ledger: N7, the execution layer never read a block's silence (the testnet lane's finding, 7 October 2026), the fix's shape

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 08:07:56 +00:00
parent 3ef9619a3f
commit 5b4f76b64f

View file

@ -2075,6 +2075,14 @@ The fork gate's chain stopped finding blocks: every submission answered `block h
Per tier: a home miner, rig or pool whose node came from a build that omitted the feature mines nothing and shows "invalid proof-of-work" on every block (the devnet's shipped binaries did not: the shipper's scripts build both packages together, and every suite and gate before tonight did too); a node operator cannot tell the two binaries apart from the version string; a holder is untouched. Status: Open, the fix class is a decision: (a) make `igneum-pow` a default feature of kaspad and keep the stub behind `--no-default-features` for the tests that want it, or (b) a CI check that fails any script or playbook building `kaspad` without `--features igneum-pow` and without `-p igneum-miner` on the same line, and the version string carrying the engine (`igneumd 2.1.0 (igneum-pow)` against `(stub)`) so a node names its own engine. (a) closes the class; (b) catches it. The node lane recommends (a) for 0.3.17 with the version string of (b) in either case; the shipper's build lines are safe today.
### N7. The execution layer never read a block's silence: with the signing bonus on, the EVM ledger credits a silent block 80/20 while the UTXO coinbase pays 72/28 (found by the testnet lane, 7 October 2026, wiring the bonus into the two-node base-unit gate)
`igneum/exec/src/executor.rs` credited every blue block's miner `producer_share(subsidy)` and the pool `proving_pool_share(subsidy)` from the schedule alone ("computed from consensus data alone"); nothing in igneum/exec mentioned silence or the bonus. The UTXO coinbase (`CoinbaseManager::producer_and_pool`) moves a tenth of a silent producer's subsidy share to the pool output. So wherever `signing_bonus_activation_daa` is reached, a silent block's producer is paid 72 percent of the subsidy on the UTXO side and 80 on the EVM side and the pool escrow is 28 against 20: the bridge is not the identity for silent blocks, which is exactly what the base-unit gate asserts (eth_getBalance equals the sum of the segment rewards; every segment reward equals the coinbase's producer amount). Invisible for the first weight window of a chain (nobody is a voter before min_daa), then on every silent block; the devnet never turned the bonus on, the testnet as approved turns it on at genesis. the project lead's word (09:1x UK): fix it.
Per tier, before the fix: a silent miner on a network with the bonus on would have been paid its full share on the EVM side and the bonus share on the UTXO side, the pool escrow would differ between the ledgers by the bonus, and nothing refuses such a block, so it would have sat unnoticed until an audit.
Fix (the node side, ca3-v4-0318; the shard guest's port of the executor is the proving lane's): `igneum::silent_split(subsidy, silent, bonus_bps)` in consensus-core is the one arithmetic both ledgers apply; the coinbase manager goes through it; `SegmentBlock::silent` carries consensus's `finality_silent_builder` (a pure function of the block's past, new on the consensus API and the session) and `ChainBlockEnv::signing_bonus_bps` the bps at the chain block's DAA (0 while the switch is off); `execute_segment` credits the split. Known failed first: a silent blue block with the bonus on credits 72/28, a block that signed or the bonus off 80/20, the sum unchanged; the coinbase test asserts its outputs equal the split. The guest statement gains the two inputs, so the shard program id re-pins (the testnet genesis pins it anyway). Harness case owed: a silent block with voters must credit 72/28 on both ledgers (the vote-or-burn harness's bonus case, the exec record against the UTXO outputs per merging chain block) or the gate fails. Commit hash: in the status log once green.
## Status updates, 5 October 2026 (ledger sweep, night of 4 to 5 October)
`docs/review/ledger-sweep-2026-10-05.md` holds the runs, the commands and the running table. Every Open, Proposed, Unmeasured or pending entry was read against its experiment line; the status lines above carry the evidence inline, marked "Sweep (5 October 2026)" where a note was added and "Was:" where the status changed. Items owned by the other two night branches (F23, F24, G12, X18, the flood memory growth; the base-fee floor, testnet parameters, G13, G14, public text) were left to them.