diff --git a/docs/plans/igneum-2.0.md b/docs/plans/igneum-2.0.md index 56683ca78..a3346cc52 100644 --- a/docs/plans/igneum-2.0.md +++ b/docs/plans/igneum-2.0.md @@ -114,6 +114,20 @@ The behaviour (rule v4, the anchored table): a checkpoint locks when two thirds The plan's integration test (ordering, finality, proof queues, voter tables and seed transitions together, not a simulation alone): not run by this lane today. What exists: the fast-time three-node harness (`tools/finality-attacks/v3.mjs`, real fork choice and finality, no proof queue) queued on build-3 for the known-failed v3 partition line; the proving layer and the voter-table folds run on the same node line but no harness drives all five together. Clock: the known-failed line in the 20:00 report at the latest; the five-together harness is a D5 pin for the node lane with this lane's scenario list, not a Mac job. +**The miner-voted bring-forward as a mechanism (the rotation lane's layer 4, `docs/design/class-rotation-four-layers.md` sections 2 and 6, carried here as a D5 pin; status: a research-class prototype behind `rotation_v6_activation_daa` on a fork branch, the tally `vote_carries` with unit tests; nothing on any network):** + +- Activation rule. A `FlipVote` is an item in the coinbase finality section (tag 8, the Leave item's shape, carried last so an older decoder stops cleanly): a BLS signature by a finality voter's key over `"igneum-flip-v1/" || chain_id || 0 || index || hash(C_i) || family_id || target_height`, where `family_id` is the NEXT scheduled family epoch's bank structure and `target_height` an hourly epoch boundary. A node tallies at every lock over 720 consecutive checkpoint indices (six hours; four on the fast-time file) by Q2's block reading, weighted by W2 at `C_i`: the vote carries when at every one of the last 240 indices the keys whose latest flip vote names the same `(family_id, target_height)` hold at least two thirds of active weight AND at least half of total 30-day weight. When it carries and the schedule admits the height (at least `rotation_vote_delay_daa`, 14,400 DAA s, ahead), the node installs the flip: the family epoch that was scheduled for a later height starts at `target_height`, with the draw layer 3 makes from that height's reference block; the installed flip is persisted in the finality state and re-installed on load, so a restarted node never computes the plain schedule beside peers that flipped (fault 7's class, 8 October 2026). +- "No veto" as a mechanism, not a label. The scheduled family epoch is a height written at genesis, not a vote; a target at or past the scheduled height is invalid and dropped; the tally has no negative vote; so nothing can delay a scheduled change and the only thing a vote can do is bring the next one forward. Abstention blocks a bring-forward (the two-thirds-of-active test), and that is all abstention can do. +- Coalition behaviour. A fleet at a third of weight blocks every bring-forward while it holds a third of active weight and cannot delay the schedule; if it goes silent it leaves the active denominator within a presence window and, at a third of total, pauses finality (which costs it its own locks). A fleet with majority weight is the finality problem itself (twenty days of 100 percent hashrate to two thirds) and could carry a bring-forward, which only hurts a chip; it cannot delay. The vote adds no new threshold to buy: a third of active weight is a third of the 30-day blocks. +- Partition handling. No flip vote counts while finality is paused (the tally runs at locks, over certified checkpoints), so a vote cannot carry one-sided: a partition shorter than the lead heals before the flip; one longer has paused finality on at least one side (the partition row above), the vote is void there and the schedule stands; a vote carried before the split flips on both sides at the same height from the same reference block. Under rule v4 a recovery lock counts as a lock. +- Old-client behaviour. The schedule is genesis-fixed, so a client that does not implement the tally computes the plain schedule and, after a carried flip, refuses the flipped family's blocks at `target_height`: the tally is therefore part of the consensus rule from the height `rotation_v6_activation_daa` names, under the digest arm every switch uses (a binary carrying the field peers with one that does not until the height), and the 2.0 line restarts at v2.0.0 with it, so there is no older client on the network once it is live; a node synced from a pruning proof cannot tally below its pruning point and takes the schedule (owed, the class signal's same gap). Replayed or forged votes: the tag separates a flip vote from a checkpoint vote, `chain_id` stops cross-network replay, `index || hash(C_i)` expires it with its checkpoint, two flip votes by one key at one index naming different targets are equivocation under 3.6's evidence shape. +- Pins: [ ] the 720-index tally against `sim/finality_v2.py` under the F2 eclipse, the bought-keys case and rule v4's pause and recovery (this lane, after the partition rows); [ ] the fast-time harness run of a carried flip across a partition (the rotation harness with `rotation_vote_window` 4), the node lane; [ ] the pruning-proof node's tally. + +**The seed and VDF pipeline (`docs/spec/04-seeds-and-vdf.md`, `docs/analysis/era-vdf-2026-10-07.md`; carried here as a D5 pin):** + +- The property it protects, stated: seed-selection protection and nothing else (the standing rule above: rotation is optional to the security argument). The miner who finds the last block before a reference block could compute the program that block implies, benchmark it, and withhold the block if the program is bad for it; with the delay (the class-group VDF, T at 300x the 2-second decision window at the reference core, 108,000,000 squarings for the era at the measured 30,000 per second) no candidate's draw is knowable inside the window, so withholding has the same expected program as publishing and only burns the block: gain 0 in every row of the grinding table (measured by the re-roll harness: fires with the VDF off, silent with it on, the era record's section 3). It is not an ASIC-resistance claim and is not counted in any resistance ratio. +- Behaviour when finality is unavailable at a seed boundary, defined: every seed (hour, week, era) is drawn from the last selected-chain block below the boundary less the lead, on the header's own selected chain, certified or not; a finality pause of any length changes nothing for rotation (the partition row's seed line, `finality-guarantees.md` section 8); the certified binding is rejected because it would couple the seed to finality liveness and would need a rule for a certificate that lands late, and the delay does not need it. Tested: the determinism and re-roll gates of the era record; owed: the harness reading of the program id on both sides of a boundary during a pause (the harness line below). + **User-facing rule, carried:** included, executed, proven and finalised are four distinct states (section 9 of the statement: the claim, the source of truth and whether each can be withdrawn; only finalised cannot), and a safe pause is reported as a pause (`finality_active` false, reason `paused`, or `recovered` for one window after a recovery lock), never as an unchanged guarantee. Where the interfaces differ today (the wallet's "finality not active" on a block under a lock, the explorer's `final` for finalised, the live page's missing executed and finalised, the receipt pages' "proven" in the verifier's sense) is listed there for the wallet, explorer, live and reference-apps lanes. - Not guaranteed, stated: at or above one third of equivocating weight two certificates can coexist (reported, never resolved); a recovery lock's bound is the imbalance rule above, not one third; a loss of half or more of the last certified table has no in-protocol exit; an even split pauses until the heal; the first month; body availability and execution correctness (proven execution is not finality: the four interface words, included, executed, proven, finalised, are defined once in section 9 of the statement with where each interface shows them today).