diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index f4c518d5..0c551d60 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -411,7 +411,7 @@ Self-test PASS on every pack (cache FNV 448274a57f508cbc); both rows in the ledg | p34 | 1.25x | | site 1, 1.35 percent | | | p4 | 1.22x | | site 1, 1.45 percent | unattributed, 1.57x on sub-version 1 | -Every failing seed is ONE low-entropy load site; the mechanism is lineage-blind (AP-F8-1's residual) and the acceptance could not see it because it never ran the shadow block (AP-F8-3). SUB-VERSION 3's FIRST COMMIT: ca3-v4-amend ddacfbd3, 14:20:37Z (origin and build, gate GREEN): the acceptance executes the shadow block as the hash does, the test pins it to verify.rs on the seven v4 programs; PROGRAM_SUBVERSION_V4 = 3; byte 7; (A) and (B) held in a stash. Epoch-0 id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3; the devnet seed still accepts at attempt 1, so its program is sub-version 2's under the new id); the seven fingerprints unchanged from sub-version 2 for the same reason (e370fb2080b7dbb1, b7237555d31fc3cf, b6b167fa15dfe2c9, 28bdf65eff33f2c4, e26d38c46f3f1b16, dd8fdf6ff4f59eed, 8bf40f5cb858d835; control 90f794dd556f7a3b; Metal = Apple OpenCL 14:18:41 to 14:19:13Z), so the fleet and PC 2 G1s already read them and the G1 on sub-version 3's packs is a re-run of a known result; packs zip packs-ca3-v4-sub3 sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154; the ledger entry carries AP-F8-2's exhaustion half FIXED-AND-PASSED at 8bdcbdd8 and AP-F8-3 fixed here; the suite and the 4,096-seed census at ddacfbd3 on box 2. THE LOCALISATION (the hash lane): p23's band is dataset- and nonce-independent and reproduces in the acceptance's own execution: site 7 (instruction 38) reads r6 after 25 mulhi, 31 or r6 |= r4, 35 xor r6 ^= r4, which is r6 and not r4, an AND mask the lineage rule counts as fresh because the xor's operand is the or's; over 2^20 evaluations on the closed-form words site 7 reads 874,953 distinct word indices against about 1,046,500 at every other site (0.84 of uniform, 2.2 s on one box-2 core); over 2^24, 8,979,203 against about 16,260,000 (0.55, 35 s). THE COST LINES FOR THE SECOND COMMIT (0.3.22): structural (an abstract value class tracking shared operands) 0 s per attempt, this idiom only; the distinct-index ratio at 2^20 2.2 s per chosen candidate; at 2^24 35 s; no dataset-aware form needed (no cache fill). The hash lane's recommendation: the ratio at 2^20 with the threshold set from the clean seeds' per-site spread (p23's site 0.84; every clean site 0.995 to 1.000), plus the structural rule for the idiom so the ratio is a never-firing check on it. The attack-pass lane's verdict: sub-version 3 is the stream to gate and cannot read green by 19:00Z; byte 5 for 0.3.21 stands on its evidence. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the project lead takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +Every failing seed is ONE low-entropy load site; the mechanism is lineage-blind (AP-F8-1's residual) and the acceptance could not see it because it never ran the shadow block (AP-F8-3). SUB-VERSION 3's FIRST COMMIT: ca3-v4-amend ddacfbd3, 14:20:37Z (origin and build, gate GREEN): the acceptance executes the shadow block as the hash does, the test pins it to verify.rs on the seven v4 programs; PROGRAM_SUBVERSION_V4 = 3; byte 7; (A) and (B) held in a stash. Epoch-0 id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3; the devnet seed still accepts at attempt 1, so its program is sub-version 2's under the new id); the seven fingerprints unchanged from sub-version 2 for the same reason (e370fb2080b7dbb1, b7237555d31fc3cf, b6b167fa15dfe2c9, 28bdf65eff33f2c4, e26d38c46f3f1b16, dd8fdf6ff4f59eed, 8bf40f5cb858d835; control 90f794dd556f7a3b; Metal = Apple OpenCL 14:18:41 to 14:19:13Z), so the fleet and PC 2 G1s already read them and the G1 on sub-version 3's packs is a re-run of a known result; packs zip packs-ca3-v4-sub3 sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154; the ledger entry carries AP-F8-2's exhaustion half FIXED-AND-PASSED at 8bdcbdd8 and AP-F8-3 fixed here; the suite and the 4,096-seed census at ddacfbd3 on box 2. THE LOCALISATION (the hash lane): p23's band is dataset- and nonce-independent and reproduces in the acceptance's own execution: site 7 (instruction 38) reads r6 after 25 mulhi, 31 or r6 |= r4, 35 xor r6 ^= r4, which is r6 and not r4, an AND mask the lineage rule counts as fresh because the xor's operand is the or's; over 2^20 evaluations on the closed-form words site 7 reads 874,953 distinct word indices against about 1,046,500 at every other site (0.84 of uniform, 2.2 s on one box-2 core); over 2^24, 8,979,203 against about 16,260,000 (0.55, 35 s). THE COST LINES FOR THE SECOND COMMIT (0.3.22): structural (an abstract value class tracking shared operands) 0 s per attempt, this idiom only; the distinct-index ratio at 2^20 2.2 s per chosen candidate; at 2^24 35 s; no dataset-aware form needed (no cache fill). The hash lane's recommendation: the ratio at 2^20 with the threshold set from the clean seeds' per-site spread (p23's site 0.84; every clean site 0.995 to 1.000), plus the structural rule for the idiom so the ratio is a never-firing check on it. The attack-pass lane's verdict: sub-version 3 is the stream to gate and cannot read green by 19:00Z; byte 5 for 0.3.21 stands on its evidence. THE THRESHOLD NUMBERS FOR SUB-VERSION 3's SECOND COMMIT (the hash lane, box 2, the per-site distinct-index ratio over 2^20 evaluations against the window expectation N minus N^2 / 2W, on the 64 F8 programs as ddacfbd3 draws them, 2.8 s per seed on one core, all sixteen sites): the 55 clean seeds' per-seed minimum 0.9962 to 1.0000 (median 0.9999); over all 880 clean site rows min 0.9960, p1 0.9990, p5 1.0000, median 1.0000. The nine failing seeds' minimum site: p23 0.8361 (site 7), p18 0.9274 (site 6), p19 0.9335 (site 15), p15 0.9432 (site 2), p56 0.9654 (site 2); then p34 0.9927, p4 0.9961, p8 0.9963, p10 0.9963. A threshold of 0.98 sits 0.016 under the clean minimum and 0.015 over the strong five's maximum and rejects exactly those five; the weak four (1.22x to 1.50x in F8's gate) sit inside the clean spread at 2^20 and no threshold reaches them without rejecting clean seeds; a 2^24 run (35 s per candidate) on the weak four, p23 and five clean seeds measures whether they separate there (p23 went 0.84 to 0.55). The structural rule is in and bites where the band was: with the shared-operand relation tracked in the draw and in (a'), p23's attempt 1 draws site 7 from r5 instead of r6 (the or-then-xor on r4 marked r6 lossy); the devnet seed still accepts at attempt 1 (id unchanged); the (a') fixpoint carries the relation. THE COORDINATOR'S LINE: decide by the 2^24 lines: if they separate the weak four from the clean seeds with a gap at least the 2^20 gap, commit (iii), the 2^20 ratio at 0.98 always plus the 2^24 ratio only when the 2^20 per-seed minimum sits under a band edge set from the clean p1 with margin (0.999 fires it on about 1 percent of clean candidates, 35 s once an hour on a node); otherwise commit (i), the 2^20 ratio at 0.98, and name the weak four (p4, p8, p10, p34) as the open tail in the ledger and the commit, unattributed-and-chased, not absorbed. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the project lead takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the project lead's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule