diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index 9d68c4d53..64e291a70 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -2473,6 +2473,14 @@ F8's 64-seed gate on 017e7037 (the attack-pass lane, box 2, last seed 16:00:20 U Owed (recorded, not run, by the project lead's word): G2 (the CPU verifier on 1,024 hashes per card) on the amended stream; G3 (the Metal fuzz, edge, stats and determinism runs) on the amended stream; the hash-rate ladder re-measure on the M5 Max and the RTX 5090 (the amendment changes the base program's source draws, not the op mix or the load count, so the latency-bound rows of `docs/analysis/latency-shadow-2026-10-06.md` are expected to hold within their spread; unmeasured); AMD (the RX 9070 XT, PC 1); the 2019-class verifier core (O-1.14); F8's phase E (the 64-seed dynamic census) on the amended stream, which is the attack-pass lane's and the test of the per-op table. The row reads FIXED-AND-PASSED only after phase E passes against the amended class. +### AP-F8-3. The deterministic last-resort program is handed to the chain unchecked, and the rule would refuse 9.0 percent of such programs + +Finding (7 October 2026, the in-house pass adv-accept-3, report-acceptance-rule-3.md at 0c150e3c, log 95-lastresort.tsv on branch adv-accept-3; routed by the hash lane, sub-version 3's owner, to class v5's igneum-pow): class v4's last resort (`last_resort_v4`, AP-F8-2: the candidate at attempt 256 with every `or`, `mul` and `mulhi` rewritten to `xor`) is accepted as drawn, with no run of the rule; on 2,500 chain-shaped seeds the real rule refuses 223 of the rewritten programs (9.0 percent), 209 of them by part (a), a load reading a register no instruction wrote since the previous load from it. Unreachable: the measured rejection rate per attempt is 0.67 to 0.68, so the 256th attempt is reached with probability about 4.6e-44 per epoch seed (10^-43), and no chain reaches it; 0.3.22, 0.3.23 and the testnet pin do not move. Wrong by construction all the same: a consensus path that hands out a program the rule would refuse. + +Answer: correct. Sub-version 3's last resort is recorded as UNREACHABLE AND UNVERIFIED against the rule, and stays as frozen (017e7037's line; nothing moves on class v5's frozen object 1c420786 either). Class v5's is VERIFIED: `last_resort_v5` (igneum-pow `generator.rs`, class-v5 8ca66afa, the post-freeze commit, keyed on the state flag so no class v4 program moves) takes the rewrite, re-sources every stale load to the lowest register written since its last load and walks that to a fixpoint (`repair_stale_loads`: part (a) by construction, only load sources move), then runs the whole rule, over a scan of 256 candidates from the cap; the first that passes is the program. Past the scan the first repaired candidate stands as drawn (the draw stays total), behind 4.6e-44 times the repaired candidates' rejection rate (about 0.09) to the power of 256: under 1e-300. Known-failed test first, `class_v5_last_resort_is_verified_known_failed_adv3_steer_2` (seed adv3/steer/2 of adv-accept-3's label space, Devnet 3's genesis as the era): the sub-version 3 rewrite fails part (a) at instruction 47 reading r3; the repair restores (a); class v5's last resort passes the whole rule at attempt 256 (id 9b29c9481f6941d4); steer seeds 11, 33, 56, 58 and 77 (the log's other part-(a) rows) pass too. Suite green on box 2 at 8ca66afa (74 unit tests, the pinned packs unchanged), gate GREEN. + +Status: Fixed in class v5 (8ca66afa, 0.3.25's igneum-pow line); sub-version 3's path recorded as unreachable and unverified by the hash lane's AP-F8-1 entry. + ## Genesis forward-compatibility entries (7 October 2026, mission item 8, branch `genesis-forward`) The three genesis fields of `docs/analysis/mission/mission.md` section 2.8, built on the node fork branch `genesis-forward` (from release-0.3.19-node dc141409) and the repo branch `genesis-forward`; the design and the gates in `docs/design/genesis-forward.md`. Every switch is never on the devnet (its digest c562d70e... does not move); the testnet genesis sets all three (the testnet lane re-pins and re-digests). diff --git a/site/ledger.html b/site/ledger.html index 881707af1..9a97ed843 100644 --- a/site/ledger.html +++ b/site/ledger.html @@ -4,13 +4,13 @@ Igneum ledger: every criticism, answered - + - + @@ -18,7 +18,7 @@ - + @@ -53,7 +53,7 @@