutex. For 2^24 nonces that is 128 MiB of result data per batch. Its benchmark times the kernel/synchronisation but reads the full result only for warm-up, so the benchmark does not include the same per-batch production cost.\n\nOpenCL already contains a select kernel that returns matching nonce/hash pairs plus sentinel words, with a counter and full-read fallback when more than 256 hits occur. This is not missing everywhere: it is a cross-backend parity opportunity. Port the proven shape to CUDA first as a separate selection pass, retaining correctness sentinels and overflow handling. Then test fusion/asynchronous overlap if justified. Metal still scans shared output on the CPU; unified memory means it is not the same PCIe-copy problem, so profile it separately.\n\nBenchmark accepted shares per wall-joule in serving mode, including setup, stale cancellation, readback, host power and pool submission. No percentage gain is claimed here.\n",
"source_ranges": [
{
"path": "mining/proto-cuda/nvrtc/worker.cpp",
"start": 1254,
"end": 1295
},
{
"path": "mining/proto-cuda/nvrtc/worker.cpp",
"start": 1318,
"end": 1341
},
{
"path": "mining/proto-opencl/host.c",
"start": 1652,
"end": 1705
},
{
"path": "mining/proto-opencl/host.c",
"start": 1882,
"end": 1899
},
{
"path": "mining/proto-metal/main.swift",
"start": 3344,
"end": 3370
}
],
"required_regressions": [
"Compare exact found nonce/hash sets with full-read mode, including all-hit overflow and zero-hit cases.",
"Test stale jobs, high-32 rollover, tail batches and asynchronous buffer reuse.",
"Compare production throughput and wall energy, not only the isolated kernel timer."
]
},
{
"id": "F11",
"title": "Ember needs workload-aware identity and objective-aware search",
"priority": "P2 - product performance",
"evidence_status": "STATIC SOURCE + REACHABILITY EXAMPLE",
"body": "\nEmber has useful thermal/fault checks, power and clock controls, calibration rows and fleet priors. Its shipped tier tests pass in this review. Those tests do not measure actual safe tuning or globally optimal settings.\n\nThe five-step hill climb proposes memory-up, core-down or both, even for MaxRate (which changes the score to MH/s). Starting from a low-clock efficiency prior, this search cannot propose a higher core clock or change the fixed power cap to escape that starting regime. A full sweep can choose a new start, so the finding is a limitation of this climb, not evidence every MaxRate setting is wrong.\n\nThe prior key uses card model, driver major and class. The workload class helper is based on load/wide-load counts. This is insufficient as a validated measurement identity for changes in memory geometry, compiler, reg64 schedule or concurrent proving. A prior may remain a useful starting hint; it should not be treated as a current certified optimum.\n\nUse a two-sided, bounded search appropriate to the chosen objective; rebase when switching goals; fingerprint the actual workload/backend and retain per-device calibration separately from fleet hints. Use paired A/B/A samples, a stability soak and rejected-work checks. Support separate mining-only, proving-only and hybrid profiles, coordinated by the device scheduler. Optimise accepted work or transparent net-return estimates, not raw displayed MH/s alone.\n",
"source_ranges": [
{
"path": "mining/app/igneum-app/src/ember.rs",
"start": 211,
"end": 280
},
{
"path": "mining/app/igneum-app/src/ember.rs",
"start": 493,
"end": 520
},
{
"path": "mining/app/igneum-app/src/ember.rs",
"start": 606,
"end": 619
}
],
"required_regressions": [
"Goal switch from an efficiency prior can explore higher core/power when policy allows.",
"Driver, workload, dataset, compiler and device changes invalidate certification while retaining optional hints.",
"Thermal/error/late-share events revert safely, including process or machine crash."
]
},
{
"id": "F12",
"title": "Pool payouts have a broadcast-before-durable-intent window",
"priority": "P1 - payment integrity",
"evidence_status": "STATIC SOURCE + ISOLATED CRASH SEQUENCE",
"body": "\nThe payout loop broadcasts first, then updates in-memory balances and records; disk snapshots are a separate periodic loop. If a transaction succeeds externally and the process dies before the debit is durable, restart can load the old payable balance and send again using a later nonce. A lost RPC response creates a related uncertain-outcome problem. The isolated model shows 100 units due becoming 200 externally paid under those assumptions; no actual transaction was sent.\n\nReceipt checking does exist, and failed receipts re-credit balances. Do not describe this as a pool with no receipt logic. However, a receipt is marked confirmed immediately and the loop subsequently visits only sent records; the supplied path does not establish finality-aware reorg handling.\n\nPersist an idempotent payment intent and exact signed transaction/hash BEFORE broadcast, reserve the balance atomically, reconcile the same intent after timeout/restart, and finalise against the chain's declared finality. Use explicit prepared/broadcast/mined/finalised/reorged/replaced states. Test crashes around every durable step.\n",
"source_ranges": [
{
"path": "mining/pool/src/payout.rs",
"start": 228,
"end": 261
},
{
"path": "mining/pool/src/payout.rs",
"start": 265,
"end": 296
},
{
"path": "mining/pool/src/main.rs",
"start": 138,
"end": 149
}
],
"required_regressions": [
"Crash before/after broadcast, response timeout, restart before snapshot: no duplicate payment or silent debt loss.",
"Same signed transaction retried, fee replacement reconciled by intent, not a new payment.",
"Receipt reorg and finality pause leave correct pending obligations."
]
},
{
"id": "F13",
"title": "Pool admission and membership need bounded resources",
"priority": "P1 - service resilience",
"evidence_status": "STATIC SOURCE + ISOLATED MEMBERSHIP MODEL",
"body": "\nThe server checks MAX_LINE after reading a full line, uses an unbounded outgoing channel, and inserts a nonce into a job's seen set before validation. Repeated Authorize requests create fresh members without removing or rejecting the prior one, while disconnect removes only the latest member. The small state-machine reproduction leaves two members after three authorizations on one connection and disconnect.\n\nThese are resource-control issues, not demonstrated remote exploits against a running pool. The verifier semaphore is a useful existing control but does not bound every queue or allocation.\n\nEnforce frame size while reading, bounded write queues, connection/request budgets, a single authenticated membership per session, cheap target/context prefilters, and bounded deduplication with in-flight handling. Test slow readers and malformed/invalid share floods without expensive network attacks. Member vote keys are already committed into the template; preserve that improvement.\n",
"source_ranges": [
{
"path": "mining/pool/src/server.rs",
"start": 62,
"end": 99
},
{
"path": "mining/pool/src/server.rs",
"start": 115,
"end": 175
},
{
"path": "mining/pool/src/server.rs",
"start": 234,
"end": 255
},
{
"path": "mining/pool/src/server.rs",
"start": 281,
"end": 299
},
{
"path": "mining/pool/src/node.rs",
"start": 41,
"end": 48
}
],
"required_regressions": [
"Repeated authorization rejected or atomically replaces and cleans prior state.",
"Oversized unterminated frame rejected within fixed memory/time budget.",
"Slow clients and invalid share floods cannot grow unbounded member, nonce or outgoing state."
]
},
{
"id": "F14",
"title": "Developer fleet control must not silently become the public client trust model",
"priority": "P1 - public client/independence gate",
"evidence_status": "STATIC SOURCE + BOOLEAN GUARD REPRODUCTION",
"body": "\nThe supplied settings explicitly call remote jobs default-on for the devnet build. Jobs are signed and have a visible disable switch; disabling aborts work. This is not a hidden unauthenticated backdoor. It is still powerful publisher control: run-script, fetch, collect, restart and update-now jobs share the OTA signing key, and some jobs run elevated or as WSL root.\n\nThe updater's auto-off guard is bypassed for an urgent release (unsupported version or nearby fork). This is intentional in the supplied policy, not a signature bypass. The remaining staging/safety checks still apply. An operator who disabled automatic updates should not unknowingly grant an urgency label permission to install arbitrary future software.\n\nSeparate a controlled lab/developer build from the public miner; remove arbitrary remote execution from the public default or use narrow explicit per-capability consent and a separate trust root. Keep user update acceptance distinct from consensus activation. Emergency safety notifications may pause unsupported operations; they should not silently override the user's installation choice. Review any manifest-delivered consensus overrides under the same rule.\n",
"source_ranges": [
{
"path": "mining/app/igneum-app/src/config.rs",
"start": 75,
"end": 81
},
{
"path": "mining/app/igneum-app/src/config.rs",
"start": 135,
"end": 151
},
{
"path": "mining/app/igneum-app/src/jobrun.rs",
"start": 1,
"end": 19
},
{
"path": "mining/app/igneum-app/src/ota.rs",
"start": 540,
"end": 555
},
{
"path": "mining/app/igneum-app/src/ota.rs",
"start": 589,
"end": 595
}
],
"required_regressions": [
"Public build has no default arbitrary remote execution and a documented least-privilege boundary.",
"Automatic updates off remains off for urgent manifests until explicit action.",
"A compromised fleet/update signing key cannot silently acquire wallet access or activate a consensus change."
]
}
],
"probe_results": {
"review": "Igneum updated-stack source review",
"date": "2026-10-08",
"native_rust_executed": false,
"gpu_executed": false,
"sp1_executed": false,
"probe_count": 13,
"probes": [
{
"probe": "cache_wrong_statement_after_success",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"cold_wrong_context": "Invalid",
"warm_wrong_context": "Verified",
"limitation": "No SP1 proof constructed; models the supplied early-return cache logic."
},
{
"probe": "cache_negative_context_poisoning",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"valid_context_after_bad_context": "Invalid",
"fresh_valid_context": "Verified"
},
{
"probe": "cache_zero_id_accepts_pinned_epoch",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"result": "Verified",
"accepted_ids": [
"vk-B"
],
"cached_id": "ZERO",
"limitation": "Reachability depends on host configuration and how the cache entry was populated."
},
{
"probe": "reg64_rotate_xor_prefix_equivalence",
"classification": "EXACT_ALGEBRA_WITH_RANDOMIZED_CHECKS",
"comparisons": 33024,
"point_updates": 4096,
"mismatches": 0,
"equation": "a[k]=ROL(r[k],63-k); P=XOR(a[k],k<s); S=XOR(a[k]); addr=r[s]^ROR(P,1)^S^P^a[s]",
"limitation": "Extra cached state and updates cost hardware. This does not prove a whole-hash shortcut, smaller necessary state or a GPU/ASIC speedup."
},
{
"probe": "anchored_recovery_threshold",
"classification": "PURE_PREDICATE_REPRODUCTION",
"old_table_weights": "40 honest A + 40 honest B + 20 equivocating in both",
"both_sides_before_window": [
false,
false
],
"both_sides_after_window": [
true,
true
],
"pause_only_post_window_100_of_100": false,
"limitation": "Both branches must satisfy sliding-table, ancestry and dust rules too. Source simulations separately report this case. No real-node conflict produced. Historical-checkpoint backfill may affect healing."
},
{
"probe": "pool_epochseeds_schema_mismatch",
"classification": "STATIC_SOURCE_ASSERTION",
"required_field": "shadow_reps",
"present_in_supplied_pool_initializer": false,
"limitation": "Would fail against the supplied node definition; cargo was not available and the pool vendor tree is absent."
},
{
"probe": "v6_research_vs_canonical_enum",
"classification": "STATIC_SOURCE_ASSERTION",
"reg64_chain_exists": true,
"canonical_enum_v6_exists": false,
"limitation": "Not a claim that v6 work is absent. Release manifest and end-to-end activation are not demonstrated by these snapshots."
},
{
"probe": "pool_send_before_journal_crash",
"classification": "ISOLATED_FAILURE_SEQUENCE",
"original_due": 100,
"paid_after_crash_and_retry": 200,
"transaction_nonces": [
0,
1
],
"assumptions": [
"First send accepted on network",
"Pool has enough funds for retry",
"Restart loads pre-send snapshot",
"No external recovery process absent from supplied path"
],
"limitation": "No actual transaction broadcast. Models the missing durable-intent window."
},
{
"probe": "pool_reauthorize_cleanup",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"authorizations_on_one_connection": 3,
"members_left_after_disconnect": 2,
"limitation": "No pool server was run. Static handler contains no prior-member guard/removal."
},
{
"probe": "ember_climb_direction",
"classification": "ALGORITHMIC_REACHABILITY_EXAMPLE",
"illustrative_start_core_mhz": 1300,
"illustrative_faster_core_mhz": 1800,
"can_climb_propose_higher_core_from_start": false,
"limitation": "A full sweep can choose a new starting point; no claim the illustrative higher clock is faster on an actual GPU."
},
{
"probe": "ota_disabled_but_urgent",
"classification": "BOOLEAN_GUARD_REPRODUCTION",
"auto_update": false,
"urgent": true,
"install_asked": false,
"consent_guard_blocks": false,
"limitation": "Actual application also requires a valid staged release and safe_to_apply; applies to supplied devnet policy."
},
{
"probe": "cuda_high32_boundary_positive",
"classification": "SOURCE_ASSERTION_AND_ARITHMETIC_CHECK",
"parts": [
{
"high32": 0,
"low32": 4294967264,
"count": 32
},
{
"high32": 1,
"low32": 0,
"count": 64
}
],
"alignment_guard_present": true,
"limitation": "No GPU execution; confirms the earlier host-level alignment omission is covered in this archive."
},
{
"probe": "economic_table_displayed_inequality",
"classification": "ARITHMETIC_CHECK",
"condition": "fleet cost exceeds annual miner revenue",
"displayed_fleet_musd": 18,
"displayed_revenue_musd": [
40,
80
],
"displayed_pass_consistent": false,
"limitation": "The table or condition may contain a typo; underlying economic workbook was not reproduced."
}
],
"source_sha256": {
"node/igneum/exec/src/proving.rs": "92302ee089fca720f2ee6ac0756c0054a01c995db4c997d358683a2a08f3401b",
"node/igneum/exec/src/nativeverify.rs": "bbb11e72495c04f44172c2ec6f230919f8ff96b8b45847e03efacd063f94da96",
"pow/src/verify.rs": "033ae9f2ccd32e1170e7ff4f259b206b26e78ddc9ebf68d7b26933794aa1f345",
"node/consensus/src/processes/finality.rs": "6194a96a80e5ec5a4daeb63afa8fda55a8c7a2f959d5becab60ea733790f5bf4",
"node/consensus/pow/src/igneum.rs": "8264d300db90ee5e4c0f568f3e4f847e9c2c1028312827f38e8458d2c13bedfd",
"mining/pool/src/node.rs": "54e52ee3ca45d2b482b2acf066d1ba613fa7fc7aaf7075fc5919d61257a126d4",
"pow/src/generator.rs": "751f39aeedb2987856343e2a67c7aeca7daa47ddafe5192c50a19b1d425e3a8a",
"mining/pool/src/payout.rs": "839619378b7e9b0b7eda22ce900aa2ada6410aa90e3d7f1f000a02f0b8449c1f",
"mining/pool/src/main.rs": "cca75f5452a46b53f13fe268989e12feb4767e67623f154d637b133249ae4a67",
"mining/pool/src/server.rs": "aaf86c5acec3e22a53580ee8ff2000ddc619a90c9f28d2ddad600e38c9e99bdc",
"mining/app/igneum-app/src/ember.rs": "e1e9d83e37b3acb47e89027994dba1638d7c4c547a0d1f587b95455cbe3c4873",
"mining/app/igneum-app/src/ota.rs": "d4c12a6c673b701ae432f23f758aad8a51979b3cabb82e33fb735f014cb09212",
"mining/proto-cuda/nvrtc/worker.cpp": "faf4782ff0fbfdea594e4635200a75db9084f96c663053d7c074df8e5bebf92f",
"v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexistence-model.md": "8b2b8964a77bac49c88c3d9c801455f18d9e730859b61ef958ffa3fa79f0de4a"
}
},
"artifact_integrity": {
"checks": [
{
"kind": "shard",
"artifact": "elf",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-program.elf",
"bytes": 2832504,
"sha256": "150f4c05a2951fc56174a87089707a030b18df8fbe7e053a66459edb83053083",
"match": true
},
{
"kind": "shard",
"artifact": "vk",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-program.vk",
"bytes": 104,
"sha256": "8b4da5bff86d963f4210a78e5d800a1cd00ab41b158f6962f4ac009edc249d4c",
"match": true
},
{
"kind": "aggregator",
"artifact": "elf",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-aggregator.elf",
"bytes": 319744,
"sha256": "143d9c243dd12e87e90be71f6b8cd42353e513bf8ce78903ef6f972f1bc9aa7b",
"match": true
},
{
"kind": "aggregator",
"artifact": "vk",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-aggregator.vk",
"bytes": 104,
"sha256": "ad17bc1ae5be816554dbb13cb5b4d242678adfb8e1a4f7247ceb8b5ba9001b9f",
"match": true
}
],
"scope": "Byte integrity only. Does not verify build reproducibility, program-key derivation, proof validity or deployed node embedding."
},
"archive_manifest": [
{
"archive": "igneum-v6-freeze-tree-2026-10-08(1).zip",
"sha256": "f448981b2ceeab2e59e8bbd137a1a13ea1c730ecd9db72b9a89bd2bbf5d85acb",
"files": 49
},
{
"archive": "igneum-proving-2026-10-08(1).zip",
"sha256": "9ccf4112e274f586392e8e4a4f98ece2e82b4990fe5f1ee89ae0ee0a151ce01e",
"files": 75
},
{
"archive": "igneum-ember-2026-10-08(1).zip",
"sha256": "c219211b49fccda65b151df230b10ded5971ac2a8c7d1e5847c0a68bffe4cf4a",
"files": 11
},
{
"archive": "igneum-node-dag-2026-10-08.zip",
"sha256": "ead2cf94092b7e27aab2e44d653b2d969cb2a52878ef12abf6e5d7a9e7421cff",
"files": 354
},
{
"archive": "igneum-mining-workers-2026-10-08.zip",
"sha256": "808abcecf157a3716d1c72fa6e76c540bf5808af1c0e4dd0fd888576d546cade",
"files": 1016
}
]
}

View file

@ -0,0 +1,32 @@
# Igneum updated-stack review reproduction pack
These probes accompany the 8 October 2026 review of the supplied v6, proving, Ember, DAG/node and mining-worker/pool archives.
## What this does
- Checks the source shapes underlying the findings.
- Reproduces the proof-verdict cache's context-sensitive failure in a small control-flow model.
- Checks an exact alternative evaluation of the reg64 rotate-XOR address expression.
- Reproduces the pure recovery-quorum predicate, pool payout crash window, repeated-authorisation cleanup, tuner search-direction limitation and updater guard.
- Includes a positive nonce-boundary check and the economic table's displayed inequality check.
It does **not** compile or execute the Rust node or pool, create or verify an SP1 proof, execute GPU kernels, broadcast a transaction, measure mining economics or conduct a live attack. A probe succeeding means the described finding or arithmetic was reproduced, not that Igneum passed an acceptance gate.
## Reproduce
Requires Python 3.10+ and the five original source ZIPs, or their byte-identical `(1)` duplicates. No Python packages are needed.
```sh
python3 prepare.py --archives /path/to/source-zips --out ./workspace
python3 reproduce.py --root ./workspace --out ./reproductions.json
```
The prepare step verifies archive hashes and does not execute supplied source. It creates portable directory copies instead of symlinks. The results list hashes of the specific source files checked. The ELF/key byte-integrity result and the actual Node tier-test output from the review are included separately; program-key derivation and native proofs are not checked.
## Important interpretation
- The cache model stubs cryptographic verification; it isolates the premature return before context is checked.
- The reg64 mixer retains additional cached information. Its update/storage cost must be measured. Equivalence does not establish an ASIC advantage or full-hash shortcut.
- The finality model is only the anchored threshold. The source's reported partition simulations supply additional evidence; no real node was run by the reviewer.
- The payout model assumes the first send succeeded externally before the local snapshot was updated. No on-chain test was performed.
- No user source files have been modified or deployed.

View file

@ -0,0 +1,27 @@
[
{
"archive": "igneum-v6-freeze-tree-2026-10-08(1).zip",
"sha256": "f448981b2ceeab2e59e8bbd137a1a13ea1c730ecd9db72b9a89bd2bbf5d85acb",
"files": 49
},
{
"archive": "igneum-proving-2026-10-08(1).zip",
"sha256": "9ccf4112e274f586392e8e4a4f98ece2e82b4990fe5f1ee89ae0ee0a151ce01e",
"files": 75
},
{
"archive": "igneum-ember-2026-10-08(1).zip",
"sha256": "c219211b49fccda65b151df230b10ded5971ac2a8c7d1e5847c0a68bffe4cf4a",
"files": 11
},
{
"archive": "igneum-node-dag-2026-10-08.zip",
"sha256": "ead2cf94092b7e27aab2e44d653b2d969cb2a52878ef12abf6e5d7a9e7421cff",
"files": 354
},
{
"archive": "igneum-mining-workers-2026-10-08.zip",
"sha256": "808abcecf157a3716d1c72fa6e76c540bf5808af1c0e4dd0fd888576d546cade",
"files": 1016
}
]

View file

@ -0,0 +1,49 @@
#!/usr/bin/env python3
"""Safely unpack the five user-provided archives into a portable review layout.
No builds, downloads, network access or source execution occur here.
"""
import argparse, hashlib, shutil, stat, zipfile
from pathlib import Path, PurePosixPath
ARCHIVES = {
'v6': ('igneum-v6-freeze-tree-2026-10-08.zip','f448981b2ceeab2e59e8bbd137a1a13ea1c730ecd9db72b9a89bd2bbf5d85acb'),
'proving': ('igneum-proving-2026-10-08.zip','9ccf4112e274f586392e8e4a4f98ece2e82b4990fe5f1ee89ae0ee0a151ce01e'),
'ember': ('igneum-ember-2026-10-08.zip','c219211b49fccda65b151df230b10ded5971ac2a8c7d1e5847c0a68bffe4cf4a'),
'dag': ('igneum-node-dag-2026-10-08.zip','ead2cf94092b7e27aab2e44d653b2d969cb2a52878ef12abf6e5d7a9e7421cff'),
'workers': ('igneum-mining-workers-2026-10-08.zip','808abcecf157a3716d1c72fa6e76c540bf5808af1c0e4dd0fd888576d546cade'),
}
p = argparse.ArgumentParser()
p.add_argument('--archives',type=Path,required=True)
p.add_argument('--out',type=Path,required=True)
a = p.parse_args()
if a.out.exists() and any(a.out.iterdir()):
raise SystemExit('Output directory must be empty; refusing to overwrite data.')
a.out.mkdir(parents=True,exist_ok=True)
for key,(name,expected) in ARCHIVES.items():
zpath = a.archives/name
if not zpath.exists():
candidates = sorted(a.archives.glob(name[:-4]+'*.zip'))
zpath = next((x for x in candidates if hashlib.sha256(x.read_bytes()).hexdigest()==expected),zpath)
if not zpath.exists():
raise SystemExit('Missing archive: '+name)
if hashlib.sha256(zpath.read_bytes()).hexdigest()!=expected:
raise SystemExit('Archive differs from reviewed snapshot: '+name)
dest=a.out/key
with zipfile.ZipFile(zpath) as z:
if sum(i.file_size for i in z.infolist())>512*1024*1024:
raise SystemExit('Unexpected archive size')
for i in z.infolist():
pp=PurePosixPath(i.filename)
if pp.is_absolute() or '..' in pp.parts or '\\' in i.filename or any(':' in x for x in pp.parts):
raise SystemExit('Unsafe archive path: '+i.filename)
if stat.S_ISLNK(i.external_attr>>16):
raise SystemExit('Symlink in archive: '+i.filename)
z.extract(i,dest)
for alias,src in {
'pow':'v6/igneum-v6-freeze-tree/igneum-pow',
'node':'dag/igneum-node-dag/node',
'mining':'workers/igneum-mining-workers',
'prove':'proving/igneum-proving/proving/igneum-prove',
}.items():
shutil.copytree(a.out/src,a.out/alias)
print('Prepared '+str(a.out.resolve()))

View file

@ -0,0 +1,70 @@
TAP version 13
# Subtest: the shipped table validates with no faults
ok 1 - the shipped table validates with no faults
---
duration_ms: 3.627802
type: 'test'
...
# Subtest: the measured rows are the record's (the 5090 at its 1,300 MHz knee, the 5080 at 1,100, the 4070 at its tune, the 9070 XT grid, the M5 Max meter)
ok 2 - the measured rows are the record's (the 5090 at its 1,300 MHz knee, the 5080 at 1,100, the 4070 at its tune, the 9070 XT grid, the M5 Max meter)
---
duration_ms: 0.573775
type: 'test'
...
# Subtest: every entry carries the three tiers where the card has a lever, and only max where it has none
ok 3 - every entry carries the three tiers where the card has a lever, and only max where it has none
---
duration_ms: 1.437987
type: 'test'
...
# Subtest: the match rule takes the longer name: a 5070 Ti is not a 5070, a 4060 Ti is not a 4060, a 9060 XT is not a 9070 XT
ok 4 - the match rule takes the longer name: a 5070 Ti is not a 5070, a 4060 Ti is not a 4060, a 9060 XT is not a 9070 XT
---
duration_ms: 0.395181
type: 'test'
...
# Subtest: a class flip reads stale exactly as src/ember.rs tiers_stale does
ok 5 - a class flip reads stale exactly as src/ember.rs tiers_stale does
---
duration_ms: 0.461529
type: 'test'
...
# Subtest: known-failed: a power rung under 50 is refused
ok 6 - known-failed: a power rung under 50 is refused
---
duration_ms: 1.007864
type: 'test'
...
# Subtest: known-failed: a row missing a field tier_from_json reads is refused
ok 7 - known-failed: a row missing a field tier_from_json reads is refused
---
duration_ms: 1.01198
type: 'test'
...
# Subtest: known-failed: a tuned row dearer per hash than stock is refused, and a max tier that is not stock
ok 8 - known-failed: a tuned row dearer per hash than stock is refused, and a max tier that is not stock
---
duration_ms: 1.432099
type: 'test'
...
# Subtest: known-failed: a card class of the brief left out is refused, and a stale uj (not w over mhs) is refused
ok 9 - known-failed: a card class of the brief left out is refused, and a stale uj (not w over mhs) is refused
---
duration_ms: 2.615351
type: 'test'
...
# Subtest: known-failed: a table under another class is refused
ok 10 - known-failed: a table under another class is refused
---
duration_ms: 0.914827
type: 'test'
...
1..10
# tests 10
# suites 0
# pass 10
# fail 0
# cancelled 0
# skipped 0
# todo 0
# duration_ms 87.189946

View file

@ -0,0 +1,8 @@
{
"rustc": null,
"cargo": null,
"nvcc": null,
"nvidia_smi": null,
"python": "Python 3.13.5",
"node": "v22.16.0"
}

View file

@ -0,0 +1,158 @@
{
"review": "Igneum updated-stack source review",
"date": "2026-10-08",
"native_rust_executed": false,
"gpu_executed": false,
"sp1_executed": false,
"probe_count": 13,
"probes": [
{
"probe": "cache_wrong_statement_after_success",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"cold_wrong_context": "Invalid",
"warm_wrong_context": "Verified",
"limitation": "No SP1 proof constructed; models the supplied early-return cache logic."
},
{
"probe": "cache_negative_context_poisoning",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"valid_context_after_bad_context": "Invalid",
"fresh_valid_context": "Verified"
},
{
"probe": "cache_zero_id_accepts_pinned_epoch",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"result": "Verified",
"accepted_ids": [
"vk-B"
],
"cached_id": "ZERO",
"limitation": "Reachability depends on host configuration and how the cache entry was populated."
},
{
"probe": "reg64_rotate_xor_prefix_equivalence",
"classification": "EXACT_ALGEBRA_WITH_RANDOMIZED_CHECKS",
"comparisons": 33024,
"point_updates": 4096,
"mismatches": 0,
"equation": "a[k]=ROL(r[k],63-k); P=XOR(a[k],k<s); S=XOR(a[k]); addr=r[s]^ROR(P,1)^S^P^a[s]",
"limitation": "Extra cached state and updates cost hardware. This does not prove a whole-hash shortcut, smaller necessary state or a GPU/ASIC speedup."
},
{
"probe": "anchored_recovery_threshold",
"classification": "PURE_PREDICATE_REPRODUCTION",
"old_table_weights": "40 honest A + 40 honest B + 20 equivocating in both",
"both_sides_before_window": [
false,
false
],
"both_sides_after_window": [
true,
true
],
"pause_only_post_window_100_of_100": false,
"limitation": "Both branches must satisfy sliding-table, ancestry and dust rules too. Source simulations separately report this case. No real-node conflict produced. Historical-checkpoint backfill may affect healing."
},
{
"probe": "pool_epochseeds_schema_mismatch",
"classification": "STATIC_SOURCE_ASSERTION",
"required_field": "shadow_reps",
"present_in_supplied_pool_initializer": false,
"limitation": "Would fail against the supplied node definition; cargo was not available and the pool vendor tree is absent."
},
{
"probe": "v6_research_vs_canonical_enum",
"classification": "STATIC_SOURCE_ASSERTION",
"reg64_chain_exists": true,
"canonical_enum_v6_exists": false,
"limitation": "Not a claim that v6 work is absent. Release manifest and end-to-end activation are not demonstrated by these snapshots."
},
{
"probe": "pool_send_before_journal_crash",
"classification": "ISOLATED_FAILURE_SEQUENCE",
"original_due": 100,
"paid_after_crash_and_retry": 200,
"transaction_nonces": [
0,
1
],
"assumptions": [
"First send accepted on network",
"Pool has enough funds for retry",
"Restart loads pre-send snapshot",
"No external recovery process absent from supplied path"
],
"limitation": "No actual transaction broadcast. Models the missing durable-intent window."
},
{
"probe": "pool_reauthorize_cleanup",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"authorizations_on_one_connection": 3,
"members_left_after_disconnect": 2,
"limitation": "No pool server was run. Static handler contains no prior-member guard/removal."
},
{
"probe": "ember_climb_direction",
"classification": "ALGORITHMIC_REACHABILITY_EXAMPLE",
"illustrative_start_core_mhz": 1300,
"illustrative_faster_core_mhz": 1800,
"can_climb_propose_higher_core_from_start": false,
"limitation": "A full sweep can choose a new starting point; no claim the illustrative higher clock is faster on an actual GPU."
},
{
"probe": "ota_disabled_but_urgent",
"classification": "BOOLEAN_GUARD_REPRODUCTION",
"auto_update": false,
"urgent": true,
"install_asked": false,
"consent_guard_blocks": false,
"limitation": "Actual application also requires a valid staged release and safe_to_apply; applies to supplied devnet policy."
},
{
"probe": "cuda_high32_boundary_positive",
"classification": "SOURCE_ASSERTION_AND_ARITHMETIC_CHECK",
"parts": [
{
"high32": 0,
"low32": 4294967264,
"count": 32
},
{
"high32": 1,
"low32": 0,
"count": 64
}
],
"alignment_guard_present": true,
"limitation": "No GPU execution; confirms the earlier host-level alignment omission is covered in this archive."
},
{
"probe": "economic_table_displayed_inequality",
"classification": "ARITHMETIC_CHECK",
"condition": "fleet cost exceeds annual miner revenue",
"displayed_fleet_musd": 18,
"displayed_revenue_musd": [
40,
80
],
"displayed_pass_consistent": false,
"limitation": "The table or condition may contain a typo; underlying economic workbook was not reproduced."
}
],
"source_sha256": {
"node/igneum/exec/src/proving.rs": "92302ee089fca720f2ee6ac0756c0054a01c995db4c997d358683a2a08f3401b",
"node/igneum/exec/src/nativeverify.rs": "bbb11e72495c04f44172c2ec6f230919f8ff96b8b45847e03efacd063f94da96",
"pow/src/verify.rs": "033ae9f2ccd32e1170e7ff4f259b206b26e78ddc9ebf68d7b26933794aa1f345",
"node/consensus/src/processes/finality.rs": "6194a96a80e5ec5a4daeb63afa8fda55a8c7a2f959d5becab60ea733790f5bf4",
"node/consensus/pow/src/igneum.rs": "8264d300db90ee5e4c0f568f3e4f847e9c2c1028312827f38e8458d2c13bedfd",
"mining/pool/src/node.rs": "54e52ee3ca45d2b482b2acf066d1ba613fa7fc7aaf7075fc5919d61257a126d4",
"pow/src/generator.rs": "751f39aeedb2987856343e2a67c7aeca7daa47ddafe5192c50a19b1d425e3a8a",
"mining/pool/src/payout.rs": "839619378b7e9b0b7eda22ce900aa2ada6410aa90e3d7f1f000a02f0b8449c1f",
"mining/pool/src/main.rs": "cca75f5452a46b53f13fe268989e12feb4767e67623f154d637b133249ae4a67",
"mining/pool/src/server.rs": "aaf86c5acec3e22a53580ee8ff2000ddc619a90c9f28d2ddad600e38c9e99bdc",
"mining/app/igneum-app/src/ember.rs": "e1e9d83e37b3acb47e89027994dba1638d7c4c547a0d1f587b95455cbe3c4873",
"mining/app/igneum-app/src/ota.rs": "d4c12a6c673b701ae432f23f758aad8a51979b3cabb82e33fb735f014cb09212",
"mining/proto-cuda/nvrtc/worker.cpp": "faf4782ff0fbfdea594e4635200a75db9084f96c663053d7c074df8e5bebf92f",
"v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexistence-model.md": "8b2b8964a77bac49c88c3d9c801455f18d9e730859b61ef958ffa3fa79f0de4a"
}
}

View file

@ -0,0 +1 @@
Prepared /mnt/data/igneum_stack_review_portable

View file

@ -0,0 +1,37 @@
{
"checks": [
{
"kind": "shard",
"artifact": "elf",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-program.elf",
"bytes": 2832504,
"sha256": "150f4c05a2951fc56174a87089707a030b18df8fbe7e053a66459edb83053083",
"match": true
},
{
"kind": "shard",
"artifact": "vk",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-program.vk",
"bytes": 104,
"sha256": "8b4da5bff86d963f4210a78e5d800a1cd00ab41b158f6962f4ac009edc249d4c",
"match": true
},
{
"kind": "aggregator",
"artifact": "elf",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-aggregator.elf",
"bytes": 319744,
"sha256": "143d9c243dd12e87e90be71f6b8cd42353e513bf8ce78903ef6f972f1bc9aa7b",
"match": true
},
{
"kind": "aggregator",
"artifact": "vk",
"path": "proving/igneum-proving/proving/igneum-prove/elf/igneum-prove-aggregator.vk",
"bytes": 104,
"sha256": "ad17bc1ae5be816554dbb13cb5b4d242678adfb8e1a4f7247ceb8b5ba9001b9f",
"match": true
}
],
"scope": "Byte integrity only. Does not verify build reproducibility, program-key derivation, proof validity or deployed node embedding."
}

View file

@ -0,0 +1,158 @@
{
"review": "Igneum updated-stack source review",
"date": "2026-10-08",
"native_rust_executed": false,
"gpu_executed": false,
"sp1_executed": false,
"probe_count": 13,
"probes": [
{
"probe": "cache_wrong_statement_after_success",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"cold_wrong_context": "Invalid",
"warm_wrong_context": "Verified",
"limitation": "No SP1 proof constructed; models the supplied early-return cache logic."
},
{
"probe": "cache_negative_context_poisoning",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"valid_context_after_bad_context": "Invalid",
"fresh_valid_context": "Verified"
},
{
"probe": "cache_zero_id_accepts_pinned_epoch",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"result": "Verified",
"accepted_ids": [
"vk-B"
],
"cached_id": "ZERO",
"limitation": "Reachability depends on host configuration and how the cache entry was populated."
},
{
"probe": "reg64_rotate_xor_prefix_equivalence",
"classification": "EXACT_ALGEBRA_WITH_RANDOMIZED_CHECKS",
"comparisons": 33024,
"point_updates": 4096,
"mismatches": 0,
"equation": "a[k]=ROL(r[k],63-k); P=XOR(a[k],k<s); S=XOR(a[k]); addr=r[s]^ROR(P,1)^S^P^a[s]",
"limitation": "Extra cached state and updates cost hardware. This does not prove a whole-hash shortcut, smaller necessary state or a GPU/ASIC speedup."
},
{
"probe": "anchored_recovery_threshold",
"classification": "PURE_PREDICATE_REPRODUCTION",
"old_table_weights": "40 honest A + 40 honest B + 20 equivocating in both",
"both_sides_before_window": [
false,
false
],
"both_sides_after_window": [
true,
true
],
"pause_only_post_window_100_of_100": false,
"limitation": "Both branches must satisfy sliding-table, ancestry and dust rules too. Source simulations separately report this case. No real-node conflict produced. Historical-checkpoint backfill may affect healing."
},
{
"probe": "pool_epochseeds_schema_mismatch",
"classification": "STATIC_SOURCE_ASSERTION",
"required_field": "shadow_reps",
"present_in_supplied_pool_initializer": false,
"limitation": "Would fail against the supplied node definition; cargo was not available and the pool vendor tree is absent."
},
{
"probe": "v6_research_vs_canonical_enum",
"classification": "STATIC_SOURCE_ASSERTION",
"reg64_chain_exists": true,
"canonical_enum_v6_exists": false,
"limitation": "Not a claim that v6 work is absent. Release manifest and end-to-end activation are not demonstrated by these snapshots."
},
{
"probe": "pool_send_before_journal_crash",
"classification": "ISOLATED_FAILURE_SEQUENCE",
"original_due": 100,
"paid_after_crash_and_retry": 200,
"transaction_nonces": [
0,
1
],
"assumptions": [
"First send accepted on network",
"Pool has enough funds for retry",
"Restart loads pre-send snapshot",
"No external recovery process absent from supplied path"
],
"limitation": "No actual transaction broadcast. Models the missing durable-intent window."
},
{
"probe": "pool_reauthorize_cleanup",
"classification": "ISOLATED_CONTROL_FLOW_REPRODUCTION",
"authorizations_on_one_connection": 3,
"members_left_after_disconnect": 2,
"limitation": "No pool server was run. Static handler contains no prior-member guard/removal."
},
{
"probe": "ember_climb_direction",
"classification": "ALGORITHMIC_REACHABILITY_EXAMPLE",
"illustrative_start_core_mhz": 1300,
"illustrative_faster_core_mhz": 1800,
"can_climb_propose_higher_core_from_start": false,
"limitation": "A full sweep can choose a new starting point; no claim the illustrative higher clock is faster on an actual GPU."
},
{
"probe": "ota_disabled_but_urgent",
"classification": "BOOLEAN_GUARD_REPRODUCTION",
"auto_update": false,
"urgent": true,
"install_asked": false,
"consent_guard_blocks": false,
"limitation": "Actual application also requires a valid staged release and safe_to_apply; applies to supplied devnet policy."
},
{
"probe": "cuda_high32_boundary_positive",
"classification": "SOURCE_ASSERTION_AND_ARITHMETIC_CHECK",
"parts": [
{
"high32": 0,
"low32": 4294967264,
"count": 32
},
{
"high32": 1,
"low32": 0,
"count": 64
}
],
"alignment_guard_present": true,
"limitation": "No GPU execution; confirms the earlier host-level alignment omission is covered in this archive."
},
{
"probe": "economic_table_displayed_inequality",
"classification": "ARITHMETIC_CHECK",
"condition": "fleet cost exceeds annual miner revenue",
"displayed_fleet_musd": 18,
"displayed_revenue_musd": [
40,
80
],
"displayed_pass_consistent": false,
"limitation": "The table or condition may contain a typo; underlying economic workbook was not reproduced."
}
],
"source_sha256": {
"node/igneum/exec/src/proving.rs": "92302ee089fca720f2ee6ac0756c0054a01c995db4c997d358683a2a08f3401b",
"node/igneum/exec/src/nativeverify.rs": "bbb11e72495c04f44172c2ec6f230919f8ff96b8b45847e03efacd063f94da96",
"pow/src/verify.rs": "033ae9f2ccd32e1170e7ff4f259b206b26e78ddc9ebf68d7b26933794aa1f345",
"node/consensus/src/processes/finality.rs": "6194a96a80e5ec5a4daeb63afa8fda55a8c7a2f959d5becab60ea733790f5bf4",
"node/consensus/pow/src/igneum.rs": "8264d300db90ee5e4c0f568f3e4f847e9c2c1028312827f38e8458d2c13bedfd",
"mining/pool/src/node.rs": "54e52ee3ca45d2b482b2acf066d1ba613fa7fc7aaf7075fc5919d61257a126d4",
"pow/src/generator.rs": "751f39aeedb2987856343e2a67c7aeca7daa47ddafe5192c50a19b1d425e3a8a",
"mining/pool/src/payout.rs": "839619378b7e9b0b7eda22ce900aa2ada6410aa90e3d7f1f000a02f0b8449c1f",
"mining/pool/src/main.rs": "cca75f5452a46b53f13fe268989e12feb4767e67623f154d637b133249ae4a67",
"mining/pool/src/server.rs": "aaf86c5acec3e22a53580ee8ff2000ddc619a90c9f28d2ddad600e38c9e99bdc",
"mining/app/igneum-app/src/ember.rs": "e1e9d83e37b3acb47e89027994dba1638d7c4c547a0d1f587b95455cbe3c4873",
"mining/app/igneum-app/src/ota.rs": "d4c12a6c673b701ae432f23f758aad8a51979b3cabb82e33fb735f014cb09212",
"mining/proto-cuda/nvrtc/worker.cpp": "faf4782ff0fbfdea594e4635200a75db9084f96c663053d7c074df8e5bebf92f",
"v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexistence-model.md": "8b2b8964a77bac49c88c3d9c801455f18d9e730859b61ef958ffa3fa79f0de4a"
}
}

View file

@ -0,0 +1,254 @@
#!/usr/bin/env python3
"""Igneum updated-stack review probes, 8 Oct 2026.
These are source assertions and isolated Python models. They do NOT execute the
Rust node, SP1, pool server or a GPU kernel, and are not a production test report.
Run from the extracted review root: python3 harness/reproduce.py --root .
"""
from __future__ import annotations
import argparse
import hashlib
import json
import random
from pathlib import Path
P = argparse.ArgumentParser()
P.add_argument('--root', type=Path, default=Path('.'))
P.add_argument('--out', type=Path, default=Path('results/reproductions.json'))
args = P.parse_args()
root = args.root.resolve()
results = []
checked = {}
def read(path: str, *needles: str) -> str:
p = root / path
text = p.read_text()
for needle in needles:
if needle not in text:
raise AssertionError(f'Source changed: {path}: missing {needle!r}')
checked[path] = hashlib.sha256(p.read_bytes()).hexdigest()
return text
def record(name, classification, data):
results.append({'probe':name, 'classification':classification, **data})
# Source-matched cache control flow. Signature/public-value verification is a stub.
read('node/igneum/exec/src/proving.rs',
'inner.verdicts.get(&c.proof_hash)',
'Ok(id) if accepted.is_empty() || *id == B256::ZERO || accepted.contains(id)',
'verdicts.insert(c.proof_hash, r.clone())')
read('node/igneum/exec/src/nativeverify.rs', 'if got.as_slice() != statement')
class CacheModel:
def __init__(self):
self.cache = {}
self.held = {'proof-A': ('Shard', 'statement-A', 'vk-A')}
def verdict(self, digest, kind, statement, accepted):
if digest in self.cache:
ok, value = self.cache[digest]
if not ok:
return 'Invalid'
return 'Verified' if not accepted or value == 'ZERO' or value in accepted else 'Invalid'
if digest not in self.held:
return 'Missing'
actual_kind, actual_statement, actual_vk = self.held[digest]
if kind != actual_kind:
return 'Invalid'
ok = statement == actual_statement and (not accepted or actual_vk in accepted)
self.cache[digest] = (ok, actual_vk if ok else 'context mismatch')
return 'Verified' if ok else 'Invalid'
cold = CacheModel().verdict('proof-A','Shard','statement-B',{'vk-A'})
warm = CacheModel()
assert warm.verdict('proof-A','Shard','statement-A',{'vk-A'}) == 'Verified'
warm_wrong = warm.verdict('proof-A','Shard','statement-B',{'vk-A'})
assert cold == 'Invalid' and warm_wrong == 'Verified'
record('cache_wrong_statement_after_success','ISOLATED_CONTROL_FLOW_REPRODUCTION',
{'cold_wrong_context':cold,'warm_wrong_context':warm_wrong,
'limitation':'No SP1 proof constructed; models the supplied early-return cache logic.'})
poison = CacheModel()
assert poison.verdict('proof-A','Shard','statement-B',{'vk-A'}) == 'Invalid'
wrong_first = poison.verdict('proof-A','Shard','statement-A',{'vk-A'})
assert wrong_first == 'Invalid'
record('cache_negative_context_poisoning','ISOLATED_CONTROL_FLOW_REPRODUCTION',
{'valid_context_after_bad_context':wrong_first,'fresh_valid_context':CacheModel().verdict('proof-A','Shard','statement-A',{'vk-A'})})
z = CacheModel()
z.cache['proof-A'] = (True,'ZERO')
assert z.verdict('proof-A','Shard','statement-A',{'vk-B'}) == 'Verified'
record('cache_zero_id_accepts_pinned_epoch','ISOLATED_CONTROL_FLOW_REPRODUCTION',
{'result':'Verified','accepted_ids':['vk-B'],'cached_id':'ZERO',
'limitation':'Reachability depends on host configuration and how the cache entry was populated.'})
# Exact algebraic equivalence of the reg64 address mixer. No hash or GPU benchmark.
read('pow/src/verify.rs', 'm = if started { m.rotate_left(1) ^ r[k][lane] } else { r[k][lane] };', 'r[a][lane] ^ m')
MASK = (1 << 32) - 1
def rol(x,n):
n %= 32
return ((x << n) | (x >> ((32-n) % 32))) & MASK
def naive(r,s):
m = None
for k,x in enumerate(r):
if k == s:
continue
m = x if m is None else rol(m,1) ^ x
return r[s] ^ m
class IndexedMixer:
def __init__(self, values):
self.r = [0]*64
self.a = [0]*64
self.tree = [0]*65
self.total = 0
for i,x in enumerate(values):
self.set(i,x)
def set(self,i,x):
a = rol(x,63-i)
delta = a ^ self.a[i]
self.a[i], self.r[i] = a,x
self.total ^= delta
j = i+1
while j <= 64:
self.tree[j] ^= delta
j += j & -j
def prefix(self,s):
p = 0
while s:
p ^= self.tree[s]
s -= s & -s
return p
def address(self,s):
p = self.prefix(s)
return self.r[s] ^ rol(p,31) ^ self.total ^ p ^ self.a[s]
rng = random.Random(0x1A6E20261008)
comparisons = 0
for v in [[0]*64,[MASK]*64,list(range(64)),[1 << (i%32) for i in range(64)]]:
m = IndexedMixer(v)
for s in range(64):
assert m.address(s) == naive(v,s)
comparisons += 1
m = IndexedMixer([rng.getrandbits(32) for _ in range(64)])
for _ in range(4096):
m.set(rng.randrange(64), rng.getrandbits(32))
for s in rng.sample(range(64),8):
assert m.address(s) == naive(m.r,s)
comparisons += 1
record('reg64_rotate_xor_prefix_equivalence','EXACT_ALGEBRA_WITH_RANDOMIZED_CHECKS',
{'comparisons':comparisons,'point_updates':4096,'mismatches':0,
'equation':'a[k]=ROL(r[k],63-k); P=XOR(a[k],k<s); S=XOR(a[k]); addr=r[s]^ROR(P,1)^S^P^a[s]',
'limitation':'Extra cached state and updates cost hardware. This does not prove a whole-hash shortcut, smaller necessary state or a GPU/ASIC speedup.'})
# Exact pure anchored threshold only. No signatures, fork-choice, dust or network run.
read('node/consensus/src/processes/finality.rs',
'if v4 && recovery {', '((signed_f as u128) * 2 > total_f as u128, past)')
def anchored(v4,recovery,lock,checkpoint,window,signed,total):
past = checkpoint >= min((1<<64)-1,lock+window)
if total == 0:
return False,past
if not past:
return 3*signed >= 2*total,past
if v4 and recovery:
return 2*signed > total,past
return False,past
before = [anchored(True,True,0,99,100,60,100)[0] for _ in range(2)]
after = [anchored(True,True,0,100,100,60,100)[0] for _ in range(2)]
pause100 = anchored(True,False,0,100,100,100,100)[0]
assert before == [False,False] and after == [True,True] and not pause100
record('anchored_recovery_threshold','PURE_PREDICATE_REPRODUCTION',
{'old_table_weights':'40 honest A + 40 honest B + 20 equivocating in both',
'both_sides_before_window':before,'both_sides_after_window':after,
'pause_only_post_window_100_of_100':pause100,
'limitation':'Both branches must satisfy sliding-table, ancestry and dust rules too. Source simulations separately report this case. No real-node conflict produced. Historical-checkpoint backfill may affect healing.'})
# Source-contract seam, not a cargo build.
node = read('node/consensus/pow/src/igneum.rs','pub shadow_reps: u16,')
pool = read('mining/pool/src/node.rs','let seeds = EpochSeeds { epoch: info.epoch_seed')
literal = pool.split('let seeds = EpochSeeds {',1)[1].split('};',1)[0]
assert 'shadow_reps' not in literal and '..' not in literal
record('pool_epochseeds_schema_mismatch','STATIC_SOURCE_ASSERTION',
{'required_field':'shadow_reps','present_in_supplied_pool_initializer':False,
'limitation':'Would fail against the supplied node definition; cargo was not available and the pool vendor tree is absent.'})
gen = read('pow/src/generator.rs','pub enum ProgramClass {','pub reg64_chain: bool,')
enum = gen.split('pub enum ProgramClass {',1)[1].split('}',1)[0]
assert 'V6' not in enum
record('v6_research_vs_canonical_enum','STATIC_SOURCE_ASSERTION',
{'reg64_chain_exists':True,'canonical_enum_v6_exists':False,
'limitation':'Not a claim that v6 work is absent. Release manifest and end-to-end activation are not demonstrated by these snapshots.'})
# Crash point between externally accepted transfer and durable local state.
read('mining/pool/src/payout.rs','match self.send(&a, wei, nonce).await {','s.dirty = true;')
read('mining/pool/src/main.rs','pool.cfg.snapshot_interval_s.max(1)','s.save(&path)')
disk_balance = 100
network_paid = 0
nonce = 0
network_paid += disk_balance; nonce += 1 # Accepted externally, process dies before local debit/save.
restarted_due = disk_balance
network_paid += restarted_due; nonce += 1
assert network_paid == 200
record('pool_send_before_journal_crash','ISOLATED_FAILURE_SEQUENCE',
{'original_due':100,'paid_after_crash_and_retry':network_paid,'transaction_nonces':[0,1],
'assumptions':['First send accepted on network','Pool has enough funds for retry','Restart loads pre-send snapshot','No external recovery process absent from supplied path'],
'limitation':'No actual transaction broadcast. Models the missing durable-intent window.'})
# Repeated authentication creates stale members in the supplied connection state machine.
server = read('mining/pool/src/server.rs','Msg::Authorize { pubkey, pop, label, payout, .. }','remove(&m.id)')
members = {}
current = None
for i in range(1,4):
members[i] = {'connection':'same'}
current = i
members.pop(current)
assert list(members) == [1,2]
record('pool_reauthorize_cleanup','ISOLATED_CONTROL_FLOW_REPRODUCTION',
{'authorizations_on_one_connection':3,'members_left_after_disconnect':len(members),
'limitation':'No pool server was run. Static handler contains no prior-member guard/removal.'})
# Tuner reachability, not a performance model.
read('mining/app/igneum-app/src/ember.rs', 'let core_down = |p: Point|', 'vec![mem_up(best.point), core_down(best.point)')
start = 1300
reachable = [start - 100*i for i in range(5)]
assert 1800 not in reachable and max(reachable) == start
record('ember_climb_direction','ALGORITHMIC_REACHABILITY_EXAMPLE',
{'illustrative_start_core_mhz':start,'illustrative_faster_core_mhz':1800,
'can_climb_propose_higher_core_from_start':False,
'limitation':'A full sweep can choose a new starting point; no claim the illustrative higher clock is faster on an actual GPU.'})
ota = read('mining/app/igneum-app/src/ota.rs','if !self.auto && !urgent && !self.install_asked {')
def waits(auto,urgent,asked): return not auto and not urgent and not asked
assert waits(False,False,False) and not waits(False,True,False)
record('ota_disabled_but_urgent','BOOLEAN_GUARD_REPRODUCTION',
{'auto_update':False,'urgent':True,'install_asked':False,'consent_guard_blocks':False,
'limitation':'Actual application also requires a valid staged release and safe_to_apply; applies to supplied devnet policy.'})
# Positive old finding regression: serving API enforces aligned warp group and splitting at high32 rollover.
w = read('mining/proto-cuda/nvrtc/worker.cpp','nonce_start must be 32-aligned')
# Modeled aligned partitioning mirrors the intent; not C++/GPU execution.
start = (1<<32)-32
remaining = 96
parts=[]
while remaining:
room = (1<<32)-(start & 0xffffffff)
take = min(remaining,room)
parts.append({'high32':start>>32,'low32':start&0xffffffff,'count':take})
start += take
remaining -= take
assert [p['count'] for p in parts] == [32,64]
record('cuda_high32_boundary_positive','SOURCE_ASSERTION_AND_ARITHMETIC_CHECK',
{'parts':parts,'alignment_guard_present':True,
'limitation':'No GPU execution; confirms the earlier host-level alignment omission is covered in this archive.'})
# Contradictory economic-table inequality: check only the displayed values, no economic model execution.
model = read('v6/igneum-v6-freeze-tree/docs/analysis/class-v6/coexistence-model.md',
'USD 18 M of boards against USD 40 to 80 M: PASSES')
assert not (18 > 40) and not (18 > 80)
record('economic_table_displayed_inequality','ARITHMETIC_CHECK',
{'condition':'fleet cost exceeds annual miner revenue','displayed_fleet_musd':18,
'displayed_revenue_musd':[40,80],'displayed_pass_consistent':False,
'limitation':'The table or condition may contain a typo; underlying economic workbook was not reproduced.'})
output = {'review':'Igneum updated-stack source review','date':'2026-10-08',
'native_rust_executed':False,'gpu_executed':False,'sp1_executed':False,
'probe_count':len(results),'probes':results,'source_sha256':checked}
args.out.parent.mkdir(parents=True,exist_ok=True)
args.out.write_text(json.dumps(output,indent=2)+'\n')
print(json.dumps({'probes_completed':len(results),'output':str(args.out),'reg64_comparisons':comparisons},indent=2))

File diff suppressed because it is too large Load diff