diff --git a/docs/analysis/chip-model-v3.md b/docs/analysis/chip-model-v3.md index e98ed5e42..40ba2a3ea 100644 --- a/docs/analysis/chip-model-v3.md +++ b/docs/analysis/chip-model-v3.md @@ -205,6 +205,8 @@ Per row: reads per hash = 128 f; items recomputed = 128 (1 - f); ops per hash = Correction, 7 October 2026 (the in-house adversarial pass, lane adv-cache-3, report 091edc34): the partial-store rows above and adv-cache's Q1b table price a chip that holds every k-th line of the 64-line chain and recomputes a read at offset o in o evaluations ((k - 1) / 2 on average). The exact pebbling optimum for the chain (dynamic programming, checked against exhaustive search at 10 to 16 lines) sits under that curve: blocks per read 16.0 against 31.5 at f = 1/64 (the one held line belongs at line 32, not line 0), 10.5 against 15.5 at 2/64, 6.09 against 7.5 at 4/64, 3.17 against 3.5 at 8/64, 1.45 against 1.5 at 16/64, equal from f = 1/2. So a chip holding 1/64 of the cache pays 9.3x the item's ops, not 17.4x; at f = 1/2 and above nothing moves, and the SRAM column and the full-store verdict stand (no point on the curve beats the full store under the op budget or under energy). Memory-bound rate = the ceiling / (128 f). Compute-bound rate = 50 T op/s / ops per hash (the section 1 budget). + +Second correction, 8 October 2026 (the in-house adversarial pass, lane adv-cache-2, report section 2.3 and its Q3(3) window-layer reading, tip 3f50d6c4): the partial-store rows model a chip that holds a fraction f of the ITEMS chosen uniformly, so it serves f of the reads and recomputes 1 - f. The item-read distribution is not uniform: the exact window-layer distribution (matching the 4,096-program census to four digits; top quarter mean 0.3382, top half 0.5811 of reads) lets a chip holding the hottest f of items serve 0.4219, 0.7188 and 0.8907 of reads at f = 0.25, 0.5 and 0.75 on the measured programs, so the f = 0.25 and f = 0.5 rows overstate the recompute share by up to 2.3x (1.8x on the first shard's read) and the f = 0.75 row by about 2.3x on the miss side. The f = 1 row, the SRAM column and the full-store verdict do not move (a chip that holds everything recomputes nothing either way), and no served number rests on f under 1; the partial-store rows stay as the uniform-store bound with this note until the hottest-f rows are drawn from the window distribution, which is the next pass of this section. The rate is the smaller; "binding" names it. Power = rate x (128 f x E_read + 128 (1 - f) x 6.3 nJ) + static (memory, controller, and 20 W for the recompute die's clocks and leakage when `f < 1`). Energy per hash = power / rate. "Gain, rate" = rate / 136.1 MH/s (per chip, the section 2 metric); "with the 3x factor" multiplies the compute-bound rate by @@ -357,6 +359,12 @@ Reading: NO. Class v5 with the shadow at zero leaves the strongest chip at 5.1x Per tier: a miner on class v4 pays the premium and gets the 2.1x to 3.9x chip ceiling in exchange; on class v5 with the shadow kept the ceiling stays and the dataset is the chain's; on class v5 with the shadow dropped the premium goes and the ceiling returns to 5x to 9x. The decision is the founder's; this section gives the number. +### 5.11 Two columns from the counter-asic-4 research file (7 October 2026, 22:3x UK; `docs/analysis/counter-asic-4-research.md` sections 15 to 19 at bca23f96, the research lane's reading, carried here as the chip model's own columns) + +The k column. k is the chip core's energy per op over the GPU's at the same operating point, and the model's 3.4x row takes k about 0.33 for an ALU-shaped core. On the public figures the int8 tensor tile is the one GPU block whose energy per op a chip at the same node cannot undercut with certainty: the 4090 measures 0.056 pJ per MAC; NVIDIA's 5 nm INT4 test chip reads 0.021 pJ per MAC at 0.46 V and about 0.1 at nominal (JSSC 2023, via Dally's NASEM slides; claimed), so INT8 at 2x to 4x that gives k 0.7 to 3 with the centre near 1; every ALU-shaped block reads k 0.3 to 0.8 on the same sources. A shadow built of tensor tiles at the ALU shadow's premium (about 11,400 u8 tiles per hash) therefore gives 2.1x at k = 1 and 1.6x at k = 1.5 and removes the k 0.3 column from the table; it needs a SIMD byte-dot verifier (the scalar one at 12.4 ms fails the 10 ms gate). This is a design candidate, not the shipped stream: the shipped shadow is ALU-shaped and its row stays 2.1x at k = 1 and 3.4x at k about 0.33. + +The capex column. The `f = 1` GDDR7 chip of 5.5 is USD 2.8 per MH/s of silicon and memory, which is USD 0.00016 per MH/s-hour of capex over two years against USD 0.000023 of electricity: capex-dominated 7x, as the 5090 is (USD 14.7 per MH/s at MSRP, 10x). A 64 MiB hot table adds about USD 15 of N5 die, the shadow core USD 25 to 40, an interposer USD 200, so the chip's capex reaches at most about USD 4.3 per MH/s: the per-unit capex wall is unreachable by 3x to 7x, and the break-even market cap moves only through the project cost (the mission lane's model: about USD 100 M with the N5 shadow core, about 200 M if the shadow runs per load and forces one die or an interposer; the per-load form behind that figure, the 16 x 27 placement, was closed on 7 October 2026 at night when it failed the value-level acceptance test across drawn eras, so the 200 M row rests on no construction shown to exist until a sound per-load class, one pass of a 432-instruction sub-block per load, is drawn, accepted and measured). Every figure here is modelled on cited or claimed parts; the research lane's microbench (20 probes, the mma_u8 and l2 rows the ones this model would take) is on PC 1's queue after the hot-table job. + ## 6. The per-day derivation (item 2) 6 October 2026, Counter ASIC 3.0 item 2, worker `derive` (`docs/plans/counter-asic-3-derivation.md`; everything diff --git a/docs/evidence.md b/docs/evidence.md index 4910bd485..07b80e10b 100644 --- a/docs/evidence.md +++ b/docs/evidence.md @@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml` | 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet | | 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet | | 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet | -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet | | 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet | | 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet | | 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet | diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index 09d7d35df..12a261bb8 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -29,7 +29,7 @@ Evidence locations referenced below: `docs/bench-log.md`, `proto-metal/TESTS.md` ### M1. The program space is tiny "Eleven integer ops, 64 instructions, 8 iterations, a splitmix register init. That is not RandomX. RandomX leans on a superscalar out-of-order CPU with floating point and branches. Yours is a sea of 32-bit ALUs and a memory bus. A chip for that is a weekend." -Status: Decided (6 October 2026, 17:35 UTC, by the owner; decisions item 1, corrected): no standing bounty. A team with a real 2x chip earns more by mining than any bounty pays, so a device bounty attracts nobody; the tiers announced at 17:25 UTC are withdrawn. The claim "under 2x" is backed by the paid independent cryptanalysis (the Monero route: four paid reviews, no bounty) and by the public benchmark with M22's metrics. Optional, the owner's call later: one cryptanalysis prize of USD 50,000 for a published 2x or better shortcut in the mixer, the chained cache or the acceptance rule, escrowed before it is named; nothing public before that. The claim stays a target until the audit and the benchmark have reported. Was: Open, program space counted, the claim stands as a target (5 October 2026, evening sweep). Was: Open, experiment scheduled. Sweep (5 October 2026): nothing runnable; the bounty, the public benchmark and a chip design are M22's decisions and hardware. The nearest number stays M16's arithmetic. +Status: Decided (6 October 2026, 17:35 UTC, by the owner; decisions item 1, corrected): no standing bounty. A team with a real 2x chip earns more by mining than any bounty pays, so a device bounty attracts nobody; the tiers announced at 17:25 UTC are withdrawn. The claim "under 2x" is backed by the in-house adversarial pass and by the public benchmark with M22's metrics. The claim stays a target until the audit and the benchmark have reported. Was: Open, program space counted, the claim stands as a target (5 October 2026, evening sweep). Was: Open, experiment scheduled. Sweep (5 October 2026): nothing runnable; the bounty, the public benchmark and a chip design are M22's decisions and hardware. The nearest number stays M16's arithmetic. Decision owner: the founder, decided 6 October 2026 (`docs/plans/ledger-decisions.md`, outcomes section). Sweep (5 October 2026, evening): the program space, swept as arithmetic from the version 2 generator (`igneum-pow/src/generator.rs`: 16 load slots as a uniform 16-subset of instructions 1 to 63, then nine draws per instruction, 592 draws per program; 10 non-load operations with weights 12/10/8/8/8/7/6/6/6/4; 8 registers; a 31-way rotation, a 32-way bit and a 5-way mask per instruction; two 32-bit immediates). Counting choices: the slot subset is 48.4 bits; the operation draw carries 3.26 bits of entropy (of log2 10 = 3.32); operations and registers alone give about 770 bits per program; with the rotation, bit and mask fields about 1,550 bits; with the immediates about 5,650 bits, all capped by the 256-bit seed, so the space a chip has to serve is 2^256 distinct programs drawn from a structure of about 2^1550 shapes, and the critic is right that it is a small instruction set: 12 operations, 8 registers, no floating point, no branches, by design (vendor-identical rounding). What the sweep adds to the ledger's answer is the number that matters for a fixed-function design, the spread a chip must absorb: under generator version 2 every accepted program does 120 to 128 distinct loads per hash (median 128.00, 20,000-program census), so the per-program hash-rate spread on a memory-bound device is the 1.10x residual the census measured, not the 2.7x of version 1; the chip's advantage therefore cannot come from the program (it is one fixed memory-bound shape) and must come from the memory system or from the recompute route, which is M16's cost model (`docs/analysis/m16-recompute-attacker-2026-10-05.md`: 1.5x to 2.4x at equal integer budget before any fixed-function factor, 3x to 6x with one, and the mixer-cost lever that cuts it below 1x). The experiment that closes M1 is unchanged: the bounty and the public benchmark (M22, decision owner the founder). @@ -1587,7 +1587,7 @@ Run (5 October 2026, night): `python3 sim/difficulty/record_report.py devnet-202 ### M22. The ASIC challenge has no scoring rules, and 2x is not the economic line "Your bounty says 'beats a GPU by more than 2x'. Per what? Hashes per second, per joule, per dollar, on the average program or the worst hour? A chip at 1.6x with half the capital cost wins. And nobody has published eligible hardware, funding or a judge." -Status: Decided (6 October 2026, 17:35 UTC, by the owner; decisions item 1, corrected): no bounty, so no bounty terms; M22's metrics (hashes per second and per joule per program over at least 100 epochs as a distribution, capital cost per unit of hash rate at a stated volume, the longevity term, the shortcut classes scored separately) become the public benchmark's scoring rules and the brief of the paid cryptanalysis; the optional USD 50,000 cryptanalysis prize, if ever set, is escrowed before it is named. Was: Open, decision for the founder (terms, judge and funding) and experiment scheduled (extends O-1.17). Sweep (5 October 2026): nothing runnable; the terms, judge and funding are the founder's decision. +Status: Decided (6 October 2026, 17:35 UTC, by the owner; decisions item 1, corrected): no bounty, so no bounty terms; M22's metrics (hashes per second and per joule per program over at least 100 epochs as a distribution, capital cost per unit of hash rate at a stated volume, the longevity term, the shortcut classes scored separately) become the public benchmark's scoring rules and the brief of the in-house adversarial pass. Was: Open, decision for the founder (terms, judge and funding) and experiment scheduled (extends O-1.17). Sweep (5 October 2026): nothing runnable; the terms, judge and funding are the founder's decision. Decision owner: the founder, decided 6 October 2026 (`docs/plans/ledger-decisions.md`, outcomes section). Answer: Correct. M1 and O-1.17 name a bounty for "more than 2x" without a metric, a judge or a fund, and 2x is a design target for the hash, not an economic threshold: a chip at 1.5x per joule and 3x per dollar of capital is an economic ASIC whatever the hash-rate ratio says. The scoring rules go out with the January 2027 benchmark: hashes per second and per joule measured per program over a published set of at least 100 epochs, reported as a distribution (worst decile, median), never as one average; capital cost per unit of hash rate at a stated volume; a longevity term against the instruction-family reserve and the dataset growth of spec 1.13; and the shortcut classes (recomputation, partial storage, weak-program selection) scored separately. Eligible hardware assumptions, the judge, the reward and the payer are the founder's decisions (fud-fixes row 50: the payer is the entity). The supportable public claim until a design has been scored: across the tested workloads and the stated economic assumptions, consumer GPUs remain competitive against the best independently proposed specialised design. Extends M1, M16 and C13. @@ -2503,11 +2503,7 @@ Owed (recorded, not run, by the founder's word): G2 (the CPU verifier on 1,024 h Owed (recorded, not run, by the founder's word): G2 (the CPU verifier on 1,024 hashes per card) on the amended stream; G3 (the Metal fuzz, edge, stats and determinism runs) on the amended stream; the hash-rate ladder re-measure on the M5 Max and the RTX 5090 (the amendment changes the base program's source draws, not the op mix or the load count, so the latency-bound rows of `docs/analysis/latency-shadow-2026-10-06.md` are expected to hold within their spread; unmeasured); AMD (the RX 9070 XT, PC 1); the 2019-class verifier core (O-1.14); F8's phase E (the 64-seed dynamic census) on the amended stream, which is the attack-pass lane's and the test of the per-op table. The row reads FIXED-AND-PASSED only after phase E passes against the amended class. -Status: Fixed in part, finding bounded, stated (7 October 2026, night, the Counter ASIC lane's words): class v4 sub-version 3 (igneum-pow 017e7037, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under 1.2x with the four-seed tail accepted by the coordinator as the window model's unattributed residue (no chip consequence); the pass then attributed the class by value (eight live hot sets at 1.54x to 2.24x in the lowest 30 of 29,032 accepted programs, each about 1 MB of items at 0.3 percent of reads, 1.002x to a chip); class v5 (1c420786, frozen 21:53 UK) carries the fix as rule (c'''), the per-site distinct-index floor at 0.995 on the state flag (its census refuses 2.435 percent of accepted programs; seven of seven live hot sets refused at 0.9821 to 0.9919; the eighth's ratio owed tonight), with a named residual (three mild shadow-block-written concentrations at 0.9992 to 0.9997, about 1.0004x, a value-level test in the next class); the record is `docs/plans/counter-asic-3-status.md` section 7c and the class v5 design's section 14. The eighth live hot set (seed 122960, id 4be7393ab6c84802, the deepest found: X_f +0.111 percent, 1.54x the window model, its hottest item at 475,616 reads from an all-ones source) reads minimum site 12 at 0.9824 at the acceptance's own 2^20 sample (live 0.9822), refused by class v5's (c''') floor at 0.995; so the floor refuses eight of eight live hot sets by X_f at or above f found in the tail of 88,051 accepted programs (minimum sites 0.9821 to 0.9919) against 0 hot sets in 20 random programs; what it misses stays the three mild shadow-block-written concentrations at 0.9992 to 0.9997 (Devnet 3's first program among them), about 1.0004x to a chip, the value-level test in the next class (22:41 BST; the logs under `docs/analysis/cryptanalysis/logs/adv-accept/` on branch adv-accept; the v5 design's section 14). The RTX 5080 grid's knee is not in tonight; X37 keeps the 5080's stock premium only. - -## Genesis forward-compatibility entries (7 October 2026, mission item 8, branch `genesis-forward`) - -The three genesis fields of `docs/analysis/mission/mission.md` section 2.8, built on the node fork branch `genesis-forward` (from release-0.3.19-node dc141409) and the repo branch `genesis-forward`; the design and the gates in `docs/design/genesis-forward.md`. Every switch is never on the devnet (its digest c562d70e... does not move); the testnet genesis sets all three (the testnet lane re-pins and re-digests). +Status: Fixed in part, finding bounded, stated (7 October 2026, night, the Counter ASIC lane's words): class v4 sub-version 3 (igneum-pow 017e7037, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under 1.2x with the four-seed tail accepted by the coordinator as the window model's unattributed residue (no chip consequence); the pass then attributed the class by value (eight live hot sets at 1.54x to 2.24x in the lowest 30 of 29,032 accepted programs, each about 1 MB of items at 0.3 percent of reads, 1.002x to a chip); class v5 (1c420786, frozen 21:53 UK) carries the fix as rule (c'''), the per-site distinct-index floor at 0.995 on the state flag (its census refuses 2.435 percent of accepted programs; seven of seven live hot sets refused at 0.9821 to 0.9919; the eighth's ratio owed tonight), with a named residual (three mild shadow-block-written concentrations at 0.9992 to 0.9997, about 1.0004x, a value-level test in the next class); the record is `docs/plans/counter-asic-3-status.md` section 7c and the class v5 design's section 14. The eighth live hot set (seed 122960, id 4be7393ab6c84802, the deepest found: X_f +0.111 percent, 1.54x the window model, its hottest item at 475,616 reads from an all-ones source) reads minimum site 12 at 0.9824 at the acceptance's own 2^20 sample (live 0.9822), refused by class v5's (c''') floor at 0.995; so the floor refuses nine of nine live hot sets by X_f at or above f found in the tail of 269,250 accepted programs (minimum sites 0.9809 to 0.9919; the ninth, seed 228763 from a non-saturated source, at 0.9809 on 8 October 2026) against 0 hot sets in 20 random programs; what it misses stays the three mild shadow-block-written concentrations at 0.9992 to 0.9997 (Devnet 3's first program among them), about 1.0004x to a chip, the value-level test in the next class (22:41 BST; the logs under `docs/analysis/cryptanalysis/logs/adv-accept/` on branch adv-accept; the v5 design's section 14). The public sentence (the coordinator's wording, 7 October 2026, night; the count moved to nine at 01:13 BST on 8 October when the ninth live hot set, seed 228763 from a non-saturated source, read 0.9809 and was refused): nine of nine hot sets refused; the diffuse era-stride excess, bounded under 0.1 percent of a hash's reads per site, is not caught by the floor and is the next class's test. The reason, read by the in-house pass (adv-cache-2) and the class v5 lane together: the distinct-index count at 2^20 sees concentration on few word indices whatever their source, saturated or not (the hot sets put about 3 percent of a site's reads on 512 indices, so the ratio falls to 0.981 to 0.992; the final tally 9 of 9 live hot sets and both single-item programs refused, 7 clean-live programs refused among the 12 deepest, 3 mild residuals missed) and not a diffuse excess over the top 0.1 percent of items (16,384 items), which is what the era-stride low-bit law produces (13 of 27 drawn-era programs carry a site over 1.04x, 8 over 1.2x, worst 1.75x; 0 of 29 refused at the 2^20 sample, minimum sites 0.9965 to 1.0000); its chip value is about 1.0024x at the worst site read, under this row's bound by an order; the row for it is AP-F8-6. The RTX 5080 grid's knee is not in tonight; X37 keeps the 5080's stock premium only. ### AP-F8-4. The program id's derivation text omitted generator 4's sub-version suffix (interoperability, documentation; no object change) @@ -2517,6 +2513,19 @@ Fix (15008aca and 0f45c8be on ca3-v4-amend, landed on master through the gate on Status: Fixed (7 October 2026, night): the id and its derivation text come from one byte recipe, every pinned pack's id re-derives from its own text in the suite (the igneum-pow suite on box 2 green at 0f45c8be: 64 + 2 + 7 + 4 + 19 + 2 + 7), the spec states the suffix; no object moved. +### AP-F8-5. The public specification did not describe the shipped acceptance rule (documentary; no object change) +"An implementation written from docs/spec/01-lottery-hash.md section 1.4.6 at 017e7037 mines a different program from the node on 264 of 400 epochs." Found by the in-house pass adv-accept-3 (report-acceptance-rule-3.md at 0c150e3c, finding 3, section 6.2, 7 October 2026, night): the text described (a), (b) and (c) with a 32-attempt cap and an id without a suffix, while the code adds (a') with the shared-operand rule, (c'), (c'') at 2^20 evaluations, the 256-attempt cap keyed on the class v4 shape, the total draw with the last resort, generator 4 and the sub-version suffix, and executes the 256-instruction shadow block 27 times per iteration inside the acceptance interpreter. Measured (sweep 97, 400 seeds, 1,317 attempt verdicts): 759 verdicts differ (758 the code rejects and the text accepts: (a') 733, (c'') 15, (c) 10; 1 the other way, the shadow block changing a (c) statistic); 264 of 400 seeds choose another attempt; the parts the text did carry, (a) and (b), agree on every row. + +Status: Spec fixed (7 October 2026, night, the site audit lane by main's order, branch spec-accept-23): sections 1.4.3 and 1.4.6 of `docs/spec/01-lottery-hash.md` rewritten to the shipped rule at igneum-pow 017e7037 with every constant named and every order of operations stated (1.4.3: the two per-register states of the draw, the dataflow table, the shared-operand rule, the shadow block's draw and the draw counts per class; 1.4.6.1 to 1.4.6.6: (a) cyclic over two passes, (b), (a') to the fixpoint then a checking pass, (c) with the shadow executed and its limits in a table, (c') and (c'') with the integer form of the ratio compare, the attempts and the two caps with the measured per-part rates, the last resort stated as unreachable and unverified, the program id with the generator-4 suffix, a constants table in the shape the crate's read-back test parses, the pinned ids a reader must reproduce); section 1.7 gains the shadow block's execution; section 1.13.1 names the two consumed era draws. The hash lane's `igneum-pow/tests` read-back test parses the two tables against the crate's `pub const` items and derives every pinned id (its landing is the row's check; AP-F8-4 carries the derivation-text half of the same finding). Fixed on two measurements by the finding lane: Q4c at master 8b834634, before the closed-form dataset was stated, a text-only implementation of sections 1.3, 1.4.2, 1.4.3, 1.4.6, 1.6, 1.7 and 1.13.1 re-derived the 400 epoch programs of sweep 97 under the Devnet 3 era with 0 of 400 differing on any field and one function (`dataset_elem`) taken from the crate (report section 6.5, log 983-textderive-8b834634.tsv); Q4d at master 56eebc0d, with `dataset_elem` written from 1.4.6.4 and its two pinned vectors reproduced, 0 of 400 differing with 0 crate imports (report section 6.6, log 984-textderive-56eebc0d.tsv, 8 October 2026, 01:5x UK). + +Answer: Correct, and the largest divergence source the pass found was documentary. The rule the chain runs was right; the text a second implementer would read was three sub-versions behind it. The fix is the text, written to the code line by line, and a test that fails when the two drift again. + +Evidence: `docs/analysis/cryptanalysis/report-acceptance-rule-3.md` sections 6.2 to 6.4 (branch adv-accept-3); `docs/spec/01-lottery-hash.md` 1.4.3, 1.4.6, 1.7, 1.13.1 (branch spec-accept-23); `igneum-pow/src/accept.rs`, `igneum-pow/src/generator.rs` at 017e7037. + +## Genesis forward-compatibility entries (7 October 2026, mission item 8, branch `genesis-forward`) + +The three genesis fields of `docs/analysis/mission/mission.md` section 2.8, built on the node fork branch `genesis-forward` (from release-0.3.19-node dc141409) and the repo branch `genesis-forward`; the design and the gates in `docs/design/genesis-forward.md`. Every switch is never on the devnet (its digest c562d70e... does not move); the testnet genesis sets all three (the testnet lane re-pins and re-digests). + ### GF1. A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point "When a quantum computer comes, every BLS vote key is forged and the chain has no way to change the scheme without a fork of the kind you say you never need." diff --git a/docs/ledger-public.md b/docs/ledger-public.md index fc004eb61..e20d55ac6 100644 --- a/docs/ledger-public.md +++ b/docs/ledger-public.md @@ -2,7 +2,7 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository. -192 items. By status: Conceded, stated 52; Fixed 31; Decided 22; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Spec fixed 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed, stated; restated 1; Fixed, stated; restated further 1; Fixed in part, finding bounded, stated 1; Fixed as a genesis lever, measurement owed 1. +193 items. By status: Conceded, stated 52; Fixed 31; Decided 22; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Spec fixed 2; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed, stated; restated 1; Fixed, stated; restated further 1; Fixed in part, finding bounded, stated 1; Fixed as a genesis lever, measurement owed 1. | Id | Claim or criticism | Status | What was done | Evidence | |---|---|---|---|---| @@ -194,6 +194,7 @@ Generated by `tools/ledger/export-public.mjs` from `docs/fud-ledger.md`; a gate | P23 | An unwound transaction leaves the node's view until its sender resends it | Fixed on a branch, pending merge | a fork a commit (the P23 commit, on the merge of `ledger-fixes` and `ledger-fixes-2` onto the 0.3.11 fork tip a commit); `EvmPool::on_chain_removed` (igneum/exec/src/pool.rs) and `ExecService::requeue_unwound`… | [igneum/exec/src/pool.rs](../igneum/exec/src/pool.rs) | | AP-F8-1 | A load whose source was last written by `or`, `mul` or `mulhi` makes a cross-hash hot set | Fixed in part, finding bounded, stated | Class v4 sub-version 3 (igneum-pow a commit, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under… | [docs/analysis/ca3-v4-uniform.md](../docs/analysis/ca3-v4-uniform.md) | | AP-F8-4 | The program id's derivation text omitted generator 4's sub-version suffix (interoperability, documentation; no object change) | Fixed | The id and its printed derivation come from one byte recipe (`generator::IdRecipe`, `program_id_recipe`, `program_id_class_recipe`, `Program::program_id_derivation`), so the two cannot drift; the emitter prints that… | [igneum-pow/tests/derivation.rs](../igneum-pow/tests/derivation.rs) | +| AP-F8-5 | The public specification did not describe the shipped acceptance rule (documentary; no object change) | Spec fixed | Sections 1.4.3 and 1.4.6 of `docs/spec/01-lottery-hash.md` rewritten to the shipped rule at igneum-pow a commit with every constant named and every order of operations stated (1.4.3: the two per-register states of the… | [docs/analysis/cryptanalysis/report-acceptance-rule-3.md](../docs/analysis/cryptanalysis/report-acceptance-rule-3.md) | | GF1 | A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point | Fixed | The byte costs nothing now and a fork later. | none named | | GF2 | A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration | Fixed | The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. | none named | | GF3 | A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant | Fixed as a genesis lever, measurement owed | Consumer LLC is 96 to 128 MB today and datacentre 256 MB (`chip-model-v3`, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. | none named | diff --git a/docs/plans/counter-asic-3-public-text-2026-10-07.md b/docs/plans/counter-asic-3-public-text-2026-10-07.md index ee0afaded..583a12c57 100644 --- a/docs/plans/counter-asic-3-public-text-2026-10-07.md +++ b/docs/plans/counter-asic-3-public-text-2026-10-07.md @@ -20,7 +20,7 @@ The chip model. We price the strongest chip we can design against an RTX 5090 an | When a stored-dataset chip pays for itself | at about USD 100 M of market cap in the first two years, not before | modelled, 7 October 2026 | | The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class) | 5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x) | modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state | -What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word. +What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet. ## 3. The miner page's line @@ -30,4 +30,4 @@ Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 35 | # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification | |---|---|---|---|---|---|---|---| -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet | diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index 48a1c0d6a..43ea10337 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -465,7 +465,7 @@ Reading: the class v4 premium is 145.3 W at the unlocked clock (not the 80 W of | 1,200 | 133.80 | 305.1 | 0.439 | 129.54 | 215.7 | 0.601 | 1,192 | | 1,100 | 122.43 | 287.3 | 0.426 | 118.70 | 209.4 | 0.567 | 1,087 | -The knee by main's rule (more than 1 percent lost against unlocked): 1,300 MHz on both classes (the rate within 1.5 percent of unlocked down to it; v3 falls 5.1 percent at 1,200, v4 10.5 percent at 1,100); the best MH per watt one step past it: v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W, 168.6 W recovered for 2.2 percent of rate), v3 at 1,300 (134.62, 223.3 W, 0.603, 106.6 W for 1.4 percent). The v4 premium 143.8 W unlocked, 81.8 W at the best points; the v4 rate 0.25 percent over v3 unlocked and 0.61 percent under at the best points; the residual at the floor is the shadow's ALU work, not the clock. Per tier: a 5090 owner on class v4 locked at 1,200 to 1,300 MHz draws 305 to 313 W instead of 474 for 1.5 to 2.2 percent less rate, MH per watt up 49 to 52 percent; the Ember knob (0.3.24, the hash lane on the engine side, the UI lane's drawing) carries these as its reference rows. A FAULT FOUND AND FIXED: the steps 1,000 down to 300 and the closing reset got no answer from the Power Helper and the card sat at the 1,100 lock for about five minutes after the job (118 to 122 MH/s live); the installed app's own Ember tune on the 5080 wrote the same cmd.txt with higher sequence numbers while the script wrote lower ones, and the helper skips any sequence at or under the last run; the restore job run-ca3-pc1-clocks-restore-20261007 (exit 0 at 20:45:58Z) put the 5090 back at 2,865 MHz; the fix 45f9497f on the mirror (the sequence base from helper.log and cmd.txt, re-based after a timeout, an unanswered lock stops the grid, the task restarted before every reset); the rule for the knob: it takes its sequences from the engine's counter and no script shares the file with a running tune. The driver's floor below 1,100 is unmeasured. THE PC 1 QUEUE after the shipper's 0.3.23 host job (main, 21:5x UK): the 5080 full grid with the fix; the research lane's SM-sparse kernel job (the hash on a fraction of the SMs, several chains per thread, the rest clock-gated; the research lane hands the kernel to the hash lane); the third 5090 pass from 1,100 down to the driver's floor at the tail; then the 9070 XT G1 and ladder, the v5 AMD bench, item 6 on AMD, the 5080 and 9070 XT tunes, the L2 cache-policy hot table; each exit line to the shipper and the coordinator; the honest site sentence (the premium at the knee and the floor it buys, labelled measured, the Ember knob named as how a user gets there) once the 5080 reads. THE DERIVATION FINDING FIXED (the hash lane, 15008aca and 0f45c8be on the mirror): one byte recipe (generator::IdRecipe) builds the id and the printed text; program.json states the generator 4 suffix and the rung form; spec 1.4.6 corrected (class v5 = generator 5, no suffix); tests/derivation.rs re-derives all 18 pinned packs from their own text (the plain text gives 8aa9f185d63f269e for the devnet v4 pack, the known-failed case); 38 packs' program.json re-exported with ids, kernels and fingerprints byte-identical; the full igneum-pow suite green on box 2. CLASS V5 FROZEN: class-v5 1c420786 on both box mirrors at 21:53 UK (the (c''') floor with its number; section 14 with seven of seven live hot sets refused at 0.9821 to 0.9919, seed 170 at 0.9880 the seventh, and the three mild residuals at 0.9992 to 0.9997 named at about 1.0004x; the pinned pack unchanged; the flip-stale harness PASS on the matched binaries at 21:03 UK; the AP-F4-1 first form and the AP-F1-1 shadow rule, the latter's measured trigger 11 permille maximum over 6,000 first draws against the 30 bound, 0 redraws; the igneum-pow suite green on box 2: 73 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7; the gate GREEN at 58 checks). The kits lane: the 0.3.24 kit is packs-ca3-v5-20261007T183921Z.zip sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 (state.igsd1 included), fingerprint 82b19cbde8557ea5 on Metal, Apple OpenCL and a CUDA 4090; AMD on PC 1's queue, Intel deferred; the shipper has the line. The attack-pass lane runs F8 at 2^24, F9 at 10^5 and F1 on 1c420786 under class v5. The v5 lane's next commit on the freeze: AP-F4-1 in the agreed form (cost at most 205 against the median 226, w32 without the position-32 digit, k >= 1 and all-ROT-equal rejected, the known-failed day 29,337 = 2050-04-28) and the verified last resort (part (a) repaired by re-sourcing stale loads, then the whole rule over a 256-candidate scan, known-failed first on adv-accept-3's adv3/steer/2); both move the stream only on days and seeds the chain never reaches. THE FOURTH EXCEPTION ON THE RESTART STEP (the fast-time lane's held-miner run on the third pair 63524e28, 20:4xZ): the IBD catch-up's body sync anchored on the node's own sink and moved only on a whole chunk's successful join, so with the honest headers arriving as one chunk failing on its v5 tail it fetched nothing and the executor never reached the seed block; the relay hold-off and the mining hold from the earlier fixes read green on that run. FIXED by the node lane at f0c56f50 (the refused chunk split by consensus's own record, the anchor moved to the highest validated header, the honest v4 prefix through the seed block, only the unvalidated headers deferred; kaspa-p2p-flows 38). PAIR 4 = v5-object-0323 c8f9b383, re-archived from the frozen 1c420786 (generator.rs and accept.rs moved since ab6f980b, memhard.rs not), building on build-1 at gate priority since 20:54:32Z with the line's gates beside it; the restart step's PASS must come from pair 4; the object commit lands the minute it does, with dn3-g1's DAA at the cut plus 7,200 rounded up to the 3,600 boundary and its UTC clock named; the testnet lane told to pair its re-cut with 1c420786. The crossing clock is not yet a reading: about 22:15Z (23:15 BST) at the earliest if every line reads green on its first pass. The site audit lane: no other "12 days" form served; its row-17 edit keeps main's outside-check clause and adds the 5090 efficiency numbers. THE CHIP TEXTS, THE X9 WORDING RETIRED (main's order from the counter-asic-4 research file d7721ebe, 22:0x UK): the withdrawn Antminer X9's claimed ratio ("a third of a CPU's energy per RandomX hash") is against a CPU core (about 100 pJ per instruction, Horowitz and Dally, claimed), not a GPU lane (6.5 to 10.4 pJ measured), so a chip three times better than a CPU is worse than a GPU lane per op and the X9 is not a pessimistic chip core against us. The served texts (the home line, the litepaper's lead, chip table, ladder sentence and chip bullet, /claims through it, the miner line, evidence row 17) now give the floor and the premium as measured numbers at the 5090's knee: the chip at 2.1x per joule with a core as good as a GPU lane (k = 1) and 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the shadow's premium 81.8 W at the best points (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W, 7 October 2026), Ember Tune's core-clock knob named as how a user gets there; the ledger text check's pins X35 and X36 moved with the wording; no "3.9x" remains on any served page. One number stated against main's wording: main's line read "2.9x with one three times better", which in the research file is the figure for the RE-WEIGHTED op mix (row 3, held by the coordinator until the SM-sparse read); today's mix at a core three times better reads 3.4x in the same file, so the served text carries 3.4x and the 2.9x waits for the re-weight to ship. THE RESEARCH FILE's TWO ORDERS: (1) the texts as above; (2) one zero-code measurement at the PC 1 tail after the third 5090 pass: the 5 October hot-table packs (packs-ca2-hot, 32 and 64 MiB) with the worker's `--variant ldcs` (dataset loads streaming, evict-first; the hot loads plain and L2-resident) against base on the 5090, the rate ratio g and the watts (the 5 October rows without the hint g 0.84 to 0.87); the one class where a chip's cost per op (a 64 MiB SRAM read, 0.2 to 0.5 nJ approximate) may exceed the GPU's (an L2 hit, 0.1 to 0.3 nJ); Metal has no such hint. The shadow stays at rung 0; the op-mix re-weight waits for the SM-sparse read (the research lane's worker variants sp170/85/43/21/11-w32, one block of 32 warps per SM, run through the hash lane's efficiency script in its ca4 mode at 4f3a064e; the no-prompt and sequence rules hold by the same code). THE 0.3.24 PAIRING RULED (the shipper, 22:1x UK): the v5 object commit pairs with the frozen class-v5 1c420786 as it stands (the gates and the attack-pass lines run on it); the post-freeze fix 8ca66afa is 0.3.25's pairing. 0.3.25's FIRST ROW: class-v5 8ca66afa (both mirrors, 22:10 UK, on 1c420786): (1) AP-F4-1 in the agreed form (decc7c17): the day's draw rejected when cost A = 64 + sum(w32(MUL_i) - 1) is at most 205 against the median 226, w32 over bit positions 0 to 31 (the position-32 carry digit dropped), any MUL with w32 at most 3 rejected (k >= 1), the eight ROT all equal rejected, a rejected block redrawn whole from the continuing stream; known-failed first on chain day 29,337 (2050-04-28): the sub-version 3 block of that day read cost 203, rejected at 205 and redrawn under class v5. (2) Class v5's verified last resort: the rewrite, then repair_stale_loads (a stale load re-sourced to the lowest register written since its last load, to a fixpoint), then the whole rule over a 256-candidate scan from the cap; the unchecked fallback past the scan under 1e-300; known-failed first on adv-accept-3's adv3/steer/2 (the sub-version 3 rewrite fails part (a) at instruction 47 reading r3; the repair restores (a) moving only load sources; class v5's last resort passes at attempt 256, id 9b29c9481f6941d4; steer 11, 33, 56, 58 and 77 pass too); sub-version 3's path untouched. The stream moves only on days and seeds the chain never reaches: the pinned v5 packs byte-identical, the fingerprint 82b19cbde8557ea5 and the epoch-0 id e5a4ac5978462156 unchanged; the igneum-pow suite green on box 2 (74 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7), the gate GREEN at 58 checks. The harness's class-walk case (v4 floor 0, v3 never) read FAIL on the unfixed fork 546fe4b5 (the known-failed shape, 22:08 UK) and runs on pair 4. THE IN-HOUSE PASS, THE EIGHTH HOT SET (adv-accept, 22:06 BST, the wider sweep over 88,051 accepted programs): seed 122960 (id 4be7393ab6c84802, the lowest 256-unit ratio at 0.9885) reads live at 2^24 X_f +0.111 percent, X/f 1.11, 1.54x the window model, with the heaviest single item measured tonight (0x81ad88 at 475,616 reads, 0.022 percent of all reads, 16x 100767's hottest) from an all-ones source at instruction 4 (writer shfl at 3); site 12's saturated-source share 0.353 percent, a third of (c')'s limit; the other four lowest 256-unit proxies clean live, so the 256-unit proxy is noise at its own extreme and the 2^20 ratio is the selector; the tally 8 hot sets in 30 tail seeds against 0 in 20 random; the price unchanged (0.34 percent of reads on 1 MB, 1.002x); its minimum-site ratio at 2^20 against the 0.995 floor OWED (ordered first), deciding whether the freeze record reads eight of eight refused or names the first hot set the floor misses. THE 5080 AT STOCK (run-ca3-pc1-v4-eff-5080-20261007-b, exit 0 at 21:03:02Z, the card alone, 60 s, both fingerprints matched): class v4 71.43 MH/s at 255.1 W (0.280 MH/W, sm 2,958, mem 14,801 MHz); class v3 71.30 at 170.7 W (0.418); the v4 premium 84.4 W (49 percent over v3's draw), the rate 0.18 percent over v3; against the fleet's rented 5080 (71.16 MH/s at 143.4 W on class v4, driver 580) the rate agrees to 0.4 percent and the watts do not (255 against 143), a question to the fleet lane (its sampler, a cap on the rented card, the memory clock) before either row enters the public table; the lock grid did not run in -b (a PowerShell function defined below its first call left the script without the helper path; nothing set, nothing to restore), republished as -c at 21:07:10Z with the full grid (unlocked to 300 MHz, about 58 minutes). The site audit lane's row 17 and litepaper paragraph carry the 1,400 MHz rows labelled measured, with the best-points clause asked beside the 88 W at 1,400. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +The knee by main's rule (more than 1 percent lost against unlocked): 1,300 MHz on both classes (the rate within 1.5 percent of unlocked down to it; v3 falls 5.1 percent at 1,200, v4 10.5 percent at 1,100); the best MH per watt one step past it: v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W, 168.6 W recovered for 2.2 percent of rate), v3 at 1,300 (134.62, 223.3 W, 0.603, 106.6 W for 1.4 percent). The v4 premium 143.8 W unlocked, 81.8 W at the best points; the v4 rate 0.25 percent over v3 unlocked and 0.61 percent under at the best points; the residual at the floor is the shadow's ALU work, not the clock. Per tier: a 5090 owner on class v4 locked at 1,200 to 1,300 MHz draws 305 to 313 W instead of 474 for 1.5 to 2.2 percent less rate, MH per watt up 49 to 52 percent; the Ember knob (0.3.24, the hash lane on the engine side, the UI lane's drawing) carries these as its reference rows. A FAULT FOUND AND FIXED: the steps 1,000 down to 300 and the closing reset got no answer from the Power Helper and the card sat at the 1,100 lock for about five minutes after the job (118 to 122 MH/s live); the installed app's own Ember tune on the 5080 wrote the same cmd.txt with higher sequence numbers while the script wrote lower ones, and the helper skips any sequence at or under the last run; the restore job run-ca3-pc1-clocks-restore-20261007 (exit 0 at 20:45:58Z) put the 5090 back at 2,865 MHz; the fix 45f9497f on the mirror (the sequence base from helper.log and cmd.txt, re-based after a timeout, an unanswered lock stops the grid, the task restarted before every reset); the rule for the knob: it takes its sequences from the engine's counter and no script shares the file with a running tune. The driver's floor below 1,100 is unmeasured. THE PC 1 QUEUE after the shipper's 0.3.23 host job (main, 21:5x UK): the 5080 full grid with the fix; the research lane's SM-sparse kernel job (the hash on a fraction of the SMs, several chains per thread, the rest clock-gated; the research lane hands the kernel to the hash lane); the third 5090 pass from 1,100 down to the driver's floor at the tail; then the 9070 XT G1 and ladder, the v5 AMD bench, item 6 on AMD, the 5080 and 9070 XT tunes, the L2 cache-policy hot table; each exit line to the shipper and the coordinator; the honest site sentence (the premium at the knee and the floor it buys, labelled measured, the Ember knob named as how a user gets there) once the 5080 reads. THE DERIVATION FINDING FIXED (the hash lane, 15008aca and 0f45c8be on the mirror): one byte recipe (generator::IdRecipe) builds the id and the printed text; program.json states the generator 4 suffix and the rung form; spec 1.4.6 corrected (class v5 = generator 5, no suffix); tests/derivation.rs re-derives all 18 pinned packs from their own text (the plain text gives 8aa9f185d63f269e for the devnet v4 pack, the known-failed case); 38 packs' program.json re-exported with ids, kernels and fingerprints byte-identical; the full igneum-pow suite green on box 2. CLASS V5 FROZEN: class-v5 1c420786 on both box mirrors at 21:53 UK (the (c''') floor with its number; section 14 with seven of seven live hot sets refused at 0.9821 to 0.9919, seed 170 at 0.9880 the seventh, and the three mild residuals at 0.9992 to 0.9997 named at about 1.0004x; the pinned pack unchanged; the flip-stale harness PASS on the matched binaries at 21:03 UK; the AP-F4-1 first form and the AP-F1-1 shadow rule, the latter's measured trigger 11 permille maximum over 6,000 first draws against the 30 bound, 0 redraws; the igneum-pow suite green on box 2: 73 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7; the gate GREEN at 58 checks). The kits lane: the 0.3.24 kit is packs-ca3-v5-20261007T183921Z.zip sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 (state.igsd1 included), fingerprint 82b19cbde8557ea5 on Metal, Apple OpenCL and a CUDA 4090; AMD on PC 1's queue, Intel deferred; the shipper has the line. The attack-pass lane runs F8 at 2^24, F9 at 10^5 and F1 on 1c420786 under class v5. The v5 lane's next commit on the freeze: AP-F4-1 in the agreed form (cost at most 205 against the median 226, w32 without the position-32 digit, k >= 1 and all-ROT-equal rejected, the known-failed day 29,337 = 2050-04-28) and the verified last resort (part (a) repaired by re-sourcing stale loads, then the whole rule over a 256-candidate scan, known-failed first on adv-accept-3's adv3/steer/2); both move the stream only on days and seeds the chain never reaches. THE FOURTH EXCEPTION ON THE RESTART STEP (the fast-time lane's held-miner run on the third pair 63524e28, 20:4xZ): the IBD catch-up's body sync anchored on the node's own sink and moved only on a whole chunk's successful join, so with the honest headers arriving as one chunk failing on its v5 tail it fetched nothing and the executor never reached the seed block; the relay hold-off and the mining hold from the earlier fixes read green on that run. FIXED by the node lane at f0c56f50 (the refused chunk split by consensus's own record, the anchor moved to the highest validated header, the honest v4 prefix through the seed block, only the unvalidated headers deferred; kaspa-p2p-flows 38). PAIR 4 = v5-object-0323 c8f9b383, re-archived from the frozen 1c420786 (generator.rs and accept.rs moved since ab6f980b, memhard.rs not), building on build-1 at gate priority since 20:54:32Z with the line's gates beside it; the restart step's PASS must come from pair 4; the object commit lands the minute it does, with dn3-g1's DAA at the cut plus 7,200 rounded up to the 3,600 boundary and its UTC clock named; the testnet lane told to pair its re-cut with 1c420786. The crossing clock is not yet a reading: about 22:15Z (23:15 BST) at the earliest if every line reads green on its first pass. The site audit lane: no other "12 days" form served; its row-17 edit keeps main's outside-check clause and adds the 5090 efficiency numbers. THE CHIP TEXTS, THE X9 WORDING RETIRED (main's order from the counter-asic-4 research file d7721ebe, 22:0x UK): the withdrawn Antminer X9's claimed ratio ("a third of a CPU's energy per RandomX hash") is against a CPU core (about 100 pJ per instruction, Horowitz and Dally, claimed), not a GPU lane (6.5 to 10.4 pJ measured), so a chip three times better than a CPU is worse than a GPU lane per op and the X9 is not a pessimistic chip core against us. The served texts (the home line, the litepaper's lead, chip table, ladder sentence and chip bullet, /claims through it, the miner line, evidence row 17) now give the floor and the premium as measured numbers at the 5090's knee: the chip at 2.1x per joule with a core as good as a GPU lane (k = 1) and 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the shadow's premium 81.8 W at the best points (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W, 7 October 2026), Ember Tune's core-clock knob named as how a user gets there; the ledger text check's pins X35 and X36 moved with the wording; no "3.9x" remains on any served page. One number stated against main's wording: main's line read "2.9x with one three times better", which in the research file is the figure for the RE-WEIGHTED op mix (row 3, held by the coordinator until the SM-sparse read); today's mix at a core three times better reads 3.4x in the same file, so the served text carries 3.4x and the 2.9x waits for the re-weight to ship. THE RESEARCH FILE's TWO ORDERS: (1) the texts as above; (2) one zero-code measurement at the PC 1 tail after the third 5090 pass: the 5 October hot-table packs (packs-ca2-hot, 32 and 64 MiB) with the worker's `--variant ldcs` (dataset loads streaming, evict-first; the hot loads plain and L2-resident) against base on the 5090, the rate ratio g and the watts (the 5 October rows without the hint g 0.84 to 0.87); the one class where a chip's cost per op (a 64 MiB SRAM read, 0.2 to 0.5 nJ approximate) may exceed the GPU's (an L2 hit, 0.1 to 0.3 nJ); Metal has no such hint. The shadow stays at rung 0; the op-mix re-weight waits for the SM-sparse read (the research lane's worker variants sp170/85/43/21/11-w32, one block of 32 warps per SM, run through the hash lane's efficiency script in its ca4 mode at 4f3a064e; the no-prompt and sequence rules hold by the same code). THE 0.3.24 PAIRING RULED (the shipper, 22:1x UK): the v5 object commit pairs with the frozen class-v5 1c420786 as it stands (the gates and the attack-pass lines run on it); the post-freeze fix 8ca66afa is 0.3.25's pairing. 0.3.25's FIRST ROW: class-v5 8ca66afa (both mirrors, 22:10 UK, on 1c420786): (1) AP-F4-1 in the agreed form (decc7c17): the day's draw rejected when cost A = 64 + sum(w32(MUL_i) - 1) is at most 205 against the median 226, w32 over bit positions 0 to 31 (the position-32 carry digit dropped), any MUL with w32 at most 3 rejected (k >= 1), the eight ROT all equal rejected, a rejected block redrawn whole from the continuing stream; known-failed first on chain day 29,337 (2050-04-28): the sub-version 3 block of that day read cost 203, rejected at 205 and redrawn under class v5. (2) Class v5's verified last resort: the rewrite, then repair_stale_loads (a stale load re-sourced to the lowest register written since its last load, to a fixpoint), then the whole rule over a 256-candidate scan from the cap; the unchecked fallback past the scan under 1e-300; known-failed first on adv-accept-3's adv3/steer/2 (the sub-version 3 rewrite fails part (a) at instruction 47 reading r3; the repair restores (a) moving only load sources; class v5's last resort passes at attempt 256, id 9b29c9481f6941d4; steer 11, 33, 56, 58 and 77 pass too); sub-version 3's path untouched. The stream moves only on days and seeds the chain never reaches: the pinned v5 packs byte-identical, the fingerprint 82b19cbde8557ea5 and the epoch-0 id e5a4ac5978462156 unchanged; the igneum-pow suite green on box 2 (74 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7), the gate GREEN at 58 checks. The harness's class-walk case (v4 floor 0, v3 never) read FAIL on the unfixed fork 546fe4b5 (the known-failed shape, 22:08 UK) and runs on pair 4. THE IN-HOUSE PASS, THE EIGHTH HOT SET (adv-accept, 22:06 BST, the wider sweep over 88,051 accepted programs): seed 122960 (id 4be7393ab6c84802, the lowest 256-unit ratio at 0.9885) reads live at 2^24 X_f +0.111 percent, X/f 1.11, 1.54x the window model, with the heaviest single item measured tonight (0x81ad88 at 475,616 reads, 0.022 percent of all reads, 16x 100767's hottest) from an all-ones source at instruction 4 (writer shfl at 3); site 12's saturated-source share 0.353 percent, a third of (c')'s limit; the other four lowest 256-unit proxies clean live, so the 256-unit proxy is noise at its own extreme and the 2^20 ratio is the selector; the tally 8 hot sets in 30 tail seeds against 0 in 20 random; the price unchanged (0.34 percent of reads on 1 MB, 1.002x); its minimum-site ratio at 2^20 against the 0.995 floor OWED (ordered first), deciding whether the freeze record reads eight of eight refused or names the first hot set the floor misses. THE 5080 AT STOCK (run-ca3-pc1-v4-eff-5080-20261007-b, exit 0 at 21:03:02Z, the card alone, 60 s, both fingerprints matched): class v4 71.43 MH/s at 255.1 W (0.280 MH/W, sm 2,958, mem 14,801 MHz); class v3 71.30 at 170.7 W (0.418); the v4 premium 84.4 W (49 percent over v3's draw), the rate 0.18 percent over v3; against the fleet's rented 5080 (71.16 MH/s at 143.4 W on class v4, driver 580) the rate agrees to 0.4 percent and the watts do not (255 against 143), a question to the fleet lane (its sampler, a cap on the rented card, the memory clock) before either row enters the public table; the lock grid did not run in -b (a PowerShell function defined below its first call left the script without the helper path; nothing set, nothing to restore), republished as -c at 21:07:10Z with the full grid (unlocked to 300 MHz, about 58 minutes). The site audit lane's row 17 and litepaper paragraph carry the 1,400 MHz rows labelled measured, with the best-points clause asked beside the 88 W at 1,400. THE 0.3.24 OBJECT COMMIT AND PIN: v5-object-0323 774f16c9 (21:26:35Z, both mirrors; the fork 432ea3d6 + f0c56f50 + 9ad1d9c6 + 294e3670 + the pool lane's 95ae3e50), paired with the frozen igneum-pow 1c420786: program_class_v5_activation_daa 28,800 (the Devnet 3 seed node at virtual DAA 16,208 at 21:22:24Z; the publish minute 22:30Z = DAA 20,264; plus 7,200 = 27,464; the next 3,600 boundary 28,800, epoch 8), byte 6 counted exactly, the window 86,400; the crossing on Devnet 3 by height about 00:52Z on 8 October (01:52 BST) at 1.0 DAA/s; the constant holds while the publish DAA stays at or under 21,600 (22:52:16Z), past which the node lane re-reads dn3-g1 and re-cuts to 32,400; chain id 4463 below the floor and 4464 from it; the three heights stay, the pool split never. Its gates: core 155 of 155, miner 28 of 28, pow 19 of 19, p2p-flows 38 of 38, exec 46 of 46, consensus 126 of 126 on the gate-priority rerun at 21:44:24Z (the earlier one red at 205 ms on the latency bound under a box load of 127, the known load class); the canary set on build-1 (21:29:38Z to 21:31:18Z): the digest moves to 4a284b1d on igneum-devnet-3 as the v5 arm requires, "this node stamps object version 6 into its headers (block version 1538)", the override file refused, two empty nodes handshake on 4a284b1d, the shared-devnet node refused on network mismatch, a 0.3.23 node refused on the digest both ways; every Devnet 3 node restarts inside one minute at the fleet's named clock on pre-placed binaries. release-0.3.24-node OPEN at 774f16c9 on both mirrors (21:45:19Z, the shipper's word), artefact /srv/artefacts/0324-774f16c9/node-lane (igneumd ed36f246...); the testnet staging 47b9b229 on the pin all green (consensus 134, core 175, exec 47, miner 28, p2p-flows 38, pow 19, digest b2e856ed). THE FAST-TIME GATE CLOSED: SUMMARY PASS (cross-c8f9b383-2) at 21:36:35Z on the matched pair c8f9b383 (igneumd f1b5b32c..., igneum-pow 1c420786), every check green, none skipped: class v4 sub-version 3 from genesis at rung 0; rung 1 by signal from epoch 6 at 21:29:39Z; class v5 by signal at byte 6 counted exactly from epoch 8 (DAA 480) at rung 1 at 21:31:33Z on 4 of 4 nodes, 9,985 bps, before the floor; the second rung at epoch 12 the rule's earliest allowed; 11 of 11 program ids equal to the CPU verifier's; 0 PoW rejections on the honest nodes; the stale node 69 of 69 refused; the restart step: n2 stopped at DAA 455, restarted on its own datadir at DAA 500 at 21:31:56Z, no lock fault, no IBD refusal, "class v5 catch-up done: 19 deferred headers validated after 6 s", nothing of its own accepted during the catch-up and 75 after, at n0's sink 12.1 s after its start; four sinks equal at 660; the digest-compat PASS from 20:08:30Z stands; records on v5-fasttime 4419e8d3. The three earlier pairs (959b57c9, 63524e28, 432ea3d6) each failed the restart step on a node defect fixed in the next (the IBD refusal, the catch-up's anchor at the node's own sink, the node mining while its catch-up waited). THE FLOOR READS EIGHT OF EIGHT (adv-accept, 22:41 BST): seed 122960 (the deepest live hot set) reads minimum site 12 at 0.9824 at the acceptance's 2^20 sample (live 0.9822), REFUSED by (c''') at 0.995 (its site 12 puts 1.31 percent of its reads on word indices read 8 or more times, the largest repeated-index share measured; 100767's site 6: 0.17); every live hot set by X_f at or above f found in the tail of 88,051 accepted programs is refused (minimum sites 0.9821 to 0.9919) against 0 hot sets in 20 random programs; the floor misses the three mild concentrations at 0.9992 to 0.9997 (Devnet 3's first program among them), about 1.0004x; the v5 design's section 14 and the ledger's AP-F8-1 carry the line. THE 0.3.24 CUT waits on the attack-pass verdicts on 1c420786 alone (F8's two halves on build-2 since 21:17:41Z, about 22:20 to 22:35Z; F9 at 10^5 and F1 on build-1); the lease pool now pre-empts adv holders at any size for a v5 or release waiter after 120 s (lease ce30e357). PC 1 EXCEPTION: the Power Helper task dies within seconds of each start since 21:08:34Z (six starts, zero commands, the task Running while no helper process exists; the last good command the 20:45:52Z rgc, its idle exit clean at 21:05:52Z); the suspect the shipper's 0.3.23 host job at 20:51Z replacing the install folder's exe under the registered task, the second a panic in the helper's start path; a read-only diagnostic plus a 20 s unelevated probe placed; the locked grids (the 5080 full grid, the third 5090 pass), the SM-sparse job and the tunes wait on the helper; the lock-free jobs run (the 9070 XT G1 and ladder from 21:27:41Z, then the family run and the v5 AMD bench); nothing raises a prompt to get round it. THE 5080 AT STOCK (two runs agreeing, -b and -c): class v4 71.42 MH/s at 254.5 W (0.281 MH/W, sm 2,960, mem 14,801), class v3 71.30 at 170.8 W (0.418), the premium 84 W; against the fleet's rented 5080 (71.16 MH/s at 145.4 W busy mean, cap 350 W not binding, 1 Hz power.draw instantaneous on Linux driver 580, bench batches with host gaps) the rate agrees to 0.4 percent and the watts do not (110 W apart, the sampler field on Blackwell under two drivers or the load shape); the public table carries the method per row and takes neither as the card's figure until both power fields are sampled on both sides (the fleet's re-measure, PC 1's next NVIDIA pass). THE CA4 SECOND PASS (bca23f96, sections 15 to 19): the tensor-tile k column (2.1x at k = 1, 1.6x at k = 1.5, the k 0.3 column removed for a tensor shadow; a design candidate needing a SIMD byte-dot verifier) and the capex column (the f = 1 GDDR7 chip USD 2.8 per MH/s, at most 4.3 with the hot table, the shadow core and an interposer; capex-dominated 7x; the break-even cap moving only through the project cost) carried into chip-model-v3 as section 5.11. THE PUBLIC TEXTS (main's two orders, 22:3x UK): the served sentence "the one outside check is staged and waits on its escrow and the publish word" read as an escrowed prize to a reader and is replaced everywhere it is served (evidence row 17, the litepaper and /claims through it, the public text file) by "no outside review has run yet", the in-house pass sentence kept; the forbidden-strings gate gains the phrase class ("outside check", "waits on its escrow", "staged and waits", "the publish word"; the bare words stay allowed, since the proving pool's escrow and a staged build are ordinary). THE /miners DESIGN PASS is on the mirror's ca3-coord at e88edae4 with the full gate GREEN (the overlap check clean at 390 to 1600 px after two fixes: the phone grid gives every cell its own area; the desktop row is six columns with the class v4 cost and the date as the muted second line under the card name, the card layout below 1,100 px, the wrapper scrolling as a safety); the 1440 and 390 dark captures go to main for the word on the look; nothing deploys from the branch before it. The in-house pass: four lanes complete (adv-cache, adv-accept-2, adv-cache-3, adv-mixer; adv-mixer's Q1 BOUND on the commutation probe at 0 in 1,454,080,000 over 1,024 days, its SAT row a solver-reach bound at the one-hour cap); adv-mixer-2 one row from complete; adv-accept, adv-accept-3, adv-cache-2 and adv-mixer-3 sweeping to 00:00 BST. F8 ON CLASS V5: PASS (the attack-pass lane, 22:03Z; the frozen igneum-pow class-v5 1c420786, binary sha256 0f5c98dc41a1b3aa...; the pairing bit for bit on 66 validation lines, the library drawing Devnet 3's epoch-0 program as e5a4ac5978462156; 64 seeds p2 to p65 at 2^24 nonces each, chain path, the v5 dataset from v5-dn3-epoch0's state.igsd1 on day 20,733, window-model control, build-2 under lease pool class v5 as two halves of 32, ended 21:58:43Z and 22:03:21Z): 61 of 64 under 1.2x of the window model (0.9919x to 1.144x, p75 1.0024x); 3 over, all inside the named four-seed residue and none new: p10 1.5047x (hottest item 0x4018f5 at 346 reads of 2^31, no predicted source), p8 1.3787x (419 reads), p4 1.2166x (363 reads); p34 reads 0.9997x under the (c''') floor; every strong seed of sub-versions 1 and 2 at 0.9997x to 1.0001x (p23 1.0000, p19 0.9997, p15 0.9998, p18 1.0001, p56 1.0000); seed for seed the ratios equal sub-version 3's within 0.001 except where the floor moved a draw: the state leaves change the words, not the read addresses. F9 (10^5 exhaustion) and F1 (10^5 redundancy) on 1c420786 and F4's 2^24 on 8ca66afa hold or wait in build-1's pool as strengthening lines. THE 0.3.24 NODE PIN MOVED on the shipper's word to 47b9b229 (the object 774f16c9 plus the testnet re-cut 34892a36) after the Devnet 3 canary set read clean on its own binary (21:59:04Z to 22:00:43Z: digest 4a284b1d, byte 6, the override refused, shutdown 725 ms, the handshake, the shared-devnet dialler and a 2720d8d2 node refused); release-0.3.24-node at 47b9b229 on both mirrors (22:01:05Z), igneumd 6bc18ac2..., pairing 1c420786; the build-server lane builds the pairs and the hive from it; the Devnet 3 digest 4a284b1d, the testnet b2e856ed; the floor 28,800 and its slip rule, the dn3-g1 re-read armed for 22:30Z. THE AMD HALF OF G1 PAID (run-ca3-pc1-v4-sub3-amd-g1-20261007, exit 0 at 21:46:14Z, the RX 9070 XT alone): 14 of 14 fingerprints equal to the Mac's Metal and Apple OpenCL and to the 5090's (the control, the seven sub-version 3 packs, the five ladder packs), self-test PASS on all; the ladder rows flat within 2.3 percent from 930 to 330,700 ops per hash (18.8 to 19.2 MH/s; the installed worker's control cross-check 18.96), the card latency-bound on the whole ladder; the watts row owed (the ADLX sampler read 0 samples in the per-pack windows). THE HELPER FAULT READ: not the shipper's; the task's exe is the install folder's 0.3.20 (mtime 12:24:42Z, sha256 0443ae17..., untouched by the host jobs); the helper's code path runs (an unelevated probe answered a dev line in 4 s); the scheduler refuses the ELEVATED instance from a non-interactive start (Last Result 0x800710E0, the task's logon mode interactive only); at 21:41:32Z the 0.3.20 engine's own tune took its legacy "task not registered" branch (the old sweep.rs helper.ps1 written, cmd.txt truncated), the prompt path, so whether a prompt stood on the desk is for the founder's screen in the morning; the class (the engine's registered() check and its fallback, the scheduler's logon mode) is the update-return lane's for 0.3.24; the locked PC 1 jobs stay parked. THE CA4 PROTOTYPES (the research lane, counter-asic-4 6404f62b): two experimental classes behind the pack, no consensus change: +shlx (the shadow's 256 instructions and 27 passes split into 16 sub-blocks of 16, each run after its load) and +mm (R int8 mma u8 tiles per iteration after the shadow; CUDA native PTX, the shuffle reference on Metal and OpenCL; the verifier scalar plus AVX2, SIMD pinned equal to scalar on 64 seeds); the suite green (64 + 7 + 4 + 19 + 2 + 7), the pinned packs byte-identical; packs exported with every OVERALL PASS (mx8_sh256x27 control, mx8_shl256x27, mm128, mm512, mm1430 at 11,440 tiles per hash); their card rows on PC 1 behind the helper; by construction neither lowers the premium (the per-load placement moves the chip's capex, the tile block its k floor). THE LEDGER CLOSE landed the chip rows on the mirror's master at b94a77ad (22:56 BST): X35 and X36 restated, AP-F8-1 with the eight-of-eight sentence, X37 new (the class v4 premium: measured, levers in flight). THE RECORD LANDED (23:24 BST): the regroup 2336a3c5, the outside-check rewrite and chip model 5.11 (6c19c790) and the status 015cc839 picked onto ca3-coord-record from the mirror's master and merged as ddfaf7a7 through the gate (GREEN, 7 checks in 30 s on f252b514); the first pick hit the audit lane's best-points clause in the litepaper, claims and evidence pages and the resolution keeps master's text with only the escrow sentence replaced by "No outside review has run yet." (main: the right sentence); the design pass stays on ca3-coord for its own landing on main's word after the captures. ADV-ACCEPT-3 CLOSED (the v5 lane, 23:12 UK): 8ca66afa closes its class as stated (the 9.0 percent of rewritten 256th-attempt programs the rule refuses are repaired for part (a) and re-drawn under the 256-candidate scan; the known-failed test on adv3/steer/2, five more steer rows passing); ledger row AP-F8-3 written (sub-version 3's last resort recorded unreachable and unverified, class v5's verified) at class-v5 7f58af97 with the v5-kits branch merged (the OpenCL, NVRTC and Metal hosts with the leaves upload, the kit scripts); the kit zip rebuilt from the merged tip, /srv/artefacts/packs/packs-ca3-v5-20261007T221001Z.zip sha256 4aaf9b9edfad0e466f6b6b59051250afad6a8e0a340728ec068bec48113c0fc9, the packs and the fingerprint 82b19cbde8557ea5 unchanged; Metal, Apple OpenCL and CUDA agree; AMD and Intel fingerprints owed. A GAP: tools/ledger-page.mjs renders only [A-Z]\d+ ids, so no AP-* row (AP-F8-1 to AP-F8-4) reaches /ledger; the site audit lane widens the regex tonight as its own commit with a known-failed case. THE SPEC SPLIT: the site audit lane holds 1.4.3, 1.4.6 and 1.13 (the acceptance-rule rewrite on spec-accept-23) and builds tools/ci/spec-constants-check.mjs, a constants table in the spec parsed against the crate's pub consts (known-failed first) with the class v4 test vectors stated in 1.4.6, since the attack-pass lane has no read-back test and writes none; the hash lane sent it the file and line of every constant from 017e7037 (= master's igneum-pow byte for byte, cf7d6ccb) plus ACCEPT_TAG, the window cap literal in distinct_ratio_pass and the full Devnet 3 genesis hex, no wrong values, one text quirk: the (c) reject prints "limit 163" while MAX_SATURATED is 164 (the first refused count); main's ruling: the spec words the constant, the message string is corrected on the post-freeze line, never in the frozen 1c420786. The v5 lane's 1.4.7 and 1.8.6 are on both mirrors at class-v5 73daadc2 (23:23 UK; full gate GREEN 58 checks at 066c9cbb): class v5's load class, generator 5 and the id, (c''') with the 0.995 floor and the census, the verified last resort, AP-F4-1 and AP-F1-1, the activation object byte 6 and the seven-window 95 percent signal, the test vectors (the three pinned packs, seed 100767, day 29,337, adv3/steer/2), 1.4.7.6 the constants table in the audit lane's shape (Constant, Value, Where); the state leaves (IGSD1 stream, leaf derivation, keyed sample, the leaf line before M_0, the per-epoch refresh and the witness, the measured cost). THE ERA-DRAW MECHANISM (the crypto lane's adv-cache-2, 6e34ebe3, 23:1x to 23:3x BST; report-chained-cache-2.md section 2.3, the 61-program table: 2 real, 27 drawn-era with epoch and era hex, attempt, id, R, site and ratio, 32 devnet-era controls): the mild residual class has its mechanism; a product's biased low bits (P(bit 0) = 1/4, measured exactly) survive the odd stride multiplier and the stride rotation places them at address bits R and up, inside the 28-bit item index unless R is 28 or more; the devnet era draws R = 29 and cuts them off, so 2 of 32 devnet-era programs carry a site over 1.04x while 13 of 27 drawn-era programs (R 3 to 22) do, 8 over 1.2x, worst era-drawn-28 site 15 at 1.7451x and era-drawn-25 site 11 at 1.3571x; under the 2 GiB genesis dataset (D = 29) R = 29 would show it too; the devnet's cleanliness is an era-draw accident, the chain prevalence is the drawn-era figure. The price to a partial-store chip stays under 0.1 percent of a hash's reads per site, so no chip number moves. Disposition: the class v5 (c''') census was already across drawn eras (each of the 4,600 f8 seeds carries its own era bytes), so the 2.435 percent and the eight of eight stand; the pointed reading runs on box 2 (the v5 lane, about 20 minutes from 23:3x): the 2^20 floor read on the 27 drawn-era programs plus era-fixed-20 and four devnet controls, reporting how many of the eight over 1.2x and the band 1.04x to 1.2x the 0.995 floor refuses; the value-level question (biased product bits feeding an address, independent of the distinctness ratio) and the era draw's R range go to the CA4 file as a named requirement with this reading as its evidence, and the research lane's per-load census gains a drawn-era split; nothing in class v4 or v5 moves without main's word. THE ATTEMPTS CENSUS on the frozen sub-version 3 rule (adv-accept row 90, 23:24 BST, 10,000 seeds): 21,119 rejected candidates, by first failing part (a') unfresh 83.3 percent, (a) stale 11.7, (b) no injecting write 3.1, (c'') low-entropy site 1.1, (c) constant bit 0.4, (c) saturated 0.3, (c') 0.1, the distinct-address floor 0.04, lane-constant and bias 0; per-candidate rejection 0.6787, flat at 67.5 to 68.7 percent over attempts 0 to 3 (independent draws); accepted-attempt mean 2.112, max 24; 0 exhaustions; P(256 consecutive rejections) 8e-44 per seed, so the last-resort draw is unreachable by chance and the attempt index is no lever for a seed-steering attacker; accepted programs' distinct-item mean 127.95 of 128, minimum 123.67; spec 1.4.6's 5.14 percent (the class v3 census) is stale against it, the audit lane rewrites; the second 10,000 queued on build-1. Also PASS: the line census at 2^35 + 3 x 2^33 and the 16,384-day weak-day scan. THE PC 1 QUEUE TONIGHT (the hash lane): run-ca3-pc1-amd-family-20261007-e exit 0 at 22:09:25Z (the 9070 XT alone, gfx1201, driver 3683.0, 32 CUs, three runs every row exact against the alu chain; step costs as a ratio to alu 741 G steps per second: rotr 1.05, shflx 0.89 (bperm native), shl 0.92, shr 0.99, bfe 1.03 native and 0.83 C sequence, andn 0.93, perm 1.21 emulated (perm_amd refused), popc 0.85, clz 0.83, sel 0.72, shfla 0.77 (bperm), dot4 0.75 native (dot4_khr refused), mm8 1.20 (gfx12 path, unverified); the khr and intel shuffle builds refused as on 6 October); the shipper's 0.3.24 host slot holds PC 1; on its "slot closed": fetch-ca3-v5-kit-20261007 (the 4aaf9b9e zip), then run-ca3-pc1-v5-amd-bench-20261007 (the v5 lane's script, the 9070 XT by name, beside the miners, about 3 minutes), lock-free and non-elevated, quiet. The Intel fingerprint: main first routed it to PC 1, the hash lane's device lists (the 22:09Z --list, the kit README) show no Arc on PC 1, and main's second word places the Arc B580 as PC 2's eGPU (tonight's PC 2 crash was an Intel driver install over that card while it mined); the job (tools/class-v5/pc1-intel-v5-bench.ps1 at a4b08245) moves to PC 2 by job after the shipper's 0.3.23 take 3 smoke and the update-return lane's scheduler proof have reported on that box, never concurrent with an install or a build there, the same lock-free class; a fingerprint that differs from 82b19cbde8557ea5 holds that card's v5 kit out of 0.3.24 and the crossing time is stated on its page row. PC 2 carries the RTX 5080 since about 15:00Z (tonight's stock row is that card). THE HASH LANE'S LANDING (the derivation fix, the no-prompt rule, the PC 1 job scripts, the Ember core-clock knob 74585c91: the ladder below 45 percent in 100 MHz steps to a 20 percent floor, the stop rule at the knee or on a faulted row, lock_result and the card's lock_* fields, 18 Ember tests and the app crate's 158 green on box 2, the 1 percent tolerance landing the 5090 at 1,854 MHz on tonight's rows and 1.5 percent at 1,300, the tolerance the manifest's; ledger row AP-F8-4) went RED once on the pre-public scrub (the founder's name in a ledger row and two script comments), fixed, the mirror's master merged in again, the gate rerunning from 23:2x; the merge commit follows. THE FLOOR'S FULL TALLY (adv-accept gap-deep4, 23:25 BST): the four deepest remaining 256-unit seeds all read under 0.995 at the acceptance sample (148927 at 0.9814, 150347 at 0.9896, 34501 at 0.9929, 29307 at 0.9912); the first three clean live (0.9998x to 1.0028x), 29307 at 1.29x on one item from a non-saturated source, no hot set by X_f. Over everything the lane read at 2^20: 8 of 8 live hot sets refused; 6 clean-live programs refused (false refusals) and 1 clean passed among the 9 deepest 256-unit seeds; 3 mild residuals missed at about 1.0004x. The lane's reading of why both sides exist: (c'') counts repeated word indices on the stand-in, which the live set usually spreads thin rather than concentrating, so a low ratio is not a hot set; that is the 2.4 percent clean rejection the floor pays, and a true hot set needs the value-level source test to be caught without it (the CA4 requirement). THE SPEC REWRITE committed on spec-accept-23 (the audit lane, 23:3x UK): 1.4.3 and 1.4.6.1 to 1.4.6.6 to the shipped rule at 017e7037, the shadow block in 1.7, the ninth era draw in 1.13.1, ledger AP-F8-5 (the stale spec text) with the public ledger regenerated, the two tables in the check's shape (Constants of the shipped rule: Constant, Value, Where, 17 rows; Pinned program ids: Seed, Attempt, Id, Note, 6 rows with Devnet 3's full genesis hash and the three must-differ ids); the full gate running; it merges the mirror's master after the hash lane's landing so the check and the text arrive together. THE PER-LOAD FIX (the research lane, counter-asic-4 2f718001, pushed 22:24Z; the fixed pack mx8_shl256x27_v2 22:29Z, attempt 3, id bd64b207a30413fb, the first export 854050a4293f0615 kept as the known-failed record): known-failed first at 22:16Z (tests/ca4_trace.rs on build-2): the first export derived 10,728 distinct items of 12,288 over three units (the class v4 shape 12,286), 1,482 same-iteration duplicate lanes at sites 8, 10 and 15; the mechanism from the 64-seed census (29 of 64 seeds failing, up to 620 duplicate lanes a seed, sources collapsed to 1 to 17 distinct values in 32 lanes): a lossy base writer (mulhi, mul, or) followed by 27 passes of the 16-instruction map collapses the register before the next load, so the static last-writer rule catches only part of it. The fix in two layers: the static redraw (a sub-block writer of the next load's source drawn from the injecting families when it is mul, mulhi or or) and the dynamic acceptance test stepping the per-load sub-blocks in the order the class executes (accept.rs alu_step inside run_unit) with a new rejection DuplicateLanes (any load reading one address in two lanes of a unit), a rejected candidate redrawing the attempt. After, 22:23Z: 12,287 of 12,288 and 0 duplicate lanes on the genesis seed; the census (64 seeds x 2 units on a second dataset, 16,384 load rows) 1 duplicate pair in all (seed ca4-census/49 site 3, the chance floor of a 2^24 index space, about 0.5 pairs expected; the class v4 shape's own trace shows 2 of 12,288 from the same floor); the suite 64 + 2 + 7 + 4 + 19 + 2 + 7 passed on build-2. Owed: the Metal fingerprint (the Mac, one at a time under the measure lock), the F8-form uniformity on the fixed export through the attack-pass harness, the drawn-era split of the census (R 3 to 22 against 28 to 31) and the biased-low-bits requirement row from adv-cache-2, the PC 1 card row on both exports. Nothing in class v4 or v5 moves. THE "LIMIT 163" FIX (the hash lane): the one-line fix on a post-freeze branch off the mirror's master, pow-reject-text-24 at 79c5c07d (pre-push GREEN): the (c) saturated reject text prints its limit as MAX_SATURATED - 1 and names 164 as the first refused count, with the test the_saturated_reject_text_prints_its_limit_from_the_constant reading the printed limit back (green on box 2); the frozen 1c420786 line untouched; it lands with 0.3.25's line. The derivation fix's landing: the second gate run RED on the public-ledger check (AP-F8-4's last paragraph must start with one of the six status words), the row now closing "Status: Fixed (7 October 2026, night)" and docs/ledger-public.md regenerated; the third gate run from 23:3x UK. PC 2's Intel job prepared as run-ca3-pc2-v5-intel-bench-20261007 (the kit fetch to PC 2 first) behind the shipper's "PC 2 clear"; the CA4 packs job on PC 1 runs both per-load exports (dir and id on every row). THE FLOOR RE-CUT (main's ruling, the shipper 23:3x UK): the 28,800 floor lost to the clock (the pairs, the hive kits, the fleet's fetches and the ten minutes after the last FETCHED cannot land before 23:52 BST, past the 22:52:16Z slip point), so the node lane re-cuts program_class_v5_activation_daa to 32,400 (epoch 9) on release-0.3.24-node, the same object otherwise (pairing 1c420786, chain id 4464 from the floor, the testnet re-cut inside); the new pin and its gates about 25 minutes from 23:3x; the crossing on Devnet 3 by height then about 01:52Z on 8 October (02:52 BST) at 1.0 DAA/s; the move minute after F9 and F1 PASS and the last FETCHED. THE ERA READING ON THE FLOOR (the v5 lane, box 2, 23:3x BST, igneum-pow at 73daadc2, the 2^20 acceptance sample): 0 of 29 of adv-cache-2's programs are refused by the 0.995 floor at their listed attempt, and the class v5 draw lands on the same attempt as class v4 for all 29; the six over 1.2x read minimum sites 0.9965 to 0.9997 (era-drawn-15's 1.51x site 14 at 0.9965 the lowest), the 1.04x to 1.2x band 0.9986 to 0.9998, the clean ones 0.9999 to 1.0000, the devnet-era controls 0.9996 to 0.9999. So the floor's statistic does not reach adv-cache-2's class: the distinct-index count at 2^20 reads concentration on FEW items (adv-accept's hot sets put 3 percent of a site's reads on 512 word indices, moving the collision count by thousands), not a diffuse excess over the top 0.1 percent of items (era-drawn-15's 1.51x is about +0.08 percent of the site's reads spread over 16,384 items, a few hundred collisions, inside the clean spread). Two classes, two instruments: the floor closes the few-item hot sets (8 of 8); the era-stride diffuse class needs the per-site item-share test at live scale or a draw rule on R and the shadow block's last write (the next class's row); its chip value is bounded by its own diffuseness (a 1 MiB hot table of the top 0.1 percent of items serves about 1.0024x at the worst site read so far, under the AP-F8-1 bound by an order). The v5 design's section 14 gains this paragraph with the 61-row log (era-drawn-25 to -28 and the 32 controls running; era-drawn-28 at 1.75x the one to watch) and its bound sentence corrected (the "top-0.1-percent share under about 1.3x" form, never served, lived in section 14 only); a ledger row for the miss asked. Nothing in the freeze moves. MAIN'S ROW WORDING for Devnet 3: a 0.3.23 node that has not updated falls off at the digest move minute (the fleet's named minute, about 00:52 BST at the latest), not at the 02:52 crossing; the row reads "update before or the node stops following Devnet 3; class v5 begins at DAA 32,400, about 02:52 BST". F4 ON CLASS V5 PASS (the attack-pass lane, 8ca66afa, build-1 under class adv, 379 s, ended 22:3x UTC; the agreed w32 convention, median 226, 2^24 chain days from 20,729): M1 0 of 2^24 days over 1.1x, the minimum cost 206 (day 27,016, 1.097x), so the bound holds with no margin and no day over the line, mean 225.79, sd 6.07 (the pre-rule census 5.69e-4 over, min 203); M2 0 days with k >= 2; day 29,337 redrawn under the rule (203 to 228), day 20,729 at 219 unchanged; AP-F4-1 FIXED-AND-PASSED; F9 and F1 under class release on build-1, lines within the hour. THE CA4 FILE (the research lane, 22:3x UTC, sections 20.2a and 20.2b): the drawn-era split of the per-load census: 16 eras over the fixed class, 2 units each, R under 28: 12 eras, 3,072 rows, 0 duplicate pairs; R 28 and up: 4 eras, 1,024 rows, 0 pairs; every era accepted at attempt 3; the adv-cache-2 reading written as a named requirement (value-level bit-bias of the index at a product-sourced site, judged across drawn eras split by R, owed for every CA4 class and the same item as class v5's acceptance; the per-load dynamic rule covers distinctness, not bias). Metal fingerprints (22:30 UTC, M5 Max under the measure lock): the fixed per-load pack ee5d7c71180e5ea7, vectors 3 of 3, 26.88 MH/s against the control's 27.01 (the placement costs Apple nothing); the tile packs bit-exact against the Rust verifier on the Metal reference path (mm128 270e4ae36b37e9a1, mm512 a1c1ff3148d775d1); the Apple cost is the finding: 1,024 tiles per hash take 35 percent of the M5 Max's rate, 4,096 take 78 percent, so a tile shadow at the ALU shadow's premium would take the Apple tier out unless Metal gains an integer matrix path; the tile class moves from rank 3 to beside rank 5 until that path is measured. Main's rule: no served number mentions the per-load fix before its F8-form uniformity and drawn-era split (the split now read; the uniformity owed). THE PUBLIC SENTENCE ON THE FLOOR (main's wording, 23:3x UK): "eight of eight hot sets refused; the diffuse era-stride excess, bounded under 0.1 percent of a hash's reads per site, is not caught by the floor and is the next class's test", the same words on ledger row AP-F8-1 (landing from ca3-coord-record 6d09d96e with the two-instrument reading and the AP-F8-6 pointer), on AP-F8-6 and in the v5 design's section 14 (the v5 lane, class-v5 54e52b8a at 23:36 BST carrying AP-F8-6, F4's PASS in the attack row and its clock corrections: build-2 prints CEST, every page time re-read to BST); no served page carries a hot-set sentence tonight, so the sentence reaches readers through the ledger once the AP-* regex fix lands. F4's no-margin hold (the minimum accepted cost 206 against the 205 bound at day 27,016) is a record sentence, not a served number. ADV-MIXER-2 CLOSED (the crypto lane, 2a632579 on build/adv-mixer-2, 23:37 BST; 0.31 box-hours, 0 pod-hours): the redraw rule (continue the stream and redraw all 40 draws when the LUT cost A is 205 or less, or a 2-adder MUL, or all ROT equal) over 2^24 and 2^28 days leaves 0 days over 1.1x; 6.0e-4 of days redrawn once, 3e-7 twice, never three times; the mean cost unchanged; verdict BOUND for every chip, GPU and the verifier (gain 1.0 every day at 9,360 ops per item), FINDING on the per-day FPGA LUT-area reading only (2^-10.8 of days over 1.1x, worst 28 April 2050 at 1.113x), closed by the redraw rule or by the spec's O-1.10 day derivation; five lanes closed (adv-cache, adv-accept-2, adv-cache-3, adv-mixer, adv-mixer-2), four to the 00:00 reading (adv-accept, adv-accept-3, adv-cache-2, adv-mixer-3). THE HASH LANE'S BRANCH ON MASTER: da2fc101 at 23:37 BST (ca3-v4-amend a7ff10a2; the full gate GREEN, 69 checks in 351 s): the derivation fix with AP-F8-4 and the regenerated public ledger, the no-prompt rule (publish-jobs.sh refuses --elevated; playbook-quit-check rule 3), the PC 1 and PC 2 job scripts, the Ember core-clock knob for 0.3.24 (ember.rs, state.rs, engine.rs; 18 Ember and 158 app tests green on box 2), the ca3-v4-uniform parallel census; igneum-pow against 017e7037 differs in generator.rs (the recipe refactor, every id and pin unchanged), emit.rs (the one print) and tests/derivation.rs only; the shipper's tip for 0.3.24's engine work is this master. THE 0.3.24 NODE PIN RE-CUT (the node lane, every gate green at 22:39:31Z): c9e385eb on release-0.3.24-node (47b9b229 with Devnet 3's class v5 floor at 32,400, epoch 9, the same object otherwise; pairing 1c420786): build 22:34Z rc 0 (igneumd 7a841b20..., /srv/artefacts/0324-c9e385eb/node-lane), consensus 134 at gate priority, core 175, exec 47, miner 28, p2p-flows 38, pow 19; the Devnet 3 canary set with the new digest d0d6a4754f3bfc4a173aeaddbab0e151583047283932b70cbb8e27878c115e91 (byte 6, override refused, handshake, the shared-devnet dialler and a 2720d8d2 node refused); the testnet canary on b2e856ed unchanged. The floor from the 22:30:17Z read (DAA 20,268, 1.0 DAA/s): about 01:52:29Z on 8 October (02:52 BST), holding for a move minute up to a publish at DAA 25,200 (23:52:29Z, 00:52 BST). The fast-time SUMMARY on c9e385eb asked; the fleet lane asked whether its hub or any reader depends on build-1's three old-object Devnet 3 nodes (the seed on 27632, the observer node, node1), whether they join the move or retire, and which 0.3.24 node the DAA is read from after it; the crossing read at 32,400 and the TESTNET_PARAMS v5-at-0 re-cut follow on that node. THE FAST-TIME GATE ON THE RE-CUT: SUMMARY PASS (cross-0324-c9e385eb) at 22:49:32Z (23:49 BST) on the shipped 0.3.24 re-cut c9e385eb (igneumd 7a841b20..., igneum-miner 1e209b9e..., igneum-pow at the freeze 1c420786), build-1 under lease pool class v5, 22:36:25Z to 22:49:32Z, every check green: rung 1 by signal at epoch 6 (22:42:54Z), class v5 by signal at byte 6 from epoch 8 at rung 1 (22:44:54Z, 4 of 4, 9,985 bps), 11 of 11 ids equal to the CPU verifier's, the stale node 86 of 86 refused with 0 accepted after the first refresh, the restart step across the boundary on a kept datadir resynced in 28.1 s with the catch-up done after 10 s and 0 of its own blocks during it, four sinks equal at 660, honest nodes 0 PoW rejections; record on v5-fasttime 76276be6, docs/design/class-v5-harness/fasttime/cross-0324-c9e385eb.json. The 0.3.24 move's gates left (the shipper's correction of this record): not F9 and F1's full 10^5 PASS (landing about 00:40 BST, too close to the 00:52 ceiling) but an F9/F1 interim line from the attack-pass lane read inside the five minutes before the minute showing 0 exhausted, 0 panics and 0 redundancy failures over everything drawn so far (16,003 seeds at 23:35 BST, max attempt 25), any non-zero holding the move, the full 10^5 the record line after; the minute named by the fleet on the last FETCHED plus ten once the build-server lane's c9e385eb pairs land. THE 61-ROW ERA READING (the v5 lane, box 2, 23:4x to 23:5x BST, docs/design/class-v5-harness/v5-listed-adv-cache-2-full.log): 0 of 61 refused by the 0.995 floor at the table attempts (the two real programs, 27 drawn-era, 32 devnet-era controls), every class v5 draw on the class v4 attempt; era-drawn-28 (id 5e9eb01efbbf653e, attempt 6, R 15, the worst of adv-cache-2's census at 1.7451x) reads its biased site 15 at 0.9969, over the floor by 0.0019; era-drawn-25 (1.3571x, R 21) site 11 at 0.9994; the eight over 1.2x span 0.9965 to 0.9997 while the eight few-item hot sets sat 0.003 to 0.013 under the line. Main's sentence opens AP-F8-6 and section 14 verbatim with the two-instrument reading under it. THE CLASS V5 ATTEMPTS CENSUS for 1.4.7 (1,000 f8 seeds through the chain draw, v5-attempts-census-1000.log, the crypto lane's form): 3,219 candidates, 2,219 rejected, per-candidate rejection 0.6893 (sub-version 3: 0.68), accepted attempt mean 2.219, 0 exhaustions, P(256 consecutive) 4.4e-42; first failing part (a') 83.4 percent of rejections, (a) 10.7, (b) 3.0, (c'') 1.2, (c''') 1.0 (0.7 percent of candidates, one in 140: the floor's own share, 0.045 on the attempt mean), (c) 0.7 together, (c') none; the 5.14 percent of class v3 that 1.4.6 quotes is the audit lane's to replace. Both on class-v5 at 3b1dffd6 with main's sentence (891dd008), the mirror's master merged (e0471019: AP-F8-1's update and AP-F8-4 taken, the program-id recipe form with the state tag, no conflict), the design page's pre-public scrub (the founder's name six times, gone), M35's status word and the regenerated public ledger; the push waits on the full gate and the pinned-packs test on the merged tree (the proof that e5a4ac5978462156 and the other ids still derive under master's recipe form). THE 00:00 BST READINGS (the crypto lane; the verified roll-up of all nine lanes in section 13 of in-house-pass.md on crypto-engage, every branch tip read from the mirror and igneum-pow identical to 017e7037 on each). adv-accept, tip a7c49399 (about 5.5 box-hours, 0 pod-hours): 182,646 distinct accepted programs drawn (18 percent of the 10^6); eight pass every part of the frozen rule and flag the live hot-set test at 2^24 (X at 0.1 percent +0.102 to +0.221, 1.54x to 2.24x), all in the lowest 34 stand-in-ratio seeds against 0 in 20 random; each about 1 MB of items holding 0.26 to 0.41 percent of reads, 1.002x at the largest; the mechanism a near-saturated source at one site mapped by the era stride to one fixed item (plus two lesser shapes); the exemplar reads the same under the class v5 dataset. Against the class v5 floor: 8 of 8 refused; 3 mild residuals missed (adv-cache-2's rotation class, a load_index question not a floor question); 6 clean programs refused among the 9 deepest (the 2.4 percent). Q2 BOUND (54 programs plus 17 reads, 0 disagreements). Row 90: 0.6787 per candidate, (a') 83.3 percent, 0 exhaustions, P 8e-44. Partial named: 18 percent of seeds, 54 live rows, row 90 at half; a longer pass adds rows of the same shapes, not a different answer, unless a seed reads a hot set over 1 percent of reads, which 182,646 draws did not produce. THE PER-LOAD CLASS CLOSED (the research lane, for main; clock readings UTC): the per-load shadow fix held for distinctness and then met the value-level requirement from adv-cache-2, and the construction did not survive it; the per-load 16 x 27 class is dead as a chain class. 22:44 the attempt verdicts on four seeds (igneum-genesis 0 of 32 accepted); 22:47 the 64-seed census under the full rule (duplicate lanes at a load row plus the one-count of every index bit per site over the 64 units, 6-sigma band): 22 of 1,621 candidates accepted (1.4 percent), 42 of 64 seeds exhaust the chain's 32 attempts (an epoch without a program); the first failing test per candidate: biased index bit 775, duplicate lanes 643, the base rule 110, (b) 43, (a) 28; candidate 0 of the class carries index bit 0 set in 40 of 1,024 addresses (z 29.5); 22:52 the suite green (64 + 5 + 7 + 4 + 19 + 2 + 7); the acceptance rule with BiasedIndexBit for this class and the tests pushed as the record, the file's 20.2a closed. The structural reason: 27 passes of a 16-instruction map right before a load is an iterated small function and collapses or biases the load's address register before any base instruction re-randomises it; the class v4 shape has 64 base instructions and 16 loads between its block and every load. Both exports were accepted only because the rule did not model the placement; their PC 1 rows stay as an energy reading of the placement, labelled unsound. Rank 4 and the USD 200 M capex row rest on a construction not shown to exist (chip model 5.11's clause marked so in this landing); the sound form is one pass of a 432-instruction sub-block per load (a program segment, not an iterated map), a new class to draw, accept and measure, not tonight's. Replicated by a second instrument: the class v4 shape on this pre-amendment generator carries the adv-cache-2 product bit at address bit R exactly in 14 of 17 drawn eras (one-count 250 or 780 of 1,024, z 15 to 19), 0 duplicate pairs across the eras. What stands from the two prototypes: the tile block (bit-exact on the Metal reference, the AVX2 verifier at 0.047 us per tile, the Apple emulation cost 35 to 78 percent) awaiting its 5090 rows; the per-load placement closed. THE SPEC REWRITE ON MASTER (the site audit lane, 8b834634 at 23:56 BST; gate GREEN on 64e2a91b, 71 checks; the igneum-pow suite green on the box for that commit with derivation.rs and spec_readback.rs): spec 01 sections 1.4.3 and 1.4.6.1 to 1.4.6.6 rewritten to 017e7037 with the 20-row constants table (ACCEPT_TAG, the window-cap literal, MAX_SATURATED as the first refused count with the 163 message noted) and the 6-row pinned-ids table with Devnet 3's full genesis hex; the shadow block in 1.7; the ninth era draw in 1.13.1; tools/ci/spec-constants-check.mjs in the gate (known-failed first, every Constant | Value | Where table, pending rows skipped while absent); igneum-pow/tests/spec_readback.rs (ids derived through the crate, each class v4 row drawn to its attempt); ledger AP-F8-5 after AP-F8-4; the ledger-page fix (both heading forms, the pass as its own section, known-failed self-test in the gate; AP-F8-1, AP-F8-4 and AP-F8-5 render on /ledger); the fud-ledger's two prize clauses and "paid independent cryptanalysis" removed at the source so the regenerated page carries neither (commit 90424d5a, merge 64e2a91b). A HARDWARE FACT IN DISPUTE, for main: tonight's 5080 efficiency rows came from PC 1 jobs (run-ca3-pc1-v4-eff-5080-20261007-b and -c), the audit lane's record reads the RTX 5080 and the Arc B580 on PC 1, the hash lane's 22:09Z device list on PC 1 shows the 5090, the 9070 XT and the 4070 only, and main places the 5080 and the B580 on PC 2; identity-check.sh's "PC 2" substitution text names cards and is left card-free until the PC 2 job's own --list settles which cards sit where. THE IDENTITY CHECK'S PC 2 TEXT (the CI steward, 00:05 UK on 8 October): tools/ci/identity-check.sh rewrites "PC 2" card-free as "the second Windows rig" (commit 40f2be54, merge 0d2cf334, gate GREEN 71 checks, identity grep 0 hits over 306 export files and 52 served pages); line 69's PC 1 list untouched; the reason recorded in a bash comment above the perl call. THE 32,400 FLOOR LOST (the node lane, 00:0x UK on 8 October): dn3-g1's chain read DAA 25,126 at 23:52:03Z and 25,169 at 23:52:38Z, so the publish DAA passed 25,200 at about 23:53:09Z with no 0.3.24 move made (build-1's three Devnet 3 nodes last restarted about 21:31Z on the 0.3.23 move; the old seed holds 38 peers on ba75bf6f; no move minute was named). The next boundary is 36,000 (epoch 10), about 02:52Z on 8 October (03:52 BST) at 1.0 DAA/s, holding for a publish up to DAA 28,800 (about 00:53Z, 01:53 BST). Two routes put to the shipper and main: the same re-cut script on release-0.3.24-node (program_class_v5_activation_daa 36,000, nothing else, the same gate set, about 20 minutes to the pin line), or the fleet names its minute first and the floor is cut from it in one go (publish DAA plus 7,200 to the next 3,600) instead of a fourth chase; the pin c9e385eb stands meanwhile. THE FLOOR RE-CUT FROM A NAMED MINUTE (the shipper, 00:1x BST on 8 October, under the slip rule main set with the object commit): the floor re-cuts once more to 39,600 (epoch 11, about 04:52 BST) from a move minute the shipper named: 02:00 BST on 8 October, or the fleet's last FETCHED plus ten if later but before 02:53 BST (DAA 32,400, the ceiling); the node lane's pin line in about 20 minutes with the new Devnet 3 digest; the F9/F1 interim read at 01:55 BST; the publish minute equals the move minute (the apps' entries at or after it); the fast-time SUMMARY PASS reruns on the new pin as part of its gate set; the cause of the lost floor named: the c9e385eb pairs and the two PC jobs unreported for forty minutes, so the fleet had nothing to point its move file at. "slot closed" on PC 1 still waits on the host job's exit. THE 0.3.24 NODE PIN AT 39,600 (the node lane): dfbd1e10 on release-0.3.24-node (both mirrors, 23:54:13Z) = c9e385eb with program_class_v5_activation_daa 39,600 (epoch 11), nothing else; pairing igneum-pow 1c420786; every gate green at 00:01:52Z (build 23:56Z rc 0 at gate priority, igneumd 4870ccf2..., igneum-miner aa8c2978..., /srv/artefacts/0324-dfbd1e10/node-lane; pow 19, consensus 134, p2p-flows 38, exec 47, core 175, miner 28); the Devnet 3 canary set (23:56:33Z to 23:58:13Z): digest b1ba78229b069dc395fa666638a686a66615eb760d251798adfa6a654a415f82 on igneum-devnet-3 from ba75bf6f, object version 6 stamped (block version 1538), the override file refused, shutdown 2,015 ms, two empty nodes handshaking on it, the shared-devnet dialler rejected, a 2720d8d2 node refused on the digest both ways; the testnet canary b2e856ed unchanged (byte 7, a live old-object testnet node refused). The cut's read: dn3-g1 at DAA 25,169 at 23:52:38Z (1.0 DAA/s), the publish DAA at the named minute 01:00Z about 29,211, plus 7,200 = 36,411, the boundary 39,600 about 03:53:09Z on 8 October (04:53 BST), holding for a publish up to DAA 32,400 (about 01:53:09Z, 02:53 BST). The one gate running: the fast-time pair on dfbd1e10 (about 13 minutes from its start). c9e385eb is void as a pin; the F9/F1 interim read armed at 00:55Z. THE TWO PC QUEUES AT 01:03 BST (the hash lane): PC 1's "slot closed" has not come (the shipper's 0.3.24 host job, the build-server lane's, took the slot at 22:13Z for an expected two to three minutes; nothing reported in 110 minutes); nothing of the hash lane's has run on PC 1 since 22:09:25Z; the v5 kit fetch and the 9070 XT v5 bench are prepared and unpublished (tools/ca3-v4-amend/pc1-publish-20261007.sh, steps v5-kit and v5-amd), so no 9070 XT class v5 fingerprint exists yet; the lock protocol holds unless main says the lock-free pair goes ahead of the silent host job. PC 2's "clear" has not come either (the 0.3.23 take 3 smoke and the scheduler proof unreported by either lane); the Intel job is prepared and unpublished. THE HARDWARE FACT, read from tonight's PC 1 lines: nvidia-smi on PC 1 lists GPU 0 RTX 5090 (bus 01:00.0) and GPU 1 RTX 5080 (bus 0D:00.0); its OpenCL list carries the RX 9070 XT (gfx1201) and the integrated gfx1036 and no Intel platform; so the 5080 is on PC 1 (the audit lane's record right, the 22:09Z device-list summary short by one card) and the Arc B580 is not, which agrees with main's word that it is PC 2's eGPU; the kits row, the bench notes and identity-check's card-free PC 2 text stand on that. The locked PC 1 jobs stay parked (the 5080 full grid, the third 5090 pass, SM-sparse, the microbench and packs knee states, the two Ember tunes, the hot-table ldcs rows); the lock-free CA4 rows queue after the v5 bench on the same "slot closed". THE 00:00 BST READINGS, THE OTHER THREE (read by the crypto lane from each branch's report on the mirror at 01:03 BST; the roll-up section 13 of in-house-pass.md at crypto-engage c84ba51b with adv-accept's reading at 1b4e07ff; all nine branch tips read back from the mirror and igneum-pow IDENTICAL to 017e7037 on every one: adv-mixer d2ba3134, adv-mixer-2 2a632579, adv-mixer-3 4ebe2455, adv-cache 555c3e42, adv-cache-2 9384ee09, adv-cache-3 9452c0bf, adv-accept a7c49399, adv-accept-2 92168536, adv-accept-3 0c150e3c). adv-accept-3 (exhaustion or steering of the draw), tip 0c150e3c, every sweep ended 23:05 BST, about 3.3 box-hours, 0 pod-hours: Q1 exhaustion BOUND (per attempt accept 0.323, reject 0.677 ((a') 0.568, (a) 0.079, (b) 0.022, dynamic parts about 0.009), geometric histogram, P(exhaust) 0.677^256 = 4.6e-44, 0 of 16,337 seeds at the cap); Q1b the last resort FINDING (correctness; the mirror fired at cap 256 byte-identically; of 3,000 last-resort programs the real rule rejects 271, 9.0 percent: 251 by (a), 14 by (b), 6 by (c) distinct sum; handed out unchecked; unreachable; closed in class v5 by 8ca66afa, AP-F8-3); Q2 steering BOUND (45 of 48 planted rows fired, the real rule rejects every effective plant by (a'); 975 seeds at the first part, min ratio 0.998, 18 of 18 chain re-draws equal); Q2b the price of a seed property at 1 in 10^6 tries is a shadow block with 38 multiplies of 256 against a mean 74, about 2 to 3 percent of the f = 1 chip's energy per hash, the load critical path worth nothing at the memory activate ceiling; Q2c the 256-unit ratio is noise as a selector; Q3 program id FINDING (documentation: the "sub/" || 3_le16 suffix omitted from program.json and spec 1.4.6; a text-derived implementation computes 30956569d8f3d8d7 for Devnet 3 against the pack's fce15bf61030be57; 0 collisions over 10^7 pairs; fixed as AP-F8-4 at da2fc101); Q4 determinism DONE (the (c'') f64 compare never disagrees with the integer rule on any of the 2^20 + 1 values, margins 0.32 to 0.44 counts; a second interpretation agrees on 5,748 of 5,748 verdicts of 1,792 seeds); Q5 the era lever BOUND (400 eras, no stride under NAF weight 7, all 31 rotations, 354 distinct interleaves; epoch 0's accepted attempt is 3 under every era, so the era moves the address map, not the program). Partial named: the steering sweep at 975 of a planned 10^5 seeds (about 8 box-hours more at 32 cores). adv-cache-2 (the hot-set attack), tip 9384ee09 at 23:52 BST, about 2.2 box-hours by wall times threads over 96 (the boxes at load 400 to 600 for the first two hours), 0 pod-hours; two shards still queued at 00:00 (lines-2e30-s2c, warps-devnet-2e25-v2), named partial: Q1 the line index PASS (pooled 16 days; segments max +4.84 sigma against a control's +4.24, lines +5.61 against +5.35, chi2/dof 0.99937, top 0.1 and 1 percent of lines 1.0003x and 1.0002x of control; the 2^35 + 3 x 2^33 census all PASS; 0 mirror mismatches); Q2a the real programs PASS on the hot-set test (devnet at 2^26 1.0002x; Devnet 3 at 2^26 items 1.0071x, lines 1.0000x) with the FINDING at Devnet 3 site 0; Q2b all 64 programs done, every one clear on the hot-set test (items 0.9993x to 1.0075x of the windowed control) but the site class as recorded above (13 of 27 drawn-era over 1.04x, 8 over 1.2x, worst 1.7451x; the v5 floor refuses 0 of 61; AP-F8-6); Q3(1) steering by t PASS (worst cell 3.95 sigma in 2 x 2,112 cells); Q3(2) the weak-day scan PASS over 16,384 days (2^30 derivations in 707 s; worst per-day max bucket +8.13 sigma against the control's +7.78; the plant fired at +1,090); Q3(3) the window layer: the exact distribution matches the 4,096-program census to four digits (top quarter mean 0.3382, top half 0.5811), with a FINDING against the chip model's table: the f = 0.25 and f = 0.5 partial-store rows overstate the recompute share by up to 1.8x at f = 0.5, the full-store (f = 1) verdict unchanged (a correction owed in chip-model-v3's partial-store rows; no served number rests on f under 1); Q4 the prices: the only measured excess over f is the window layer's and the line reference multiplicity (a hottest-lines half store hits 57.8 percent instead of 50 at a higher miss cost than the stride). adv-mixer-3 (the statistical distinguisher and round margin), tip 4ebe2455 at 00:41 BST, still RUNNING at 01:03 (Q3 and Q4 at k = 8 on day 20729, queue 07 in the pool, the SAT ladder at k = 3 timed out; the total box-hours the lane's to give): Q1 the exhaustive round-0 line-index census over all 2^32 t PASS to k = 8 on days 20729 and 20733 and at k = 2, 3, 4, 8 on 20730 (z within 1.5); Q2 single-bit avalanche FINDING at k = 1 (354 and 266 holes, 130,000 cells beyond 6 sigma, the known one-application diffusion), PASS from k = 2 at 2^24 (0 holes, worst z under 5.3 through k = 8); Q2b the t-bit avalanche the same shape; Q3 differential multiplicity over 576 low-weight differences FINDING at k = 1 (695 and 537 deterministic output bits), PASS k = 2 through 7, k = 8 running; Q4 and Q4b linear correlations PASS from k = 1 (worst c 0.00046 to 0.00062, z under 5.1); Q5 rotational-XOR PASS from k = 1; Q6 SAT: k = 1 SATISFIABLE in 137 s (t = 0x49880000 verified through the real code), k = 2 and 3 TIMEOUT at the one-hour cap. The round margin as it stands: no statistic survives 2 of the 8 applications between reads; a chip gets nothing from the k = 1 findings because every read sits behind 8. The lanes' own lines go into section 13.1 as they arrive. THE LANES' OWN 00:00 LINES (adv-accept-3 and adv-mixer-3, 01:0x BST, in section 13.1 of in-house-pass.md): adv-accept-3's P(exhaust) refined to 1.0e-43 per epoch seed from 62,240 full-rule candidates plus 3.0e6 static candidates; Q2 steering BOUND over 19,975 full-rule and 1e6 static seeds, no property buying over about 1.03x at 1 in 1e6 tries; a second documentary FINDING: an implementation written from the spec text (not the code) at 017e7037's spec differs on 264 of 400 epoch programs, the same text-against-code gap as the id suffix (the audit lane's rewrite 8b834634 with spec_readback.rs is the fix; the proof that it closes this is a re-run of the text-derived implementation against the rewritten text, asked); a plant note: the floor-0.97 known-failed variant did not fire because the (c'') ratios are bimodal (accepted 0.989 to 0.999, rejected 0.814 to 0.966), replaced by a single-pass (a) variant that did; 3.3 box-hours, nothing running. adv-mixer-3: about 3.0 wall-hours of sweep plus 4 single-core CaDiCaL hours; the round margin stated as 6 of 8 applications between reads and 70 of 72 per item on every measured statistic, the k = 1 effects one mechanism (the lowest-set-bit trail through one application, dead once both addends carry a difference), nothing saving one application against 9,360 ops per item; still running at 4 cores on build-1 (2^27 and 2^28 avalanche rows, finish about 03:00 BST) and the day-20733 SAT ladder on build-2 (about 03:45 BST); not attempted: multi-bit linear masks and a MILP trail bound. adv-cache-2's own line still owed. ADV-CACHE-2'S OWN LINE (01:05 BST, tip 3f50d6c4; section 13 of in-house-pass.md now carries every lane's reading in its own words plus the verified roll-up): the drawn-era prevalence read on the SAME 32 base programs is 2 of 32 under the devnet era against 16 of 32 under drawn eras (8 over 1.2x, worst 1.75x), the mechanism carried by rotl(x times M, R) into the item index unless R is 29 or 30 (2 of 31 rotations), with a sub-class of warp-uniform sources once in 16,000 warps; the window layer's price restated: a chip holding the hottest f of items serves 0.4219, 0.7188 and 0.8907 of reads at f = 0.25, 0.5 and 0.75, so the chip model's partial-store rows overstate the recompute share by up to 2.3x on these programs, the f = 1 verdict unchanged (the correction to chip-model-v3's partial-store rows is the coordinator's next commit); partial named (the drawn-era windows census of 4,096 and one line shard in the pool); the longer-pass line: the biased-site rate per era in closed form (the R in {29, 30} rate 2 in 31) and a 2^28 read of the worst site. Nothing of the pass stands between the pool and a higher-class job except two pre-emptable shards on box 2. THE SPEC-TEXT RE-DERIVATION ORDERED (01:06 BST): adv-accept-3 re-derives its 400 epoch programs from the rewritten spec text alone at master 8b834634 (1.4.3 to 1.4.6 grown from 79 to 198 lines with the constants and pinned-ids tables), lease pool 16 --min 8 class adv, row Q4c in its report; the expected reading 0 of 400, any non-zero naming the diverging sentence to the audit lane; the proof that AP-F8-5 closed the text-against-code gap. THE CHIP MODEL'S PARTIAL-STORE ROWS carry a second correction (section 5, 8 October 2026) from adv-cache-2's window-layer reading: a chip holding the hottest f of items serves 0.4219, 0.7188 and 0.8907 of reads at f = 0.25, 0.5 and 0.75, so the uniform-store rows overstate the recompute share by up to 2.3x; the f = 1 row, the SRAM column and the full-store verdict unchanged, no served number on f under 1. THE CLASS V5 PACKS TEST ON THE MERGED TREE (the v5 lane, 01:0x UK): the job ran on box 2 the minute two adv-accept holders ended (65 cores; no lease fault, plain starvation before); 19 passed, 1 FAILED: v5_pack_is_the_v4_program_over_the_state_leaves (tests/packs.rs:977), the byte-for-byte compare of every pinned pack file with the crate's export. The ids are EQUAL (v4-genesis exports a217c7f698880830 as pinned; the state tag rides in master's recipe form unchanged); what differs is the program_id_derivation TEXT in program.json, which master's export (the hash lane's AP-F8-4 read-back form) now writes as "... || attempt_le32 || 'sub/' || sub_version_le16" for generator 4 while the pinned packs carry the pre-suffix wording. Disposition: the three pinned packs re-exported from the merged crate (text only; the ids, kernel texts, leaves and the fingerprint 82b19cbde8557ea5 must come out byte-identical, proved by the same test); the CLI rebuilding on build-1 from 51aa5bc4, the export from the box's IGSD1 streams, the packs test and the full suite on box 2 at 16 cores, then the push; readiness about 01:35 UK. The 0.3.24 kit zip (packs-ca3-v5-20261007T221001Z.zip) carries the old derivation text in its program.json files: a text field only, no id, kernel or fingerprint change, so the kit stands for 0.3.24 and the shipper is told; the re-exported packs go in the next kit. THE ONE 0.3.24 KIT, NAMED for the shipper (01:1x BST): packs-ca3-v5-20261007T183921Z.zip, sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 the pin pairs with; the fleet keeps placing it. The 23:11 zip packs-ca3-v5-20261007T221001Z.zip (sha256 4aaf9b9e..., /srv/artefacts/packs/ on build-1, from class-v5 7f58af97) carries the same packs, ids, kernels, leaves, fingerprint and derivation text and differs only in the merged kit host code and scripts beside the packs; it is the bench lanes' kit for the fingerprint jobs. The coordinator's earlier line naming 4aaf9b9e as the 0.3.24 kit was wrong and is corrected here. THE SPEC-TEXT READ-BACK RUNNING (adv-accept-3's Q4c, 01:11 BST on build-2, lease pool 16 --min 8 class adv): the same 400 epoch seeds re-derived from the spec text at master 8b834634 alone (1.3, 1.4.2, 1.4.3, 1.4.6, 1.6, 1.7, 1.13.1; a fresh text interpretation), compared field for field with the chain draw; the count about 01:21. One sentence already named divergent before the count: 1.4.6 part (c) cites dataset_elem(idx, S[0], S[1]) "of verify.rs" without stating its six operations, so part (c) cannot be computed from the text alone and the derivation takes that one function from the crate; the audit lane is to state the closed form's six operations in the text or the constants table, else 1.4.6 stays code-dependent on that line. A NINTH LIVE HOT SET (adv-accept, 01:12 BST): seed 228763 (id 2c4be0f6dc44c423, stand-in 0.9820) at 2^24 (X at 0.1 percent +0.118, 1.82x the window model), its single hottest item 0xe2cc96 at 1,218,380 reads, 0.057 percent of ALL reads, the largest single item of the pass (40x 100767's), from a NON-saturated source r0 at site 9 (the sel register), saturated-source share 0.000: the third shape at scale, a value-level concentration neither (c') nor a saturation test can see by construction; its 2^20 ratio against the 0.995 floor lands in minutes and decides whether the floor's instrument reaches it (if missed, the exemplar for the next class's non-saturated case). 638990 reads 1.51x beyond the gate with one item at 0.027 percent (r0, no saturation), no hot set; 623492 clean. Tally: 9 hot sets in 37 tail seeds against 0 in 20 random, 269,250 programs drawn; the price unchanged at 1.002x (0.27 percent of reads on 1 MB; one item 64 bytes). The public sentence's "eight of eight" moves to "nine of nine" or gains the first miss when the ratio reads. THE FLOOR REACHES THE NON-SATURATED SHAPE (adv-accept gap-tail3, 01:13 BST): seed 228763 reads minimum site 9 at 0.9809 at the 2^20 sample, the lowest of the pass, REFUSED; 638990 site 2 at 0.9872, REFUSED; 623492 (clean live) site 0 at 0.9922, REFUSED, a seventh false refusal. Final tally over everything the lane read at 2^20: 9 of 9 live hot sets refused (0.9809 to 0.9919), both single-item programs refused, 7 clean-live programs refused and 1 passed among the 12 deepest 256-unit seeds, 3 mild residuals missed at about 1.0004x. The reading: the distinct-index ratio reads any few-item concentration whatever its source, saturated or not, and misses only the diffuse era-stride excess; the class v5 floor closes the hot-set class entire at the 2.4 percent clean-rejection cost; the next class's value-level test is for the diffuse class alone. The public sentence reads "nine of nine hot sets refused" from here (the v5 lane's follow-up cfce57ea rides its push; AP-F8-1 on master updates with the next record commit). THE FAST-TIME GATE ON dfbd1e10: SUMMARY PASS (cross-0324-dfbd1e10) at 00:12:57Z on 8 October (01:13 BST), the shipped re-cut's binaries (igneumd 4870ccf2..., igneum-miner aa8c2978..., igneum-pow 1c420786), build-1 under lease pool class v5, 23:58:56Z to 00:12:57Z, every check green: rung 1 by signal at epoch 6 (00:05:37Z), class v5 by signal at byte 6 from epoch 8 at rung 1 (00:07:46Z, 4 of 4, 9,985 bps), 12 of 12 ids equal to the CPU verifier's, the stale node 95 of 95 refused, the restart step across the boundary on a kept datadir resynced in 36.2 s with the catch-up done after 11 s (4 IsInIBD refusals of its own miner during it, 0 of its blocks accepted), four sinks equal at 661, 0 PoW rejections on the honest nodes; record on v5-fasttime 0a09eb78, docs/design/class-v5-harness/fasttime/cross-0324-dfbd1e10.json. Every gate on the pin is green; the move waits on the pairs on the dl host, the last FETCHED plus ten, and the F9/F1 interim read. THE RE-EXPORT READ (the v5 lane, box 1 with the merged crate ac285733): the three pinned packs' only difference was program.json's program_id_derivation text (generator 4 now "|| 'sub/' || sub_version_le16", generator 5 the class recipe "igneum-program-rw/ ..."); ids, kernel texts, leaves.bin, vectors and the fingerprint 82b19cbde8557ea5 byte-identical; the pinned packs carry the merged text; the full gate and the full igneum-pow suite with the packs test and spec_readback running on that tree, the push and commit string about 01:45 UK; main's sentence at nine of nine on AP-F8-6, section 14 and spec 1.4.7.2 at class-v5 b5d6368d (nothing with eight of eight reached the mirror). AP-F8-1's two eight-of-eight lines on master move to nine in this record commit. THE MOVE'S SOURCE (the shipper's ruling at 01:05 BST, corrected to this record at 01:1x): the 02:00 BST move does not wait on the build-server lane's pairs; that lane is dark (nothing published since 23:05 BST, nothing answered since 00:17), so the fleet moves EVERY Devnet 3 node from the node lane's dfbd1e10 pair at /srv/artefacts/0324-dfbd1e10/node-lane on build-1 (igneumd 4870ccf2, igneum-miner aa8c2978, the pair every gate ran on, native glibc 2.39 on every fleet box), the way dn3-g1 and g2 moved at 22:30; the fleet's puller fetches from build-1, not the dl host. The move waits on the fleet publishing the dfbd1e10 move file and naming the minute (asked 01:05) and the F9/F1 interim at 01:55. The hive and the Windows pairs are the dark lane's loss for tonight unless main gives the shipper the word to build them (asked 01:06); the Mac entry publishes at the minute regardless; if the fleet has not published the move file by 01:40 BST, main and the coordinator hear it with the clock. THE PC 1 LOCK VOID, THE V5 AMD BENCH PUBLISHED (the hash lane, 01:1x BST): the shipper's 0.3.24 host job was never published to the jobs file, so the slot was void (the shipper's "slot void" at 01:05 BST); the v5 kit fetch landed on both PCs at 00:12:06Z (919,273 bytes, sha256 ok); run-ca3-pc1-v5-amd-bench-20261007 published 00:14:19Z (the 9070 XT by name, about 3 minutes, lock-free), its start line printing app_version, so the 0.3.20 or 0.3.23 reading of PC 1's app comes with the fingerprint; PC 2's Arc job needs only the shipper's "PC 2 clear". PC 1's app had NOT taken the 0.3.23 kit as of the last reads (every job log through 21:46Z app_version 0.3.20; the install folder's exe igneum-app 0.3.20, mtime 12:24:42Z, sha256 0443ae17...). The update-return lane (a22d765a2e0355a9f) last spoke at 23:0x BST: the helper workaround for 0.3.20 scripts (truncate cmd.txt, restart the task, wait for helper.alive, then write; or four leading " dev " padding lines), the locked jobs held as they are, power-helper-24 b9a72b9b merged into release-0.3.24 (daa7427b: a silent change becomes a logged line, the helper writes its exit reason), install-close-23 4ad6c199 for 0.3.23's take 3, the re-probe job when PC 1's app has taken the 0.3.23 kit; nothing since. THE SPEC-TEXT READ-BACK PASS (adv-accept-3 Q4c, 01:11 to 01:15 BST on build-2 at 16 cores; report section 6.5 on build/adv-accept-3, log 983-textderive-8b834634.tsv, pushed): the spec text at master 8b834634, implemented fresh without the crate's generator or rule, reproduces the same 400 class v4 epoch programs as the code with 0 of 400 differences (every instruction, the chosen attempt, the id, the rejection sequence); the 264-of-400 divergence against the text at 017e7037 is closed, so AP-F8-5 reads fixed on a measurement. The one remaining gap: 1.4.6.4 names dataset_elem "of verify.rs" without its six operations, so parts (c), (c') and (c'') still take that function from the crate; the audit lane's one-sentence closed form (asked 01:1x) closes it, and the read-back re-runs on the new text. THE AMD CLASS V5 FINGERPRINT (PC 1's RX 9070 XT, gfx1201, beside the miners, lock-free): 82b19cbde8557ea5 at 01:16:14 BST, equal to the kit e6c088bb's on Metal, Apple OpenCL and CUDA, self-test PASS, the v4-genesis control 892b6d55a7ddcfcb PASS; the 0.3.24 kit stands on four platforms; Intel waits on PC 2 (held until main's word, since the 0.3.23 take 3 never ran there); PC 1's queue continues with the CA4 unlocked rows. The kits row reads: Metal, Apple OpenCL, CUDA, AMD equal; Intel not measured tonight. THE UPDATE-RETURN LANE'S THREE READINGS (01:17 BST, from the live manifest and the intake): (1) 0.3.23 take 3 (install-close-23 4ad6c199) never reported; the live manifest igneum-app-latest.json reads 0.3.23 published 20:37:44Z with platforms = {mac} only, NO Windows entry, so neither PC has anything to take through its update path; PC 2's app run is still take 1's relaunch from 21:08:43Z (997 uploads, last 00:16Z); (2) PC 1 will not take 0.3.23 unattended tonight for want of a Windows entry; its run win-ae432dc7-20261007-160110 (0.3.20) never restarted (2,376 uploads, last 00:16Z), mining 18.96 MH/s on the 9070 XT; when a Windows entry is published the 0.3.20 engine's OTA takes it with no hand; the 21:41:32Z helper.ps1 write was not the prompt path (0.3.20 writes that file unconditionally), so no screen is owed in the morning for it; (3) the re-probe job (relay/playbooks/pc1-helper-reprobe.ps1 on power-helper-24 69f3c733) waits only on PC 1's exe becoming 0.3.21 or later; the 0.3.20 workaround is cleared to run tonight as a lock-free job so the locked grids go ahead: per grid job, before the first command, empty sweep\cmd.txt, Stop-ScheduledTask and Start-ScheduledTask 'Igneum Power Helper', wait until helper.alive is within 4 s, then write the lines with climbing sequences (in 0.3.20 the skip is the line count at the helper's start, fixed for its life); the helper idle-exits 20 minutes after its last command and the next start must begin over an empty file again; never pad after a command. The coordinator's order to the hash lane on it: the locked grids proceed in the earlier order (the 5080 full grid, the third 5090 pass to the driver's floor, SM-sparse, the two Ember tunes, the hot-table ldcs rows), each with its restore step, under the no-prompt rule; a Start-ScheduledTask that reads the 0x800710E0 refusal again stops the job and reports, nothing escalates. THE LOCKED GRIDS UNDER THE WORKAROUND (the hash lane, 01:2x BST; commit 24f9858e on the mirror): the three lock scripts carry the cleared sequence (empty sweep\cmd.txt, Stop- then Start-ScheduledTask 'Igneum Power Helper', helper.alive within 4 s with a 60 s cap, then dev + command with climbing sequences; repeated before any write when helper.alive is older than 10 s; a refused start 0x800710E0 or no heartbeat stops the lock path with the text on RESULT lines, nothing escalates; no padding; each grid job ends with rgc through the same sequence and the applications clock read back). PC 1's app_version on the v5 bench's start line: 0.3.20 (no Windows 0.3.23 published, nothing to take). The CA4 SM-sparse job run-ca4-pc1-ca4sparse-5090-20261007 runs since 00:20:40Z on the earlier padded script (unlocked rows first, then its 1,300 knee attempt; about 25 to 50 minutes); then in order on the shipper's acks: the 5080 full grid as run-ca3-pc1-v4-eff-5080-20261007-d, the third 5090 pass (1,100 MHz down), the microbench and the seven packs, the 5080 Ember tune, the 9070 XT tune pass, the hot-table ldcs rows; the 5080 grid's knee and best points to the site audit lane for row 17 as read. THE ATTEMPTS CENSUS COMPLETE (adv-accept row 90, 01:34 BST, 20,000 seeds, closing the partial named at 00:00): 42,711 rejected candidates; (a') 83.5 percent, (a) 11.6, (b) 3.0, (c'') 1.1 (459 candidates), constant bit 0.4, saturated 0.3, (c') 0.05, distinct 0.04, lane-constant and bias 0; per-candidate rejection 0.681, flat across attempts 0 to 3 (the halves agree to a tenth of a percent); accepted-attempt mean 2.136, max 28; 0 exhaustions; P(256 consecutive rejections) 2e-43 per seed. The number for spec 1.4.6: under sub-version 3 the per-candidate rejection is 68.1 percent and the expected attempt 2.1. adv-accept's shards run on in the pool's gaps under the mechanical yield; the box-hours cross 8 later tonight. CLASS-V5 LANDED ON BOTH MIRRORS (the v5 lane, 091a0758 at 01:40 UK): the full pre-push gate GREEN at 71 checks (stamp on 48d38493, the last code change); the igneum-pow suite on box 2 (74 unit, derivation 2, derive 7, mixer 4, packs 20 with the three pinned packs byte-identical to the merged crate's export, so e5a4ac5978462156, 7c54302b487340a1, a217c7f698880830 and 82b19cbde8557ea5 hold under master's recipe form, recheck 2, scratch 7, spec_readback 2); spec-constants 28 rows agreeing; identity grep 0 hits. Carried since 61588347: main's sentence at nine of nine on AP-F8-6, section 14 and spec 1.4.7.2; the 61-row era reading and the class v5 attempts census on the spec, the page and the ledger; AP-F8-3; spec 1.4.7 and 1.8.6 with the constants and id tables; the AMD fingerprint row; the kits branch and master merged; two corrections the proofs found: master's program_id_derivation text lacked the class v5 rung-0 arm (the v5 packs' text named the class recipe while the id was the plain form; the arm added to the TEXT, re-exported, ids unchanged; a post-freeze change on the class-v5 line, so 0.3.25's pairing, never 1c420786's), and the public-export scrub (the founder's name six times on the page, the zone name in three files; gone). Incoming to the page: the Arc fingerprint, F9 and F1. THE MOVE FILE NOT PUBLISHED (the shipper, 01:41 BST): build-1's /fleet/move.json still names commit 2720d8d2 with the 22:30 BST minute; no FETCHED count, no named minute; the fleet lane (ac055d60427caab99) has answered nothing since its 22:4x report (asks at 01:05, 01:16 and 01:41; its task output last written 22:21 BST, its last action a hand read of dn3-g1's proven share), the second dark lane beside the build-server lane (last written 22:36 BST). So 02:00 BST cannot hold; the 02:53 BST ceiling (DAA 32,400) stands only if a signed move file lands at once and the 34 pullers fetch inside forty minutes; main has the clock line with the two options (wake or replace the fleet lane; or a fourth re-cut from a morning minute, the Mac entry standing down with it). The publish record's shape stands: the Mac entry at the minute (staged, DMG 1aa301cc, both folders, armed); the hive and the Windows pairs on main's word; the pairing 1c420786, 091a0758 0.3.25's. Every other gate on dfbd1e10 green and recorded. THE RUNG-0 ARM CONFIRMED (the v5 lane, 01:4x UK): 987e90e8 touches only Program::program_id_derivation, the text in program.json; Program::program_id untouched (the v5 rung-0 plain-form branch since the freeze); the crate at 091a0758 and 1b5684ec (master 35602b30 merged, pushed 01:41 UK) derives every pinned id byte for byte (packs 20 on box 2 comparing all three pinned packs' files including program_id and leaves.bin; spec_readback 2); the shipper told 091a0758 and 1b5684ec are 0.3.25's pairing, 0.3.24 on 1c420786. THE SM-SPARSE JOB (run-ca4-pc1-ca4sparse-5090-20261007, exit 0 at 00:41:53Z, 1,171 s, the 5090 alone, every fingerprint matched, the Power Helper answering every command on the padded write, the card left unlocked at 2,855 MHz): the SM-sparse reading does NOT exist; the research lane's worker ran its base kernel on every variant row (its race line "race 0 ms variant base" on all 48 rows, no NVRTC compile text), so --bench never honoured --variant sp-w32; the sparse rows equal base in rate and drift in watts with the card's heat only; the rerun waits on the research lane's exe honouring the flag. What stands: a repeat of the efficiency pass at two states, 32 s rows, the card alone: v4 unlocked 137.07 MH/s at 465.5 W (0.294 MH/W), at 1,300 MHz 134.26 at 309.9 W (0.433; 155.6 W back for 2.05 percent of rate); v3 unlocked 136.71 at 331.6 W (0.412), at 1,300 134.03 at 219.4 W (0.611; 112.2 W back for 1.97 percent); the v4 premium 133.9 W unlocked, 90.5 W at the knee; the three power fields agree within 0.2 W on every row (power.draw = instant = average on driver 617.14), which settles the field question on PC 1's side and leaves the 5080's 110 W gap to the fleet's rented card's sampler. Next on the shipper's ack: the 5080 full grid (-d) through the cleared helper sequence, the third 5090 pass, the microbench, the seven packs, the two tunes, the hot-table ldcs rows (kit and job at 292fcc75). THE --variant FAULT FIXED (the research lane, counter-asic-4, UTC clocks on 8 October): 00:44 the fix (a --bench with --variant runs the pinned race and installs the named kernel; the RESULT line carries variant=, sparse_blocks=, block_warps=; a served kernel other than the requested one prints variant_not_installed); 00:46 the known-failed test on build-1 against the real class v4 pack, no card (base: race off, 524,288 blocks of 32, "variant base"; sp43-w32: race on, 43 sparse blocks of 32 warps, the rewritten kernel with the nonces argument and the unit function, 43 blocks of 1,024; PASS; before the fix both read the base shape); 00:46 the Windows exe igneum-worker-cuda-ca4sparse3.exe sha256 0ba97edcd5c46a302a7ff5ddd1bbb1e493ca15f64d0757820ed645972df3bb56, mingw exit 0; the commit after 2d0013d1; the hash lane has the sha, the test's lines and the rerun's job shape (the same 48 rows, the race line per row); the op-mix re-weight stays behind the SM-sparse reading, the served 3.4x standing; the clean efficiency repeat in the file's 20.3a (6.6 pJ per counted op). THE SPEC'S LAST CRATE-DEPENDENT SENTENCE CLOSED (the site audit lane, master 56eebc0d at 01:49 BST, gate GREEN on c2c92eab, 71 checks; spec_readback now 3 tests): 1.4.6.4 states dataset_elem in full (the eight operations, the three constants, 32-bit wrapping) with two pinned vectors (dataset_elem(0x00000fed, 0x9E3779B9, 0x7F4A7C15) = 0x5c7dabd2; dataset_elem(0x0fffffff, 0, 0) = 0x7662c1ec) that spec_readback.rs reads from the text and checks against the crate, so part (c) computes from the text alone (34845c47); 1.4.6.5 names the class v2 figures as class v2's and carries the shipped rule's own census sentence (20,000 seeds, 68.1 percent rejected per candidate, the per-part shares, mean attempt 2.1, max 28, 0 exhaustions, 2e-43). The text-derived re-run on this text is the proof it is sufficient end to end (asked of adv-accept-3). THE MOVE FILE STAGED (the shipper, 01:5x BST): id mdfbd-1, commit dfbd1e10, want_digest b1ba7822, both pair slots on build-1's served tarball dfbd1e10-node-lane.tgz (e59ed0e6), at_epoch 0, signed with the fleet key on the Mac and verified against the fleet's public key in the puller's namespace; the read-back on placing it: the served file's id by curl and the first FETCHED on the relay intake; the 34 pullers fetch inside their one-minute timers (27 MB from build-1), the last FETCHED about five minutes after the file, the earliest minute ten after that. THE REAL LATEST-PUBLISH CLOCK: the file alone halts every miner on the restart, because each box's pack gate PAIR_MINER_SHA16 lacks aa8c2978 and the puller does not carry the file's miner sha into the restart environment; so route (A) also needs one ssh line on each of the 34 boxes before the minute with the fleet's tooling (the fleet lane's, or the shipper's on main's word). Absent main's word by 02:15 BST the shipper stands the Mac entry down under the ceiling rule (no app alone on b1ba7822) and 0.3.24 becomes a morning minute with a fourth re-cut. ROUTE (A) STAGED TO ONE COMMAND (the shipper, 01:5x BST): the gate script r0324/move/pair-gate-aa8c2978.py in its scratch (dry run by default, apply on the literal argument, the fleet's own Box helper and label list, nothing restarted); the dry run read 33 of 35 boxes, every one carrying the old gate list with fb147dd1 last and aa8c2978 absent, no env-last override; unreachable dn3-relay and p2-4090-1b (dead Vast proxies; they fall off at the move and rejoin by the pull); the apply about 90 s for the 33 with each gate read back and counted. THE F9/F1 INTERIM (the attack-pass lane, read at 01:5x BST): 71,292 seeds, 0 exhausted, 0 panics, max attempt 30; F1 0 failures at 2 h 23 min; the move's gate reads clear. On main's (A): apply 02:00, the file placed 02:02, the last FETCHED about 02:05, the minute 02:15 BST; main has the clock. Nothing applies before the word. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the founder's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule diff --git a/docs/plans/release-0.3.22.md b/docs/plans/release-0.3.22.md index bf2dcd568..30dc7acf1 100644 --- a/docs/plans/release-0.3.22.md +++ b/docs/plans/release-0.3.22.md @@ -154,3 +154,33 @@ The 0.3.23 node's heights move Devnet 3's digest to ba75bf6f, and the one-box-at **The node pin: release-0.3.24-node = 47b9b229** (774f16c9's v5 object plus the testnet re-cut 34892a36), fast-forwarded on both mirrors at 23:01:05 BST after the Devnet 3 canary set read clean on its own binary (igneumd 6bc18ac2, igneum-miner b55b60c7, /srv/artefacts/0324-tn-47b9b229/node-lane; digest 4a284b1d with no file, object version 6 stamped into the headers, the override refused, shutdown 725 ms, two empty nodes handshaking, the shared-devnet dialler and a 2720d8d2 node refused both ways); the pairing igneum-pow class-v5 1c420786. **The hash-side board (the Counter lane, 23:0x BST):** F8 on 1c420786 PASS at 23:03 BST (64 seeds at 2^24 on the chain path with the v5 dataset, the pairing bit for bit, 61 of 64 under 1.2x, the three over inside the named residue p4/p8/p10, p10 1.5047x the worst), F4 PASS (byte-identical to v4's census), the (c''') floor measured, the kit e6c088bb byte-identical to the tip, the fingerprint 82b19cbde8557ea5 on three platforms (AMD on PC 1's queue, Intel deferred). **Main's ruling on the clock:** the cut's gates are F4, F8 and the consensus rerun, all green, so the cut runs now (the pin, the pairs, the hive, the staging, no gap); F9 (10^5 exhaustion) and F1 (10^5 redundancy), running on build-1 as strengthening lines, gate the PUBLISH and the one-minute move: the move file publishes at at_epoch 0 for the fetches, and its minute is named only after both read PASS; anything but PASS and the staging stays staged, main hears first. The 28,800 floor holds for a publish by 23:52 BST (the node lane re-reads dn3-g1 at 23:30 BST and on the minute); past it the constant re-cuts to 32,400 and the pairs with it. **The app tree: release-0.3.24 = 1a58f384 on the mirror** (the version bump first, rule 15 green at six places; dash-24 19ab2a87; pool-finish-22 05f86a7f with dn3-split-read.mjs as the pool lane's; igneum-pow and proto-cuda/packs-ca3-v5 from 1c420786, which the Mac node pair build on 774f16c9 needed (StateStream, StateLeaves, ProgramClass::V5) and the build-server lane's --ship seed class the same, its overlay re-pointed; publish-public.sh's interface fix 80a4cfb1; power-helper-24 f1395775 and b9a72b9b (the engine never runs an elevated helper of its own on Windows, the task registered S4U with the right power-helper-task@unattended, the helper's start facts and exit reasons); the Windows pin to 47b9b229); app gate GREEN on build-1 (289 + 35 + 8), UI 87, pre-push 60. The Mac node pair builds on 47b9b229 under the lock from 23:06 BST; the 0.3.24 host is a fresh PC 1 build (version.h 0.3.24) in a slot after the hash lane's family run; the pairs, the hive with three kit zips (the two sub-version 3 and the v5 kit) and the Windows chain on the build-server lane. The PC 1 helper reading (the update-return lane, 23:01 BST): the elevated helper on PC 1 is alive and blind, not dead: the 0.3.20 helper's pre-0.3.21 skip rule skipped every 2-line rewrite as present at start; Stop-ScheduledTask writes no exit line; 0x800710E0 is the scheduler's record of a Start meeting a running instance; no crash; the 0.3.23 kit carries the effective_skip fix and PC 1 answers again once that kit replaces its exe. + +## 16. The floor re-cut to 32,400 and the move minute's gate (23:3x BST) + +**Main's ruling (23:31 BST):** the 28,800 floor is lost to the clock (the pairs from 47b9b229, the hive kits, the fleet's fetches and the ten minutes after the last FETCHED cannot land before 23:52 BST), so the constant re-cuts now rather than at 23:52: **release-0.3.24-node = c9e385eb** (23:32:09 BST; 47b9b229 with program_class_v5_activation_daa 32,400, epoch 9, everything else unchanged: byte 6, the window 86,400, the heights, the pool split at never, chain id 4463 below and 4464 from the floor, the testnet re-cut, pairing 1c420786); its gate set runs from 23:32:12 BST (the build at gate priority on build-1, consensus at gate priority and the five other suites on build-2, the Devnet 3 canary with the mixed-version step, the testnet canary, the fast-time pair); 774f16c9 and 47b9b229 are void as pins and their pairs with them. From dn3-g1's read at 23:30:17 BST (DAA 20,268 at 1.0 DAA/s): the floor lands about 02:52 BST on 8 October and holds for a move minute up to a publish at DAA 25,200, about 00:52 BST. After the digest move the node lane's DAA reads come from a 0.3.24 node the fleet names (build-1's 0.3.22 seed falls off at the move). The app side: release-0.3.24 = 25528e4b (the Windows pin to c9e385eb on 9854030b's crate); the Mac node pair and DMG rebuilt under the lock on c9e385eb from 23:34 BST. + +**The move minute's gate (main, 23:36 BST):** F9's full 10^5 completes about 00:40 BST, too close to the 00:52 ceiling, so the minute is named on the new pin, the last FETCHED plus ten, and an F9/F1 interim line from the attack-pass lane read inside the five minutes before the minute showing 0 exhausted, 0 panics and 0 redundancy failures over everything drawn so far (16,003 seeds at 23:35 BST, 0 exhausted, max attempt 25; geometric at 0.68, the same shape as sub-version 3's 10^6; exhaustion unreachable by construction with the 256 cap and the deterministic last resort); any non-zero before the minute holds the move and main hears first; the full 10^5 lands as the record line after. + +**The Devnet 3 row for the site and this record (main's wording through the Counter lane):** a 0.3.23 node that has not updated falls off at the digest move minute, not at the crossing; the crossing is the class change on nodes already past the digest. Served as: "update before or the node stops following Devnet 3; class v5 begins at DAA 32,400, about 02:52 BST", the minute filled when the fleet names it. + +## 17. The second lost floor and the named minute (00:5x BST, 8 October) + +**c9e385eb's gates all green at 23:39:31 BST** (build at gate priority, consensus 134, exec 47, pow 19, p2p-flows 38, core 175, miner 28, both canary sets; the fast-time SUMMARY PASS cross-0324-c9e385eb at 23:49:32 BST: the ladder's rung 1 by signal at epoch 6, class v5 by signal at byte 6 from epoch 8, 11 of 11 program ids equal to the CPU verifier's, the stale node refused 86 of 86, the restart step across the boundary resynced in 28.1 s, four sinks equal). The app side re-pinned to c9e385eb (release-0.3.24 = 25528e4b), the Mac pair (igneumd 29448a07, igneum-miner 9c7b5601) and the DMG 23fa82b7 built under the lock, the Mac entry re-staged in both folders. **The 32,400 floor lost at 00:53 BST:** dn3-g1 read DAA 25,126 at 00:52:03 and 25,169 at 00:52:38, the publish DAA past 25,200 at about 00:53:09 with no move made. The cause: the build-server lane reported nothing from 00:17 BST (the c9e385eb pairs and hive ordered at 23:41, the 0.3.24 host job on PC 1 in the slot since 23:13, 0.3.23 take 3 on PC 2 since 22:58; a read of all three asked at 23:43 and again at 00:57), so the fleet had no pairs to point its move file at and named no minute; the fleet's 22:59 BST proven-share line also unreported (asked four times). **The named minute (the shipper, 00:56 BST, to stop a fourth chase):** the move minute is 02:00 BST on 8 October (01:00Z), or the fleet's last FETCHED plus ten if later but before 02:53 BST; the floor cut from it in one go: program_class_v5_activation_daa 39,600 (epoch 11; the publish DAA at 01:00Z about 29,200, plus 7,200 is 36,400, the next 3,600 boundary), about 04:52 BST, holding for a publish up to DAA 32,400 at about 02:53 BST (a fifty-minute margin past the minute); the same gate set on the new object, the pin line in about 20 minutes, the pairs from it, the move file, the F9/F1 interim read at 01:55 BST (the attack-pass lane sends it unprompted), the apps' entries at or after the minute. If the build-server lane stays silent past 01:05 BST, the fleet moves from the node lane's pair as dn3-g1 and g2 did at 22:30, and the hive and the Windows pair wait on main's word for another builder. The crossing estimate for the record: about 04:52 BST on 8 October (chain id 4464 from that block); the Devnet 3 row's "" reads 02:00 BST unless the fleet names a later one. + +## 18. The 0.3.24 pin dfbd1e10 and the dark lane (01:0x BST, 8 October) + +**The pin: release-0.3.24-node = dfbd1e10**, every gate green at 01:01:52 BST (build at gate priority 00:56 BST, igneumd 4870ccf2 / igneum-miner aa8c2978 under /srv/artefacts/0324-dfbd1e10/node-lane, igneum-pow-v5 8 paths; pow 19, consensus 134 at gate priority, p2p-flows 38, exec 47, core 175, miner 28; the Devnet 3 canary with digest b1ba7822, object version 6 in the headers, the override refused, shutdown 2,015 ms, two empty nodes handshaking, a 2720d8d2 node refused both ways; the testnet canary on b2e856ed refusing a live old-object seed). The object: the class v5 floor at 39,600 (epoch 11, about 04:53 BST on 8 October), the Devnet 3 digest b1ba7822 from ba75bf6f, holding for a publish up to DAA 32,400 at about 02:53 BST; everything else as c9e385eb. The fast-time SUMMARY on it runs on its lane. The app side: release-0.3.24 = 20213a7b (the Windows pin to dfbd1e10 on 9854030b's crate), the Mac node pair (igneumd 7907e161, igneum-miner e0979436) and the DMG 1aa301cc (45,653,186 B) built under the lock at 00:59 BST, the Mac entry re-staged in both token folders (interface 1.0.2, the floor file kept) and armed for the fleet's minute. + +**The build-server lane dark (read at 01:04 BST):** the dl host's jobs file was last published at 23:05 BST and carries no 0.3.24 host job for PC 1 and no 0.3.23 take 3 for PC 2 (its last jobs there: 0.3.23's host build and upload, take 2's ISCC log read); the lane answered nothing after 00:17 BST to asks at 23:43, 00:57 and 01:04. With it sit the c9e385eb and dfbd1e10 hands, seed and Windows pairs, the 0.3.24 hive with the v5 kit, the 0.3.24 Windows chain, 0.3.23's Windows entry (and so the card), and its tooling commits (the detached-helper rule, the inline-rm check, the publisher's digest gate, the alias assertion, push-inputs' overrides). Rulings by the shipper, main asked to confirm: "slot void" to the hash lane at 01:05 BST (PC 1's lock-free queue moves: the v5 kit fetch, the 9070 XT v5 bench, the CA4 unlocked rows); the fleet moves EVERY Devnet 3 node from the node lane's dfbd1e10 pair (native glibc 2.39, the fleet's boxes' class), as dn3-g1 and g2 did at 22:30, aa8c2978 into the pack gate's list, build-1's three nodes restarted by the fleet itself on the minute; the 0.3.24 deploy publishes the Mac entry alone if no hive exists by the minute (the HiveOS alias stays on 0.3.23 and that gap is recorded; the public Mac alias moves in the same publish by main's rule); the Windows app chain waits for daylight or another builder, so tonight's 0.3.24 is Mac (and HiveOS if the shipper takes the package on main's word), with the 0.3.23 and 0.3.24 Windows entries and the card behind them. Main's word asked on three points: the shipper taking the hive and the Windows node pair through build-remote (the lease tool or plain), the Windows app chain's owner and hour, and take 3's publisher. + +**The 0.3.24 class v5 kit, one line for a reader diffing kits (the Counter lane, 01:1x BST):** the 0.3.24 packs are packs-ca3-v5-20261007T183921Z.zip, sha256 e6c088bb, the kits lane's export byte-identical to the frozen igneum-pow 1c420786 the pin pairs with (the v5-dn3-epoch0 pack, program id e5a4ac5978462156, fingerprint 82b19cbde8557ea5); packs-ca3-v5-20261007T221001Z.zip (4aaf9b9e, from class-v5 7f58af97) carries the same three packs, ids, kernels and leaves and differs only in the kit host code beside them (the bench lanes' kit for the fingerprint jobs, not the miners' pack set); the next export changes the program_id_derivation TEXT field only (the "sub/" suffix wording), the ids unchanged. The fleet places e6c088bb on every Devnet 3 box; the hive carries it. + +## 19. 01:41 BST: no move file, two lanes dark + +**dfbd1e10 fully gated:** the fast-time SUMMARY PASS cross-0324-dfbd1e10 at 01:12:57 BST (the shipped binaries; 12 of 12 program ids equal to the CPU verifier's, the stale node refused 95 of 95, the restart across the v5 boundary resynced in 36.2 s with its own mining held, four sinks equal), on top of every box gate green at 01:01:52; the kit's fingerprint 82b19cbde8557ea5 equal on four platforms (Metal, Apple OpenCL, CUDA, and the RX 9070 XT at 01:16:14 BST on PC 1, the v4 control PASS; Intel held with PC 2); class-v5 091a0758 (text arm and page rows, ids unchanged) landed at 01:40 as a post-freeze commit and is 0.3.25's with 8ca66afa; 0.3.24 pairs with 1c420786 as published. + +**The clock line (01:41 BST):** the fleet published no dfbd1e10 move file: build-1's /fleet/move.json still names commit 2720d8d2 with the 22:30 BST minute; no FETCHED count, no named minute, no 0.3.24 DAA reader for the node lane, no answer on build-1's three old-object nodes, no 22:59 or 23:59 BST proven-share line (asks at 01:05, 01:16, 01:41; the fleet lane's last line was its 22:4x report). With the build-server lane dark since 00:17, the two lanes that could move the fleet are silent, and the two that remain cannot (the node lane holds no box keys for the pods; the shipper holds the Mac). So the 02:00 BST minute cannot hold and the 02:53 ceiling (DAA 32,400) stands only if a signed move file lands within minutes and the 34 pullers fetch inside forty. Main's word asked on: (a) waking or replacing the fleet lane tonight (the puller is self-contained: a new signed move file at build-1's /fleet/ naming the node-lane pair and a minute is all the boxes need); (b) otherwise a fourth re-cut of the floor from a morning minute main names, the 0.3.24 Mac entry standing down until then (rule 5: no app alone on b1ba7822); (c) the four words from 01:06 and 01:20 (the hive and the Windows node pair by the shipper; the Windows app chain's owner and hour; take 3's publisher; "PC 2 clear" on the dark lane's ground). The attack-pass interim reads at 01:55 regardless; PC 1's lock-free queue runs (the CA4 unlocked rows from 01:17 BST). The update-return lane's PC 2 S4U proof and PC 1 re-probe stand on take 3, which never ran. + +**Route (A) staged, not placed (01:50 BST):** the dfbd1e10 pair tarball on build-1 and served (fleet/dfbd1e10-node-lane.tgz, 27,495,110 B, sha256 e59ed0e6; igneumd 4870ccf2, igneum-miner aa8c2978); the move file (id mdfbd-1, commit dfbd1e10, want_version igneumd/2.1.0-dfbd1e10, want_digest b1ba7822, both pair slots on that tarball, at_epoch 0) written and signed with the fleet key in the shipper's scratch (r0324/move), the signature verified against the fleet's public key in the puller's namespace; nothing on /fleet/ changed, no box fetched. **The gap that stops (A) as the file alone:** every box's pack gate (box-dn3.sh's PAIR_MINER_SHA16 default list 07246920, c29f33bb, dfdc6883, fb147dd1) lacks aa8c2978 and the puller restarts box-dn3.sh from the box's running environment without reading the move file's miner sha into it, so a move by the file alone restarts every node on b1ba7822 with every miner refused as "not a paired miner" (the 22:31 shape on all 34 boxes at once, chain rate zero until a hand fixes the list); the fix before the minute is one line per box over ssh with the fleet's keys and tooling (on this Mac under ~/igneum-fleet; the Vast proxies limit reach), the fleet lane's work or, on main's word, the shipper's. **Rule for the puller (0.3.25 tooling):** the move file names the pair's miner sha and the puller carries it into PAIR_MINER_SHA16 for the restart, so a pair's miner is paired by the file that moved it, never by a list a hand keeps. **The node lane's three facts (01:5x BST):** a 0.3.24 reader node on build-1 (dfbd1e10's binary, loopback JSON RPC 28690, never mines) dials ten fleet nodes and follows the chain from the move, so the crossing read waits on no fleet reader; the fourth re-cut is one script run from a named minute (about 20 minutes to the pin plus 14 for the fast-time pair); a morning minute later than about 12:50 BST on 8 October puts the floor at or above 79,200 (the difficulty v3 height) and moves the three heights up with it in the same commit. + +**Route (A) ready on one word (01:56 BST):** the gate script (r0324/move/pair-gate-aa8c2978.py: one line per box putting aa8c2978 into the pack gate's list in env-last and box-dn3.sh's default, dry run by default, apply on a literal argument, nothing restarted) dry-ran over the fleet's inventory with the fleet's Box helper, reads only: 33 of 35 Devnet 3 boxes reachable, every one on the old list (fb147dd1 last, aa8c2978 absent, no env-last override); unreachable dn3-relay and p2-4090-1b (dead Vast proxies; they fall off at the move and rejoin by the pull); the apply about 90 s with each gate read back. The F9/F1 interim at 01:55 BST read zeros across the line (71,292 seeds drawn, 0 exhausted, 0 panics, max attempt 30; F1 at 2 h 23 min with 0 redundancy failures), so the move's gate clears from the attack-pass lane; the full 10^5 and F1's result land as the record lines after. On "A": the gate line 02:00, the move file placed at at_epoch 0 02:02, the last FETCHED about 02:05, the minute 02:15 BST (publish DAA about 30,100, inside the 02:53 ceiling), the Mac entry at the minute, the fleet lane stopped and respawned after. Absent the word by 02:15: the stand-down, the fourth re-cut from a morning minute before 12:50 BST, the Mac entry held. diff --git a/docs/spec/01-lottery-hash.md b/docs/spec/01-lottery-hash.md index 18d917311..c73ea8ff8 100644 --- a/docs/spec/01-lottery-hash.md +++ b/docs/spec/01-lottery-hash.md @@ -118,30 +118,52 @@ The version 1 lever measurement (`load_weight = 17`, `proto-metal/MEMHARD.md` se ### 1.4.3 Draw order -From the program stream of 1.3.3, in this order, whether or not an op uses a value. +Implemented (`igneum-pow/src/generator.rs`, `candidate_from_words_class`; every path the chain and the packs take). From the program stream of 1.3.3, in this order, whether or not an op uses a value. The same procedure draws every class; a class changes what a draw is used for, never whether it is taken, so the stream stays aligned across classes. (1) Load slots. Let `p[0..62] = 1..63` (instruction 0 is never a load: nothing is fresh before it). For `i` in 0..15 draw `j = i + below(63 - i)` and swap `p[i]` and `p[j]`. The load slots are `p[0..15]`, a uniform 16-subset of 1..63. -(2) For each instruction `k` in 0..63, nine draws: +(2) For each instruction `k` in 0..63, in this order: ``` roll = below(75); op = first entry of the table of 1.4.2 whose cumulative weight exceeds roll (on a load slot the roll is drawn and ignored and op = load) dst = below(8) src: on an ALU slot a = below(7); src = a + (a >= dst) - on a load slot E = the registers other than dst, in register order, that an earlier instruction of this - program has written and that no later load has used as its source (E is empty before - instruction 0); if E is not empty, a = below(|E|) and src = E[a]; - if E is empty, a = below(7) and src = a + (a >= dst), and 1.4.6 (a) rejects the program + on a load slot E = the eligible registers (below), in register order; + if E is not empty, a = below(|E|) and src = E[a]; + if E is empty, a = below(7) and src = a + (a >= dst) (the fallback; 1.4.6 (a) or (a') rejects the program) b = below(8) (src2) imm = low32(next()) imm2 = low32(next()) rot = 1 + below(31) bit = below(32) mask = 1 << below(5) +under an era (every chain program of class v3 and v4; section 1.13.1): +k_off = below(3) +o = low32(next()) AND (2^k_off - 1) (k_off and o are kept on a load slot and are (0, 0) on an ALU slot) ``` -16 slot draws plus 64 x 9: 592 draws per program. A program is fully determined by its eight seed words. A load's source holds a value written in the same iteration that no earlier load has read, so no load repeats the address of an earlier load of the same hash, across the iteration boundary included (the first form of the rule, with every register eligible at instruction 0, left the wrap open and failed 1.4.6 (a) on 36 percent of programs; census section 7.1). +Eligible registers. Two per-register states are carried through the draw, updated after every instruction is drawn: + +| State | Start | After an instruction with `dst = d`, `src = a` | Used by | +|---|---|---|---| +| `fresh[r]` | all false | `fresh[a] = false` if the op is a load; then `fresh[d] = true` | every class | +| `fresh_value[r]` | all true | the table below, then the shared-operand rule | class v4 only | + +Under class v2 and class v3, `E` is every register `r != dst` with `fresh[r]`: written by an earlier instruction of this program and not read by a later load. Under the class v4 shape (`is_class_v4_shape`: the 256-instruction shadow block over the class v3 base, the pass count and the era set aside), `E` is every register `r != dst` with `fresh[r]` and `fresh_value[r]`: fresh by dataflow as well. The dataflow table (AP-F8-1, sub-version 2; `docs/analysis/ca3-v4-uniform.md`), evaluated with the values before the instruction: + +| Op drawn | `fresh_value[d]` after it | +|---|---| +| `load` | `fresh_value[a]` (a saturated source reads one fixed word and leaves a constant) | +| `add`, `sub`, `xor`, `mad`, `shfl` | `fresh_value[d] OR fresh_value[a]` | +| `rotl`, `rotr` | `fresh_value[d]` (a rotate maps all-ones and zero to themselves) | +| `or`, `mul`, `mulhi` | false | + +The shared-operand rule (sub-version 3): after `or d |= s`, a later `xor d ^= s` or `sub d -= s` with neither `d` nor `s` written in between computes `d AND NOT s`; after `xor d ^= s`, a later `or d |= s` computes `d OR s`. Either pair is lossy though its second op would count as injecting on its own (F8's p23: `or r6 |= r4; xor r6 ^= r4`). So the draw keeps `pair[d] = (op, s)` for the last `or` or `xor` written to `d`, and when the instruction drawn is the second half of such a pair on the same `s`, `fresh_value[d]` is set false whatever the table says. Then: `pair[d]` becomes `(op, a)` if the op is `or` or `xor` and the pair rule did not fire, else none; and every `pair[r]` whose `s` equals `d` is cleared (a write to a register clears every pair that names it as the operand). The `src2` register `b` takes no part in either state. + +(3) The latency-shadow block (class v4; Counter ASIC 3.0 item 8). After the 64 base instructions, `V4_SHADOW_INSTRS = 256` further instructions are drawn from the same stream, so the base program of a class v4 seed is the class v3 program of that seed draw for draw. Every shadow slot is an ALU slot: `roll = below(75)` and the op from the table of 1.4.2, `dst = below(8)`, `a = below(7); src = a + (a >= dst)`, `b = below(8)`, `imm`, `imm2`, `rot`, `bit`, `mask` as above; under an era `below(3)` and `next()` are drawn and ignored. No shadow instruction is a load, and the shadow block takes no part in the two states above during the draw (the acceptance rule's (a') reads it, section 1.4.6.3). The block runs `V4_SHADOW_REPS = 27` times at the end of every iteration (section 1.7); the latency ladder (`docs/design/latency-ladder.md`) moves the pass count alone and never the draw. + +Draw counts: 16 slot draws plus 64 x 9 = 592 under class v2; 64 x 11 + 16 = 720 under class v3 with an era; 720 + 256 x 11 = 3,536 under class v4 with an era. A program is fully determined by its eight seed words and its class. A load's source holds a value written in the same iteration that no earlier load has read, so no load repeats the address of an earlier load of the same hash, across the iteration boundary included (the first form of the rule, with every register eligible at instruction 0, left the wrap open and failed 1.4.6 (a) on 36 percent of programs; census section 7.1). Test vector: for seed `igneum-genesis` (attempt 0, program id `bcc1248b10cc90f2`, section 1.4.6) the first eight instructions are (`proto-cuda/packs/igneum-genesis-mh/program.json`): @@ -168,21 +190,135 @@ A program is transmitted as the seed bytes, never as instructions. A node hands ### 1.4.6 Program acceptance -Implemented (`igneum-pow/src/accept.rs`, `proto-metal/main.swift`; ledger M6 Fixed). A candidate program is accepted only if all of the following hold, and every conforming implementation MUST evaluate them identically. +Implemented (`igneum-pow/src/accept.rs`; `proto-metal/main.swift` for the class v2 parts; ledger M6 Fixed, AP-F8-1 to AP-F8-3, AP-F8-5). A candidate program is accepted only if every part below that applies to its class holds, and every conforming implementation MUST evaluate them identically. The verdict is accept or reject; the reason is the first failing part in the order of this section and is reported, never relied on. -(a) For every `load`, some instruction between the previous `load` from the same source register and this one, in cyclic order over the 64 instructions, writes that register. +| Part | Name | Class v2 and v3 | Class v4 | +|---|---|---|---| +| (a) | stale load source, cyclic | yes | yes | +| (b) | an injecting write per register | yes | yes | +| (a') | dataflow freshness to a fixpoint, with the shared-operand rule | no | yes | +| (c) | the dynamic test over 2,048 hashes | yes, the 64 base instructions | yes, with the shadow block executed | +| (c') | saturated load sources | no | yes | +| (c'') | the distinct-index ratio at 2^20 evaluations | no | yes | -(b) Every register `r0..r7` is the destination of at least one `add`, `sub`, `xor`, `mad`, `shfl` or `load`. +The class v4 parts and the class v4 cap are keyed on the class v4 shape (`accept::is_class_v4_shape`): the 256-instruction shadow block over the class v3 base, the pass count and the era set aside, so a rung of the ladder keeps every rule and class v2 and v3 verdicts never move. -(c) The program is interpreted (section 1.7) for 64 units at base nonces `low32(next()) AND NOT 31` from a SplitMix64 stream seeded with `FNV-1a-64("igneum-accept/" || seed words as little-endian bytes)`, with init words `I` equal to the seed words and dataset words `dataset_elem(idx, S[0], S[1])` of `verify.rs` (the six-operation closed form of the version 0.1 packs) at 2^28 words (`idx = src AND 0x0fffffff`, a constant of this rule whatever the live dataset size) in place of the memory-hard dataset. Over those 2,048 evaluations: no register has a bit equal in every final value; no `load` site (iteration, instruction) reads one address in all 32 lanes of any unit; the number of final register values equal to 0 or 2^32 - 1 is below 164 (1 percent of 16,384); every output bit's ones count is within 136 of 1,024 (6 sigma); and the number of distinct masked dataset addresses read by one lane in one evaluation, summed over the 2,048 evaluations, exceeds 245,760 (a mean above 120 of the 128 loads). +#### 1.4.6.1 Part (a): no stale load source -Attempts. Attempt 0 of a program seed `b` (the 32-byte epoch seed, or the UTF-8 of a seed string) is the candidate drawn from `seed_words_from_bytes(b)`. If it fails, attempt `k = 1, 2, ...` is drawn from `seed_words_from_bytes(b || k_le32)`; the first accepted candidate is the program of the epoch. Measured rejection rate under this generator: 5.14 percent over 100,000 seeds (census section 7) and the 20,000-seed confirmation of `docs/bench-log.md` (4 October 2026), so the probability that 32 consecutive candidates fail is below 2^-136, and an implementation MAY treat 32 consecutive failures as a consensus fault (`MAX_ATTEMPTS`). +Over the 64 base instructions, twice in a row (so the second pass sees the state carried over the iteration boundary): keep `pending[r]`, set when a load reads `r` and cleared when any instruction writes `r` (its `dst`). A load that reads `r` while `pending[r]` is set rejects the program. The shadow block is not read here. -Program id. `FNV-1a-64("igneum-program/" || generator_le32 || seed words as little-endian bytes || attempt_le32 || suffix)` with `generator = 2` under class v2 and `generator = 3` under class v3 (no suffix), and `generator = 4` under class v4 with the suffix `"sub/" || sub_version_le16` (the class v4 stream's sub-version, 3 since 7 October 2026: `PROGRAM_SUBVERSION_V4` in `generator.rs`, `IGNEUM_PROGRAM_SUBVERSION` in program.h, `"sub_version"` in program.json; without the suffix Devnet 3's epoch-0 id reads 30956569d8f3d8d7 where the chain and the packs say fce15bf61030be57); class v5 is `generator = 5` with no suffix. A program of a non-default class (a read-width, scratch, mixer, derivation, era, shadow or hot rung other than class v4's rung 0) uses the tag `"igneum-program-rw/"` and appends the class's fields after `attempt_le32` (`generator::program_id_class_recipe`). Every pack prints its own derivation as `program_id_derivation` in program.json, built from the same byte recipe the id is hashed from (`generator::IdRecipe`), and `igneum-pow/tests/derivation.rs` re-derives every pinned pack's id from that text. Two implementations that agree on the id agree on the generator version, the seed words, the attempt and, under class v4, the sub-version. +#### 1.4.6.2 Part (b): an injecting write per register -Why the closed form: the test is then a pure function of the program (no cache, no day), costs 1.3 to 3.4 ms on one core, and the census checked on 100,000 programs that its verdict agrees with the memory-hard dataset's on all but 39 threshold-edge cases (section 7.3). What the three parts catch: (a) the empty-list fallback of 1.4.3; (b) registers that saturate to all ones (2.4 percent of candidates); (c) zero-absorbing register sets, lane-constant load sites, output bias and value-level address repeats (2.1 percent). Not in the rule, and why: a contraction as the last write (80 percent of programs) and the `or` count are too common and (c) already catches the cases that matter; the load critical path is a hash-rate question, not a weakness. +Every register `r0..r7` is the `dst` of at least one `add`, `sub`, `xor`, `mad`, `shfl` or `load` among the 64 base instructions. The shadow block is not read here. -Test vectors for the rule (`igneum-pow accept --seed ...`): +#### 1.4.6.3 Part (a'): dataflow freshness in the steady state (class v4) + +The draw of 1.4.3 keeps in-pass sources fresh; this part closes the iteration boundary (a source last written late in the previous iteration or in the shadow block, which the draw's empty-list fallback can pick: F8's p11, an `or` at 63 feeding a load at 1). One pass walks the 64 base instructions then the 256 shadow instructions, in that order (the order of one iteration), applying the `fresh_value` table and the shared-operand rule of 1.4.3 to the states `fresh_value[0..7]` and `pair[0..7]`. Start with every register fresh and no pair (the init words are a per-lane hash of the nonce). Run passes until a pass changes neither state (the state only ever falls, so at most 8 passes change it; the implementation runs at most 9 and stops at the first unchanged one). Then run one checking pass in the same order: a load whose source is not fresh at that point rejects the program (`UnfreshLoadSource`, the instruction index counted over base then shadow). + +#### 1.4.6.4 Part (c): the dynamic test + +The program is interpreted for `ACCEPT_UNITS = 64` units of 32 lanes, `ACCEPT_HASHES = 2,048` hashes, with these inputs and nothing of the live chain: + +| Input | Value | +|---|---| +| Base nonces | the first 64 values of SplitMix64 seeded with `FNV-1a-64("igneum-accept/" || seed words as little-endian bytes)`, each `low32(next()) AND NOT 31`; unit `u` runs lanes `base_u + 0 .. base_u + 31` | +| Init words `I` | the program's eight seed words (section 1.6) | +| Dataset | the closed form `dataset_elem(idx, S[0], S[1])` below (the version 0.1 packs' stand-in; `S[0]`, `S[1]` are seed words 0 and 1) at `ACCEPT_DATASET_LOG2 = 28`, 2^28 words, `MASK = 0x0fffffff`, whatever the live dataset size | +| Address of a load with source value `x` | without an era `idx = x AND MASK`; under an era the form of 1.13.1 at `D = 28`: `k = min(k_off, 2)`, `y = rotl(x * M, R)`, `idx = ((y AND (MASK >> k)) OR ((o AND (2^k - 1)) << (28 - k))) AND MASK` | +| Execution | section 1.7 exactly, the shadow block included under class v4: after instruction 63 of every iteration the 256 shadow instructions run 27 times with that iteration's `sel` (sub-version 3, AP-F8-3; until it, the test ran the base instructions alone and judged a program the chain never hashes) | + +The closed form, 32-bit wrapping arithmetic throughout (`verify.rs`, `dataset_elem`; the rule's only dataset, never the chain's): + +``` +dataset_elem(i, S0, S1): + x = i XOR S0 + x = x * 0x9E3779B1 + x = x XOR (x >> 15) + x = x + S1 + x = x * 0x85EBCA77 + x = x XOR (x >> 13) + x = x * 0xC2B2AE3D + x = x XOR (x >> 16) + return x +``` + +A load reads `dataset_elem(idx, S[0], S[1])` and XORs it into `dst`, as 1.4.1 reads `dataset[idx]`. Test vectors, pinned by `igneum-pow/tests/spec_readback.rs`: `dataset_elem(0x00000fed, 0x9E3779B9, 0x7F4A7C15) = 0x5c7dabd2`; `dataset_elem(0x0fffffff, 0x00000000, 0x00000000) = 0x7662c1ec`. The register initialisation is section 1.6 with `I` the seed words; `sel`, the instruction semantics and the output fold are section 1.7. + +During the run: a `load` whose 32 lanes compute one address in any unit rejects the program (`LaneConstantSite`, checked at every load of every iteration and unit, the shadow block has none). After the run, over the 2,048 final register states and 2,048 outputs, in this order: + +| Check | Limit | Reject | +|---|---|---| +| Nonce-independent bits | no register has a bit equal in all 2,048 final values | `ConstantBit` | +| Saturated finals | the number of final register values equal to 0 or 2^32 - 1 is below `MAX_SATURATED = 164` (1 percent of 16,384) | `Saturated` | +| (c'), (c'') | class v4 only, section 1.4.6.5 | | +| Output bias | every output bit's ones count is within `BIAS_TOLERANCE = 136` of 1,024 (6 sigma) | `OutputBias` | +| Distinct addresses | the number of distinct `idx` values one lane read in one hash, summed over the 2,048 hashes, exceeds `MIN_DISTINCT_SUM = 245,760` (a mean above 120 of the 128 loads; `loads x 2,048 x 120 / 128` for a class with another load count) | `DistinctAddresses` | + +#### 1.4.6.5 Parts (c') and (c''): the load sources (class v4) + +A load site is a load's ordinal within the iteration, 0 to 15, in instruction order. Both parts read the same interpreter and the same nonce stream as (c). + +(c') Saturated sources. Over the 64 units of (c), every site is evaluated 64 x 32 x 8 = 16,384 times. A site whose source value `x` was 0 or 2^32 - 1 in `MAX_SATURATED = 164` or more of them rejects the program (`SaturatedSource`, the first such site in order). A saturated source reads one fixed word whatever delivered the saturation; the draw's rule removes the writers it can see and this count catches every delivery. + +(c'') The distinct-index ratio. The one test that runs past the 64 units: `ACCEPT_UNITS_DISTINCT_V4 = 4,096` units, the first 4,096 base nonces of the same stream (the 64 of (c) are its first 64), so every site is evaluated `N = 2^20` times. For each site `s`, `d_s` is the number of distinct `idx` values it computed over those evaluations, `W_s = 2^28 >> min(k_off_s, 2)` is its window in words, and the expectation of a uniform source on that window is `E_s = N - N^2 / (2 W_s)` (an integer at these constants: 2^20 - 2^11, 2^20 - 2^12, 2^20 - 2^13). The site's ratio `d_s / E_s` must reach `MIN_DISTINCT_RATIO_V4 = 0.98`; the first site under it, in order, rejects the program (`LowEntropySite`). The implementation compares in f64; the integer comparison `50 d_s >= 49 E_s` gives the same verdict for every value of `d_s` at these constants (the margin is at least 0.32 of a count; adv-accept-3 section 6.1), and an implementation MAY use it. The floor sits in a measured gap: the accepted population's minimum is 0.983 to 0.989 and the rejected population's maximum 0.966 over 20,275 draws of two lanes, so a floor anywhere in 0.967 to 0.988 gives the same verdicts on every program seen (adv-accept-3 section 6.4). `MAX_SOURCE_REPEAT_V4 = 8` exists in the file and is not part of the rule. + +What the parts catch: (a) the empty-list fallback of 1.4.3; (b) registers that saturate to all ones (2.4 percent of class v2 candidates, the class v2 census); (c) zero-absorbing register sets, lane-constant load sites, output bias and value-level address repeats (2.1 percent of class v2 candidates); (a') the cross-hash hot set of a load fed by `or`, `mul` or `mulhi` through the iteration boundary (AP-F8-1); (c') the same set delivered any other way; (c'') a low-entropy index band the lineage rules cannot see (F8's p23, p18, p19, p15, p56). Under the shipped rule, measured on 20,000 seeds (adv-accept's attempts census on sub-version 3, 42,711 rejected candidates, 8 October 2026): 68.1 percent of candidates are rejected, flat across attempts; of the rejections (a') takes 83.5 percent, (a) 11.6, (b) 3.0, (c'') 1.1, (c) constant bits 0.4, (c) saturated finals 0.3, (c') 0.05 and (c) the distinct sum 0.04; the accepted attempt is 2.1 on average and 28 at most, 0 seeds of 20,000 reached the cap, and 256 consecutive rejections have probability about 2 x 10^-43. Why (c) uses the closed form: the test is a pure function of the program (no cache, no day), costs about 3 ms on one core for the 64 units and 2.8 s with (c'') on the chosen candidate, and the census checked on 100,000 class v2 programs that its verdict agrees with the memory-hard dataset's on all but 39 threshold-edge cases (section 7.3). Not in the rule, and why: a contraction as the last write (80 percent of programs) and the `or` count are too common and (c) already catches the cases that matter; the load critical path is a hash-rate question, not a weakness; a 2^24 stage of (c'') does not separate the open F8 tail (p4, p8, p10, p34 read the clean seeds' values there; ledger AP-F8-1). + +#### 1.4.6.6 Attempts, the cap, the last resort and the program id + +Attempts. Attempt 0 of a program seed `b` (the 32-byte epoch seed, or the UTF-8 of a seed string) is the candidate drawn from `seed_words_from_bytes(b)`. If it is rejected, attempt `k = 1, 2, ...` is drawn from `seed_words_from_bytes(b || k_le32)`; the first accepted candidate is the program of the epoch. The cap is `MAX_ATTEMPTS = 32` under class v2 and v3 and `MAX_ATTEMPTS_V4 = 256` under the class v4 shape (`max_attempts_for`). + +| Rate, per candidate | Class v2 (census, 100,000 seeds, 4 October 2026) | Class v4 sub-version 3 (adv-accept-3, 3,009,928 candidates of 10^6 seeds and 62,240 of 19,975 full-rule seeds, 7 October 2026) | +|---|---|---| +| Accepted | 0.9486 | 0.323 | +| (a') | not a part | 0.568 | +| (a) | | 0.079 | +| (b) | | 0.022 | +| (c), (c'), (c'') together | | about 0.009 | +| Seeds reaching the cap | 0 of 100,000 | 0 of 1,019,975 | +| Probability a seed reaches the cap | below 2^-136 | 0.677^256, about 4.6 x 10^-44 | + +Under class v2 and v3 an implementation MAY treat the cap as a consensus fault. Under class v4 the draw is total (AP-F8-2): a seed whose 256 candidates are all rejected takes the last-resort program, the candidate at attempt 256 with every `or`, `mul` and `mulhi` of its base program and its shadow block rewritten to `xor` (`dst`, `src` and every other field kept), handed to the chain as drawn with no further check. With no lossy op left, (a') holds by construction. The rest of the rule is not checked on it, and does not hold on every seed: on 3,000 seeds the real rule rejects the last-resort program of 271 (251 by (a), the fallback-drawn load source the rewrite does not touch; 14 by (b); 6 by (c)'s distinct sum), so sub-version 3's last resort is stated here as unreachable and unverified (adv-accept-3 finding 1, ledger AP-F8-3); class v5 carries the verified construction (section 1.4.7). + +Program id. `FNV-1a-64("igneum-program/" || generator_le32 || seed words as little-endian bytes || attempt_le32 || suffix)` with `generator = 2` under class v2 and `generator = 3` under class v3 (no suffix), and `generator = 4` under class v4 with the suffix `"sub/" || sub_version_le16` (the class v4 stream's sub-version, `PROGRAM_SUBVERSION_V4 = 3` since 7 October 2026: `IGNEUM_PROGRAM_SUBVERSION` in program.h, `"sub_version"` in program.json; without the suffix Devnet 3's epoch-0 id reads 30956569d8f3d8d7 where the chain and the packs say fce15bf61030be57); class v5 is `generator = 5` with no suffix (section 1.4.7). A class v4 program at rung 0 of the ladder uses that form; a program of any other class or rung (a read-width, scratch, mixer, derivation, era, shadow or hot rung other than class v4's rung 0) uses the tag `"igneum-program-rw/"` and appends the class's fields after `attempt_le32` (`generator::program_id_class`). Every pack prints its own derivation as `program_id_derivation` in program.json, built from the byte recipe the id is hashed from, and a worker MUST refuse a pack whose generator version, class, era seed or sub-version is not its own (`packcheck.rs`). Two implementations that agree on the id agree on the generator version, the seed words, the attempt and, under class v4, the sub-version. + +Constants of the shipped rule. One row per constant the rule depends on, the value as the crate has it; a reader implementing from this text uses these and nothing else. `tools/ci/spec-constants-check.mjs` (the pre-push gate) reads every table of this shape in this file back against the crate's `pub const` items and fails on a difference; `igneum-pow/tests/spec_readback.rs` derives every pinned id below through the crate. + +| Constant | Value | Where | +|---|---|---| +| generator::INSTR_COUNT | 64 | instructions per base program | +| generator::LOAD_SLOTS | 16 | load slots per program | +| generator::ITERATIONS | 8 | iterations per hash | +| generator::LANES | 32 | lanes per unit | +| generator::GENERATOR_VERSION_V4 | 4 | the class v4 generator | +| generator::PROGRAM_SUBVERSION_V4 | 3 | the id suffix "sub/" || le16 | +| generator::MAX_ATTEMPTS | 32 | the cap under class v2 and v3 | +| generator::MAX_ATTEMPTS_V4 | 256 | the cap under the class v4 shape | +| generator::V4_SHADOW_INSTRS | 256 | shadow instructions per program | +| generator::V4_SHADOW_REPS | 27 | shadow passes per iteration at rung 0 | +| accept::ACCEPT_TAG | "igneum-accept/" | the domain tag of the base-nonce stream | +| accept::ACCEPT_UNITS | 64 | (c) units | +| accept::ACCEPT_HASHES | 2048 | (c) hashes | +| accept::ACCEPT_DATASET_LOG2 | 28 | log2 of the closed-form dataset | +| accept::MAX_SATURATED | 164 | (c) saturated finals and (c') saturated sources: the first refused count (the reject message prints 163, the last allowed) | +| accept::BIAS_TOLERANCE | 136 | (c) output bias, inclusive | +| accept::MIN_DISTINCT_SUM | 245760 | (c) distinct-address sum, exclusive | +| accept::ACCEPT_UNITS_DISTINCT_V4 | 4096 | (c'') units, 2^20 evaluations per site | +| accept::MIN_DISTINCT_RATIO_V4 | 0.98 | (c'') ratio floor, inclusive | +| accept::distinct_ratio_pass | 2 | the window cap of (c''): `W_s = 2^28 >> min(k_off_s, 2)`, a literal inside the function | + +Pinned program ids. A reader who follows 1.4.3 and this section reproduces these from the seed, the attempt and the sub-version above. The era seed of each chain row is the same 32 bytes as its program seed (the devnet stand-in of 1.13.1). `igneum-pow/tests/spec_readback.rs` derives each id through the crate and draws each class v4 row with the era to its stated attempt; a "must differ" row asserts the current derivation gives another id. + +| Seed | Attempt | Id | Note | +|---|---|---|---| +| edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 | 1 | a785001687d8688a | the shared devnet's epoch-0 seed under class v4 sub-version 3 (generator 4, the suffix); attempt 0 is rejected under class v4 | +| edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 | 0 | 73bcbfe8ccf988f1 | the same seed under class v3 (generator 3, no suffix): the class v3 control | +| edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 | 1 | c120d7963abdcd96 | must differ: generator 4 without the suffix, the stream of 6 October 2026 (sub-version 0, never stamped) | +| edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 | 1 | 1a4230699a6b9c60 | must differ: sub-version 1, the stream 0.3.20 and 0.3.21 shipped as object byte 5 | +| edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 | 1 | a788661687db4bb3 | must differ: sub-version 2, never shipped | +| 4020cb4382e3fe4b281c817c02582e147d8f851f566ae9172b28912b8e68b925 | 0 | fce15bf61030be57 | Devnet 3's epoch-0 seed (its genesis hash) under class v4 sub-version 3, accepted at attempt 0; 30956569d8f3d8d7 without the suffix | + +Test vectors for the class v2 rule (`igneum-pow accept --seed ...`): | Seed | Attempt 0 | Attempt 1 | |---|---|---| @@ -192,7 +328,7 @@ Test vectors for the rule (`igneum-pow accept --seed ...`): | `igneum-census-2026-10-03/37` | rejected, (c) 245,230 distinct addresses (mean 119.74) | accepted, `947705cc4eb1df0a` | | `igneum-census-2026-10-03/51` | rejected, (b) r4 has no injecting write | accepted, `9869afcc028bf9f1` | -The Rust crate and the Swift prototype derive identical instruction lists and identical 96-vector sets on all five seeds (`docs/bench-log.md`, 4 October 2026). +The Rust crate and the Swift prototype derive identical instruction lists and identical 96-vector sets on all five seeds (`docs/bench-log.md`, 4 October 2026). For the class v4 rule, a second implementation written from the module table of `accept.rs` and this section agreed with the crate on 5,748 of 5,748 attempt verdicts over 1,792 seeds, part for part, with its known-failed control fired (adv-accept-3 section 6.4); an implementation written from the text of this section as it stood before 7 October 2026 mined a different program on 264 of 400 epochs (adv-accept-3 section 6.2, ledger AP-F8-5), which is why every constant and every order of operations is now stated here. ## 1.5 Fixed memory footprint @@ -244,6 +380,8 @@ The output folding rotations (7, 14, 21; 9, 18, 27) are Implemented, prototype v `shfl` makes the 32 lanes of a unit interdependent: the hash of one nonce is defined only as a member of its aligned group of 32 (section 1.9). +Class v4 (Counter ASIC 3.0, the latency shadow): after instruction 63 of every iteration, and before the next iteration samples `sel`, the program's 256-instruction shadow block (section 1.4.3 (3)) is applied `V4_SHADOW_REPS` times with the iteration's `sel`, 27 at rung 0 of the latency ladder, so one hash runs 64 x 8 base instructions and 256 x 27 x 8 = 55,296 shadow instructions. The shadow holds no load. The acceptance interpreter of 1.4.6.4 runs the same block the same way (sub-version 3). The ladder (`docs/design/latency-ladder.md`) moves the pass count by miner signal and nothing else in this section. + ## 1.8 The memory-hard dataset Implemented (`memhard.rs`), construction and measurements in `proto-metal/MEMHARD.md`. Every constant below is a prototype value, to be fixed at gate 1, unless marked Definition. What fixes them is the shortcut-ratio and time-memory trade-off measurement on NVIDIA and AMD discrete cards (section 1.16 items 2 and 3) and an external review of the primitives (ledger M7). @@ -321,6 +459,8 @@ item(t) = s Eight dependent cache reads (`ITEM_ROUNDS = 8`, prototype value): the address of read `r` depends on every earlier read. Nine mixer applications under program class v2. +Under class v5 the item's init words carry the leaf of section 1.8.6. + Program class v3 (Counter ASIC 2.0, decided 5 October 2026, delegated; the founder confirms for the public testnet genesis) applies the mixer `m = 8` times per round with distinct round keys (`LoadClass::mixer_mult`; `docs/plans/mixer-x4.md` section 2), the eight dependent reads unchanged: ``` @@ -441,7 +581,7 @@ The era seed `E_n` is the 32-byte output of the 1-hour VDF of section 4.4 (in th `epoch_len` is the one era-table parameter set by miners rather than by the draw: 90% of blue blocks over a 7-day window carrying the same ladder index (3 bits of the header version, encoding Open in section 5.8) sets that length from the first day boundary at least 2 days after the window closes (section 5.7). It is not a code upgrade: the rule, the ladder and the window are genesis constants, and the chain carries no release. The era stream consumes its draw so that a future draw of this parameter changes no other parameter's value. The threat it answers is a per-program hard datapath (an FPGA fleet: 42 to 160 minutes per compile on a mid-size part, PRflow, FPT 2019, hours on large parts; at 600 s nothing it compiles ever runs); it does not answer a programmable chip, which the other layers answer. The floor 600 is set by the slowest compile-ahead measured (the Metal variant race, 38 s on the M5 Max, 6.3% of a 600-s epoch and inside the 600-s seed window; `docs/plans/epoch-length.md` section 6). -The table layout and the working-set window (Counter ASIC 2.0 layers 4 and 8, decided IN on 5 October 2026, delegated: the six-era hash-rate spread is 1.3% on the RTX 5090, 3.2% on the RX 9070 XT and 0.8% on the M5 Max, under the 5% rule; `docs/plans/era-layout.md`) are drawn under program class v3 by a second stream `S` seeded with words 0 and 1 of `seed_words_from_bytes("igneum-era/" || E_n)` (the index is not in the preimage: `E_n` commits to `n` through the VDF input), seven draws in this order whether or not a value is used: +The table layout and the working-set window (Counter ASIC 2.0 layers 4 and 8, decided IN on 5 October 2026, delegated: the six-era hash-rate spread is 1.3% on the RTX 5090, 3.2% on the RX 9070 XT and 0.8% on the M5 Max, under the 5% rule; `docs/plans/era-layout.md`) are drawn under program class v3 by a second stream `S` seeded with words 0 and 1 of `seed_words_from_bytes("igneum-era/" || E_n)` (the index is not in the preimage: `E_n` commits to `n` through the VDF input), nine draws in this order whether or not a value is used (the eighth and ninth, `epoch_len` and the latency ladder, are consumed and not read: both are set by miner signal, and consuming their slots means a later use of either changes no other draw; `generator::era_draw`): 1. `W = allowed[below(|allowed|)]`: the width in words of every dataset load of the era, from the genesis-fixed set `allowed`; the set is `{1}` (4 bytes, the read-width decision of 5 October 2026), so the draw is consumed and the width pinned. 2. `M = low32(next()) OR 1`: the stride multiplier, odd, so `x -> x * M` is a bijection. diff --git a/igneum-pow/tests/spec_readback.rs b/igneum-pow/tests/spec_readback.rs new file mode 100644 index 000000000..61b1bb0df --- /dev/null +++ b/igneum-pow/tests/spec_readback.rs @@ -0,0 +1,143 @@ +//! Spec read-back, the ids half (adv-accept-3 finding 3, ledger AP-F8-5, 7 October 2026): every table of +//! `docs/spec/01-lottery-hash.md` headed `| Seed | Attempt | Id | Note |` names program ids a reader of sections 1.4.3 +//! and 1.4.6 must reproduce. This test derives each one through the crate (never by re-hashing the hex in a script): +//! a row whose Note says "must differ" asserts the current derivation gives another id (an earlier stream or +//! sub-version of the same seed); every other row asserts `program_id` over `attempt_words(seed, attempt)` under the +//! row's generator (3 for "class v3", 5 for "generator 5", else 4) equals the id, and, for a class v4 row, that the +//! chain's own draw with the era seed (the same bytes unless the Note names another) accepts at that attempt. +//! The constants half is `tools/ci/spec-constants-check.mjs` (the pre-push gate; no build). +use igneum_pow::verify::dataset_elem; +use igneum_pow::generator::{attempt_words, generate_from_seed_bytes_program_class, program_id, ProgramClass, GENERATOR_VERSION_V3, GENERATOR_VERSION_V4}; +use std::path::PathBuf; + +const SPEC: &str = "../docs/spec/01-lottery-hash.md"; + +struct Row { + line: usize, + seed: String, + attempt: u32, + id: u64, + note: String, +} + +fn rows() -> Vec { + let path = PathBuf::from(env!("CARGO_MANIFEST_DIR")).join(SPEC); + let text = std::fs::read_to_string(&path).unwrap_or_else(|e| panic!("{}: {e}", path.display())); + let lines: Vec<&str> = text.lines().collect(); + let header = |l: &str| { + let cells: Vec = l.trim().trim_matches('|').split('|').map(|c| c.trim().to_string()).collect(); + cells == ["Seed", "Attempt", "Id", "Note"] + }; + let mut out = Vec::new(); + let mut i = 0; + while i < lines.len() { + if !header(lines[i]) { + i += 1; + continue; + } + let mut j = i + 1; + if j < lines.len() && lines[j].trim_start().starts_with("|---") { + j += 1; + } + while j < lines.len() && lines[j].trim_start().starts_with('|') { + let cells: Vec = lines[j].trim().trim_matches('|').split('|').map(|c| c.trim().trim_matches('`').to_string()).collect(); + assert!(cells.len() >= 4, "{}:{}: a Seed | Attempt | Id | Note row needs four cells", SPEC, j + 1); + let attempt: u32 = cells[1].parse().unwrap_or_else(|_| panic!("{}:{}: attempt {:?} is not an integer", SPEC, j + 1, cells[1])); + let id = u64::from_str_radix(cells[2].trim_start_matches("0x"), 16).unwrap_or_else(|_| panic!("{}:{}: id {:?} is not 16 hex", SPEC, j + 1, cells[2])); + out.push(Row { line: j + 1, seed: cells[0].clone(), attempt, id, note: cells[3..].join("|") }); + j += 1; + } + i = j; + } + assert!(!out.is_empty(), "{SPEC}: no table headed | Seed | Attempt | Id | Note |"); + out +} + +fn seed_bytes(seed: &str) -> Vec { + let hex = seed.len() == 64 && seed.chars().all(|c| c.is_ascii_hexdigit()); + if hex { + (0..32).map(|k| u8::from_str_radix(&seed[2 * k..2 * k + 2], 16).unwrap()).collect() + } else { + seed.as_bytes().to_vec() + } +} + +fn generator_of(note: &str) -> u32 { + if note.contains("class v3") { + GENERATOR_VERSION_V3 + } else if note.contains("generator 5") { + 5 + } else { + GENERATOR_VERSION_V4 + } +} + +#[test] +fn every_pinned_id_of_the_spec_derives_from_the_crate() { + let rows = rows(); + let mut checked = 0; + for r in &rows { + let bytes = seed_bytes(&r.seed); + let words = attempt_words(&bytes, r.attempt); + let g = generator_of(&r.note); + let derived = program_id(g, &words, r.attempt); + if r.note.contains("must differ") { + assert_ne!(derived, r.id, "{}:{}: the must-differ id {:016x} equals the current derivation for seed {} attempt {}", SPEC, r.line, r.id, r.seed, r.attempt); + } else { + assert_eq!(derived, r.id, "{}:{}: the crate derives {:016x} for seed {} attempt {} under generator {g}, the spec says {:016x}", SPEC, r.line, derived, r.seed, r.attempt, r.id); + } + checked += 1; + } + assert!(checked >= 4, "the spec carries only {checked} pinned ids; the table has shrunk"); +} + +/// The chain's own draw (the era layout over the class v3 base, the shadow block, the full rule) accepts the class v4 +/// rows at the attempt the spec states; the era seed is the program seed unless the Note names another 64-hex value +/// after "era". +#[test] +fn the_chain_draw_accepts_each_class_v4_row_at_its_attempt() { + let rows = rows(); + let mut drawn = 0; + for r in rows.iter().filter(|r| !r.note.contains("must differ") && generator_of(&r.note) == GENERATOR_VERSION_V4) { + let bytes = seed_bytes(&r.seed); + let era: Vec = match r.note.find("era ") { + Some(k) => { + let hex: String = r.note[k + 4..].chars().take_while(|c| c.is_ascii_hexdigit()).collect(); + if hex.len() == 64 { seed_bytes(&hex) } else { bytes.clone() } + } + None => bytes.clone(), + }; + let p = generate_from_seed_bytes_program_class(&format!("spec:{}", &r.seed[..16.min(r.seed.len())]), &bytes, ProgramClass::V4, Some(&era)); + assert_eq!(p.attempt, r.attempt, "{}:{}: the draw accepted seed {} at attempt {}, the spec says {}", SPEC, r.line, r.seed, p.attempt, r.attempt); + assert_eq!(p.program_id(), r.id, "{}:{}: the drawn program's id is {:016x}, the spec says {:016x}", SPEC, r.line, p.program_id(), r.id); + drawn += 1; + } + assert!(drawn >= 1, "no class v4 row to draw"); +} + +/// The closed-form dataset of 1.4.6.4: every `dataset_elem(a, b, c) = d` vector the spec prints is the crate's value. +#[test] +fn the_closed_form_vectors_of_the_spec_are_the_crates() { + let path = PathBuf::from(env!("CARGO_MANIFEST_DIR")).join(SPEC); + let text = std::fs::read_to_string(&path).unwrap(); + let mut n = 0; + for (k, line) in text.lines().enumerate() { + let mut rest = line; + while let Some(i) = rest.find("dataset_elem(0x") { + let tail = &rest[i + "dataset_elem(".len()..]; + let Some(close) = tail.find(')') else { break }; + let args: Vec = tail[..close].split(',').map(|a| u32::from_str_radix(a.trim().trim_start_matches("0x"), 16).unwrap_or_else(|_| panic!("{}:{}: bad vector argument {:?}", SPEC, k + 1, a))).collect(); + let after = &tail[close + 1..]; + if args.len() == 3 && after.trim_start().starts_with('=') { + let eq = after.find('=').unwrap(); + let hex: String = after[eq + 1..].trim_start().trim_start_matches("0x").chars().take_while(|c| c.is_ascii_hexdigit()).collect(); + let want = u32::from_str_radix(&hex, 16).unwrap_or_else(|_| panic!("{}:{}: bad vector value", SPEC, k + 1)); + let got = dataset_elem(args[0], args[1], args[2]); + assert_eq!(got, want, "{}:{}: dataset_elem({:#010x}, {:#010x}, {:#010x}) is {:#010x} in the crate, {:#010x} in the spec", SPEC, k + 1, args[0], args[1], args[2], got, want); + n += 1; + } + rest = &rest[i + 1..]; + } + } + assert!(n >= 2, "the spec prints {n} closed-form vectors; two are expected"); +} diff --git a/site/build.mjs b/site/build.mjs index 61a58d40a..f233a9453 100644 --- a/site/build.mjs +++ b/site/build.mjs @@ -419,8 +419,10 @@ for (const [file, active] of PAGES) { { const bj = JSON.parse(readFileSync(join(here, 'miner-bench.json'), 'utf8')); const isCurrent = (r) => r.generator === 'v2' && r.date >= '2026-10-06'; - const byMhW = (a, b) => ((b.mh_per_w ?? -1) - (a.mh_per_w ?? -1)) || (b.mh_s - a.mh_s) || (a.card < b.card ? -1 : 1); - const cur = bj.rows.filter(isCurrent).sort(byMhW); + const byRate = (a, b) => (b.mh_s - a.mh_s) || (a.card < b.card ? -1 : 1); + const curAll = bj.rows.filter(isCurrent).sort(byRate); + const cur = curAll.filter(r => r.group !== 'datacentre'); + const dcRows = curAll.filter(r => r.group === 'datacentre'); const earlier = bj.rows.filter(r => !isCurrent(r)).sort((a, b) => (a.card < b.card ? -1 : a.card > b.card ? 1 : a.generator < b.generator ? -1 : a.generator > b.generator ? 1 : b.mh_s - a.mh_s)); const rows = bj.rows; const fmt = (n) => Number(n).toLocaleString('en-GB', { maximumFractionDigits: 1 }); @@ -430,16 +432,17 @@ for (const [file, active] of PAGES) { // capture showed eleven columns clipped at five, every row inflated by off-screen wrapped text). The detail row moves // with its data row on a sort. const heads = [ - ['Card', 'card', 'text'], ['MH/s', 'mh_s', 'num'], ['W', 'watts', 'num'], ['MH/W', 'mh_per_w', 'num'], + ['Card', 'card', 'text'], ['MH/s', 'mh_s', 'num'], ['W', 'watts', 'num'], ['MH per wall watt', 'mh_per_w', 'num'], ['v4 cost', 'v4_cost_short', 'text'], ['Tuned', 'tuned_short', 'text'], ['Hive core / mem / PL', 'hive_short', 'text'], ['Date', 'date', 'text'], ['Who', 'by', 'text'], ]; // the short forms are one clause: the first watts or percent figure of the cost ("+16 W", "+145.3 W unlocked"), the // tune state's first words; the full sentences live in the detail row - const shortV4 = (r) => { const v = r.v4_cost || 'not measured'; if (/^not measured/.test(v)) return 'not measured'; const m = v.match(/^([+-]?[\d.,]+\s*(?:W|percent)(?:\s+(?:unlocked|of rate))?)/); return m ? m[1].replace(' of rate', ' rate') : v.split(/[,;(]| for | at /)[0].trim(); }; + const shortV4 = (r) => { if (r.v4_short) return r.v4_short; const v = r.v4_cost || 'not measured'; if (/^not measured/.test(v)) return 'not measured'; const m = v.match(/^([+-]?[\d.,]+\s*(?:W|percent)(?:\s+(?:unlocked|of rate))?)/); return m ? m[1].replace(' of rate', ' rate') : v.split(/[,;(]| for | at /)[0].trim(); }; const shortTuned = (r) => { const v = r.tuned || 'stock, mining'; return v.split(/[:;(]/)[0].replace('full Ember Tune', 'Ember Tune').replace('stock, bench only', 'stock, bench').replace('no lever on Apple silicon', 'no lever').trim(); }; const shortHive = (r) => { const h = r.hive; return (h && h.core_mhz != null) ? fmt(h.core_mhz) + ' / ' + fmt(h.mem_mhz) + ' / ' + fmt(h.pl_w) + ' W' : 'stock'; }; const cells = (r) => [ - [r.card, r.card], [fmt(r.mh_s), r.mh_s], [r.watts == null ? 'not read' : fmt(r.watts), r.watts ?? -1], [r.mh_per_w == null ? 'not measured' : fmt3(r.mh_per_w), r.mh_per_w ?? -1], + [r.card, r.card], [r.mh_s_display || fmt(r.mh_s), r.mh_s], [r.watts_display || (r.watts == null ? 'not read' : fmt(r.watts) + (r.watt_basis === 'chip' ? ' (chip watts, not wall)' : '')), r.watts ?? -1], + [r.mh_per_w == null ? 'not measured' : (r.watt_basis === 'chip' ? '\u25CB ' + fmt3(r.mh_per_w) + ' (chip watts, not ranked)' : fmt3(r.mh_per_w)), r.watt_basis === 'chip' ? -1 : (r.mh_per_w ?? -1)], [shortV4(r), shortV4(r)], [shortTuned(r), shortTuned(r)], [shortHive(r), r.hive && r.hive.core_mhz != null ? 'a ' + r.hive.core_mhz : 'z stock'], [r.date, r.date], [r.by.replace('measured by the ', '').replace('reported by the ', 'reported, '), r.by], ]; const detail = (r) => { @@ -455,7 +458,7 @@ for (const [file, active] of PAGES) { return parts.join(' · '); }; const render = (list, id) => '
' + - heads.map(([h, k, t]) => ``).join('') + + heads.map(([h, k, t]) => ``).join('') + '' + list.map(r => '' + cells(r).map(([c, v]) => ``).join('') + '' + ``).join('') + '
${esc(String(c))}
${detail(r)}
'; const sortScript = ``; - const sortStyle = ''; + const sortStyle = ''; const table = render(cur, 'bench-current'); + const dcTable = render(dcRows, 'bench-datacentre'); + const best = cur.slice().sort(byRate)[0]; + const bestLine = best ? `

Best desktop card: ${esc(best.card.replace(/ \(.*$/, ''))}, ${esc(fmt(best.mh_s))} MH/s, ${esc(fmt3(best.mh_per_w))} MH per wall watt tuned (measured, ${esc(best.date)}).

` : ''; const earlierTable = render(earlier, 'bench-earlier'); // Ember Tune's fleet priors (site/miner-priors.json, tools/tuning.mjs --priors --site): one row per card model, // driver major and program class; a row under the sample floor shows its count and no point @@ -496,10 +502,15 @@ for (const [file, active] of PAGES) { const body = scrubBench([ sortStyle, '

The table

', - '

One row per card on the current class: the class v4 program (the latency-shadow block over the class v3 hash), or a class v3 row re-measured with its class v4 cost on 6 October 2026 or later. Click a column header to sort; the table opens by MH per watt. Integrated GPUs are not listed. The earlier classes sit below, collapsed.

', + bestLine, + '

One row per card on the current class: the class v4 program (the latency-shadow block over the class v3 hash), or a class v3 row re-measured with its class v4 cost on 6 October 2026 or later. Cards you can buy first, sorted by hash rate; click a column header to sort. MH per wall watt uses board or wall power; a row whose watts are the chip\'s (Apple silicon: GPU plus DRAM from IOReport) says so and is not ranked on that column. Integrated GPUs are not listed. Datacentre cards and the earlier classes sit below, collapsed.

', '

Why the rate fell from the first bench to today. The genesis program did 104 dependent random 4-byte loads per hash over a 1 GiB dataset; the hourly program and class v3 do 128, with the mixer between them; class v4 adds about 100,000 integer operations per hash that ride in the memory wait. So the hash is bound by random-read bandwidth by design, and a card\'s MH/s is a relative number: the difficulty follows it, and the same card earns the same share of blocks at 136 MH/s on class v3 as it did at 228 MH/s on the genesis program. What a miner compares is hash per watt, and what the chain cares about is the chip edge, which the shadow work is there to cut.

', table, - `

Rows on the current class: ${cur.length}. Each row names the engineering log entry or the job it came from.

`, + `

Cards you can buy on the current class: ${cur.length}. Each row names the engineering log entry or the job it came from.

`, + '
Datacentre cards (' + dcRows.length + ' rows, rented for the measurement; about three times the rented dollars per hash of a desktop card)', + '

Rented cards measured on the class v4 program by the fleet, stock clocks. They mine; they are not what a home miner buys.

', + dcTable, + '
', '

The Hive flight sheet column. Where a card has a measured tune point, the column gives the core clock lock, the memory clock and the power limit to copy into a HiveOS flight sheet (core / mem / PL); the line under each row carries the label with the date, the class v4 cost in full, the miner and driver, the source and the note. Stock means no tune point has been measured yet. The Hive package mines at these settings through Hive\'s own overclock controls; the desktop app\'s Ember Tune lands on them by itself.

', '
Earlier classes (the genesis program, the hourly program, class v3 before the shadow): ' + earlier.length + ' rows, not comparable with the table above', '

These rows are the bench numbers of 3 and 4 October 2026: the genesis program (104 loads per hash), the hourly program and the first class v3 miner. A higher MH/s here is a different hash, not a faster card.

', @@ -520,7 +531,7 @@ for (const [file, active] of PAGES) { const toc = [{ lvl: 2, t: 'The table', id: 'table' }, { lvl: 2, t: 'How a row gets here', id: 'how' }, { lvl: 2, t: 'Fleet tuning priors', id: 'priors' }]; writeFileSync(join(here, 'miners.html'), page('Igneum GPU bench table', 'Measured Igneum hash rates per GPU: card, generator version, best MH/s, MH per watt where measured, miner version, date and the log entry each number came from.', body, toc, 'Measured hash rates per card on the Igneum lottery hash, with the generator version, the miner version, the date and the log entry behind each number.', - { path: '/miners', heading: 'GPU bench table', eyebrow: `${rows.length} measured rows, ${prows.length} fleet tuning models`, crumb: 'GPU bench table' })); + { path: '/miners', heading: 'GPU bench table', eyebrow: `${cur.length} cards you can buy, ${dcRows.length} datacentre, ${prows.length} fleet tuning models`, crumb: 'GPU bench table' })); built.push('miners.html (' + rows.length + ' rows)'); } diff --git a/site/claims.html b/site/claims.html index 347fd71c5..f86f4de02 100644 --- a/site/claims.html +++ b/site/claims.html @@ -229,6 +229,10 @@
  • A cryptography team. Not yet. One founder working with AI systems wrote the design and the code; external reviewers are named and paid before gate 3, and every security claim here is a design claim until then.
  • Finality that no amount of hardware can break. No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).
  • Finality that never pauses. No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.
  • +
  • A label that costs nothing. No. Some investors and exchanges read "GPU-mined" as 2021 whatever the proofs do, and nothing here measures that cost. The only evidence will be whether the first miner apps and verifiable-compute apps sign despite the label.
  • +
  • A chain you can debug today. Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof, and there is no public RPC, faucet or explorer for the devnet. They come in a fixed order (docs and templates, then the tracing and subscription RPCs, then a public RPC, listing and faucet, then the explorer) and no outside team is invited to build before the second step is done.
  • +
  • A veto on job results. No. A segment proof is checked against every node's own execution; a proving job for another chain is not, because no full node can re-run an arbitrary program, so a soundness bug in the proof system in force reaches the requesting contract. A job output can mint nothing and touch no system contract, and an app that acts irreversibly on a job result keeps its own fallback.
  • +
  • A delay function that outlives a quantum computer. No. The class-group delay between a locked checkpoint and the next program seed falls to the same machine that would forge the vote keys; it is flagged in the specification, not yet sized, and the fallback is a hash-chain delay behind the same version byte that moves the signature scheme, so both flip in one class change. A grindable hourly seed is a liveness nuisance against the lottery, not a break of finality.
  • A finished protocol. The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.
  • Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email hello@igneum.network, or open an issue on the public specification repository: git.igneum.network/igneum-network/spec/issues. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.

    diff --git a/site/evidence.html b/site/evidence.html index a24934014..081cd0489 100644 --- a/site/evidence.html +++ b/site/evidence.html @@ -254,7 +254,7 @@ td.mono{font-family:var(--f-mono);font-size:12.5px;min-width:180px}td.iv{color:v 14Ethereum bytecode runs unchanged, with the documented differences of spec 7.1
    Homepage Build card; litepaper Building
    tested by the teamas row 13; fixes F-exec-A, F-exec-B (spec 7.5)tools/evm-smoke/smoke.mjs: deploy via viem, increment, hashLoop, eth_estimateGas, eth_getLogs; tools/exec-attacks scenarios 1 and 3; bench-log "execution layer attack fixes"Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The Prover precompile, proof records and the shard planner are not in the nodenone yet 15Every block is proven, with the proof landing within about a minute at launch
    Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate
    implementedrepo d7e1f89 (GPU proof), e01a3cc, 292e800, eedd136 (proving/igneum-prove: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6proving/windows-wsl2 (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; igneum-prove-host --mode block on proving/fixtures/; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture block-78-increment (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in docs/benchmarks/proving-e2e.md. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on the RTX 5090 Windows rig in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind proving_v1_activation_daa (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is onenone yet 16A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)
    Litepaper Proving ("The proving budget"); roadmap gate 2
    designedspec 5.1 (Target), 7.6 (S_p provisional, 7,500,000 pgas = B_p / 4)PROVE-SHARD.bat on the RTX 5090 (pending); the end-to-end standard in docs/benchmarks/proving-e2e.md; bench-log "proving: devnet v4 shards"Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional S_p is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB cardnone yet -17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word +17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet 18The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache
    Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page
    tested by the teamreadwidth e752fc7 (docs/plans/read-width.md), ca2-era 78c0ee4, ca2-cache 2de19e5 (docs/plans/hot-table.md)The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per loadLatency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026none yet 19The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors
    Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page
    tested by the teamca2-mixer 1ab8b21 (tests/mixer.rs, tests/scratch.rs), ca2-era 78c0ee4, ca2-soundness a465881 (docs/analysis/scratch-soundness.md), igneum-pow/tests/packs.rsThe crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per cardClass v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT) job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)none yet 20No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)
    Homepage stats and Economics tiles; litepaper Supply, Economics
    implementedrepo 6ac80a3; fork "igneum-node devnet v0"; consensus/core/src/igneum.rs, coinbase.rscargo test -p kaspa-consensus-core igneum (8 pass: subsidy table, ramp, split, cap) and cargo test -p kaspa-consensus coinbase (8 pass); igneum-miner inspect 40; bench-log "igneum-node devnet v0"Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the igneum-proving-pool-v0 output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happenednone yet diff --git a/site/forbidden-strings.txt b/site/forbidden-strings.txt index ac88ce391..eec90bffd 100644 --- a/site/forbidden-strings.txt +++ b/site/forbidden-strings.txt @@ -38,3 +38,8 @@ disclosure prize # the rig names never reach a served page (verification lane, 7 October 2026: a substring grep read "PC 2" inside gRPC port numbers; this is the word-bounded check) \bPC [12]\b counsel is engaged +# 7 October 2026 (main's rule): the one outside check is never hinted at before its time; the phrase class, not the bare words (the proving pool's escrow and a staged build are ordinary) +outside check +waits on its escrow +staged and waits +the publish word diff --git a/site/ledger.html b/site/ledger.html index b5d65f082..f896139f2 100644 --- a/site/ledger.html +++ b/site/ledger.html @@ -4,13 +4,13 @@ Igneum ledger: every criticism, answered - + - + @@ -18,7 +18,7 @@ - + @@ -53,7 +53,7 @@ +

    The table

    -

    One row per card on the current class: the class v4 program (the latency-shadow block over the class v3 hash), or a class v3 row re-measured with its class v4 cost on 6 October 2026 or later. Click a column header to sort; the table opens by MH per watt. Integrated GPUs are not listed. The earlier classes sit below, collapsed.

    +

    Best desktop card: NVIDIA RTX 5090, 136.1 MH/s, 0.563 MH per wall watt tuned (measured, 2026-10-06).

    +

    One row per card on the current class: the class v4 program (the latency-shadow block over the class v3 hash), or a class v3 row re-measured with its class v4 cost on 6 October 2026 or later. Cards you can buy first, sorted by hash rate; click a column header to sort. MH per wall watt uses board or wall power; a row whose watts are the chip's (Apple silicon: GPU plus DRAM from IOReport) says so and is not ranked on that column. Integrated GPUs are not listed. Datacentre cards and the earlier classes sit below, collapsed.

    Why the rate fell from the first bench to today. The genesis program did 104 dependent random 4-byte loads per hash over a 1 GiB dataset; the hourly program and class v3 do 128, with the mixer between them; class v4 adds about 100,000 integer operations per hash that ride in the memory wait. So the hash is bound by random-read bandwidth by design, and a card's MH/s is a relative number: the difficulty follows it, and the same card earns the same share of blocks at 136 MH/s on class v3 as it did at 228 MH/s on the genesis program. What a miner compares is hash per watt, and what the chain cares about is the chip edge, which the shadow work is there to cut.

    -
    Apple M5 Max (40 GPU cores, Metal)
    27211.29+16 Wno leverstock2026-10-06team
    Generator: v2 · Class v4 cost: +16 W for 1.5 percent of rate at 102,100 ops per hash, measured 6 October 2026 · Tuned: no lever on Apple silicon (no clock or power control exposed); stock · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-miner Metal worker, class v3 program (macOS, Metal) · Source: Counter ASIC 3.0 status: item 8, the Apple M5 Max rows (IOReport GPU and DRAM watts) · Note: GPU plus DRAM watts, not wall
    NVIDIA H200 SXM (141 GB)
    313432.90.723not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA H100 SXM (80 GB)
    248.7385.60.645not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-cuda bench (Linux), class v3 control (NVIDIA driver 580.126.09, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep, a rented card) · Note: 424.0 W maximum; 98 percent of its random-read ceiling like the 5090; 1.78x the 5090's hash at 1.15x the tuned 5090's hash per watt and a third of the hash per rented dollar
    NVIDIA RTX 5090 (32 GB)
    127.7226.80.563not measuredEmber Tune1,854 / 13,801 / 460 W2026-10-06team
    Generator: v2 · Class v4 cost: not measured at this tune point (the Ember run was on the class v3 program); the unlocked and locked rows above carry the measured premium · Tuned: full Ember Tune: 1,854 MHz core lock at the 100 percent cap · Hive flight sheet: core lock 1,854 MHz, mem 13,801 MHz, PL 460 W (measured 6 October 2026 (Ember run 6: the clock lock 1,854 MHz, the memory clock as read, the limit 460 W of 575 as the cap did not bind)) · Miner: Igneum Miner 0.3.13 + Ember Tune kit 6 (mining, class v3 program) (NVIDIA driver, Windows 11) · Source: bench log: 6 October 2026, 16:01Z, Ember run 6 (ember-tune-pc1-6) · Note: against 127.9 MH/s at 311.0 W untuned (0.411 MH/W): 84 W saved for 0.15 percent of rate; the ladder's floor, not yet its optimum
    NVIDIA RTX 5070 Ti (16 GB)
    78.4145.60.539not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA A100 SXM (80 GB)
    138.4266.30.52not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA A100 PCIe (80 GB)
    155299.60.517not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5070 (12 GB)
    52102.80.506not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5080 (16 GB)
    71.2143.40.496not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 148.6 W maximum; the team's own 5080 on a dock reads 60 MH/s warming and gets its full Ember Tune on 7 October
    NVIDIA B200 (180 GB)
    416.4855.60.487not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX PRO 6000 Blackwell (96 GB)
    130.5288.70.452not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5090 (32 GB)
    135316.30.427+88.3 Wcore lock 1,400 MHz1,400 / 13,801 / 575 W2026-10-07team
    Generator: v2 · Class v4 cost: +88.3 W at this lock for +0.23 percent of rate, measured 7 October 2026 · Tuned: core lock 1,400 MHz (the efficiency pass's grid floor), memory 13,801 MHz, the driver's power limit untouched · Hive flight sheet: core lock 1,400 MHz, mem 13,801 MHz, PL 575 W (measured 7 October 2026 (the class v4 efficiency pass: the 1,400 MHz lock, the memory clock as read, the limit as the driver's default since the lock alone set the draw; the knee below 1,400 is the second pass's)) · Miner: igneum-worker-cuda bench (installed worker 0.3.20), class v4 program v4-devnet-epoch0 (NVIDIA driver 617.14, Windows 11) · Source: Counter ASIC 3.0 status: the class v4 efficiency pass (the efficiency pass job of 7 October 2026, 18:40 to 19:16 UTC, on the team's Windows desk machine, the core locked through the installed app's Power Helper task, no prompt) · Note: the v3 control at the same lock 134.68 MH/s at 228.0 W (0.591 MH/W); recovered 159.2 W for 1.36 percent of rate against the unlocked class v4 point; the best MH per watt on the grid, so the knee is below 1,400 MHz
    NVIDIA RTX 5060 (8 GB)
    31.375.40.415not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5090 (32 GB)
    136.13500.389+145.3 Wstock, benchstock2026-10-06team
    Generator: v2 · Class v4 cost: +145.3 W at the unlocked core (475.5 against 330.2 W) for +0.18 percent of rate; +88.3 W at the 1,400 MHz lock (316.3 against 228.0 W) for +0.23 percent; measured 7 October 2026 (the class v4 efficiency pass on the team's Windows desk machine, 60 s steps, every fingerprint matched) · Tuned: stock, bench only (unlocked core) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-cuda bench, class v3 program (mx8-devnet-epoch0) (NVIDIA driver, Windows 11) · Source: bench log: 6 October 2026, Counter ASIC 3.0 item 8, the 5090 rows (the control row) · Note: the control, unlocked; the 6 October +80 W reading was at the app's tuned cap; the rate is memory-bound from 2,850 to 1,400 MHz (136.8 to 135.0 MH/s), the best MH per watt at the lowest lock on the grid, so the knee is below 1,400 MHz (the second pass runs to the driver's floor)
    NVIDIA RTX 4070 (12 GB)
    3179.50.389+30 WEmber Tune1,863 / 10,251 / 100 W2026-10-06team
    Generator: v2 · Class v4 cost: +30 W (79 to 109 W) for +0.4 percent of rate at 102,100 ops per hash, measured 6 October 2026 · Tuned: full Ember Tune: 1,860 MHz core lock, 160 W cap (Ember run 6: 1,863 MHz at the 50 percent cap, 75.6 W) · Hive flight sheet: core lock 1,863 MHz, mem 10,251 MHz, PL 100 W (measured 6 October 2026 (Ember run 6: 1,863 MHz at the 50 percent cap of 200 W, 75.6 W drawn; the item 8 rows at 1,860 MHz and 160 W)) · Miner: igneum-worker-cuda bench (installed worker), class v3 control (NVIDIA driver, Windows 11) · Source: Counter ASIC 3.0 status: item 8, the RTX 4070 rows (job run-ca3-pc1-4070-shadow-20261006) · Note: 79.3 to 79.8 W at the tune point; 28.78 MH/s at 75.6 W (0.381) in Ember run 6 mining
    NVIDIA RTX 5090 (32 GB), fleet
    100.63080.327not measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voter (status line, 7 October 2026) · Note: a standing voter's status beside its prover, 18:00Z; 122 MH/s at 308 W earlier in the day (0.396 MH/W); the team's own 5090 rows above
    NVIDIA RTX 4070 Ti (12 GB)
    31.3107.30.291not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 4090 (24 GB)
    52.3183.10.285not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, the RTX 4090 hands row · Note: the hands row: the card mines and proves (17.4 GB peak while proving); the standing 4090 voters read 44.5 to 50.8 MH/s this hour beside their provers
    NVIDIA RTX 5060 Ti (16 GB)
    30.9114.80.2690.1 percent ratestock, benchstock2026-10-07team
    Generator: v2 · Class v4 cost: 0.1 percent of rate, measured 7 October 2026 · Tuned: stock, bench only (180 W default cap, never tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.19 package, prebuilt NVRTC worker (bench mode, class v4 program) (NVIDIA driver, Windows 11) · Source: bench log: 7 October 2026, the first 16 GB card: an RTX 5060 Ti in a Thunderbolt enclosure (run b) · Note: class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure
    NVIDIA RTX 4060 Ti (8 GB)
    20.177.50.259not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3060 Ti (8 GB)
    33.1129.50.256not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3090 Ti (24 GB)
    62249.50.248not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3060 (12 GB)
    26.9111.60.241not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.126.09, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 114.5 W maximum; the Devnet 3 boxes read 23.7 to 25.7 MH/s beside their nodes
    NVIDIA L40S (48 GB)
    56.4240.70.234not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3080 Ti (12 GB)
    59267.30.221not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 283.0 W maximum
    NVIDIA RTX 3070 Ti (8 GB)
    39178.30.219not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 595.71.05, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    AMD Radeon RX 9070 XT (16 GB)
    18.91990.095+2 percent ratestock, benchstock2026-10-06team
    Generator: v2 · Class v4 cost: +2 percent of rate (19.29 against 18.92 MH/s) at 102,100 ops per hash, watts owed, measured 6 October 2026 · Tuned: stock, bench only (the AMD tune pass runs 7 October: set only if the ADLX tune line reads, else measure-only) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-opencl bench (installed worker), class v3 control (Adrenalin 26.9.2, Windows 11) · Source: Counter ASIC 3.0 status: item 8, the RX 9070 XT rows (job run-ca3-pc1-amd-g1-shadow-20261006); watts from the app's telemetry read of 5 October 2026 (the job's ADLX sample parsed 0 rows) · Note: the card sits at 87 to 95 percent of its dependent random-read ceiling (2.42 to 2.68 G loads/s), in a Thunderbolt enclosure; AMD OpenCL 3683.0
    NVIDIA RTX 3090 (24 GB)
    50not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voters (status lines, 7 October 2026) · Note: the best of four standing voters this hour (42.2 to 50.0 MH/s) beside their provers; watts not read
    NVIDIA RTX A5000 (24 GB)
    47.6not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voter (status line, 7 October 2026) · Note: a standing voter's status line, 18:00Z; watts not read
    NVIDIA RTX 3080 (10 GB)
    43.7not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voter (status line, 7 October 2026) and the sweep's hands row · Note: a standing voter's status line, 18:00Z; the hands row of the sweep reads 40.82 MH/s at 204.9 W; 10 GB, no prover
    NVIDIA RTX 3070 (8 GB)
    33.7not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's 0.3.21 wipe canary (status line, 7 October 2026) · Note: the 0.3.21 wipe canary's status line, 17:07Z, beside its node; watts not read
    Intel Arc B580 (12 GB)
    11not readnot measured0.1 percent ratestock, benchstock2026-10-07team
    Generator: v2 · Class v4 cost: 0.1 percent of rate, measured 7 October 2026 · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-opencl bench, class v4 program (Intel driver, Windows 11) · Source: bench log: 7 October 2026, the Intel Arc B580 (eGPU equals slot) · Note: the same rate in the Thunderbolt enclosure and the slot; watts not read on this run
    -

    Rows on the current class: 32. Each row names the engineering log entry or the job it came from.

    +
    NVIDIA RTX 5090 (32 GB)
    136.1 stock (127.7 tuned)226.8 tuned (350 stock)0.563133.8 MH/s, 305 W, 0.439Ember Tune1,854 / 13,801 / 460 W2026-10-06team
    Generator: v2 · Class v4 cost: class v4 at the 1,200 MHz knee: 133.80 MH/s at 305.1 W (0.439 MH/W); the premium over class v3 81.8 W at the best points and 145.3 W unlocked, measured 7 October 2026 · Tuned: full Ember Tune: 1,854 MHz core lock at the 100 percent cap · Hive flight sheet: core lock 1,854 MHz, mem 13,801 MHz, PL 460 W (measured 6 October 2026 (Ember run 6: the clock lock 1,854 MHz, the memory clock as read, the limit 460 W of 575 as the cap did not bind)) · Miner: Igneum Miner 0.3.13 + Ember Tune kit 6 (mining, class v3 program) (NVIDIA driver, Windows 11) · Source: bench log: 6 October 2026, Ember run 6; Counter ASIC 3.0 status: item 8's 5090 rows and the class v4 efficiency pass (7 October 2026) · Note: one row for the card: best rate 136.1 MH/s at 350 W stock unlocked on the class v3 control (bench, 6 October 2026); best MH per wall watt 127.71 MH/s at 226.8 W at the full Ember Tune point, 1,854 MHz (Ember run 6, 6 October 2026); the class v4 efficiency pass (7 October 2026, 60 s steps, every fingerprint matched): unlocked 136.84 MH/s at 475.5 W (0.288), the 1,400 MHz lock 134.98 at 316.3 W (0.427), the knee 1,300 MHz, the best point 1,200 MHz 133.80 at 305.1 W (0.439); the fleet's standing 5090 reads 100.6 MH/s at 308 W beside its prover (reported by the fleet)
    NVIDIA RTX 5070 Ti (16 GB)
    78.4145.60.539not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5080 (16 GB)
    71.2143.40.496not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 148.6 W maximum; the team's own 5080 on a dock reads 60 MH/s warming and gets its full Ember Tune on 7 October
    NVIDIA RTX 3090 Ti (24 GB)
    62249.50.248not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3080 Ti (12 GB)
    59267.30.221not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.65.06, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 283.0 W maximum
    NVIDIA RTX 4090 (24 GB)
    52.3183.10.285not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, the RTX 4090 hands row · Note: the hands row: the card mines and proves (17.4 GB peak while proving); the standing 4090 voters read 44.5 to 50.8 MH/s this hour beside their provers
    NVIDIA RTX 5070 (12 GB)
    52102.80.506not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3090 (24 GB)
    50not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voters (status lines, 7 October 2026) · Note: the best of four standing voters this hour (42.2 to 50.0 MH/s) beside their provers; watts not read
    NVIDIA RTX 3080 (10 GB)
    43.7not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voter (status line, 7 October 2026) and the sweep's hands row · Note: a standing voter's status line, 18:00Z; the hands row of the sweep reads 40.82 MH/s at 204.9 W; 10 GB, no prover
    NVIDIA RTX 3070 Ti (8 GB)
    39178.30.219not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 595.71.05, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 3070 (8 GB)
    33.7not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's 0.3.21 wipe canary (status line, 7 October 2026) · Note: the 0.3.21 wipe canary's status line, 17:07Z, beside its node; watts not read
    NVIDIA RTX 3060 Ti (8 GB)
    33.1129.50.256not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 5060 (8 GB)
    31.375.40.415not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 4070 Ti (12 GB)
    31.3107.30.291not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX 4070 (12 GB)
    3179.50.389+30 WEmber Tune1,863 / 10,251 / 100 W2026-10-06team
    Generator: v2 · Class v4 cost: +30 W (79 to 109 W) for +0.4 percent of rate at 102,100 ops per hash, measured 6 October 2026 · Tuned: full Ember Tune: 1,860 MHz core lock, 160 W cap (Ember run 6: 1,863 MHz at the 50 percent cap, 75.6 W) · Hive flight sheet: core lock 1,863 MHz, mem 10,251 MHz, PL 100 W (measured 6 October 2026 (Ember run 6: 1,863 MHz at the 50 percent cap of 200 W, 75.6 W drawn; the item 8 rows at 1,860 MHz and 160 W)) · Miner: igneum-worker-cuda bench (installed worker), class v3 control (NVIDIA driver, Windows 11) · Source: Counter ASIC 3.0 status: item 8, the RTX 4070 rows (job run-ca3-pc1-4070-shadow-20261006) · Note: 79.3 to 79.8 W at the tune point; 28.78 MH/s at 75.6 W (0.381) in Ember run 6 mining
    NVIDIA RTX 5060 Ti (16 GB)
    30.9114.80.2690.1 percent ratestock, benchstock2026-10-07team
    Generator: v2 · Class v4 cost: 0.1 percent of rate, measured 7 October 2026 · Tuned: stock, bench only (180 W default cap, never tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.19 package, prebuilt NVRTC worker (bench mode, class v4 program) (NVIDIA driver, Windows 11) · Source: bench log: 7 October 2026, the first 16 GB card: an RTX 5060 Ti in a Thunderbolt enclosure (run b) · Note: class v4 program, 128 loads per hash, 1 GiB dataset, 10-minute window on the card alone at the stock 180 W limit: 114.8 W mean; PCIe 4.0 x4 through the enclosure
    Apple M5 Max (40 GPU cores, Metal)
    2721 (chip watts, not wall)○ 1.29 (chip watts, not ranked)+16 Wno leverstock2026-10-06team
    Generator: v2 · Class v4 cost: +16 W for 1.5 percent of rate at 102,100 ops per hash, measured 6 October 2026 · Tuned: no lever on Apple silicon (no clock or power control exposed); stock · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-miner Metal worker, class v3 program (macOS, Metal) · Source: Counter ASIC 3.0 status: item 8, the Apple M5 Max rows (IOReport GPU and DRAM watts) · Note: GPU plus DRAM watts from IOReport, not wall power, so its MH per watt is not ranked against the cards' wall figures
    NVIDIA RTX 3060 (12 GB)
    26.9111.60.241not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580.126.09, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04) · Note: 114.5 W maximum; the Devnet 3 boxes read 23.7 to 25.7 MH/s beside their nodes
    NVIDIA RTX 4060 Ti (8 GB)
    20.177.50.259not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    AMD Radeon RX 9070 XT (16 GB)
    18.91990.095+2 percent ratestock, benchstock2026-10-06team
    Generator: v2 · Class v4 cost: +2 percent of rate (19.29 against 18.92 MH/s) at 102,100 ops per hash, watts owed, measured 6 October 2026 · Tuned: stock, bench only (the AMD tune pass runs 7 October: set only if the ADLX tune line reads, else measure-only) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-opencl bench (installed worker), class v3 control (Adrenalin 26.9.2, Windows 11) · Source: Counter ASIC 3.0 status: item 8, the RX 9070 XT rows (job run-ca3-pc1-amd-g1-shadow-20261006); watts from the app's telemetry read of 5 October 2026 (the job's ADLX sample parsed 0 rows) · Note: the card sits at 87 to 95 percent of its dependent random-read ceiling (2.42 to 2.68 G loads/s), in a Thunderbolt enclosure; AMD OpenCL 3683.0
    Intel Arc B580 (12 GB)
    11not readnot measured0.1 percent ratestock, benchstock2026-10-07team
    Generator: v2 · Class v4 cost: 0.1 percent of rate, measured 7 October 2026 · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-opencl bench, class v4 program (Intel driver, Windows 11) · Source: bench log: 7 October 2026, the Intel Arc B580 (eGPU equals slot) · Note: the same rate in the Thunderbolt enclosure and the slot; watts not read on this run
    +

    Cards you can buy on the current class: 21. Each row names the engineering log entry or the job it came from.

    +
    Datacentre cards (8 rows, rented for the measurement; about three times the rented dollars per hash of a desktop card) +

    Rented cards measured on the class v4 program by the fleet, stock clocks. They mine; they are not what a home miner buys.

    +
    NVIDIA B200 (180 GB)
    416.4855.60.487not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA H200 SXM (141 GB)
    313432.90.723not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA H100 SXM (80 GB)
    248.7385.60.645not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-worker-cuda bench (Linux), class v3 control (NVIDIA driver 580.126.09, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep, a rented card) · Note: 424.0 W maximum; 98 percent of its random-read ceiling like the 5090; 1.78x the 5090's hash at 1.15x the tuned 5090's hash per watt and a third of the hash per rented dollar
    NVIDIA A100 PCIe (80 GB)
    155299.60.517not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA A100 SXM (80 GB)
    138.4266.30.52not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX PRO 6000 Blackwell (96 GB)
    130.5288.70.452not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA L40S (48 GB)
    56.4240.70.234not measuredstock, benchstock2026-10-07fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, bench only (rented, not tuned) · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-worker-cuda, class v4 program (NVIDIA driver 580, Ubuntu 24.04) · Source: bench log: 7 October 2026, every rentable card on the hash (the fleet's sweep on rented cards; hive package 0.3.20, Ubuntu 24.04)
    NVIDIA RTX A5000 (24 GB)
    47.6not readnot measurednot measuredstock, miningstock2026-10-07reported, fleet
    Generator: v2 · Class v4 cost: not measured (class v4 program only) · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: hive package 0.3.20 igneum-miner, class v4 program (NVIDIA driver, Ubuntu 24.04) · Source: the fleet's standing voter (status line, 7 October 2026) · Note: a standing voter's status line, 18:00Z; watts not read
    +

    The Hive flight sheet column. Where a card has a measured tune point, the column gives the core clock lock, the memory clock and the power limit to copy into a HiveOS flight sheet (core / mem / PL); the line under each row carries the label with the date, the class v4 cost in full, the miner and driver, the source and the note. Stock means no tune point has been measured yet. The Hive package mines at these settings through Hive's own overclock controls; the desktop app's Ember Tune lands on them by itself.

    Earlier classes (the genesis program, the hourly program, class v3 before the shadow): 6 rows, not comparable with the table above

    These rows are the bench numbers of 3 and 4 October 2026: the genesis program (104 loads per hash), the hourly program and the first class v3 miner. A higher MH/s here is a different hash, not a faster card.

    -
    Apple M5 Max (40 GPU cores, Metal)
    45.2not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-metal bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090 first run (the Apple row of the same table) · Note: genesis program, 1 GiB dataset
    Apple M5 Max (40 GPU cores, Metal)
    26.7not readnot measurednot measuredstock, miningstock2026-10-04team
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-miner devnet v4, Metal worker with prepare · Source: bench log: 4 October 2026, first hourly program swap on the live devnet: compile-ahead, no pause, two cards · Note: live devnet v4, unbroken through the hour boundary
    Apple silicon laptop (model not reported)
    24.3not readnot measurednot measuredstock, miningstock2026-10-04reported, fleet
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.1 (DMG) · Source: bench log: 4 October 2026, first outside machine on the devnet: an Apple silicon laptop through the Igneum Miner app · Note: 21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks
    NVIDIA RTX 5090 (32 GB)
    229not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-cuda bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090, memory-hard dataset (pack igneum-genesis-mh) · Note: genesis program, 104 loads per hash, 1 GiB dataset
    NVIDIA RTX 5090 (32 GB)
    185.3not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-cuda bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090 first run, dataset sweep and second program · Note: hourly program, 128 loads per hash, 1 GiB dataset
    NVIDIA RTX 5090 (32 GB)
    124.2not readnot measurednot measuredstock, miningstock2026-10-04team
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.0 package, prebuilt NVRTC worker · Source: bench log: 4 October 2026, the gfx1036 worker fault and what the Apple M5 Max could and could not reproduce · Note: live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected
    +
    Apple M5 Max (40 GPU cores, Metal)
    45.2not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-metal bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090 first run (the Apple row of the same table) · Note: genesis program, 1 GiB dataset
    Apple M5 Max (40 GPU cores, Metal)
    26.7not readnot measurednot measuredstock, miningstock2026-10-04team
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: igneum-miner devnet v4, Metal worker with prepare · Source: bench log: 4 October 2026, first hourly program swap on the live devnet: compile-ahead, no pause, two cards · Note: live devnet v4, unbroken through the hour boundary
    Apple silicon laptop (model not reported)
    24.3not readnot measurednot measuredstock, miningstock2026-10-04reported, fleet
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.1 (DMG) · Source: bench log: 4 October 2026, first outside machine on the devnet: an Apple silicon laptop through the Igneum Miner app · Note: 21.0 MH/s average over 7 minutes, 24.3 MH/s at the moment of the report, 33 accepted blocks
    NVIDIA RTX 5090 (32 GB)
    229not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-cuda bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090, memory-hard dataset (pack igneum-genesis-mh) · Note: genesis program, 104 loads per hash, 1 GiB dataset
    NVIDIA RTX 5090 (32 GB)
    185.3not readnot measurednot measuredstock, benchstock2026-10-03team
    Generator: v1 · Class v4 cost: not measured · Tuned: stock, bench only · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: proto-cuda bench (prototype, not mining) · Source: bench log: 3 October 2026, RTX 5090 first run, dataset sweep and second program · Note: hourly program, 128 loads per hash, 1 GiB dataset
    NVIDIA RTX 5090 (32 GB)
    124.2not readnot measurednot measuredstock, miningstock2026-10-04team
    Generator: v2 · Class v4 cost: not measured · Tuned: stock, mining · Hive flight sheet: stock (no measured tune point; the 5080 and 9070 XT passes and the class v4 efficiency pass land theirs when read) · Miner: Igneum Miner 0.3.0 package, prebuilt NVRTC worker · Source: bench log: 4 October 2026, the gfx1036 worker fault and what the Apple M5 Max could and could not reproduce · Note: live devnet v4, 128 loads per hash, CPU re-check clean, 0 rejected

    How a row gets here

    diff --git a/tools/ci/checks.txt b/tools/ci/checks.txt index cf61b3dd3..af73c0303 100644 --- a/tools/ci/checks.txt +++ b/tools/ci/checks.txt @@ -59,11 +59,13 @@ ship tool self-test relay unit tests miner app notice strip and update card tests launch gates: every row with its check, the handoff text clean (self-test, then the tree) +spec read-back: every constant the lottery-hash spec names agrees with the crate's pub const (known-failed fixture first; the ids half is igneum-pow/tests/spec_readback.rs) income per tier: the public table equals its inputs, the schedule arithmetic hash-origin report: a known-finished day and a known-failed day harness summaries never carry a raw 64-hex key (the writer's own redaction and check) docs-only pushes skip the compile-or-compute CI jobs (the changes job's classifier) the public ledger (docs/ledger-public.md) is what docs/fud-ledger.md generates: one row per item, no commit ids, times or team names (self-test first) +the ledger page reads both entry heading forms (M1 and AP-F8-1) so no in-house pass row is dropped from /ledger (known-failed first) every workflow job carries timeout-minutes (site 15, changes 10, pow 60, sims 45; the hung-job class of 7 October 2026) a box or network check gets one retry before it is red (retry-once self-test) gh's active account on the pushing Mac is the stored Igneum entry (self-test: another login refused and named; the hook and the merge tool run the check live) diff --git a/tools/ci/identity-check.sh b/tools/ci/identity-check.sh index e14fdf38c..86d2457b2 100755 --- a/tools/ci/identity-check.sh +++ b/tools/ci/identity-check.sh @@ -64,10 +64,11 @@ TEXT_FILES="$(find "$TMP" -type f \( -name '*.md' -o -name '*.rs' -o -name '*.py -o -name '*.csv' -o -name '*.toml' -o -name '*.txt' -o -name '*.log' -o -name '*.html' \) -print)" while IFS= read -r f; do [ -n "$f" ] || continue + # the second rig is card-free on purpose: its cards are in dispute between lanes (7 October 2026, night); the first rig's list is verified perl -pi -e ' s/the PC node at 192\.168\.[0-9.]+/the RTX 5090 node on the LAN/g; s/\bPC 1\x27s\b/the three-card Windows rig\x27s/g; s/\bPC 1\b/the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT)/g; - s/\bPC 2\x27s\b/the RTX 5090 Windows rig\x27s/g; s/\bPC 2\b/the RTX 5090 Windows rig/g; + s/\bPC 2\x27s\b/the second Windows rig\x27s/g; s/\bPC 2\b/the second Windows rig/g; s/\bthe PC node\b/the RTX 5090 node/g; s/\bWindows PC\b/an RTX 5090 on Windows/g; s/\bthe PC\x27s\b/the RTX 5090 machine\x27s/g; diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 2bc27e2c2..554d31288 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -144,11 +144,13 @@ tree_checks() { run "relay unit tests" node --test relay/test/parse.test.mjs relay/test/auth.test.mjs relay/test/wake.test.mjs relay/test/ember.test.mjs run "miner app notice strip and update card tests" node --test app/igneum-app/ui/notices.test.mjs app/igneum-app/ui/update-card.test.mjs app/igneum-app/ui/view.test.mjs app/igneum-app/ui/tune-line.test.mjs run "launch gates: every row with its check, the handoff text clean (self-test, then the tree)" bash -c 'node tools/ci/launch-gates-check.mjs --self-test && node tools/ci/launch-gates-check.mjs' + run "spec read-back: every constant the lottery-hash spec names agrees with the crate's pub const (known-failed fixture first; the ids half is igneum-pow/tests/spec_readback.rs)" bash -c 'node tools/ci/spec-constants-check.mjs --self-test && node tools/ci/spec-constants-check.mjs' run "income per tier: the public table equals its inputs, the schedule arithmetic" bash -c 'node tools/launch/income-tiers.mjs --check && node --test tools/launch/income-tiers.test.mjs && node tools/launch/income-page.mjs --check' run "hash-origin report: a known-finished day and a known-failed day" node --test tools/observer/hash-origin.test.mjs run "harness summaries never carry a raw 64-hex key (the writer's own redaction and check)" node infra/fast-time/lib/redact-keys.mjs --self-test run "docs-only pushes skip the compile-or-compute CI jobs (the changes job's classifier)" bash tools/ci/docs-only-check.sh --self-test run "the public ledger (docs/ledger-public.md) is what docs/fud-ledger.md generates: one row per item, no commit ids, times or team names (self-test first)" bash -c 'node tools/ledger/export-public.mjs --self-test && node tools/ledger/export-public.mjs --check' + run "the ledger page reads both entry heading forms (M1 and AP-F8-1) so no in-house pass row is dropped from /ledger (known-failed first)" node tools/ledger-page.mjs --self-test run "every workflow job carries timeout-minutes (site 15, changes 10, pow 60, sims 45; the hung-job class of 7 October 2026)" bash tools/ci/workflow-timeouts-check.sh --self-test run "a box or network check gets one retry before it is red (retry-once self-test)" bash tools/ci/retry-once.sh --self-test run "gh's active account on the pushing Mac is the stored Igneum entry (self-test: another login refused and named; the hook and the merge tool run the check live)" bash tools/ci/gh-account-check.sh --self-test diff --git a/tools/ci/spec-constants-check.mjs b/tools/ci/spec-constants-check.mjs new file mode 100644 index 000000000..b3043c916 --- /dev/null +++ b/tools/ci/spec-constants-check.mjs @@ -0,0 +1,138 @@ +#!/usr/bin/env node +// Spec read-back, the constants half (adv-accept-3 finding 3, ledger AP-F8-5, 7 October 2026): every table in +// docs/spec/01-lottery-hash.md whose header row is `| Constant | Value | Where |` names Rust constants of the igneum-pow +// crate with the value the text relies on, and this check fails when any value differs from the crate's `pub const`. +// So the public text and the shipped rule cannot drift apart unseen again (the spec at 017e7037 described a rule that +// mined a different program on 264 of 400 epochs). The ids half is igneum-pow/tests/spec_readback.rs (a cargo test). +// +// node tools/ci/spec-constants-check.mjs exit 1 listing every row that disagrees, is absent or does not parse +// node tools/ci/spec-constants-check.mjs --self-test a fixture with one wrong value, one absent constant and one pending +// row must fail on the first two and pass the third; the clean fixture passes +// +// Row forms. Constant: `module::NAME` (one file under igneum-pow/src) or `NAME` in backticks (every file searched). Value: +// the Rust literal as it reads (integers with or without underscores, a decimal with a dot, a byte string in double quotes). +// Where: free text; a row whose Where contains "pending" is skipped while the constant is absent from the crate (a class on +// a branch that lands code and text together) and compared once it is present. A constant defined as an expression of other +// constants (`ACCEPT_UNITS * LANES`) is evaluated. One literal that is not a const is read by name: `accept::distinct_ratio_pass` +// with the window cap `.min(N)` inside that function. +import { readFileSync, readdirSync, mkdtempSync, writeFileSync, mkdirSync, rmSync } from 'node:fs'; +import { join, dirname } from 'node:path'; +import { tmpdir } from 'node:os'; +import { fileURLToPath } from 'node:url'; + +const root = join(dirname(fileURLToPath(import.meta.url)), '..', '..'); +const SPEC = 'docs/spec/01-lottery-hash.md'; +const SRC = 'igneum-pow/src'; + +// the literals inside functions the spec names as constants: name -> [file, function, regex with one capture] +const LITERALS = { + 'accept::distinct_ratio_pass': ['accept.rs', 'distinct_ratio_pass', /\.min\((\d+)\)/], +}; + +function tables(md) { + // every table whose header is exactly Constant | Value | Where; rows until the first non-table line + const out = []; const lines = md.split('\n'); + for (let i = 0; i < lines.length; i++) { + if (!/^\|\s*Constant\s*\|\s*Value\s*\|\s*Where\s*\|\s*$/.test(lines[i])) continue; + const rows = []; let j = i + 1; + if (j < lines.length && /^\|\s*-+\s*\|/.test(lines[j])) j++; + for (; j < lines.length && /^\|/.test(lines[j]); j++) { + const cells = lines[j].replace(/^\||\|$/g, '').split('|').map(c => c.trim()); + if (cells.length < 3) continue; + rows.push({ line: j + 1, constant: cells[0].replace(/`/g, '').trim(), value: cells[1].replace(/`/g, '').trim(), where: cells.slice(2).join('|') }); + } + out.push(rows); i = j; + } + return out; +} + +function constMap(srcDir) { + // name -> { file, raw } for every `pub const NAME: T = ;` under igneum-pow/src (one line each) + const map = new Map(); const files = readdirSync(srcDir).filter(f => f.endsWith('.rs')); + for (const f of files) { + const text = readFileSync(join(srcDir, f), 'utf8'); + for (const m of text.matchAll(/^pub const ([A-Z][A-Z0-9_]*)\s*:\s*[^=]+=\s*([^;]+);/gm)) { + const name = m[1]; const raw = m[2].trim(); + const key = f.replace(/\.rs$/, '') + '::' + name; + map.set(key, { file: f, raw }); if (!map.has(name)) map.set(name, { file: f, raw, bare: true }); + } + } + return { map, files, srcDir }; +} + +function evalRust(raw, consts, depth = 0) { + // a number, a byte string, or an expression over numbers and other constants + if (depth > 8) throw new Error('constant expression too deep: ' + raw); + const s = raw.replace(/\s+as\s+(u8|u16|u32|u64|usize|i32|i64|f64)/g, '').trim(); + const bs = /^b?"((?:[^"\\]|\\.)*)"$/.exec(s); if (bs) return bs[1]; + const expr = s.replace(/[A-Z][A-Z0-9_]*/g, name => { + const c = consts.get(name); if (!c) throw new Error('unknown identifier ' + name + ' in ' + raw); + const v = evalRust(c.raw, consts, depth + 1); if (typeof v !== 'number') throw new Error(name + ' is not a number'); + return '(' + v + ')'; + }).replace(/_/g, '').replace(/(\d)(u8|u16|u32|u64|usize|i32|i64|f64)\b/g, '$1'); + if (!/^[\d\s().+\-*/<>]+$/.test(expr)) throw new Error('cannot evaluate ' + raw); + // eslint-disable-next-line no-new-func + return Number(Function('"use strict"; return (' + expr + ');')()); +} + +function parseSpecValue(v) { + const bs = /^"((?:[^"\\]|\\.)*)"$/.exec(v); if (bs) return bs[1]; + const n = Number(v.replace(/_/g, '')); if (v.trim() === '' || Number.isNaN(n)) throw new Error('not a number or a quoted string: ' + v); + return n; +} + +function check(rootDir, specRel = SPEC, srcRel = SRC) { + const md = readFileSync(join(rootDir, specRel), 'utf8'); + const { map } = constMap(join(rootDir, srcRel)); + const fails = []; let rows = 0, pending = 0; + for (const table of tables(md)) for (const r of table) { + rows++; + try { + const want = parseSpecValue(r.value); + if (LITERALS[r.constant]) { + const [file, fn, re] = LITERALS[r.constant]; + const text = readFileSync(join(rootDir, srcRel, file), 'utf8'); + const start = text.indexOf('fn ' + fn + '('); if (start < 0) throw new Error('no fn ' + fn + ' in ' + file); + const body = text.slice(start, text.indexOf('\n}', start)); const m = re.exec(body); + if (!m) throw new Error('no literal matching ' + re + ' inside ' + fn); + if (Number(m[1]) !== want) fails.push(`${specRel}:${r.line}: ${r.constant} reads ${r.value} in the spec, ${m[1]} in ${file} fn ${fn}`); + continue; + } + const c = map.get(r.constant); + if (!c) { + if (/pending/i.test(r.where)) { pending++; continue; } + fails.push(`${specRel}:${r.line}: ${r.constant} is not a pub const of ${srcRel} (and the row is not marked pending)`); continue; + } + const got = evalRust(c.raw, map); + const same = typeof want === 'string' ? want === got : Math.abs(want - got) < 1e-12; + if (!same) fails.push(`${specRel}:${r.line}: ${r.constant} reads ${r.value} in the spec, ${JSON.stringify(got)} in ${c.file} (${c.raw})`); + } catch (e) { fails.push(`${specRel}:${r.line}: ${r.constant}: ${e.message}`); } + } + if (rows === 0) fails.push(`${specRel}: no table headed | Constant | Value | Where | found`); + return { fails, rows, pending }; +} + +function selfTest() { + const d = mkdtempSync(join(tmpdir(), 'spec-constants-')); const fails = []; + try { + mkdirSync(join(d, 'docs', 'spec'), { recursive: true }); mkdirSync(join(d, SRC), { recursive: true }); + writeFileSync(join(d, SRC, 'accept.rs'), 'pub const ACCEPT_UNITS: usize = 64;\npub const ACCEPT_HASHES: usize = ACCEPT_UNITS * LANES;\npub const MAX_SATURATED: u32 = 164;\npub const MIN_DISTINCT_RATIO_V4: f64 = 0.98;\npub const ACCEPT_TAG: &[u8] = b"igneum-accept/";\npub fn distinct_ratio_pass(x: u64) -> u64 {\n let w = (x as u64).min(2);\n w\n}\n'); + writeFileSync(join(d, SRC, 'generator.rs'), 'pub const LANES: usize = 32;\npub const MIN_DISTINCT_SUM: u64 = 245_760;\n'); + const clean = '# spec\n\n| Constant | Value | Where |\n|---|---|---|\n| accept::ACCEPT_UNITS | 64 | (c) |\n| accept::ACCEPT_HASHES | 2048 | |\n| `MIN_DISTINCT_SUM` | 245760 | |\n| accept::MIN_DISTINCT_RATIO_V4 | 0.98 | |\n| accept::ACCEPT_TAG | "igneum-accept/" | |\n| accept::distinct_ratio_pass | 2 | the window cap |\n| accept::MIN_DISTINCT_RATIO_V5 | 0.995 | class v5, pending |\n\ntext\n'; + writeFileSync(join(d, SPEC), clean); + const ok = check(d); if (ok.fails.length || ok.rows !== 7 || ok.pending !== 1) fails.push('the clean fixture failed: ' + JSON.stringify(ok)); + writeFileSync(join(d, SPEC), clean.replace('| 64 |', '| 63 |').replace('| `MIN_DISTINCT_SUM` |', '| `MIN_DISTINCT_SUMM` |')); + const bad = check(d); + if (!bad.fails.some(f => /ACCEPT_UNITS reads 63/.test(f))) fails.push('a wrong value was not caught: ' + JSON.stringify(bad.fails)); + if (!bad.fails.some(f => /MIN_DISTINCT_SUMM is not a pub const/.test(f))) fails.push('an absent constant was not caught: ' + JSON.stringify(bad.fails)); + if (bad.fails.length !== 2) fails.push('the known-failed fixture had ' + bad.fails.length + ' failures, wanted 2: ' + JSON.stringify(bad.fails)); + } finally { rmSync(d, { recursive: true, force: true }); } + if (fails.length) { for (const f of fails) console.error('self-test failed: ' + f); return 1; } + console.log('self-test passed: a wrong value and an absent constant are caught and named; a pending row and the clean fixture pass; an expression over constants evaluates'); + return 0; +} + +if (process.argv.includes('--self-test')) process.exit(selfTest()); +const r = check(root); +if (r.fails.length) { for (const f of r.fails) console.error('spec-constants: ' + f); process.exit(1); } +console.log(`spec-constants: ${r.rows} rows of ${SPEC} agree with the crate's pub const items (${r.pending} pending)`); diff --git a/tools/ledger-page.mjs b/tools/ledger-page.mjs index 995d9fcf5..ad8eed7b8 100644 --- a/tools/ledger-page.mjs +++ b/tools/ledger-page.mjs @@ -45,20 +45,41 @@ function inline(s) { return t; } -const lines = readFileSync(src, 'utf8').split('\n'); -const entries = []; -let cur = null; -for (const l of lines) { - const m = /^### ([A-Z]\d+)\. (.*)$/.exec(l); - if (m) { cur = { id: m[1], title: m[2].trim(), quote: '', status: '', answer: '' }; entries.push(cur); continue; } - if (!cur) continue; - const s = l.trim(); - if (!cur.quote && s.startsWith('"')) cur.quote = s.replace(/^"|"$/g, ''); - else if (s.startsWith('Status:')) cur.status = s.slice(7).trim(); // the LAST status line wins, as tools/ledger/export-public.mjs reads it (7 October 2026: the page read the first and counted four entries as Other that the export did not) - else if (!cur.answer && s.startsWith('Answer:')) cur.answer = s.slice(7).trim(); +// An entry heading: `### M1. title` or, since 7 October 2026 night, the in-house adversarial pass's `### AP-F8-1. title` +// (the first form alone dropped every AP entry from the page while the export carried them). +const ENTRY_RE = /^### ([A-Z]\d+|AP-[A-Z]\d+-\d+)\. (.*)$/; +const secKey = id => (id.startsWith('AP-') ? 'AP' : id[0]); +export function parseLedger(text) { + const entries = []; + let cur = null; + for (const l of text.split('\n')) { + const m = ENTRY_RE.exec(l); + if (m) { cur = { id: m[1], title: m[2].trim(), quote: '', status: '', answer: '' }; entries.push(cur); continue; } + if (!cur) continue; + const s = l.trim(); + if (!cur.quote && s.startsWith('"')) cur.quote = s.replace(/^"|"$/g, ''); + else if (s.startsWith('Status:')) cur.status = s.slice(7).trim(); // the LAST status line wins, as tools/ledger/export-public.mjs reads it (7 October 2026: the page read the first and counted four entries as Other that the export did not) + else if (!cur.answer && s.startsWith('Answer:')) cur.answer = s.slice(7).trim(); + } + return entries; +} +if (process.argv.includes('--self-test')) { + // known-failed first: the single-letter form alone misses the AP entry; then the parser sees both forms + const fx = '# l\n\n### M1. The space is small\n"Eleven ops."\n\nStatus: Open.\n\n### AP-F8-1. A hot set\n"Top items."\n\nStatus: Fixed (7 October 2026).\n\nAnswer: Yes.\n'; + const old = fx.split('\n').filter(l => /^### ([A-Z]\d+)\. /.test(l)).length; + const got = parseLedger(fx); + const fails = []; + if (old !== 1) fails.push('the known-failed form did not drop the AP entry'); + if (got.length !== 2 || got[1].id !== 'AP-F8-1' || got[1].status !== 'Fixed (7 October 2026).' || got[1].answer !== 'Yes.') fails.push('the parser did not read both entry forms: ' + JSON.stringify(got)); + if (secKey('AP-F8-1') !== 'AP' || secKey('M1') !== 'M') fails.push('the section key is wrong'); + if (fails.length) { fails.forEach(f => console.error('self-test failed: ' + f)); process.exit(1); } + console.log('self-test passed: the single-letter heading form drops an AP entry (known-failed), the parser reads M1 and AP-F8-1 with their status and answer, the section key routes AP ids to the pass section'); + process.exit(0); } -const SECTION = { M: 'Mining and chips', F: 'Finality and attacks', P: 'Proving and the zkEVM', E: 'Economics and the coin', G: 'Governance and the founders', C: 'Comparisons', L: 'Legal and regulatory', X: 'Launch and\u00a0operations', D: 'Builders' }; +const entries = parseLedger(readFileSync(src, 'utf8')); + +const SECTION = { AP: 'The in-house adversarial pass', M: 'Mining and chips', F: 'Finality and attacks', P: 'Proving and the zkEVM', E: 'Economics and the coin', G: 'Governance and the founders', C: 'Comparisons', L: 'Legal and regulatory', X: 'Launch and\u00a0operations', D: 'Builders' }; function bucket(status) { const s = status.toLowerCase(); @@ -104,8 +125,8 @@ const countRows = ORDER.filter(b => counts[b]).map(b => `${c let body = ''; let lastSec = ''; for (const e of entries) { - const sec = SECTION[e.id[0]] || e.id[0]; - if (sec !== lastSec) { body += `

    ${esc(sec)}

    \n`; lastSec = sec; } + const sec = SECTION[secKey(e.id)] || secKey(e.id); + if (sec !== lastSec) { body += `

    ${esc(sec)}

    \n`; lastSec = sec; } const b = bucket(e.status); const word = statusWord(scrub(e.status)); const rest = scrub(e.status).slice(word.length).replace(/^[\s(:.]+/, '').trim();