Counter ASIC 2.0: the rolling-upgrade digest is 4d8f8bb6 (the four-field file on the 0.3.11 node); status 23:14

This commit is contained in:
igneum-josh 2026-10-05 23:14:55 +00:00
parent 1d3f10f7e5
commit 306451533d
2 changed files with 4 additions and 2 deletions

View file

@ -26,11 +26,11 @@ Built from `<node branch>` at `<commit>` on the PCs through `tools/build-job.mjs
NODE_OVERRIDE_PARAMS='{"difficulty_v2_activation_daa":33000,"proving_v0_activation_daa":84100,"fees_v1_activation_daa":210000,"finality_v3_activation_daa":135200,"program_class_v3_activation_daa":N4,"proving_v1_activation_daa":N5,"proving_v1_segment_blocks":8,"proving_v1_unproven_daa":600,"proving_v1_aggregator_share_bps":1000}'
```
The same nine-field object goes verbatim into the override files of Mac node 1, the observer node and the seed, and into the manifest's `consensus.override` (`publish-manifest.sh --override`). N5 = DAA at publish + 14,400 (the proving v1 switch, no rounding). Two digests, read on the 0.3.11 Mac node (igneumd bd7f043c..., fork 89dfcb95, 22:5x UTC): with no override file c562d70e1428c9789823cc40067623b4767f7c555ce7ff4ea11c1498f013ef6c (the rolling-upgrade digest, equal to the node agent's pinned test); with the nine-field object at N4 = N5 = 154,800 the ACTIVATION digest 0139ab9dc2992d449ec787d8f021974933631eb55740ab4b6ce9d5c226e72888, the value every node must print after the publish; the node logs "Program class v3 ... active from epoch 43 (DAA 154800 ... epochs of 3600)" and "Proving v1 ... paid from DAA 154800, 8 blocks a segment, unproven after 600 DAA, aggregator share 1000 bps". Binaries from release-0.3.11 23bc2b2: Igneum-Miner-0.3.11.dmg b7e81d4f6f3af9f9179e29faa72c844b795df757dfb2e4cd1d56cd454e78e1e7 (41,592,041 bytes; the packaged json carries the nine fields, read back from the image); the seed's Linux igneumd 63cf490d... (glibc 2.34, 89dfcb95 inside). The era seed for the devnet: the stand-in of `docs/plans/era-layout.md` (the hash of the last selected-chain block below `15,552,000 n - 7,200`; era 0 on the devnet uses the genesis hash), until the 1-hour VDF of spec 4.4 is in the node.
The same nine-field object goes verbatim into the override files of Mac node 1, the observer node and the seed, and into the manifest's `consensus.override` (`publish-manifest.sh --override`). N5 = DAA at publish + 14,400 (the proving v1 switch, no rounding). Three digests, read on the 0.3.11 Mac node (igneumd bd7f043c..., fork 89dfcb95): with no override file c562d70e1428c9789823cc40067623b4767f7c555ce7ff4ea11c1498f013ef6c (the node agent's pinned test); with the fleet's live four-field file 4d8f8bb668828a3dcf7b783b995f3d3ebfde32a092dd1dbd5bf4373c5c65a62c (the rolling-upgrade digest of publish 1, 23:13:54 UTC); with the nine-field object at N4 = N5 = 154,800 the ACTIVATION digest 0139ab9dc2992d449ec787d8f021974933631eb55740ab4b6ce9d5c226e72888, the value every node must print after the publish; the node logs "Program class v3 ... active from epoch 43 (DAA 154800 ... epochs of 3600)" and "Proving v1 ... paid from DAA 154800, 8 blocks a segment, unproven after 600 DAA, aggregator share 1000 bps". Binaries from release-0.3.11 23bc2b2: Igneum-Miner-0.3.11.dmg b7e81d4f6f3af9f9179e29faa72c844b795df757dfb2e4cd1d56cd454e78e1e7 (41,592,041 bytes; the packaged json carries the nine fields, read back from the image); the seed's Linux igneumd 63cf490d... (glibc 2.34, 89dfcb95 inside). The era seed for the devnet: the stand-in of `docs/plans/era-layout.md` (the hash of the last selected-chain block below `15,552,000 n - 7,200`; era 0 on the devnet uses the genesis hash), until the 1-hour VDF of spec 4.4 is in the node.
## 4. The order
TWO MANIFESTS, never one (C39, confirmed to the shipper 23:12 UTC): the engine writes a manifest's consensus.override at the take and restarts the node with it at the next safe window whatever binary is installed, and a 0.3.10 node refuses a file carrying program_class_v3 or the proving v1 fields (deny_unknown_fields) and dies; so publish 1 goes in this order (C40: the 0.3.11 binary itself flips the digest from the fleet's 1f4b4425 to c562d70e because the class v3 field enters it at never, so the apps must not take 0.3.11 before the hand nodes): FIRST the hand nodes and the seed on the 0.3.11 binaries with the four-field file, each printing c562d70e..., THEN the first 0.3.11 manifest with the live four-field object UNCHANGED and update-now to the apps machine by machine, every app's node joining at c562d70e; and only when every reporting app and node is on 0.3.11 does the second manifest carry the nine-field object (N4 = N5 re-pinned to tip + 14,400 rounded up to 3,600 at that moment if the 10,800 floor has passed), the hand nodes' and the seed's files switched, the digest sweep to the activation digest. The DMG's packaged nine-field line is fine for a fresh install.
TWO MANIFESTS, never one (C39, confirmed to the shipper 23:12 UTC): the engine writes a manifest's consensus.override at the take and restarts the node with it at the next safe window whatever binary is installed, and a 0.3.10 node refuses a file carrying program_class_v3 or the proving v1 fields (deny_unknown_fields) and dies; so publish 1 goes in this order (C40: the 0.3.11 binary itself flips the digest from the fleet's 1f4b4425 to c562d70e because the class v3 field enters it at never, so the apps must not take 0.3.11 before the hand nodes): FIRST the hand nodes and the seed on the 0.3.11 binaries with the four-field file, each printing 4d8f8bb668828a3dcf7b783b995f3d3ebfde32a092dd1dbd5bf4373c5c65a62c (measured on a 22-s scratch node at 23:13:54 UTC: the 0.3.11 node with the fleet's live four-field file; c562d70e... is its digest with NO override file, the node agent's pinned case), THEN the first 0.3.11 manifest with the live four-field object UNCHANGED and update-now to the apps machine by machine, every app's node joining at 4d8f8bb6; the apps still on 0.3.10 are refused by the new side from the moment the hand nodes move until each updates (the fee switch's 8 min 47 s shape), and PC 1 stays refused on 1f4b4425 until its morning relaunch; and only when every reporting app and node is on 0.3.11 does the second manifest carry the nine-field object (N4 = N5 re-pinned to tip + 14,400 rounded up to 3,600 at that moment if the 10,800 floor has passed), the hand nodes' and the seed's files switched, the digest sweep to the activation digest. The DMG's packaged nine-field line is fine for a fresh install.
1. The digest flip: a node build that carries `program_class_v3_activation_daa` at never on every node (hand nodes and the seed first: `infra/devnet/restart-hand-nodes.sh '<object without the new field>'`, then the app version through the manifest; every node prints the same `Consensus params digest`).
2. Fix N4, cut the app version (`packaging/mac/packaged-config.sh`, the three version files), commit as igneum-josh.

View file

@ -649,3 +649,5 @@ The shipper found it from the intake: PC 2 has two new engine runs (win-1ccfe586
23:13. C39, confirmed to the shipper as the order: two manifests, never one. The first 0.3.11 manifest carries the live four-field override unchanged (a 0.3.10 node dies on a file with the new fields: deny_unknown_fields, and the engine restarts the node with a taken manifest's override whatever binary is installed); the nine-field object goes in a second manifest only when every reporting app and node is on 0.3.11 (N4 = N5 re-pinned then if the 10,800 floor has passed); the hand nodes and the seed switch files at that step; the digest sweep to 0139ab9d... after it. Rollout plan section 4.
23:14. C40, confirmed to the shipper as the rule and written into section 4: publish 1 moves the hand nodes and the seed to the 0.3.11 binaries with the four-field file FIRST (each printing c562d70e), then the manifest and the apps; otherwise the apps on c562d70e and the hand nodes on 1f4b4425 would partition for the window between the publishes. Publish 2 flips everything to 0139ab9d in one sweep.
23:14. The shipper confirms the order with one measured correction: the 0.3.11 node with the fleet's live four-field file prints 4d8f8bb668828a3dcf7b783b995f3d3ebfde32a092dd1dbd5bf4373c5c65a62c (a 22-s scratch node, 23:13:54Z); c562d70e is the no-file case (the pinned test); 0139ab9d the nine-field case. So publish 1 flips the fleet from 1f4b4425 to 4d8f8bb6 (the hand nodes and the seed first, then the manifest and the apps; the 0.3.10 apps refused for the minutes until each updates, PC 1 until the morning), publish 2 to 0139ab9d in one sweep. Step 1 starts when PC 2's job gives the exes and CI is green on the pushed tree. Rollout plan section 3 carries the three digests.