diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index f69f289ed..6aa40c8b2 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -423,7 +423,7 @@ Every failing seed is ONE low-entropy load site; the mechanism is lineage-blind Known-failed test class_v4_distinct_ratio_rejects_the_low_entropy_band green on box 2 (12.95 s): p15 attempt 3 (52638ea2e8b0fd68) site 2 at 0.943; p18 attempt 2 (9a37e9489d8ba698) site 6 at 0.927; p19 attempt 0 (79d7441de0689223) site 15 at 0.933; p56 attempt 2 (486a8ad2701ec3b5) site 2 at 0.965; p23 attempt 1 (d65122675f16a1c7) draws site 7 from r5 and passes, and with r6 put back is refused by (a') UnfreshLoadSource and, run anyway, by the ratio at 0.836. Stream unchanged from ddacfbd3 (re-export diff 0 on all eight packs): id a785001687d8688a, the seven fingerprints and the packs zip sha256 4f2445c5... as recorded. THE SUITE AT 017e7037 on box 2: 103 of 103 (64 lib + 7 derive + 4 mixer + 19 packs + 2 recheck + 7 scratch, 3 diag ignored), rc 0; the lib tests 140.8 s against the 41 s whole-suite line at ddacfbd3, because every class v4 draw in the tests pays the 2^20 ratio pass on its chosen candidate (2.2 s each): a CI-time cost, not a node cost (one pass per epoch draw). CI run 37639406567 on 017e7037 success. THE CENSUS AT 017e7037 (box 2, 4,096 chain-shaped seeds plus F8's p1 to p3, draws in parallel across the cores; tools/ca3-v4-uniform now draws across available_parallelism since the serial run became a four-hour job): 4,099 programs, 0 lossy-sourced load sites of 65,584 (57,322 injecting, 8,262 bijective), 0 exhaustions; attempt histogram 0:1297 1:899 2:609 3:416 4:298 5:197 6:125 7:92 8:54 9:46 10:21 11:14 12:13 13:9 14:6 16:2 17:1, mean 2.086, max 17 (ddacfbd3 read 1328/917/622/409/284..., mean 1.998, max 17): the ratio refuses about 4 percent of candidates that pass every other test, one extra attempt on about one seed in twelve, the worst case unchanged at 17; devnet epoch-0 at attempt 1, id a785001687d8688a; F8's p2 attempt 5, p3 attempt 1. The attack-pass lane's class check: ddacfbd3's shadow-executed verdicts against 8bdcbdd8 on 598,678 chain-shaped seeds move 11,990 (2.0 percent) to a different attempt, 0 exhausted, max 32; on 017e7037 the pairing holds and the 64-seed gate at 2^24 plus the 10^6 exhaustion count run to about 16:05Z. The hash lane's ledger lines 2a111fb1 on origin and build (the GitHub 500s cleared on their own), CI run 37642582140 success at 15:25Z; the hash lane has nothing in flight. Nothing on the hash side stops a cut of sub-version 3 at 017e7037 for 0.3.22; then the attack-pass lane's 64-seed gate at 2^24 and 10^6 exhaustion count. Owed as before: G2, G3, the ladder re-measure, AMD (PC 1), the 2019-class core, the fleet and PC 2 G1 on the sub-version 3 packs (a re-run of a known result). release-0.3.21-node STAGED (the node lane, 16:0xZ): 96161037 on the mirror, at the shipper's sweep-end word, in the final order on 55768f88 (c631c64b, 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1 cherry-picked, a6864e36 and d8bceca5), pairing igneum-pow 8c728ca3 at byte 5, no re-pin. The whole set on the tip green: consensus-core 126, the consensus crate whole (lib 120, both integration targets), igneum-miner 25, kaspa-pow 17, igneum-exec 36, the three checks, 15:49 to 15:57Z on build-2. Binary built on build-1 at 15:58Z, igneumd sha256 f99340b3cf4ce32e, the string read back; the digest eada4bda on the previous live object and 4bbbe816 on the published floor file (so the 0.3.20 floor file is published), as the pin reads them. The node lane's digest and mixed-version gates on it from 16:00Z; the fleet's set from the same minute; plan 6.9 carries the steps and the two box-input rules the staging added. THE 0.3.20 RECORD (the shipper, UTC). Cases: the dc141409 run on c18-1 CASES END rc 0 at 12:37:18Z (both halves PASS); the c4459193 run on c20-1 CASES END rc 0 at 14:54:02Z with its relay half void (one RunPod host, no hairpin) and the poison half PASS (13 rejected, 0 accepted); main's (b): the publish on the dc141409 cases plus the diff argument (the class byte the only touch in the cases' territory) and c19-1's tip-following, with the separate-host relay re-run on c19-1 on the live digest as the halt condition and the Discord card's gate (CASES END about 16:25Z). PUBLISH 14:54:17Z (15:54 BST): manifest 0.3.20, mac DMG sha256 73796c5f..., Windows installer 45b2f3fb..., the hive tar d9dd12df... on the public alias. THE FLOOR FILE: program_class_v4_activation_daa 900,000 (the live DAA 294,073 at 14:51Z; 294,073 + 604,800 = 898,873 rounded up to the 3,600 boundary), window 86,400 unchanged, file sha256 294f1f80...; the digest 4bbbe8162ea9fff277aa5b16b4ffad9e2262ba5e6a5acac7b697ff77211e7328 read on c4459193's binary before the cut and on the hub's handshake line after. The pin c4459193, igneum-pow 8c728ca3, byte 5; the sweep's node pair a80ed39c / 70a5180f (the build-server lane's native build of the same tree). THE SWEEP complete 15:39Z (16:39 BST): wave 1 the hands (observer-node, node1 at 14:57Z), the Mac (15:23Z on its poller, interface 1.0.1), the hub, pool-1 and the eight heaviest voters (15:04 to 15:21Z); wave 2 the four lighter voters (15:23 to 15:26Z); wave 3 Devnet 2's four pods and bps-seed (digest 4a0b8726 unmoved); the first new-side lock 9313 at 15:28:08Z after a 23-minute split; every lock line "sweep complete before 13 October 09:00 UK (the margin; the floor is now DAA 900,000)". 0.3.17 nodes remaining: PC 1 and PC 2 (offline for the project lead's cable work; their apps update on their pollers on return) and the three testnet seeds (on the testnet, not on the devnet's floor); no devnet node of the fleet, the hands or the Mac on 0.3.17. EARLIEST FLIP: the floor at DAA 900,000 is about 7.0 days of DAA from the publish (605,927 DAA at about one a second), so about 14 October 23:00Z (15 October 00:00 BST) at the earliest, and only once the seven 86,400-DAA windows read 95 percent of blue weight signalling byte 5; the live floor of 831,600 (13 Oct 08:00Z) is replaced by the published file on every swept node, so the chain never flips to the 6 October stream. Per tier: a solo miner on the Mac or a swept box mines on; a PC miner on 0.3.17 is refused by digest when it next connects until its app updates (its poller does this on return; nothing by hand); the pool and the hub are on the pin; the auditor reads one object, one digest, one floor. -SUB-VERSION 3 PASSES BOTH GATES (the attack-pass lane, the close line dated 7 October 2026): class v4 sub-version 3, commit 017e70376489251e18564c0abce7e466e606c8b3 on ca3-v4-amend, pairing id a785001687d8688a (verified by the harness). F8's 64-seed census (p2 to p65) at 2^24 nonces each, chain path, window-model control, box 2, 14:51Z to 16:00:20Z: PASS, 60 of 64 under 1.2x (0.9915x to 1.144x); the only four over are the named tail, unattributed and chased: p10 1.5036x (identical to sub-versions 1 and 2, hottest item 0x4004da at 362 reads, no predicted source), p8 1.3776x (0x837de4, 420 reads), p34 1.2505x (0x800010, 541 reads, the one-bit value through sub at 5), p4 1.2167x (0x4000e7, 355 reads); every strong seed gone (p23 4.82x, p19 3.32x, p15 2.57x, p18 2.50x, p56 2.01x all under 1.2x); the worst ratio on the stream 1.50x; the tail's hottest items carry 355 to 541 reads of 2^31 (one to two per 2^22 items above the mean), no chip consequence. The exhaustion gate as it is: the chain-path count on 017e7037 runs slowly (the draw evaluates (c'') at 2^20 per candidate: 20,532 seeds in 59 minutes, 0 exhausted, 0 panics, max attempt 29), so a 10^6 count is two days away and is not waited on; the substance is met by construction (the 256 cap and the last resort unchanged from 8bdcbdd8, 0 of 10^6 there) and by measurement at 017e7037 on 24,631 seeds (0 exhausted, max 29; r about 0.68); the count runs on as a strengthening line. The node's epoch draw now costs about 2 attempts at 2.2 s each, 4 to 5 s per epoch on slower cores, once an hour. The hash lane's ledger at 6941da1d. SUB-VERSION 3 AT 017e7037 IS THE FROZEN GENERATOR FOR 0.3.22 (byte 7), THE TAIL RULED (main, 18:1x UK): the four seeds (p10 1.5036x with its hottest item at 362 reads, p8 1.3776x at 420, p34 1.2505x at 541, p4 1.2167x at 355, of 2^31 reads) are accepted as the window model's unattributed residue at 1.22x to 1.50x with nil chip consequence; the AP-F8-1 row CLOSES with that wording and the hottest-item counts beside it; the 10^6 count on 017e7037 runs on as the strengthening line. The attack-pass plan's start 15 October or the morning after. 0.3.21's FIRST CANDIDATE 96161037 (sha256 f99340b3cf4ce32e, string read back) passed the node lane's two gates on its own binary: the digest gate 15:59:54Z to 16:01:32Z PASS (a89be8a7 with the peers right; db9a85f9 refused, no peer); the mixed-version gate 16:01:53Z to 16:12:05Z PASS (one digest b0afb2ee on five; 252 new and 352 old accepted, 0 rejected; counts equal at 316, 493 and 604 through both clean joins and the restart step; no panic); the node side complete; the fleet's set on the same binary (the kept start with the ids gate, the wipe canary, the cases rerun, the 12 GB line, N15's restarts of p1-5090 and p2-3090-3) is what the shipper's pin word waits on; byte 5 throughout, nothing on the class v4 seam moved. DEVNET 3 NOW (the project lead through main, 17:3x BST): 0.3.22 is the Devnet 3 release (a fresh network object igneum-devnet-3 with every activation at 0 and no override file, the era VDF fork, class v4 sub-version 3 at byte 7 from genesis), the node building on build-1, genesis by 17:30Z (18:30 BST). THE HANDOFF (17:3x BST, inside the 17:40 BST line, to the shipper and the node lane): igneum-pow 017e70376489251e18564c0abce7e466e606c8b3 (the audit-freeze-2026-10-07 tag; 2a111fb1 and 6941da1d above it docs only), object byte 7, PROGRAM_SUBVERSION_V4 = 3, devnet epoch-0 program id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3), kit packs-ca3-v4-sub3 zip sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154, the eight fingerprints as recorded (equal on Metal, Apple OpenCL, the fleet 5090 and PC 2's 5090), both attack-pass gates GREEN, suite 103 of 103, CI success; the open items stated as open: the four-seed tail under main's ruling (the attribution for 0.3.23), the 10^6 count as a strengthening line, the 4 to 5 s epoch draw, the owed measurements that do not gate Devnet 3. NO FURTHER HASH CHANGE RIDES ON 0.3.22; anything from the tail goes to 0.3.23. The node lane stages the re-pin on the 0.3.21 tip as its own commit (the fork commit and the kaspa-pow suite line owed to this record); the hash lane's sub-version 3 pairing follows it. THE PUBLIC CHIP TEXT REWRITTEN LAUNCH-FIRST (the project lead: "I thought we were making it 2.1 from launch?"; master 9b996d06, docs/plans/counter-asic-3-public-text-2026-10-07.md): the testnet and mainnet objects set program_class_v4_activation_daa 0, so class v4 is live from genesis and the launch number is 2.1x to 3.9x on day one; the three texts and evidence row 17 lead with that (labels kept), then class v5, then the 5x to 9x only as the class v3 baseline the work started from, the devnet's activation height a devnet fact only; no em dashes, no prize mention, eight columns; with the site lane to apply in the same deploy as the padding sweep (its commit and deploy time owed to this record). STOP-THE-LINE ON MASTER's POW SUITE (main through the CI steward, 18:4x BST): red since 16:31 BST (runs a4eaf76 and 1210158d; program_ids_differ_between_class_v3_and_class_v4_of_one_seed and cpu_recheck_equals_the_worker_reference_for_class_v3_and_class_v4 fail on packs-ca3-v4/v4-devnet-epoch0) because era-vdf's merge 0e2d6b1c put the sub-version 1 line's generator on master against tests/recheck.rs's pins, never CI-run. Ruling: the hash lane merges ca3-v4-amend's tip 6941da1d to master through merge-to-master.sh within 15 minutes, provided its epoch-0 id equals the frozen object's; the coordinator verified the condition (6941da1d's igneum-pow byte-identical to 017e7037; recheck pins 0xa785_0016_87d8_688a with the three must-differ ids; PROGRAM_SUBVERSION_V4 = 3), so no revert; master is the 0.3.23 line after this, 0.3.22 keeps its pin at 017e7037. EXECUTED: ca3-v4-amend on master as merge cf7d6ccb (pushed 16:45:48Z through merge-to-master.sh, try 1; the branch gate GREEN, 55 checks in 317 s on 874e945d; master ac8ed2f1 merged into the branch first with docs/fud-ledger.md keeping both sides and igneum-pow taken wholesale from 6941da1d, byte-identical to 017e7037); master's CI run 37654633279 on cf7d6ccb in progress from 16:46:10Z, the pow job's conclusion owed. Master's igneum-pow is now the frozen sub-version 3 generator. THE 0.3.22 RE-PIN STAGED (the node lane, 16:38Z): fork commit bd710a36 on release-0.3.22-node (igneum-pow 017e7037 archived beside the fork as igneum-pow-amend, byte 7, epoch-0 id a785001687d8688a must-equal, the three must-differ ids, PROGRAM_SUBVERSION_V4 read as 3); the line's candidate fa7f854f (the re-pin, the era VDF merge f2ecf452, the igneum-devnet-3 object with program_class_v4_activation_daa 0 and a one-day signal window, so byte 7 is stamped and hashed from genesis); the kaspa-pow suite on build-2 from 16:38Z, its line owed; the hash lane has the commit for its pairing run. THE kaspa-pow SUITE ON THE 0.3.22 CANDIDATE 21d8f454 (build-2, 16:47:10Z): GREEN 17 of 17; the pairing test reads PROGRAM_SUBVERSION_V4 = 3, epoch-0 id a785001687d8688a, the three must-differ ids hold, the chain draw at attempt 1 against class v3's 0 on the test header; the candidate's digest for igneum-devnet-3 ab9af79f...ed23; the node stamps object 7 (block version 1794) from genesis. MASTER GREEN ON THE POW FIX: CI run 37654633279 on cf7d6ccb success at 16:54:51Z, the igneum-pow job success; master's igneum-pow the frozen 017e7037 byte for byte; build-1's amend checkout synced to 874e945d (its packs-ca3-v4 carries the sub-version 3 kit). THE CHIP TEXTS LIVE (the site lane, site-ui-5): sections 1 to 4 applied verbatim in b34d1932, master cc593483, live on igneum.network at 16:47Z (home row 03 "under class v4 from the first block"; /litepaper#chip-model the new paragraph and the reordered table with the class v3 row last; /miner the new line; /evidence row 17 "2.1x (k = 1) to 3.9x" in eight columns); the litepaper's abstract rewritten launch-first too; tools/ci/ledger-text-check.mjs X35 asserts the launch-first sentence on the home page and "so the launch number is the class v4 row" on the litepaper; no prize mention. /claims (the litepaper's limits section) rewritten launch-first by the coordinator in the litepaper's chip bullet (2.1x to 3.9x under class v4 from the first block with its labels, class v5, then the class v3 baseline "never the launch state", the recompute chip under 1x, the X9 history), /claims rebuilt from it, the ledger text check 61 of 61, the padding and overlap sweeps green in the 56-check gate, master 0a999646 at 17:01:47Z. DEVNET 3's FIRST GO (the fleet lane): dn3-g1 on 21d8f454 up 16:50:21Z from an empty datadir, digest ab9af79f matching the build-1 read, genesis a6fa348e executed (chain id 4463), object 7 / block version 1794, era VDF from DAA 0, no override file, mining from 16:50:42Z; the dn3_ observer running since 16:38:29Z; DN3_GO_DATE=2026-10-07 in /srv/hands/dn3/dn3.env, the hash-origin timer's first dn3_ report 8 October 08:30Z. BUT NO BLOCK ACCEPTED: dn3-g1 refuses every block its miner finds with "the block timestamp is too far into the future: block timestamp is 1791417600001 but maximum timestamp allowed is 1791392281213" (16:57:51Z): 1791417600001 ms = 2026-10-08T00:00:00.001Z, the template stamping genesis + 1 ms, so the igneum-devnet-3 genesis object carries 8 October 00:00Z, one day after the intended 7 October 00:00Z; every block is seven hours in the future and refused before PoW on any node with any miner or pack; the pack is not the suspect (the node draws the epoch's program under its own igneum-pow and hands the pack to the worker; the exported kit is for G1 and recheck only). The fix is the node lane's (a past genesis timestamp, moving the genesis hash and the digest) and a rebuild; the fleet reruns the go within the minute of the new pair; if the corrected build lands by about 17:20Z the pair lock is about 17:35Z (18:35 BST). Spend at 17:00Z about USD 410 of 1,000. GITHUB SUSPENDED (17:0xZ): every push to origin refused with "Your account is suspended" (403); the API reads 404 for the user igneum-labs and the repo (the shape of a suspended account, not a revoked token); with the project lead (the ticket route given by main); until GitHub answers, every lane pushes to the build-1 mirror (/srv/igneum.git over ssh) and the mirror is the record, merges landing through the box gate stamp under the shipper's exception window. This branch is on the mirror at a33a7859 (17:09Z); master's last origin landing 0a999646 (17:01:47Z). DEVNET 3 MINES (the fleet lane, 17:08Z): dn3-g1 on the corrected candidate 69d1b56e (genesis 7 October 00:00Z, hash 4020cb43..., digest 83eb50cdf2eda4cb...) accepted its first block at 17:06:19.920Z, 3 blocks by 17:06:44Z, 0 rejected; dn3-g2 joining, the pair's first common lock about 17:15Z (18:15 BST), then the late joiner and the canary's ten minutes; the hands pair for 69d1b56e landed 17:05:54Z, the shipper ruling whether the genesis bytes are the node lane's or the hands'. Per tier: the first chain that hashes class v4 sub-version 3 (byte 7) from genesis is live on the fleet; the launch-first chip texts describe it exactly. DEVNET 3's EPOCH-0 PROGRAM ID (the node lane): fce15bf61030be57 on igneum-devnet-3 (genesis 4020cb43...b925), read in the 0.3.22 miner's "cache ready" line on build-1 at 17:10:39Z and on dn3-g1 at 17:12Z, the node accepting 85 of 85 GPU blocks; a785001687d8688a stays the shared devnet's epoch-0 id (genesis edc4fa84) and the kaspa-pow pairing pin; the pairing is unchanged, the id follows the seed; the fleet's pack-id gate reads fce15bf61030be57 at epoch 0 and the node's per-epoch value after; the exported kit's eight packs are the shared devnet's seeds, so a Devnet 3 kit, if the hive wants one, is a re-export over 4020cb43's seeds (the hash lane's, on request). DEVNET 3's PAIR AGREES (the fleet lane, 17:19Z): dn3-g2 up 17:17:58Z on the same bytes, digest and genesis, synced from dn3-g1 and mining from 17:18:15Z; the pair agrees on every determined finality checkpoint (20, 21, 22 on identical blocks in both logs); 702 blocks, 0 rejected on either, by 17:19:08Z. The first LOCK lands about 19:10Z (20:10 BST): the object's finality window is 7,200 DAA ("window filling, 681 of 7200") at about 1 block/s, the object as cut, nothing wrong. Two independent nodes agree on the chain since 17:18Z; finality signatures start two hours in; the hash-origin daily (dn3_ tables, DN3_GO_DATE 2026-10-07) counts from today once the observer units are enabled on the shipper's go. The shipper rules whether the genesis is declared on the pair's agreement or on the first lock; the late joiner, the empty-datadir canary (ten minutes) and the spare placing on the hands pair; the standing boxes' second nodes after the joiners on the shipper's word. Spend 17:20Z about USD 412 of 1,000. GITHUB RULE (main through the shipper, 18:02 BST): no push, fetch or poll of GitHub from this lane or its sub-lanes, not even a retry; the box mirror on build-1 and build-2 is origin and the box gate stamp the verdict until it lifts. DEVNET 3's EPOCH-0 PACK EXPORTED (the hash lane): program.json 0xfce15bf61030be57, attempt 0, sub_version 3 (dn3-g1 drew the export path's seed); igneum-pow at 874e945d (byte-identical to 017e7037 and master's), --epoch-hex and --era-hex the genesis 4020cb43...b925, class mx8-eraaf3a9139+sh256x27, day bytes "igneum-day/" || le64(20733) (the chain's rule day = timestamp_ms / 86,400,000; the program and id day-independent, the dataset and fingerprint rolling with the UTC day); Metal fingerprint e510ad92b4d24846 at 2^24 from base 0, Apple OpenCL equal, vectors 3 of 3; on build-1 /srv/artefacts/packs/v4-devnet3-epoch0/ and .zip sha256 e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334, the sub3 kit zip beside it (4f2445c5...); in the 0.3.22 hive package order with the kit. [user]'S THREE ORDERS (through main, 18:3x BST), with his correction (18:4x BST: everything in-house, nothing external): (1) BUILD CLASS V5 NOW on the 0.3.23 line (program class v5, its own activation height, object byte 6): the generator and verifier in igneum-pow (+0.2 ms per warp against the 10 ms gate), the node side (the state commitment into the dataset derivation, the stateless/stale-chip rule known-failed first on a stale dataset), the hot-set, weak-day and shadow-redundancy rules routed to this class, the attack-pass families re-run on v5, the kit for Metal, CUDA, OpenCL/AMD and Intel with fingerprints equal, the crossing on Devnet 3 by height after its gate, miner cost rows per card; the v5 lane resumed with the order, owing tonight the design-to-code gap in one list and a UTC clock for the first v5 pack. (2) CRYPTANALYSIS IN-HOUSE: no outside firms, no paid lots, no briefs to anyone; the three targets (the mixer M_r, the chained cache, the acceptance rule) attacked by three adversarial lanes that have never worked on the hash code, each given only an outsider's inputs (the public kit, the frozen object, the spec, the attack-pass harnesses), a written attack plan first, a budget of box hours, a report in the attack-pass shape (the claimed break or the bound reached, reproducible); the Counter ASIC lane the defender, main ruling disputes; plans within two hours, first results by tomorrow evening; a coordinator lane spawned for it (docs/plans/cryptanalysis/in-house-pass.md, funding.md's lots rewritten to the internal pass). The served sentence "the cryptanalysis plan buys three external lots" rewritten on the litepaper, /claims and evidence row 17 to the internal adversarial pass, labelled internal, the one outside check staged on its escrow and the publish word (the served text never names the prize or the project lead, by the forbidden-strings gate). (3) OWED MEASUREMENTS on PC 1: released tonight after the shipper's 0.3.21 host build (the line "PC 1 released" about 18:05Z, the window to 17:30Z on 8 October, an elevated job allowed under the standing rules); the hash lane prepares the three job files on the sub-version 3 kit (the 9070 XT G1 and ladder rows, item 6's step costs on AMD, the 5090 clock rows elevated, dr736 if it fits), published one at a time on the coordinator's relay of the line, --cards-off on the measured card alone, the desk left usable; the rows land in the public table with their labels. Nothing in (1) or (3) reaches outside the fleet, the boxes and the PCs. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the project lead takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +SUB-VERSION 3 PASSES BOTH GATES (the attack-pass lane, the close line dated 7 October 2026): class v4 sub-version 3, commit 017e70376489251e18564c0abce7e466e606c8b3 on ca3-v4-amend, pairing id a785001687d8688a (verified by the harness). F8's 64-seed census (p2 to p65) at 2^24 nonces each, chain path, window-model control, box 2, 14:51Z to 16:00:20Z: PASS, 60 of 64 under 1.2x (0.9915x to 1.144x); the only four over are the named tail, unattributed and chased: p10 1.5036x (identical to sub-versions 1 and 2, hottest item 0x4004da at 362 reads, no predicted source), p8 1.3776x (0x837de4, 420 reads), p34 1.2505x (0x800010, 541 reads, the one-bit value through sub at 5), p4 1.2167x (0x4000e7, 355 reads); every strong seed gone (p23 4.82x, p19 3.32x, p15 2.57x, p18 2.50x, p56 2.01x all under 1.2x); the worst ratio on the stream 1.50x; the tail's hottest items carry 355 to 541 reads of 2^31 (one to two per 2^22 items above the mean), no chip consequence. The exhaustion gate as it is: the chain-path count on 017e7037 runs slowly (the draw evaluates (c'') at 2^20 per candidate: 20,532 seeds in 59 minutes, 0 exhausted, 0 panics, max attempt 29), so a 10^6 count is two days away and is not waited on; the substance is met by construction (the 256 cap and the last resort unchanged from 8bdcbdd8, 0 of 10^6 there) and by measurement at 017e7037 on 24,631 seeds (0 exhausted, max 29; r about 0.68); the count runs on as a strengthening line. The node's epoch draw now costs about 2 attempts at 2.2 s each, 4 to 5 s per epoch on slower cores, once an hour. The hash lane's ledger at 6941da1d. SUB-VERSION 3 AT 017e7037 IS THE FROZEN GENERATOR FOR 0.3.22 (byte 7), THE TAIL RULED (main, 18:1x UK): the four seeds (p10 1.5036x with its hottest item at 362 reads, p8 1.3776x at 420, p34 1.2505x at 541, p4 1.2167x at 355, of 2^31 reads) are accepted as the window model's unattributed residue at 1.22x to 1.50x with nil chip consequence; the AP-F8-1 row CLOSES with that wording and the hottest-item counts beside it; the 10^6 count on 017e7037 runs on as the strengthening line. The attack-pass plan's start 15 October or the morning after. 0.3.21's FIRST CANDIDATE 96161037 (sha256 f99340b3cf4ce32e, string read back) passed the node lane's two gates on its own binary: the digest gate 15:59:54Z to 16:01:32Z PASS (a89be8a7 with the peers right; db9a85f9 refused, no peer); the mixed-version gate 16:01:53Z to 16:12:05Z PASS (one digest b0afb2ee on five; 252 new and 352 old accepted, 0 rejected; counts equal at 316, 493 and 604 through both clean joins and the restart step; no panic); the node side complete; the fleet's set on the same binary (the kept start with the ids gate, the wipe canary, the cases rerun, the 12 GB line, N15's restarts of p1-5090 and p2-3090-3) is what the shipper's pin word waits on; byte 5 throughout, nothing on the class v4 seam moved. DEVNET 3 NOW (the project lead through main, 17:3x BST): 0.3.22 is the Devnet 3 release (a fresh network object igneum-devnet-3 with every activation at 0 and no override file, the era VDF fork, class v4 sub-version 3 at byte 7 from genesis), the node building on build-1, genesis by 17:30Z (18:30 BST). THE HANDOFF (17:3x BST, inside the 17:40 BST line, to the shipper and the node lane): igneum-pow 017e70376489251e18564c0abce7e466e606c8b3 (the audit-freeze-2026-10-07 tag; 2a111fb1 and 6941da1d above it docs only), object byte 7, PROGRAM_SUBVERSION_V4 = 3, devnet epoch-0 program id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3), kit packs-ca3-v4-sub3 zip sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154, the eight fingerprints as recorded (equal on Metal, Apple OpenCL, the fleet 5090 and PC 2's 5090), both attack-pass gates GREEN, suite 103 of 103, CI success; the open items stated as open: the four-seed tail under main's ruling (the attribution for 0.3.23), the 10^6 count as a strengthening line, the 4 to 5 s epoch draw, the owed measurements that do not gate Devnet 3. NO FURTHER HASH CHANGE RIDES ON 0.3.22; anything from the tail goes to 0.3.23. The node lane stages the re-pin on the 0.3.21 tip as its own commit (the fork commit and the kaspa-pow suite line owed to this record); the hash lane's sub-version 3 pairing follows it. THE PUBLIC CHIP TEXT REWRITTEN LAUNCH-FIRST (the project lead: "I thought we were making it 2.1 from launch?"; master 9b996d06, docs/plans/counter-asic-3-public-text-2026-10-07.md): the testnet and mainnet objects set program_class_v4_activation_daa 0, so class v4 is live from genesis and the launch number is 2.1x to 3.9x on day one; the three texts and evidence row 17 lead with that (labels kept), then class v5, then the 5x to 9x only as the class v3 baseline the work started from, the devnet's activation height a devnet fact only; no em dashes, no prize mention, eight columns; with the site lane to apply in the same deploy as the padding sweep (its commit and deploy time owed to this record). STOP-THE-LINE ON MASTER's POW SUITE (main through the CI steward, 18:4x BST): red since 16:31 BST (runs a4eaf76 and 1210158d; program_ids_differ_between_class_v3_and_class_v4_of_one_seed and cpu_recheck_equals_the_worker_reference_for_class_v3_and_class_v4 fail on packs-ca3-v4/v4-devnet-epoch0) because era-vdf's merge 0e2d6b1c put the sub-version 1 line's generator on master against tests/recheck.rs's pins, never CI-run. Ruling: the hash lane merges ca3-v4-amend's tip 6941da1d to master through merge-to-master.sh within 15 minutes, provided its epoch-0 id equals the frozen object's; the coordinator verified the condition (6941da1d's igneum-pow byte-identical to 017e7037; recheck pins 0xa785_0016_87d8_688a with the three must-differ ids; PROGRAM_SUBVERSION_V4 = 3), so no revert; master is the 0.3.23 line after this, 0.3.22 keeps its pin at 017e7037. EXECUTED: ca3-v4-amend on master as merge cf7d6ccb (pushed 16:45:48Z through merge-to-master.sh, try 1; the branch gate GREEN, 55 checks in 317 s on 874e945d; master ac8ed2f1 merged into the branch first with docs/fud-ledger.md keeping both sides and igneum-pow taken wholesale from 6941da1d, byte-identical to 017e7037); master's CI run 37654633279 on cf7d6ccb in progress from 16:46:10Z, the pow job's conclusion owed. Master's igneum-pow is now the frozen sub-version 3 generator. THE 0.3.22 RE-PIN STAGED (the node lane, 16:38Z): fork commit bd710a36 on release-0.3.22-node (igneum-pow 017e7037 archived beside the fork as igneum-pow-amend, byte 7, epoch-0 id a785001687d8688a must-equal, the three must-differ ids, PROGRAM_SUBVERSION_V4 read as 3); the line's candidate fa7f854f (the re-pin, the era VDF merge f2ecf452, the igneum-devnet-3 object with program_class_v4_activation_daa 0 and a one-day signal window, so byte 7 is stamped and hashed from genesis); the kaspa-pow suite on build-2 from 16:38Z, its line owed; the hash lane has the commit for its pairing run. THE kaspa-pow SUITE ON THE 0.3.22 CANDIDATE 21d8f454 (build-2, 16:47:10Z): GREEN 17 of 17; the pairing test reads PROGRAM_SUBVERSION_V4 = 3, epoch-0 id a785001687d8688a, the three must-differ ids hold, the chain draw at attempt 1 against class v3's 0 on the test header; the candidate's digest for igneum-devnet-3 ab9af79f...ed23; the node stamps object 7 (block version 1794) from genesis. MASTER GREEN ON THE POW FIX: CI run 37654633279 on cf7d6ccb success at 16:54:51Z, the igneum-pow job success; master's igneum-pow the frozen 017e7037 byte for byte; build-1's amend checkout synced to 874e945d (its packs-ca3-v4 carries the sub-version 3 kit). THE CHIP TEXTS LIVE (the site lane, site-ui-5): sections 1 to 4 applied verbatim in b34d1932, master cc593483, live on igneum.network at 16:47Z (home row 03 "under class v4 from the first block"; /litepaper#chip-model the new paragraph and the reordered table with the class v3 row last; /miner the new line; /evidence row 17 "2.1x (k = 1) to 3.9x" in eight columns); the litepaper's abstract rewritten launch-first too; tools/ci/ledger-text-check.mjs X35 asserts the launch-first sentence on the home page and "so the launch number is the class v4 row" on the litepaper; no prize mention. /claims (the litepaper's limits section) rewritten launch-first by the coordinator in the litepaper's chip bullet (2.1x to 3.9x under class v4 from the first block with its labels, class v5, then the class v3 baseline "never the launch state", the recompute chip under 1x, the X9 history), /claims rebuilt from it, the ledger text check 61 of 61, the padding and overlap sweeps green in the 56-check gate, master 0a999646 at 17:01:47Z. DEVNET 3's FIRST GO (the fleet lane): dn3-g1 on 21d8f454 up 16:50:21Z from an empty datadir, digest ab9af79f matching the build-1 read, genesis a6fa348e executed (chain id 4463), object 7 / block version 1794, era VDF from DAA 0, no override file, mining from 16:50:42Z; the dn3_ observer running since 16:38:29Z; DN3_GO_DATE=2026-10-07 in /srv/hands/dn3/dn3.env, the hash-origin timer's first dn3_ report 8 October 08:30Z. BUT NO BLOCK ACCEPTED: dn3-g1 refuses every block its miner finds with "the block timestamp is too far into the future: block timestamp is 1791417600001 but maximum timestamp allowed is 1791392281213" (16:57:51Z): 1791417600001 ms = 2026-10-08T00:00:00.001Z, the template stamping genesis + 1 ms, so the igneum-devnet-3 genesis object carries 8 October 00:00Z, one day after the intended 7 October 00:00Z; every block is seven hours in the future and refused before PoW on any node with any miner or pack; the pack is not the suspect (the node draws the epoch's program under its own igneum-pow and hands the pack to the worker; the exported kit is for G1 and recheck only). The fix is the node lane's (a past genesis timestamp, moving the genesis hash and the digest) and a rebuild; the fleet reruns the go within the minute of the new pair; if the corrected build lands by about 17:20Z the pair lock is about 17:35Z (18:35 BST). Spend at 17:00Z about USD 410 of 1,000. GITHUB SUSPENDED (17:0xZ): every push to origin refused with "Your account is suspended" (403); the API reads 404 for the user igneum-labs and the repo (the shape of a suspended account, not a revoked token); with the project lead (the ticket route given by main); until GitHub answers, every lane pushes to the build-1 mirror (/srv/igneum.git over ssh) and the mirror is the record, merges landing through the box gate stamp under the shipper's exception window. This branch is on the mirror at a33a7859 (17:09Z); master's last origin landing 0a999646 (17:01:47Z). DEVNET 3 MINES (the fleet lane, 17:08Z): dn3-g1 on the corrected candidate 69d1b56e (genesis 7 October 00:00Z, hash 4020cb43..., digest 83eb50cdf2eda4cb...) accepted its first block at 17:06:19.920Z, 3 blocks by 17:06:44Z, 0 rejected; dn3-g2 joining, the pair's first common lock about 17:15Z (18:15 BST), then the late joiner and the canary's ten minutes; the hands pair for 69d1b56e landed 17:05:54Z, the shipper ruling whether the genesis bytes are the node lane's or the hands'. Per tier: the first chain that hashes class v4 sub-version 3 (byte 7) from genesis is live on the fleet; the launch-first chip texts describe it exactly. DEVNET 3's EPOCH-0 PROGRAM ID (the node lane): fce15bf61030be57 on igneum-devnet-3 (genesis 4020cb43...b925), read in the 0.3.22 miner's "cache ready" line on build-1 at 17:10:39Z and on dn3-g1 at 17:12Z, the node accepting 85 of 85 GPU blocks; a785001687d8688a stays the shared devnet's epoch-0 id (genesis edc4fa84) and the kaspa-pow pairing pin; the pairing is unchanged, the id follows the seed; the fleet's pack-id gate reads fce15bf61030be57 at epoch 0 and the node's per-epoch value after; the exported kit's eight packs are the shared devnet's seeds, so a Devnet 3 kit, if the hive wants one, is a re-export over 4020cb43's seeds (the hash lane's, on request). DEVNET 3's PAIR AGREES (the fleet lane, 17:19Z): dn3-g2 up 17:17:58Z on the same bytes, digest and genesis, synced from dn3-g1 and mining from 17:18:15Z; the pair agrees on every determined finality checkpoint (20, 21, 22 on identical blocks in both logs); 702 blocks, 0 rejected on either, by 17:19:08Z. The first LOCK lands about 19:10Z (20:10 BST): the object's finality window is 7,200 DAA ("window filling, 681 of 7200") at about 1 block/s, the object as cut, nothing wrong. Two independent nodes agree on the chain since 17:18Z; finality signatures start two hours in; the hash-origin daily (dn3_ tables, DN3_GO_DATE 2026-10-07) counts from today once the observer units are enabled on the shipper's go. The shipper rules whether the genesis is declared on the pair's agreement or on the first lock; the late joiner, the empty-datadir canary (ten minutes) and the spare placing on the hands pair; the standing boxes' second nodes after the joiners on the shipper's word. Spend 17:20Z about USD 412 of 1,000. GITHUB RULE (main through the shipper, 18:02 BST): no push, fetch or poll of GitHub from this lane or its sub-lanes, not even a retry; the box mirror on build-1 and build-2 is origin and the box gate stamp the verdict until it lifts. DEVNET 3's EPOCH-0 PACK EXPORTED (the hash lane): program.json 0xfce15bf61030be57, attempt 0, sub_version 3 (dn3-g1 drew the export path's seed); igneum-pow at 874e945d (byte-identical to 017e7037 and master's), --epoch-hex and --era-hex the genesis 4020cb43...b925, class mx8-eraaf3a9139+sh256x27, day bytes "igneum-day/" || le64(20733) (the chain's rule day = timestamp_ms / 86,400,000; the program and id day-independent, the dataset and fingerprint rolling with the UTC day); Metal fingerprint e510ad92b4d24846 at 2^24 from base 0, Apple OpenCL equal, vectors 3 of 3; on build-1 /srv/artefacts/packs/v4-devnet3-epoch0/ and .zip sha256 e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334, the sub3 kit zip beside it (4f2445c5...); in the 0.3.22 hive package order with the kit. [user]'S THREE ORDERS (through main, 18:3x BST), with his correction (18:4x BST: everything in-house, nothing external): (1) BUILD CLASS V5 NOW on the 0.3.23 line (program class v5, its own activation height, object byte 6): the generator and verifier in igneum-pow (+0.2 ms per warp against the 10 ms gate), the node side (the state commitment into the dataset derivation, the stateless/stale-chip rule known-failed first on a stale dataset), the hot-set, weak-day and shadow-redundancy rules routed to this class, the attack-pass families re-run on v5, the kit for Metal, CUDA, OpenCL/AMD and Intel with fingerprints equal, the crossing on Devnet 3 by height after its gate, miner cost rows per card; the v5 lane resumed with the order, owing tonight the design-to-code gap in one list and a UTC clock for the first v5 pack. (2) CRYPTANALYSIS IN-HOUSE: no outside firms, no paid lots, no briefs to anyone; the three targets (the mixer M_r, the chained cache, the acceptance rule) attacked by three adversarial lanes that have never worked on the hash code, each given only an outsider's inputs (the public kit, the frozen object, the spec, the attack-pass harnesses), a written attack plan first, a budget of box hours, a report in the attack-pass shape (the claimed break or the bound reached, reproducible); the Counter ASIC lane the defender, main ruling disputes; plans within two hours, first results by tomorrow evening; a coordinator lane spawned for it (docs/plans/cryptanalysis/in-house-pass.md, funding.md's lots rewritten to the internal pass). The served sentence "the cryptanalysis plan buys three external lots" rewritten on the litepaper, /claims and evidence row 17 to the internal adversarial pass, labelled internal, the one outside check staged on its escrow and the publish word (the served text never names the prize or the project lead, by the forbidden-strings gate). (3) OWED MEASUREMENTS on PC 1: released tonight after the shipper's 0.3.21 host build (the line "PC 1 released" about 18:05Z, the window to 17:30Z on 8 October, an elevated job allowed under the standing rules); the hash lane prepares the three job files on the sub-version 3 kit (the 9070 XT G1 and ladder rows, item 6's step costs on AMD, the 5090 clock rows elevated, dr736 if it fits), published one at a time on the coordinator's relay of the line, --cards-off on the measured card alone, the desk left usable; the rows land in the public table with their labels. Nothing in (1) or (3) reaches outside the fleet, the boxes and the PCs. DEVNET 3's PROOF WINDOW OPENED 17:57:05Z (the fleet lane): coverage from 17:44:23Z (dn3-x1, an RTX 3060 12 GB, the sm_86 SP1 floor, from DAA 0; the first segment 1024..1031 submitted 17:45:49Z, 86.1 s end to end); the first records PAID by dn3-x1's key, segments 1256..1263 (0.7036 IGN) and 1272..1279 (1.5993 IGN) in block 1403, paidShards 10 at 17:57Z; the 24 hours run to 17:57Z on 8 October; sizing: a 3060 proves a segment in 84 to 86 s (about 42 an hour) against 450 segments an hour at 1 block/s, 11 cards for a share of one, 15 placed (14 more 3060 12 GB pods on distinct Vast machines, USD 1.07/h together); a runbook rule found: a Devnet 3 block builder carries a proof record only after its own node verified it, so every Devnet 3 miner node needs IGNEUM_PROOF_VERIFIER on the host verifier (the four miners ran bare for 11 minutes, 72 records pending and 0 carried; dn3-j1 restarted with it at 17:54:37Z and carried the first). THE UTILISATION TABLE (the fleet lane, 18:00Z, for the project lead): 36 rented boxes plus the Hetzner seed, 37 GPUs, USD 197 a day at this size, today's total about USD 432 of 1,000; idle in the hour 12 by the letter, 9 of them Devnet 3 boxes rented in the last 15 minutes and syncing, 3 the 0.3.21 warm set standing between windows; the fleet's recommendation: stop Devnet 2's four boxes (USD 59.76 a day; Devnet 3 is now the staging chain) on the shipper's word, fold the 0.3.21 warm set (USD 12.72 a day) into Devnet 3's relay trio when 0.3.21's last line closes. THE PUBLIC BENCH TABLE (main's order): /miners now carries every measured card, 37 rows, with watts, MH per watt, the class v4 cost per card and the tuned state (the 5090 stock 136.1 MH/s at 350 W and tuned 127.71 at 226.8 W; the 4070 at its tune point; the 9070 XT, the M5 Max (no lever), the 5060 Ti, the Arc B580, and the fleet's rented-card sweep of 7 October: the 5080 71.16 at 143.4 W, the H100 248.70 at 385.6 W, the B200 416.35 at 855.6 W, the 4090 hands row 52.25 at 183.1 W, down to the 4060 Ti 20.10 at 77.5 W; every fleet row stock, bench only, labelled measured by the fleet or reported by the fleet). CLASS V5's DESIGN-TO-CODE GAP (the v5 lane, 19:00 UK; section 13 of docs/design/class-v5-stored-state.md at c17bc04b): igneum-pow's class v5 rebased onto the frozen sub-version 3 (v5 and its rungs draw under (a'), (c''), the shared-operand rule, the 256 cap and the last resort by merge); the fork rebased onto release-0.3.23-node with class v5 pinned to object byte 6 counted EXACTLY (byte 7 is v4 sub-version 3; the bytes are no longer ordered by class); the gap about 40 agent hours (17 the v5 lane's): the +0.2 ms per warp on the Mac (1 h), the AP-F4-1 and AP-F1-1 rules with their known-failed cases (3 h each), the attack-pass families on the v5 stream (4 h), the kits (Metal and CUDA hosts uploading leaves.bin, 2 h each; OpenCL/AMD and Intel 3 h), G1 on the 5090 and the Mac (2 h), the Devnet 3 crossing by height (3 h), the miner cost rows (3 h), the snapshot wire's day streams (3 h), the pool's per-epoch state fetch (2 h), the proof witness (4 h), the spec text (2 h); the first v5 pack's clock (Devnet 3's genesis as epoch and era seed, day 20,733) follows the suite and the day-stream bin. THE IN-HOUSE ADVERSARIAL PASS (the crypto lane, 19:05 UK): crypto-engage deb0011e on the mirror; docs/plans/cryptanalysis/in-house-pass.md (outsider inputs and withheld files, the three lanes, the budget 8 box-hours each and 24 total with a ceiling of 48 on the coordinator's word, the review roles, the clock, the label rule); funding.md's lots rewritten to the internal pass with no cash row and every firm name removed; the three lanes adv-mixer, adv-cache and adv-accept spawned 19:1x UK with outsider-only inputs, plans due 21:10 UK, first results by 18:00 UK on 8 October; the Devnet 3 epoch-0 pack added to their inputs. THE PC 1 QUEUE PREPARED (the hash lane, c1a1f1d7, nothing published): the kit fetch (zip sha256 1d441f5a..., the 8 sub-version 3 packs plus the ladder packs sh256x13/27/53/88 and sh64x52); the class v4 efficiency pass on the 5090 (elevated, --cards-off, a 17-step clock-lock grid from unlocked to 1,400 MHz with the four Ember caps on it, v4 then v3 at each step for about 60 s, the fingerprint on every step, nvidia-smi at 1 Hz, -rgc in finally; nvidia-smi has no voltage-offset lever, the lock walks the driver's V/F curve; about 40 minutes; the owed 5090 clock rows subsumed); the same on the 5080 (its unlocked row the stock point against the fleet's 71.16 MH/s); G1 on the 13 packs and the AMD ladder rows on the 9070 XT (the ladder packs' Mac fingerprints sh256x13 ff8f707210659eb1, sh256x27 892b6d55a7ddcfcb, sh256x53 663c73c61f62cc54, sh256x88 ec7ca430a061fa59, sh64x52 9dd010f79d8ca9f4); item 6's step costs on AMD (run e); the 5080 full Ember Tune (not elevated, the Power Helper carries the rights); the 9070 XT tune pass (the tune_line before and after on RESULT lines); dr736 not in the queue (its packs are not in this tree). The protocol: each exit line to the shipper, the next published on its ack, the shipper's "PC 1 released" line (after the 0.3.21 window host build) opens the queue. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the project lead takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the project lead's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule diff --git a/docs/plans/release-0.3.21.md b/docs/plans/release-0.3.21.md index 496c7a346..d8db7b724 100644 --- a/docs/plans/release-0.3.21.md +++ b/docs/plans/release-0.3.21.md @@ -64,3 +64,21 @@ sha256 279b1b690e854fc9, the string read back, pairing 8c728ca3 at byte 5. The d **Three more in (16:2x BST):** update-return-21b a64c193f (the eGPU card kind from a USB4 or Thunderbolt router in the device's parent chain, the Power Helper's fault line and its stale-prefix fix; app 255 + 32 + 8, UI 76); first-block-21 at cc9141cb replacing 6e555d47 (main's "seen once": the first-block card waits until a window has shown it, POST api/card/seen, ladder.rs card_seen; app 255 + 32 + 8, UI 67); miner-reliability-21 at 018440ae (the register: MF-11 in the update-return lane's words, MF-12 the pool stall, MF-13 the Power Helper's stale count; code unchanged since 4a28eb59, CI success). UI tests on the merged tree 76 of 76; the app gate on build-2 at the merged tip below. GitHub refused pushes with "Internal Server Error" from about 15:25 to 16:18 BST, transient. **The node order, final (16:3x BST):** on 55768f88: c631c64b first (the test-only fix of the two stale integration targets, 1026 → 1282; both green on build-2 at 15:34Z), then 52e96c94, f067f7c1, b0444f51, 437f0438, 2e32d5f6, f95178a1, a6864e36, d8bceca5; the tip's suite set runs the consensus crate whole (`-p kaspa-consensus` without `--lib`: the lib and both integration targets) beside consensus-core, the miner, kaspa-pow, the exec suite and the three checks (the suite rule from the 0.3.20 known-red finding). era-vdf-node 394a5902 is 0.3.22's. + +## 6. The shape that ships: the 0.3.21 app tree over the field node c4459193 (main, 17:5x BST) + +No node gate for 0.3.21: the app tree ships over the node already in the field (c4459193, the 0.3.20 pin, digest 4bbbe816 on the floor file). The 96161037 line (N15's numbering class, the bare-node proving ids) folds into 0.3.22 and later; its canary cells (kept-datadir ids BOTH PRESENT, wipe canary c22-1 synced in 42 minutes, 23 for 23, restart synced in 1 min 24 s) stand as readings, not as this release's gate. + +**The exact tree:** release-0.3.21 at 44b63ac9 = scaling-21 b340b904 merged (c999a104), the windows.yml smoke fix 6c4686e7 (a direct call with the exit code read, in place of Start-Process -Wait -PassThru, which raced the version read-back on run 37653903394), and the node-source pin back to c4459193 (44b63ac9). App gate GREEN on build-2 on that tree at 18:05 BST: 257 + 32 + 8, rc 0. Payload inputs on the dl host at 18:04 BST: igneumd.exe 49502cc7, igneum-miner.exe b4871b5d (c4459193's Windows pair, the 0.3.20 release's bytes), igneum-worker-cuda.exe d7a413c7, igneum-worker-opencl-intel.exe af53f194, igneum-gpu-telemetry 0d68d06e, the Linux prover pair. + +**The GitHub exception window, from 18:02 BST:** GitHub answers "Your account was suspended" (403) to every call from the igneum-labs login, API and git; the windows.yml dispatch at 18:04 BST was that 403 and no run started. Main's ruling: no lane pushes, fetches or polls GitHub, not even a retry; the box mirror /srv/igneum.git on build-1 and build-2 is origin for every lane; the box gate stamp replaces merge-to-master.sh's CI wait; the window and its start are recorded here and closed by a row when the login is restored. release-0.3.21 44b63ac9 reached both mirrors at 18:12 BST; master a4bca198 was fast-forwarded onto the mirrors (they had sat at 83977817) so every lane's origin carries a current master. + +**Windows without windows.yml:** the 0.3.10 shape. igneum-app.exe cross-built on build-1 from 44b63ac9 (GNU target, 151803c7, 4,232,704 B; igneum-ota-sign.exe ddfd9444; igneum-prove-verify.exe dbda5323), the payload zip igneum-windows-app-0.3.21-44b63ac9.zip 586beedd and the installer kit installer-kit-44b63ac9.zip 6d0b5437 on the dl host; the window host (MSVC, WebView2) and the installer (Inno Setup, rcedit) only build on a Windows box, so a signed job on PC 2 (run-20261007-172000, woken 18:20 BST) builds both, reads --version off the three exes and posts the installer back through the relay; the smoke (install silent, --version read, the app starts and exits clean) runs on PC 2 by a following signed job and is the gate line. PC 2's agent polled the relay at 18:23 BST while its app, node and miners had been down since 17:27 BST (the Intel driver install), so the jobs reach it; no job on PC 1. + +**The Mac:** Igneum-Miner-0.3.21.dmg rebuilt under the build lock at 18:15 BST with c4459193's Mac node pair (igneumd-mac b306baba, igneum-miner-mac deb4d263, the 0.3.20 release's bytes): 490919d9, 44,538,877 bytes, version 0.3.21 build 202610071714. The earlier fb517a11 (96161037's Mac node) never ships. + +**Publish reading:** about 19:15 BST on the smoke's green; the staging in a scratch copy with the live floor file and the 0.3.20 hive package unchanged; the apps on the pollers, the Mac first. + +## 7. LIVE on the Mac, 18:41:50 BST (main's ruling: the Mac entry now, Windows as its own entry) + +Deploy runbook r0321/deploy.sh --mac-only --go (preflight: the staged manifest equals the live one on consensus.override, floor 900000, 16 fields, interface 1.0.1; the DMG present and read back). Copied into the live folder at 18:40:44 BST, Vercel deploy, the live manifest read back at 18:41:50 BST: version 0.3.21, channel devnet, mac Igneum-Miner-0.3.21-c4459193.dmg 490919d9 (44,538,877 bytes), windows none, floor 900000, ui 1.0.1; the DMG from the live URL 490919d9. The 0.3.20 hive package and the floor file unchanged. The Mac poller takes it within the hour or on Check now. The Windows entry lands as its own entry when an installer passes PC 2's smoke: (2a) a per-user Inno Setup 6 install on PC 2 by job (unelevated, fail clean) and (2b) the window host by mingw on the box run in parallel; a PC 1 build job (MSVC) wins over (2b) if the project lead allows one; (2c) windows.yml when GitHub returns is the last resort. Testnet re-arm line (the node lane, 18:38 BST): fork 6ed56f63 on release-0.3.22-node, digest 87d103b6 with no file, genesis 52a3e6a9 (5 October 00:00Z, past), every gate green on the exact commit; Devnet 3's digest on that binary still 83eb50cd. The 0.3.22 node pin candidate: N15 dfae08e5 as 34a2dbaa on 6ed56f63, gates running from 18:39 BST. Signing bonus (for the project lead, the node lane): supply unchanged, only who is paid (a silent producer 72 and the pool 28 instead of 80 and 20; fees untouched); waits for 0.3.23 whatever the decision (c7ea1e21 silent_split missing). diff --git a/docs/plans/release-0.3.22.md b/docs/plans/release-0.3.22.md new file mode 100644 index 000000000..7004dfa5d --- /dev/null +++ b/docs/plans/release-0.3.22.md @@ -0,0 +1,59 @@ +# Release 0.3.22: Devnet 3 (ordered 7 October 2026, 17:2x BST; genesis by 18:30 BST on the project lead's word) + +Main's order (17:26 BST): Devnet 3 goes now, not after 0.3.21. 0.3.22's node = the release-0.3.21-node worktree on build-1 (96161037, both node gates PASS) + the sub-version 3 igneum-pow pin (the 017e7037 line, byte 7, pairing id a785001687d8688a; the Counter lane's handoff by 17:40 BST, else the node lane takes it from the audit-freeze-2026-10-07 tag) + the igneum-devnet-3 network object (its own network id and p2p port, every activation at 0: program_class_v4, difficulty_v2, finality_v3, fees_v1, proving_v1, latency_ladder rung 0; the genesis cut; NO override file on the new chain) + era VDF f2ecf452 only if its merge is clean and green in the same run (else 0.3.23 by an activation height; era_vdf_activation_daa stays at never on devnet-3 unless main's object names it). Built as an incremental on build-1's lease ahead of the 0.3.21 app gate. + +Gates before genesis: the box suite on the exact commit (the consensus crate whole, consensus-core, the miner against sub-version 3's packs, kaspa-pow, the exec suite, the three checks); from the build on the fleet's pods: the empty-datadir canary, the fresh-genesis digest agreement on two fleet boxes from empty (the same digest and the first lock between them), the late joiner's sync from them, the shutdown under 1 s, the proving ids present on a bare node. After genesis on the live chain: the relay cases (with a relay kept synced before the window, the warm rule) and the hands. Genesis on green with the fleet's two genesis boxes (the standing-fleet shape: supervisor, kill file, vote key, miner); the old devnet keeps running until Devnet 3 has 24 hours; the apps move by signed update after that. The genesis is reported as a clock reading. + +Staged (the build-server lane, 17:27 BST): the Devnet 3 seed on build-1 as a bare process (p2p 0.0.0.0:26631, gRPC 27630, JSON 27632, EVM 27810, empty datadir /home/build/dn3seed); the hands' second instances node1-dn3 (p2p 26651, rpc 26650, json 28650, evm 26830, --enable-unsynced-mining, peers the seed) and observer-dn3 (p2p 127.0.0.1:26661, rpc 26660, json 28660, evm 26860); ufw allows 26631 and 26651 since 17:27 BST; provision.sh's P2P_PORTS carries both; infra/build-server/devnet3/devnet3.{env,sh} with the NET_FLAGS placeholder until the node lane names the flag; read-back by the first log line, the commit-string count, the digest line, the "[igneum-exec] genesis executed" line and the server lines. The hands' nodes take no vote key (the miner's label is the key). The fleet: four gate pods on separate hosts renting with DESTROY=0; the fresh-genesis form, dn3_ tables, pay-by-key on the new chain and the no-stop cutover script follow; the capacity plan (a second node per standing box or a parallel set, the Devnet 3 hub) by 19:00 BST. + +The app side: the app must start its node on igneum-devnet-3 (the network flag the node lane names; the manifest's channel; no override object), the chain scene and the ladder reading the new chain's facts, the first-block and earnings rows from zero: 0.3.22's app cut after the node is live, by signed update when Devnet 3 has 24 hours. + +Era VDF (the era lane, 17:3x BST): f2ecf452 on 96161037, one round; the consensus crate whole 120 + 1 + 1, consensus-core 142, kaspa-pow 7; with the fields unset the digest is unchanged (the pinned devnet digest c562d70e read with the fields present; era_vdf_fields_enter_the_digest_only_when_set); at 0 it costs a node nothing for 180 days, then one core for an hour once; O-4.10 owed before any era 1. + +**The frozen sub-version 3 object (the Counter lane, 17:3x BST, handed to the node lane):** igneum-pow 017e70376489251e18564c0abce7e466e606c8b3 on ca3-v4-amend (the audit-freeze-2026-10-07 tag; 2a111fb1 and 6941da1d above it are docs only). Object byte 7, PROGRAM_SUBVERSION_V4 = 3, the devnet epoch-0 program id a785001687d8688a (must-differ c120d7963abdcd96, 1a4230699a6b9c60, a788661687db4bb3); the kit packs-ca3-v4-sub3 zip sha256 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154 (eight packs); fingerprints equal on Metal, Apple OpenCL, the fleet's 5090 (Linux CUDA) and PC 2 (Windows CUDA): mx8-devnet-epoch0 90f794dd556f7a3b (the v3 control), v4-devnet-epoch0 e370fb2080b7dbb1, era-0 b7237555d31fc3cf, era-1 b6b167fa15dfe2c9, era-2 28bdf65eff33f2c4, era-3 e26d38c46f3f1b16, era-4 dd8fdf6ff4f59eed, era-5 8bf40f5cb858d835. Both attack-pass gates GREEN on 017e7037 (the 64-seed hot-set census at 2^24: 60 of 64 under 1.2x; the exhaustion gate by construction and 0 of 24,631 chain-shaped seeds, max attempt 29); suite 103 of 103; CI success. Open, stated as open: the four-seed tail (p10 1.50x, p8 1.38x, p34 1.25x, p4 1.22x; main's ruling: the window model's unattributed residue with nil chip consequence; attribution for 0.3.23); the 10^6 chain-path count runs on as a strengthening line; the epoch draw costs about two attempts at 2.2 s once an hour; the owed measurements (G2, G3, the ladder, AMD on PC 1, the 2019-class core) do not gate Devnet 3. No further hash change rides 0.3.22. Devnet 3's object sets program_class_v4_activation_daa 0 and signals byte 7 from genesis. + +## 1. The candidate: release-0.3.22-node = fa7f854f (16:37:50Z, 17:37 BST) + +Three commits on 96161037: bd710a36 the sub-version 3 re-pin (byte 7, igneum-pow 017e7037, epoch-0 id a785001687d8688a, must-differ c120d796 / 1a423069 / a7886616); aded4620 era VDF (the era lane's f2ecf452, clean); fa7f854f the Devnet 3 object. The object: network igneum-devnet-3, flag `--devnet --devnet-suffix=3`, default p2p 26631 (ten above the previous suffix; gRPC, JSON and EVM on the devnet defaults unless passed); genesis 2026-10-07T00:00:00Z, payload "igneum-devnet-3 | 2026-10-07 | every upgrade on from block zero | coins here have no value | resets are announced", hash a6fa348e2a0fc6a5fa0ae3cb080160f5e2be865af71bac0068ca2fb8d1fcfd7b, bits 0x1d100000 (the DAA takes over after 600 blocks); active from DAA 0: difficulty v2, proving v0 and v1 (8 blocks a segment, 600 DAA, aggregator 1,000 bps, the fresh rule), finality v3, program class v3 and v4 (byte 7 from genesis, a one-day signal window), the latency ladder at rung 0, calibrated v1 fees, era VDF (main's ruling); at never (as on the live devnet, not in main's list): difficulty v3, the finality DAA-seconds rule, fork gate, peer directory, signing bonus, finality leave, pool split, consensus proof verify, exec restart (the chain executes from genesis). The node refuses --override-params-file on igneum-devnet-3 (mainnet, testnet, devnet suffixes 3 to 99; harness suffixes above 99 keep the file) and prints the digest with no file. Not in it: the N15 kept-datadir numbering class (p12-vast and pool-1 off by 2), 0.3.23's, the release note names it. Gates from 16:38Z: the release build on build-1 (gate priority); on build-2 the consensus crate whole, consensus-core, kaspa-pow with 017e7037's packs, the miner, the exec suite; then from the build the empty-datadir canary, the fresh-genesis digest agreement on two boxes, the late joiner, the shutdown under 1 s, the proving ids on a bare node. + +**build-1 for Devnet 3 (the build-server lane and the fleet, reconciled 17:40 BST), nothing started:** the seed a bare process on p2p 0.0.0.0:26631 (rpc 27630, json 27632, evm 27810, empty datadir /home/build/dn3seed); the observer node on Devnet 3 is the fleet's instance (/srv/hands/bin/run-observer-node-dn3.sh, appdir /srv/hands/observer-node-dn3, rpc 26650, json 28650, p2p 26651, evm 26850, its observer.mjs on dn3_ tables running); the second node1 on p2p 0.0.0.0:26671 (rpc 26670, json 28670, evm 26870, appdir /srv/hands/node1-dn3, --enable-unsynced-mining); ufw allows 26631, 26651 and 26671; four units installed and DISABLED (igneum-observer-node-dn3, igneum-observer-dn3, igneum-hash-origin-dn3.service and .timer at 08:30 UTC with --prefix dn3_). On the go, in order: the 0.3.22 pairs under /srv/artefacts/0322-fa7f854f/ with the evm-types read, devnet3.env and dn3.env pointed at that igneumd, then seed --go, node1 --go, observer-node --go, each read back by the first log line, the string count, the devnet-3 digest line, the genesis line and the server lines. + +**Main (17:4x BST):** fa7f854f accepted; the nine switches at never stay at never for the genesis (nothing untested flips under this clock); Devnet 3 is the chain they go live on by activation height, one at a time, each after its own gate, no further reset; consensus proof verify stays off until the proven share reads one. After genesis: the table of the nine (built and gated, built and ungated, not built; the owning lane; the earliest height) for the project lead. + +**The fleet's Devnet 3 set, STANDING at 16:44Z:** five boxes on five hosts (the hive package, the kill file, box-dn3.sh, a vote key each, the binary slot empty until the artefact lands): dn3-g1 RunPod 3070 (64.119.209.250, p2p mapped 21703) = the Devnet 3 HUB and default peer; dn3-g2 Vast 3070 Utah (154.64.230.67, p2p 27017) = the second genesis node; dn3-j1 Vast 3060 12 GB = the late joiner from empty; dn3-c1 Vast 3060 12 GB = the empty-datadir canary (12 GB, so the prover statement reads there); dn3-x1 Vast 3060 12 GB = spare and second joiner; hairpin checked (every Vast box reaches dn3-g1's mapped port and build-1's 26631). The cutover dn3-genesis.py (per box: the binary with its sha read back, box-dn3.sh with --devnet --devnet-suffix=3, appdir /root/fleet/dn3, no override, FRESH=1, UNSYNCED=1 on the two genesis boxes only, seeds dn3-g1, dn3-g2, build-1's 26631 and 26671; read back the string, the devnet-3 digest, the genesis hash line, synced, the first lock; nothing named on the old devnet), dry-tested. The gate dn3-gate.py: digest agreement g1/g2, the same first lock on both, the late joiner synced from them, the canary mining ten minutes with its blocks held by dn3-g1 and 0 rejects, shutdown under 1 s then the restart on the kept datadir, the proving ids on a bare node; one line per check with its UTC time, DN3 GATE PASS/FAIL. hub-1's second node staged (36610/36611/36790, outbound only, FRESH, MINE=0). Pay-by-key on the new chain through dn3-g1. The watcher on /srv/artefacts/0322-*/ starts the gate within the minute of the binary. Capacity for day one: a SECOND NODE PER STANDING BOX (box-dn3.sh on 36610/36611/36790, FRESH from empty, the box's existing key label on the new chain, MINE=1 with a second miner on the same card), rolled in three waves of 5/5/4 after the genesis pair locks, nothing stopped on the old chain; plus the five gate boxes and hub-1's and build-1's second nodes: about 22 voters; cost USD 9.2/day for the five gate boxes, the second nodes USD 0, the 0.3.21 warm set 11.52/day; the fallback a parallel set of fourteen 3070 pods (USD 44/day) only if the first wave shows card contention (the read: the live miner's rate and the dn3 node's template timing). Spend at 16:40Z: 406.49 of 1,000. + +**The 0.3.21 set, running on:** c22-1's wipe in IBD; the warm-set cases' window running; N15's live line: p2-4090-1b's kept snapshot tips were side-tip blocks on the hub's DAG, the node refused them rightly and loaded the hub's snapshot, healthy, no discontinuity line (the node lane holds the reading); p1-5090 now; roll lines p2-3090-2 2.3314 and p2-3090-3 2.8553 IGN verified by key. + +**Main (17:4x BST): yes to the second node per standing box**, three waves of 5/5/4 after the genesis pair locks, nothing stopped on the old chain, with two conditions: (1) a 24-hour exception to the one-miner-per-GPU rule, not a new rule: when the apps move to Devnet 3 and the old chain's miners stop, each box is back to one miner (written as an exception with its end in the fleet notes); (2) the contention read on wave 1 decides the fallback mechanically: a live miner's rate on any of the five down more than 10 percent against its hour-before mean, or the dn3 node's template latency above the 0.3.20 gate figure, takes the 3070 set for the remaining waves without asking; spend under the USD 1,000 ceiling either way. + +**The app side of 0.3.22 (the shipper):** the app's node starts on igneum-devnet-3 through its packaged config (Runtime.network "devnet" with devnet_suffix 3, read from igneum-app.json in the 0.3.22 package; the OTA update replaces the package, so the signed 0.3.22 update is the move), with node_dir devnet-3 (a fresh datadir beside devnet-v4, the old chain's kept for the way back), the node_override_file None on a suffixed devnet (the node refuses the file; the OTA manifest's consensus.override is ignored with a log line on devnet-3), the chain scene, the ladder, first-block and earnings reading the new chain from zero, the prover on the new chain's records; the manifest for the 0.3.22 publish carries channel "devnet-3". Cut after the genesis on its own branch release-0.3.22 off release-0.3.21's tip; published by signed update when Devnet 3 has 24 hours (main's clock). + +## 5. The genesis: 69d1b56e, 18:06:19 BST + +**The timestamp fault and the fix:** fa7f854f and 21d8f454 carried a genesis timestamp of 2026-10-08T00:00:00Z, so every block read "too far into the future"; the node lane's 69d1b56e sets 2026-10-07T00:00:00Z (genesis hash 4020cb4382e3fe4b…b925, test `every_compiled_genesis_lies_in_the_past_of_the_clock`). ab9af79f is void with it; the igneum-devnet-3 digest with no override file on 69d1b56e is 83eb50cdf2eda4cb…22b2. + +**Gates on 69d1b56e, every one green:** build-1 release build 18:03:03 BST; box suites on build-2 (kaspa-consensus whole 120 + 1 + 1 at 18:02:17, igneum-exec 36 at 18:03:09, kaspa-consensus-core 152 at 18:03:40, kaspa-pow 17 at 18:04:31, igneum-miner 25 at 18:05:22 against the sub-version 3 packs); the canary set from the artefact (object 7 / 1794, era VDF from 0, ladder rung 0, fees v1, shutdown 677 ms after SIGTERM, the override file refused exit 1 while the shared devnet still takes it, two empty nodes handshaking with equal digests, the shared-devnet node rejected with the network mismatch); the pack gate PASS by construction on dn3-g1 (miner c29f33bb = the pair's, the pack exported on the box, the hive 0.3.20 miner 4050c255 refused); the program id read back fce15bf61030be57 (see the correction below). + +**The pairs:** node-lane pair igneumd 0751598f (57,816,736 B) and igneum-miner c29f33bb under /srv/artefacts/0322-69d1b56e/node-lane/; the build-server lane's hands pair igneumd efb54938 (57,817,120 B, GLIBC_2.39) and igneum-miner 07246920 under /hands/, seed pair fb15cecf and f8c40e1c under /seed/ (the miners byte-identical to 21d8f454's: the miner does not embed the genesis). The shipper's ruling: the node-lane bytes stand as the genesis pair on dn3-g1 and dn3-g2; the hands pair goes on the joiners, hub-1 and build-1. + +**The genesis reading:** dn3-g1 (the Devnet 3 hub, 64.119.209.250:21703) up 18:04:55 BST, "igneumd/2.1.0-69d1b56e", digest 83eb50cd, "genesis 4020cb43… executed: chain id 4463", miner from 18:05:19, FIRST BLOCK ACCEPTED 18:06:19.920 BST ("PoW accepted c313ddac… by igneum-lottery-v2-bound, daa 0, epoch seed 4020cb43…"), 85 of 85 GPU blocks by 18:10, 287 by 18:14, 0 rejected. dn3-g2 (154.64.230.67:27017) up 18:17:58 BST on the same pair, synced from g1 (639 blocks at 18:18:52), mining from 18:18:15; 702 blocks, daa 702 at 18:19:08, 0 rejected on either; finality checkpoints 20 (985353b4…), 21 (e788fac0…, blue score 631), 22 (f45336bd…, blue score 660) identical on both logs. The genesis declared on that agreement at 18:25 BST (main noted it at 18:18 BST). The object's finality window is 7,200 DAA, so no checkpoint can lock before about 20:10 BST; the first lock is a follow-up line, not a gate (the fleet's check 2 re-lettered to "first common lock within 30 minutes of DAA 7200"). The go to build-1's seed (26631), node1-dn3 (26671) and the observer unit on the hands pair went at 18:24 BST; the joiners dn3-j1, dn3-c1 (ten-minute canary) and dn3-x1 place on the hands pair. Nothing in the go path reads GitHub (both lanes confirmed: /srv/artefacts, the box mirror for the observer clone, the dl host for the hive package and the kit zip). The executor on a fresh devnet-3 node logs "waiting for consensus to sync before the executor starts (the sink is 61,000 s old)" until the first block, then executes genesis: expected (the genesis is 17 hours old by design), not a fault; runbook row. + +**Program id correction (the Counter lane, 18:1x BST):** Devnet 3's epoch-0 class v4 program id is fce15bf61030be57 (read in the 0.3.22 miner's "cache ready" line on build-1 at 18:10:39 BST and on dn3-g1); a785001687d8688a is the SHARED devnet's epoch-0 id (genesis edc4fa84) and the kaspa-pow pairing pin, which is unchanged because the id follows the seed. Every Devnet 3 box's gate wants fce15bf61030be57 at epoch 0 and stops the miner on 1a4230699a6b9c60 or a785001687d8688a; the per-epoch form (the miner's line equals the node's seed-derived id, read each 3,600 DAA) is for after tonight. Both paired miners on dn3-g1 printed fce15bf61030be57, so the node drew Devnet 3's seed and the record is right. + +**The nine switches:** recorded as section 6.11 of docs/plans/counter-asic-3-node.md (branch ca3-v4-node e70535fc on the box mirror, 18:15 BST), one row per switch with state, owner, gate and the earliest Devnet 3 height; signing bonus is not gateable on 69d1b56e (c7ea1e21 silent_split missing) and is 0.3.23's; every height reads as lock time + DAA seconds at 1 block/s. + +**Found by the 0.3.21 wipe canary, fixed 18:14:35 BST:** the Hetzner live seed 188.245.5.161:26611 was still on the old sixteen-field object (digest eada4bda) one hour forty after the 0.3.20 sweep; it was never in a wave (the 15:56 go listed the hands and bps-seed, not it). Per tier: fleet voters, hub and pool-1 unaffected (they peer on the hub); every 0.3.20 app on the floor file saw a reject line at each dial of the seed and synced through the hub and node1 instead (c22-1 did); a fresh joiner configured with only the seed could not join. The build-server lane (infra/devnet/restart-seed.sh over the ops key) installed the c4459193 seed-class igneumd 4a2d8a8d and the floor file 294f1f80, unit igneumd-v4 down about 3 s, read-back "igneumd/2.1.0-c4459193", digest 4bbbe816 MATCH, 278 blocks accepted in the first minute. Rule 5 now names the seeds with a read-back line. + +## 6. After the genesis: the clocks, the rulings, the 0.3.22 tree (18:3x to 18:5x BST) + +**DN3 GATE PASS (the fleet, 18:36 BST):** digest and checkpoint agreement on dn3-g1/g2 (checkpoints 20 to 29 identical, lock line 855414eb identical), late joiner twice (dn3-j1, 911 then 1,099 blocks), canary blocks held (dn3-c1, 15 of dn3-g1's last 900), shutdown 589 ms, bare-node proving ids present; two of the six lines read by hand after script faults of the fleet's (inspect arguments reversed; a token read broken by spaces), both fixed and recorded. Eight nodes on five hosts plus build-1's seed, node1-dn3 and observer, all on 83eb50cd, about 1,900 blocks at 18:36 BST. The relay set dn3-relay, dn3-poison, dn3-twin rented for the cases. The first finality lock at DAA 7,200, about 20:10 BST; the second-node wave 1 on the standing boxes starts on that line (main's two conditions). + +**The two clocks (main):** the 0.3.22 apps publish at 18:30 BST on 8 October on green (the 24-hour line is 18:06 BST); the first Discord card (Devnet 3 + 0.3.22) publishes after the fleet's relay run on Devnet 3 reads CASES END with the relay cell read AND the 0.3.22 apps are out; the card names the first-block time, the chain id and the launch-first chip line from master 9b996d06, no prize; staged at scratchpad/r0322/discord-card-devnet3-0322.md, main reads it after the relay run. + +**The 0.3.22 app tree and its order (accepted by main):** release-0.3.22 at 27ab317e on the box mirror = release-0.3.21 44b63ac9 merged (7f07a37f) + driver-check 46cc41e9 (27ab317e; the eGPU driver-install hold and warning); app gate GREEN on build-2 at 18:33 BST (259 + 33 + 8, pre-push 56). Missing, in closing order: (a) the node pin = N15 dfae08e5 rebased onto 69d1b56e on release-0.3.22-node, gated, plus whichever switch heights are green by the cut; (b) the Windows node pair from build-1's cross and the payload inputs, the installer by the PC 2 job shape while GitHub is out, the Mac node pair and DMG on the Mac under the lock; (c) the hive 0.3.22 package with the sub-version 3 kit inside; (d) the manifest on channel devnet-3, KEEPING the floor file for the 0.3.20 and 0.3.21 apps until the intake shows no app below 0.3.22 for 24 hours (main's ruling; the 0.3.22 app ignores the file by construction); (e) the app's vote key hash to the intake and the publisher's --public ui arm; (f) node_peers adds dn3-g1 64.119.209.250:21703 and dn3-g2 154.64.230.67:27017 beside build-1. + +**the project lead's ruling on the nine switches (through main, 18:4x BST), executed by the node lane on Devnet 3 by activation height, each with its gate line and a read-back on every node, no reset, one at a time:** (1) peer directory, pool split, fork gate ON in that order, each height set the moment its 6.11 condition reads true; (2) difficulty v3, the finality DAA-seconds rule, finality leave up: mid-chain crossing tests on the fast-time harness tonight, each height set as its test goes green; (3) signing bonus: one paragraph for the project lead on whether it changes total minted supply or only who is paid, with the number; (4) mandatory proof verification ON after 24 hours of every Devnet 3 block proven on the hash-origin report, the fleet's provers on Devnet 3 from tonight, the share reported hourly; (5) exec restart never. **Mechanics (main):** a height is a constant in the igneum-devnet-3 Params of a node commit, rolled out by the sweep (one box at a time, commit string and height line read back, the hub first); never a file, no new signed-record mechanism; one commit may carry several heights staggered so the chain crosses them one at a time; a node that misses the commit forks off at the height, as designed, which is the test; each commit is a release of the node line (0.3.22, 0.3.23) and reaches the apps by the signed update. Recorded in 6.11 by the node lane as heights are set; each height to main as a clock reading. + +**Testnet re-arm (main, through the build-server lane):** the arming on fork e6dd3afd (digest 4fbb2152, genesis 01294fd3) is void (old object; a go on it hard-forks at sub-version 3). The node lane cuts a testnet genesis object on release-0.3.22-node in the Devnet 3 shape (byte 7 from genesis, every activation at 0 that Devnet 3 has at 0, era VDF at 0, a past genesis timestamp with the future-genesis test beside it, no override file, the testnet's seeds and chain id as they are); the build-server lane builds the seed-class pair under /srv/artefacts/testnet-/seed/ and dry-runs wave1-0320.sh against seed1/2/3 at height 0; nothing onto a seed and nothing mines before the project lead's word (not before 15 October, LG-2). + +**0.3.21 Windows, the toolchain finding (18:37 BST):** PC 2's installer job (take 2, 68 s) verified the payload (igneum-app.exe 151803c7 prints "igneum-app 0.3.21", igneumd.exe 49502cc7 "igneumd 2.1.0") and stopped on PC 2's toolchain: no MSVC (no window host "Igneum Miner.exe", whose host.cpp changed in update-return-21) and no Inno Setup 6 (no installer; winget refused by the job as told). Three shapes put to main at 18:45 BST: the Mac entry now and Windows later (the manifest carries a platform that lands later; 0.3.20 Windows apps do nothing until their entry arrives); winget Inno Setup on PC 2 (still no 0.3.21 host); the host by mingw on the box (dry compile asked) or Windows held until GitHub returns and windows.yml runs. deploy.sh carries --mac-only for shape (1); the full preflight stands for the Windows entry. diff --git a/docs/plans/release-rules.md b/docs/plans/release-rules.md index 6b849613b..83672fdd5 100644 --- a/docs/plans/release-rules.md +++ b/docs/plans/release-rules.md @@ -9,7 +9,7 @@ Every cut of the Igneum Miner app and its node runs under these. The dated plan 4c. **The proving ids gate (main, 7 October 2026, after the 0.3.20 blocker).** On every candidate, a node started on the LIVE override file reports both proving ids (the shard program id and the aggregator id) on its proving v1 start line, and a prover's first statement against it is accepted; a zero-id statement is the known-failed shape. It runs beside the kept-datadir read, since both share the warm pod. Why: c4459193 read the ids as unknown, built statements with zeros and refused every proof; a sweep would have stopped every prover's pay. 4a. **Every gate starts on every candidate the moment its binary builds, never after the pin (the project lead, 7 October 2026).** The digest and mixed-version gates, the kept-datadir start, the relay and poison cases and the wipe canary all begin on each candidate binary as it lands; a struck candidate's runs are stopped and its successor's begin. The post-pin wait is then the longest single form (about 80 minutes, the wipe), not the sum. 4b. **Warm pods per gate class (the project lead, 7 October 2026, ordered to the fleet lane).** The fleet keeps synced pods warm for each gate class so a case form's target starts at the tip (a kept copy of the live line, caught up), never from a kept copy far behind it; the wipe canary is the only full IBD in the set. -5. **Rollout in waves, each box read back (the project lead, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). +5. **Rollout in waves, each box read back (the project lead, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). The wave list is written, not remembered: every sweep's first wave names each Hetzner seed by address (188.245.5.161:26611 for the shared devnet; the testnet seeds when they move) beside the hands and the fleet, and the seed's row closes only on its own read-back line (string, digest, first accepted block) from the lane that holds its key (the build-server lane, infra/devnet/restart-seed.sh). Added 7 October 2026 after the 0.3.20 sweep left the seed on the old object for one hour forty, found by the 0.3.21 wipe canary's reject lines. 6. **Read-back is by commit string plus digest plus engine:** on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees `strings igneumd | grep -c igneum-pow/src/` above zero. The miner embeds no commit string; its pairing is the build line and the sha. 7. **igneum-pow pairing:** a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file). 8. **glibc classes:** HiveOS 2.31 (`--ship hive`, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (`--ship seed`), fleet 24.04 boxes native 2.39.