Finality boundary: scenario N results (N1, N2, N3, N4, N6 on build-3), the Rule v4 section in sim/results_v2.md, the spec's test table and the recovery bound's dust clause; sim: att_both (the equivocator mining on both sides), N1b key fix, N2b
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
2f30d94791
commit
4782c1ab0a
3 changed files with 112 additions and 15 deletions
|
|
@ -69,9 +69,9 @@ The argument (derived). The floor and the anchored test need the stated fraction
|
|||
|
||||
| Cause of the pause | Lasts until | v4 recovery | v4 pause only (6.5) |
|
||||
|---|---|---|---|
|
||||
| A set of a third or more is silent but keeps mining (J, N3) | it signs again; first lock 0 minutes after, 0 conflicts | at day 30 of silence the signing majority (more than half of `T_f`) recovers (N3) | for as long as it is silent |
|
||||
| A set of a third or more is silent but keeps mining (J, N3) | it signs again; first lock 0 minutes after, 0 conflicts | one recovery lock at day 30 of silence by the signing majority, then the pause again on the re-anchored table (N3: one lock in 31 days) | for as long as it is silent |
|
||||
| A set leaves gradually while locks continue (M4's gradual case) | nothing: every certificate re-anchors the table and the leavers age out of both tables | same | same |
|
||||
| A set of a third or more stops mining and signing at once (M4, N6) | the survivors hold more than half of `T_f`: day 30 after the last certificate (N6, 35 percent); exactly half or more gone: never by rule (N6, 50 percent), only by succession, a strip or an operator's certificate (7) | day 30 (35 percent); never (50 percent) | never |
|
||||
| A set of a third or more stops mining and signing at once (M4, N6) | the survivors hold more than half of `T_f`: day 30 after the last certificate (N6, 35 percent: day 30.00); exactly half or more gone: never by rule, only by succession, a strip or an operator's certificate (7); at exactly half it is a knife edge (N6, 50 percent: one seed at day 30.23, the other never) | day 30 (35 percent); the knife edge (50 percent) | never |
|
||||
| An honest partition (N1, N2) | the heal: first lock 0 minutes after, 0 conflicts; or, at day 30, on the side that holds more than half of `T_f` (the 60 of 60/40), the other side never, 0 conflicts | day 30 on one side at most | the heal only |
|
||||
| Keys worth a third or more bought or stolen and withholding (K, N4) | day 30, the honest majority of `T_f` recovering; a stolen key's owner can strip it by self-equivocation the same day (N4) | day 30 | never for a purchase; the same day for a strip |
|
||||
| The first month (3.8) | the window is full (`min_daa`) | same | same |
|
||||
|
|
@ -93,7 +93,7 @@ Rule v4 replaces Q5's expiry with the following, active for checkpoints at or ab
|
|||
1. **The anchored table never expires by time.** `T_f` is the sliding table at `C_f`, the highest certified checkpoint on the selected chain of `C_i`, with the strips and successions known at `C_i` applied. It stands until a certificate that passes it replaces it. A certificate for `i` locks only if its signers hold at least two thirds of `T_f` at `T_f`'s weights, in addition to Q3, **for as long as `daa(C_i) < daa(C_f) + 2,592,000`** (one weight window, as under v3), and
|
||||
2. **The majority-continuity recovery.** Once `daa(C_i) >= daa(C_f) + 2,592,000` with no certificate formed between `C_f` and `C_i` on this chain, a certificate for `i` locks when its signers hold at least two thirds of the sliding table `T(i)` (Q3, both tests) AND **strictly more than half** of `T_f` at `T_f`'s weights (`2 x signed_f > total_f`), AND
|
||||
3. `C_f` is an ancestor of `C_i` on the selected chain (the certificate names a chain through the last certified history; a certificate for a chain that misses any lock the node holds is a conflict under 3.11.4, as before).
|
||||
4. A lock under item 2 is a **recovery lock**: it re-anchors `T_f` at `C_i` (so the next certificate needs two thirds again), it is carried, verified and followed exactly like any other certificate (C3, C4, F1, the certificate-driven reorg of 3.5), and the node reports `finality_reason` `recovered` with the index and the signed share of the old `T_f` for one window after it, then `active`.
|
||||
4. A lock under item 2 is a **recovery lock**: it re-anchors `T_f` at `C_i` (so the next certificate needs two thirds again; against a silent third that keeps mining this is one lock per window and not a resumption, N3, which is the rule's intent), it is carried, verified and followed exactly like any other certificate (C3, C4, F1, the certificate-driven reorg of 3.5), and the node reports `finality_reason` `recovered` with the index and the signed share of the old `T_f` for one window after it, then `active`.
|
||||
5. Before the first certificate of the chain there is no anchored table and Q3 alone decides (3.8's first-month rule applies).
|
||||
|
||||
In one sentence: the last certified table is the authority until a new certificate carries the consent of two thirds of it, or, after a full window of silence, of more than half of it; nothing else, and no clock, can replace it.
|
||||
|
|
@ -110,7 +110,7 @@ A recovery certificate is verifiable by anyone holding the chain, with no operat
|
|||
|
||||
### 6.5 The cost, stated, and the one-line alternative
|
||||
|
||||
The recovery certificate's safety bound is weaker than one third. Two conflicting recovery locks need a partition that has lasted a full window with no certificate on either side AND equivocating keys whose share of `T_f` exceeds the split's imbalance: each side of an `s / (1 - s)` split with an equivocator at `a` holds `(1 - a) / 2 + a` of `T_f` in the 50/50 case, more than half for any `a > 0`; in a 60/40 split the 40 side needs `a > 0.2` to reach half. Measured (N1b, N2): at 31 days a 50/50 split with a 10 or 20 percent equivocator conflicts under `v4 recovery` and never under `v4 pause`; the 40/40 split with a 20 percent equivocator reaching both sides (60/60 of `T_f`) the same. In every such case the equivocator is stripped at the heal (3.6), the history through `C_f` is untouched (item 3), and the pair is handled as 3.11.4 says. The one-third bound of section 4 is intact for every certificate formed within a window of the last one, which is every certificate of a connected network.
|
||||
The recovery certificate's safety bound is weaker than one third. Two conflicting recovery locks need a partition that has lasted a full window with no certificate on either side AND equivocating keys that (i) hold a share of `T_f` exceeding the split's imbalance and (ii) are still in BOTH sides' canonical voter lists at the recovery index, which means they mined at least dust (100 blue blocks in the window, W3) on each side: a certificate's bitmap is over the voter list at `C_i` (C3), so a key that mined on one side only is, after a full window, not a voter on the other side whatever its anchored weight. Each side of a 50/50 split with an equivocator at `a` that mines on both holds `(1 - a) / 2 + a` of `T_f`, more than half for any `a > 0`; in a 60/40 split the 40 side needs `a > 0.2`. Measured: an equivocator mining on one side only never produces a recovery conflict (N2, 40/40 with a 20 percent equivocator reaching both: one side recovers at day 30.00, the other never, 0 conflicts); one mining on both sides is N1b and N2b (the rows in `sim/results_v2.md`, "Rule v4"; pending at the 18:00 version, in the 20:00 version). In every such case the equivocator is stripped at the heal (3.6), the history through `C_f` is untouched (item 3), and the pair is handled as 3.11.4 says. The one-third bound of section 4 is intact for every certificate formed within a window of the last one, which is every certificate of a connected network.
|
||||
|
||||
The alternative the founder can choose by deleting item 2 is the **indefinite pause** (`v4 pause` in the simulator, `P.recovery = False`; in the node, the recovery test left out). Its guarantees are strictly stronger: no certificate ever forms with less than two thirds of the last certified table, so the one-third bound holds for every certificate for ever. Its costs, measured: one purchase of keys worth a third of a window is a permanent veto on finality (N4: never in 31 days, against day 30 with the recovery), a sudden honest loss of a third of weight (a pool folding with its keys) pauses finality permanently absent succession or an operator's trusted certificate (N6: never, against day 30), and a 60/40 partition that outlasts a window pauses the 60 side until the heal instead of recovering at day 30 (N1).
|
||||
|
||||
|
|
@ -187,13 +187,13 @@ Each claim, the scenario, the known-failed line first where there is one, and th
|
|||
|
||||
| Claim | Scenario | Known-failed line | Result |
|
||||
|---|---|---|---|
|
||||
| (a) The 31-day partition at the window: no conflicting locks under the chosen rule | N1: 50/50, 60/40, 55/45 for 31 days, v3 against v4 pause and v4 recovery | v3: both sides lock alone at day 30.00, 2,679 to 2,870 conflicts (M3, re-run in N1) | pending |
|
||||
| (a) The recovery bound | N1b: 50/50 for 31 days with a 10, 20, 34 percent equivocator | 34 percent: conflicts from minute 0 under every rule (the one-third bound) | pending |
|
||||
| (b) 40/40/20 under the active-set rules | N2: honest three-way for 150 minutes and 31 days; 40/40 with a 20 percent equivocator reaching both for 31 days | the 60/60 case under v4 recovery at day 30 (6.5) | pending |
|
||||
| (c) Signing stops while mining continues | N3: 34, 40, 45 percent for 24 h under v4 recovery; 34 percent for 31 days under both v4 | none expected (as J) | pending |
|
||||
| (d) Old keys compromised against fresh hashrate | N4: keys worth 40 percent withhold, holder at 30 percent of hashrate, 31 days, v2, v3, v4 pause, v4 recovery; the self-strip on day 1 | v4 pause: never (the permanent veto, 6.5) | pending |
|
||||
| (a) The 31-day partition at the window: no conflicting locks under the chosen rule | N1: 50/50, 60/40, 55/45 for 31 days, v3 against v4 pause and v4 recovery | v3: both sides lock alone at day 30.00, 2,679 to 2,870 conflicts (M3, re-run in N1, reproduced to the checkpoint) | **measured**: v4 pause: no side locks in 31 days, 0 conflicts, every pre-heal lock kept, first lock 0 minutes after the heal, 0 post-heal stalls, every split; v4 recovery: 50/50 the same; 60/40 and 55/45 the larger side recovery-locks once at day 30.00 and then locks normally, the smaller side never, 0 conflicts, kept, heal 0 minutes |
|
||||
| (a) The recovery bound | N1b: 50/50 for 31 days with a 10, 20, 34 percent equivocator, mining on one side and on both | 34 percent: conflicts from minute 0 under every rule (the one-third bound; the quick run: 4,418 to 4,586 conflicts in 2 days) | pending (the rerun queued at 16:12 UK on build-3; the first run did not execute, a scenario-name case bug fixed in the rerun) |
|
||||
| (b) 40/40/20 under the active-set rules | N2: honest three-way for 150 minutes and 31 days; 40/40 with a 20 percent equivocator reaching both for 31 days; N2b the same equivocator mining on both sides | the 60/60 case with the equivocator mining on both sides under v4 recovery at day 30 (6.5) | **measured** (N2): honest three-way: no side locks for 150 minutes or 31 days under either v4, 0 conflicts, kept, heal 0 minutes; 60/60 with the equivocator mining on one side: v4 pause never, v4 recovery one side at day 30.00, the other never, 0 conflicts; N2b pending (queued 16:12 UK) |
|
||||
| (c) Signing stops while mining continues | N3: 34, 40, 45 percent for 24 h under v4 recovery; 34 percent for 31 days under both v4 | none expected (as J) | **measured**: 24 h: every checkpoint stalled (2,880 to 2,889), longest gap 1,440 minutes, first lock 0 minutes after the resume, 0 post-resume stalls, 0 conflicts, 0 recovery locks; 31 days at 34 percent: v4 pause no lock, v4 recovery one recovery lock at day 30 then the pause again, 0 conflicts |
|
||||
| (d) Old keys compromised against fresh hashrate | N4: keys worth 40 percent withhold, holder at 30 percent of hashrate, 31 days, v2, v3, v4 pause, v4 recovery; the self-strip on day 1 | v4 pause: never (the permanent veto, 6.5) | **measured**: first lock v2 day 20.9, v3 day 30.00, v4 pause never in 31 days (89,262 to 89,373 stalled), v4 recovery day 30.00 (one recovery lock); the holder's share decays to 0.300 under every rule; self-strip: the first lock on day 0 (571 to 736 stalled checkpoints before the evidence is carried), 0 conflicts |
|
||||
| (e) Finality paused across an epoch boundary: seeds advance, mining continues, certified history intact | derived from N1 and N3: blocks and checkpoints continue through the pause (every stalled checkpoint in the tables is a block the chain mined), 744 hourly boundaries in a 31-day pause, each seeded by its reference block (8); the fast-time harness row (11) | none | derived; harness run owed |
|
||||
| (f) The heal: a deterministic path that never reverses a lock | N1, N2: every pre-heal lock kept, first lock after the heal, post-heal stalls; the certificate-driven reorg (3.11.7, `c4.mjs`) | none | pending |
|
||||
| (f) The heal: a deterministic path that never reverses a lock | N1, N2, N6: every pre-heal lock kept, first lock after the heal, post-heal stalls; the certificate-driven reorg (3.11.7, `c4.mjs`) | none | **measured**: every pre-heal lock kept in every row of N1 and N2 (24 runs), first lock 0 minutes after every heal, 0 post-heal stalls, 0 conflicts under both v4 rules; a sudden departure of 35 percent: v3 and v4 recovery lock at day 30.00, v4 pause never (N6); at 50 percent the recovery is a knife edge (one seed day 30.23, one never) |
|
||||
| The epoch 20 template fault (today's fault 6) | the node lane's fast-time gate: every epoch boundary a template test; the release-rules record | a header refused for missing state counted as a PoW strike | node lane's regression, outside this lane's harness time (11) |
|
||||
| The cold-start deadlock (today's fault 7) | the node lane's kept-datadir gate on a chain paused over ten minutes | the sink-age guard on a node holding the chain | node lane's regression (11) |
|
||||
|
||||
|
|
|
|||
|
|
@ -97,6 +97,8 @@ class P:
|
|||
# after its checkpoint, after which the sliding table alone applies (as today)
|
||||
self.anchored = False # True: rule v4 (8 Oct 2026, the finality boundary lane): the frozen table is ANCHORED, never expiring by
|
||||
# time; it is replaced only by a certificate that passes it. Without P.recovery this is the indefinite pause.
|
||||
self.att_both = False # True: an equivocating key mines on EVERY side of a partition (its hashrate split by the draw), so it stays above
|
||||
# dust in every side's sliding table and remains a voter on both; False: it mines on the first side only (as H, I, M5)
|
||||
self.recovery = False # True (with anchored): the majority-continuity recovery: once the anchored table's checkpoint is one window
|
||||
# old with no certificate since, a certificate locks when its signers hold 2/3 of the sliding table (Q3) AND
|
||||
# MORE THAN HALF of the anchored table at its weights; the lock re-anchors the table. Recorded as a recovery lock.
|
||||
|
|
@ -230,6 +232,8 @@ class Sim:
|
|||
def _set_masks(self, v):
|
||||
v.key_mask = np.isin(self.region, v.regions)
|
||||
v.mine_mask = v.key_mask.copy()
|
||||
if self.p.att_both:
|
||||
v.mine_mask |= self.equiv
|
||||
|
||||
# ------------------------------------------------------------- partitions
|
||||
def split(self, groups):
|
||||
|
|
@ -301,6 +305,8 @@ class Sim:
|
|||
side_tot = self.hash[v.mine_mask].sum()
|
||||
if side_tot > 0:
|
||||
blocks[v.mine_mask] = self.rng.poisson(BLOCKS_PER_CP * self.hash[v.mine_mask] / side_tot)
|
||||
# att_both: the equivocator's draw lands once (the last side's), seen by every side it mines on; its sliding weight is
|
||||
# therefore one side's draw, about its full share, which overstates it there but is immaterial to the anchored test
|
||||
else:
|
||||
blocks = self.rng.poisson(BLOCKS_PER_CP * self.hash / tot) if tot > 0 else np.zeros(self.N)
|
||||
hp = (slot // SLOTS_PER_HOUR) % WINDOW_HOURS
|
||||
|
|
@ -1591,10 +1597,10 @@ def _days(xs):
|
|||
return "never" if all(x is None for x in xs) else span((x for x in xs if x is not None), "%.2f")
|
||||
|
||||
|
||||
def _part_rows(seeds, delay, name, fr, att, dur_min, rules=RULES_N, post_min=180):
|
||||
def _part_rows(seeds, delay, name, fr, att, dur_min, rules=RULES_N, post_min=180, **pkw):
|
||||
rows = []
|
||||
for lab, mk in rules:
|
||||
rs = [run_partition2(sd, fr, att, dur_min, mk(delay), pre_min=60, post_min=post_min) for sd in seeds]
|
||||
rs = [run_partition2(sd, fr, att, dur_min, mk(delay, **pkw), pre_min=60, post_min=post_min) for sd in seeds]
|
||||
n = len(fr)
|
||||
fl = [[None if r["side_first_lock"][i] is None else r["side_first_lock"][i] / 1440.0 for r in rs] for i in range(n)]
|
||||
rows.append([name, pct(att, 0) if att else "none", dur_min / 1440.0 if dur_min >= 1440 else "%d min" % dur_min, lab,
|
||||
|
|
@ -1640,9 +1646,26 @@ def scenario_n1b(args):
|
|||
"this is the recovery rule's bound, stated in the specification (the equivocator must outweigh the split's imbalance, 0 at 50/50). "
|
||||
"At a = 34% both sides hold 67% and lock from minute 0 under every rule (the one-third bound, unchanged).")
|
||||
out.append("")
|
||||
out.append("Two rows per share: the equivocator mines on the first side only (as H, I and M5; after a window it is under dust on the other side's "
|
||||
"sliding table and so not in that side's voter list, C3's canonical list at C_i), and the equivocator mines on BOTH sides (att_both: 100 blocks "
|
||||
"a month on each keeps it in both lists). The bound is the second row.")
|
||||
out.append("")
|
||||
rows = []
|
||||
for a in (0.10, 0.20, 0.34):
|
||||
rows += _part_rows(seeds, args.delay, "50/50", [0.5, 0.5], a, days * 1440, rules=RULES_N[1:])
|
||||
rows += _part_rows(seeds, args.delay, "50/50, equivocator on side 1 only", [0.5, 0.5], a, days * 1440, rules=RULES_N[1:])
|
||||
rows += _part_rows(seeds, args.delay, "50/50, equivocator mining on both sides", [0.5, 0.5], a, days * 1440, rules=RULES_N[1:], att_both=True)
|
||||
out.append(md_table(PART_HDR, rows))
|
||||
return "\n".join(out)
|
||||
|
||||
|
||||
def scenario_n2b(args):
|
||||
"""(b, continued) 40/40 with a 20 percent equivocator mining on both sides."""
|
||||
seeds = seeds_of(args)[:2]
|
||||
q = getattr(args, "quick", False)
|
||||
days = 2 if q else 31
|
||||
out = ["### N2b. The 40/40 split with a 20%% equivocator reaching and MINING on both sides (60/60 of the anchored table), %d days; seeds %s" % (days, ",".join(str(s) for s in seeds)), ""]
|
||||
rows = []
|
||||
rows += _part_rows(seeds, args.delay, "40/40 + 20% equivocator on both sides", [0.4, 0.4], 0.20, days * 1440, rules=RULES_N[1:], att_both=True)
|
||||
out.append(md_table(PART_HDR, rows))
|
||||
return "\n".join(out)
|
||||
|
||||
|
|
@ -1736,12 +1759,12 @@ def scenario_n6(args):
|
|||
|
||||
|
||||
def scenario_n(args):
|
||||
return "\n\n".join(f(args) for f in (scenario_n1, scenario_n1b, scenario_n2, scenario_n3, scenario_n4, scenario_n6))
|
||||
return "\n\n".join(f(args) for f in (scenario_n1, scenario_n1b, scenario_n2, scenario_n2b, scenario_n3, scenario_n4, scenario_n6))
|
||||
|
||||
|
||||
SCENARIOS = {"A": scenario_a, "B": scenario_b, "C": scenario_c, "D": scenario_d, "E": scenario_e, "F": scenario_f, "G": scenario_g,
|
||||
"H": scenario_h, "I": scenario_i, "J": scenario_j, "K": scenario_k, "L": scenario_l, "M": scenario_m,
|
||||
"N": scenario_n, "N1": scenario_n1, "N1b": scenario_n1b, "N2": scenario_n2, "N3": scenario_n3, "N4": scenario_n4, "N6": scenario_n6}
|
||||
"N": scenario_n, "N1": scenario_n1, "N1B": scenario_n1b, "N2": scenario_n2, "N2B": scenario_n2b, "N3": scenario_n3, "N4": scenario_n4, "N6": scenario_n6}
|
||||
|
||||
|
||||
def main(argv=None):
|
||||
|
|
|
|||
|
|
@ -678,3 +678,77 @@ M5. The equivocator across a 50/50 split (as H), v3: each side holds (1 - a)/2 +
|
|||
| 33% | 66.5% | 0 | never | never / never |
|
||||
| 34% | 67.0% | 21 to 69 | 14 to 78 | 12 to 50 / 0 to 77 |
|
||||
|
||||
## Rule v4, 8 October 2026: the anchored table and the majority-continuity recovery (the finality boundary lane, `docs/spec/finality-guarantees.md`)
|
||||
|
||||
The external review of 8 October 2026 (accepted by the founder at 16:1x UK) found the fault in M3: rule v3's frozen table expires one window after its checkpoint, a timeout, and a timeout alone cannot tell a node whether missing miners are gone or on the other side of a partition. Rule v4 anchors the table (it never expires by time; `P.anchored`, `+anchored`) and, with `P.recovery` (`+recovery`), adds the one resumption that is not a timeout: once the anchored checkpoint is a full window old with no certificate since, a certificate locks when its signers hold two thirds of the sliding table (Q3) AND strictly more than half of the anchored table at its weights, on the chain through the anchored checkpoint; the lock re-anchors the table and is counted as a recovery lock. `rule_v4()` and `rule_v4r()`; scenario N (`--scenarios N --seeds 7,11`, the six parts in parallel on 8 cores of igneum-build-3 under the lease tool at nice 19, 16:02 to 16:09 UK; the known-failed v3 rows reproduce M3 to the checkpoint). What it changes, measured:
|
||||
|
||||
- N1: v3 locks both sides of every 31-day split under two thirds alone at day 30.00 (2,679 to 2,870 conflicting locks, the fault). v4 pause: no side locks, 0 conflicts, the heal locks 0 minutes after. v4 recovery: the side holding more than half of the anchored table (the 60 of 60/40, the 55 of 55/45) recovery-locks once at day 30.00 and then locks normally on its re-anchored table; the other side never; the 50/50 split stays paused on both sides; 0 conflicts; every pre-heal lock kept.
|
||||
- N2: the honest 40/40/20 split pauses on all three sides for 150 minutes and for 31 days under both v4 rules, 0 conflicts, the heal locks at once. With a 20 percent equivocator reaching both 40 sides (60/60 of the anchored table) only the side the equivocator MINES on recovers at day 30: after a window the equivocator is under dust on the other side's sliding table and so not in that side's canonical voter list (C3) at all, whatever its anchored weight. N1b and N2b (below, the equivocator mining on both sides, `P.att_both`) carry the bound: 100 blocks a month on each side keeps it in both lists.
|
||||
- N3: a silent set that keeps mining pauses finality for as long as it is silent under v4 as under v2 and v3 (24 h at 34, 40, 45 percent: every checkpoint stalled, first lock 0 minutes after the resume, 0 conflicts). At 31 days of silence v4 pause never locks; v4 recovery locks ONCE at day 30 (the signing 66 percent being more than half of the anchored table) and then pauses again, because the re-anchored table holds the silent third as the old one did: the recovery is one lock per window against a silent-but-mining third, not a resumption, which is the rule's intent (silence pauses finality).
|
||||
- N4: keys worth 40 percent withhold while their holder mines at 30 percent: v2 resumes at day 20.9 (the bought weight below a third of the sliding table), v3 at day 30.00 (the frozen table's expiry), v4 pause NEVER (one purchase is a permanent veto: the cost of the pause-only variant), v4 recovery at day 30.00. Compromised keys whose owners strip them by self-equivocation on day 1: the first lock the same day under v4 pause (571 to 736 stalled checkpoints, the first day).
|
||||
- N6: 35 percent departing at once: v3 day 30.00, v4 pause never in 31 days, v4 recovery day 30.00. 50 percent departing: v4 recovery is a knife edge at exactly half (the simulated set is 49.x to 50.x percent of weight): one seed recovered at day 30.23, the other never; v4 pause never.
|
||||
|
||||
### N1. The 31-day partition at the frozen table's expiry (the documented case, results M3), under v3 (known-failed), v4 pause (the anchored table) and v4 recovery (the majority-continuity test); seeds 7,11, 31-day partitions, each side retargets and counts only its own blocks
|
||||
|
||||
Prediction. v3: both sides of every split under two thirds lock alone at day 30.00 when the frozen table expires, and the heal leaves conflicting locks (the fault). v4 pause: no side locks, ever; 0 conflicts; the heal locks within minutes. v4 recovery: at day 30 a side holding MORE THAN HALF of the anchored table locks alone (the 60 of 60/40, the 55 of 55/45), the other never; the 50/50 split stays paused; 0 conflicts with no equivocator; every pre-heal lock kept.
|
||||
|
||||
| split | equivocator (of total) | partition days | rule | first lock per side, day | recovery locks per side | conflicting locks | first conflict | every pre-heal lock kept | first lock after heal, min | stalls in 3 h after heal |
|
||||
|---|---|---|---|---|---|---|---|---|---|---|
|
||||
| 50/50 | none | 31.0 | v3 | 30.00 / 30.00 | 0 / 0 | 2679 to 2701 | 30.03 to 30.06 d | yes | 0 | 0 |
|
||||
| 50/50 | none | 31.0 | v4 pause | never / never | 0 / 0 | 0 | never | yes | 0 | 0 |
|
||||
| 50/50 | none | 31.0 | v4 recovery | never / never | 0 / 0 | 0 | never | yes | 0 | 0 |
|
||||
| 60/40 | none | 31.0 | v3 | 30.00 / 30.00 | 0 / 0 | 2822 to 2870 | 30.00 to 30.02 d | yes | 0 | 0 |
|
||||
| 60/40 | none | 31.0 | v4 pause | never / never | 0 / 0 | 0 | never | yes | 0 | 0 |
|
||||
| 60/40 | none | 31.0 | v4 recovery | 30.00 / never | 1 / 0 | 0 | never | yes | 0 | 0 |
|
||||
| 55/45 | none | 31.0 | v3 | 30.00 / 30.00 | 0 / 0 | 2795 to 2820 | 30.02 to 30.03 d | yes | 0 to 0 | 0 |
|
||||
| 55/45 | none | 31.0 | v4 pause | never / never | 0 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
| 55/45 | none | 31.0 | v4 recovery | 30.00 / never | 1 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
|
||||
### N2. The 40/40/20 split under the active-set rules (Q1 to Q3 with the floor at two thirds, Q5 anchored), 150 minutes and 31 days; seeds 7,11
|
||||
|
||||
Prediction. Honest three-way: no side holds two thirds of anything, so finality pauses on all three; at day 30 no side holds more than half of the anchored table (40/40/20), so v4 recovery stays paused too; the heal locks at once with 0 conflicts. Two honest 40 sides with a 20% equivocator reaching both (60/60 of the anchored table): no lock for 30 days under either v4; at day 30 both sides pass the recovery majority, the known bound of N1b.
|
||||
|
||||
| split | equivocator (of total) | partition days | rule | first lock per side, day | recovery locks per side | conflicting locks | first conflict | every pre-heal lock kept | first lock after heal, min | stalls in 3 h after heal |
|
||||
|---|---|---|---|---|---|---|---|---|---|---|
|
||||
| 40/40/20 honest | none | 150 min | v4 recovery | never / never / never | 0 / 0 / 0 | 0 | never | yes | 0 | 0 |
|
||||
| 40/40/20 honest | none | 31.0 | v4 pause | never / never / never | 0 / 0 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
| 40/40/20 honest | none | 31.0 | v4 recovery | never / never / never | 0 / 0 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
| 40/40 + 20% equivocator on both (60/60) | 20% | 31.0 | v4 pause | never / never | 0 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
| 40/40 + 20% equivocator on both (60/60) | 20% | 31.0 | v4 recovery | 30.00 / never | 1 / 0 | 0 | never | yes | 0 to 0 | 0 |
|
||||
|
||||
### N3. Signing stops while mining continues (as J), under rule v4; seeds 7,11
|
||||
|
||||
Prediction. A silent set that keeps mining stays in the sliding table and in the anchored table, so finality pauses for as long as it is silent and the first lock comes 0 minutes after it resumes, 0 conflicts (as J). At 31 days of silence the anchored table is a window old: v4 pause stays paused (the silent 34% holds a third of it); v4 recovery locks at day 30 on the signing 66%, more than half of the anchored table.
|
||||
|
||||
| silent weight | rule | silent hours | first lock after the stop, min | stalled checkpoints while silent | longest gap without a lock, min | first lock after resume, min | stalls after resume | recovery locks | conflicting locks |
|
||||
|---|---|---|---|---|---|---|---|---|---|
|
||||
| 34% | v4 recovery | 24 | never | 2880 to 2889 | 1440 | 0 | 0 | 0 | 0 |
|
||||
| 40% | v4 recovery | 24 | never | 2880 to 2889 | 1440 | 0 | 0 | 0 | 0 |
|
||||
| 45% | v4 recovery | 24 | never | 2880 to 2889 | 1440 | 0 | 0 | 0 | 0 |
|
||||
| 34% | v4 pause | 744 | never | 89286 to 89318 | 44640 | 0 | 0 | 0 | 0 |
|
||||
| 34% | v4 recovery | 744 | never | 89286 to 89318 | 44640 | 0 | 0 | 1 | 0 |
|
||||
|
||||
### N4. Old voting keys against fresh hashrate (as K): keys worth 40% of the window withhold their votes while the holder mines at 30% of the network, 31 days; seeds 7,11
|
||||
|
||||
Prediction. v2: the pause ends when the bought weight has decayed below a third of the sliding table (day 19 to 20). v3: the frozen table holds the keys at 40% until it expires, day 30. v4 pause: the anchored table holds them for ever: a permanent veto for one purchase (the cost stated in the specification). v4 recovery: day 30, the honest 60% being more than half of the anchored table and the honest 70% of hashrate two thirds of the sliding one. Self-strip: a COMPROMISED key's owner equivocates with it on day 1; the evidence strips it from every table and finality resumes that day.
|
||||
|
||||
| rule | the keys | first lock after the purchase, day | stalled checkpoints | recovery locks | holder's share at the end | conflicting locks |
|
||||
|---|---|---|---|---|---|---|
|
||||
| v2 | withhold | 20.92 to 20.97 | 64957 to 66272 | 0 | 0.300 to 0.300 | 0 |
|
||||
| v3 | withhold | 30.00 to 30.00 | 86416 to 86572 | 0 | 0.300 to 0.300 | 0 |
|
||||
| v4 pause | withhold | never | 89262 to 89373 | 0 | 0.300 to 0.300 | 0 |
|
||||
| v4 recovery | withhold | 30.00 to 30.00 | 86416 to 86572 | 1 | 0.300 to 0.300 | 0 |
|
||||
| v4 pause | withhold, owners self-strip on day 1 | 0.00 | 571 to 736 | 0 | 0.300 to 0.300 | 0 |
|
||||
|
||||
### N6. A set holding x of weight stops mining and signing at once (as M4), 31 days; seeds 7,11
|
||||
|
||||
Prediction. v3: the survivors lock when the frozen table expires, day 30. v4 pause: never (the departed weight is anchored; only succession, a strip or the heal moves it). v4 recovery: day 30 for 35% departed (the survivors hold 65% of the anchored table, more than half) and NEVER for 50% departed (exactly half is not more than half): the recovery rule's own limit.
|
||||
|
||||
| departed weight | rule | days run | first lock after the event, day | stalled checkpoints | recovery locks | conflicting locks |
|
||||
|---|---|---|---|---|---|---|
|
||||
| 35% | v3 | 31 | 30.00 | 86386 to 86511 | 0 | 0 |
|
||||
| 35% | v4 pause | 31 | never in 31 days | 89272 to 89401 | 0 | 0 |
|
||||
| 35% | v4 recovery | 31 | 30.00 | 86386 to 86511 | 1 | 0 |
|
||||
| 50% | v3 | 31 | 30.00 | 86404 to 86514 | 0 | 0 |
|
||||
| 50% | v4 pause | 31 | never in 31 days | 89287 to 89389 | 0 | 0 |
|
||||
| 50% | v4 recovery | 31 | 30.23 | 87056 to 89389 | 0 to 1 | 0 |
|
||||
|
|
|
|||
Loading…
Reference in a new issue