diff --git a/docs/evidence.md b/docs/evidence.md index c77ebe26f..4910bd485 100644 --- a/docs/evidence.md +++ b/docs/evidence.md @@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml` | 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet | | 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet | | 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet | -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); the class v4 efficiency pass of 7 October 2026 on the same card: 136.84 MH/s at 475.5 W unlocked, 134.98 MH/s at 316.3 W at the 1,400 MHz core lock, the class v3 control 134.68 MH/s at 228.0 W (`docs/plans/counter-asic-3-status.md`); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | | 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet | | 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet | | 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet | diff --git a/docs/plans/counter-asic-3-public-text-2026-10-07.md b/docs/plans/counter-asic-3-public-text-2026-10-07.md index a5f36ecb2..ee0afaded 100644 --- a/docs/plans/counter-asic-3-public-text-2026-10-07.md +++ b/docs/plans/counter-asic-3-public-text-2026-10-07.md @@ -1,10 +1,10 @@ -# The chip claim, public text (7 October 2026; REWRITTEN LAUNCH-FIRST 18:3x UK on the founder's "I thought we were making it 2.1 from launch?": the testnet and mainnet objects set program_class_v4_activation_daa to 0, so class v4 is live from genesis and the launch number is 2.1x to 3.9x on day one; the 5x to 9x is the class v3 baseline the work started from, stated only as that; the devnet's own activation height is a devnet fact only. Served since 11:03 UK on master 9162c847 with main's two cuts: no mention of the disclosure prize until the publish word, and row 17 in evidence.md's eight-column shape) +# The chip claim, public text (7 October 2026; REWRITTEN LAUNCH-FIRST 18:3x UK on the founder's "I thought we were making it 2.1 from launch?": the testnet and mainnet objects set program_class_v4_activation_daa to 0, so class v4 is live from genesis and the launch number is 2.1x to 3.4x on day one (2.1x with a core as good as a GPU lane, 3.4x with one three times better; the X9 wording retired 7 October 2026, 22:0x UK, on main's order: its claimed ratio was against a CPU core); the 5x to 9x is the class v3 baseline the work started from, stated only as that; the devnet's own activation height is a devnet fact only. Served since 11:03 UK on master 9162c847 with main's two cuts: no mention of the disclosure prize until the publish word, and row 17 in evidence.md's eight-column shape) Three texts and one ledger row, written by the Counter ASIC lane, which owns the chip model. Every number carries its label: measured (a card or a chain we ran, with the date), modelled (arithmetic on cited parts), claimed (a vendor's figure, never measured by us), designed (a rule in a class, not yet measured). Sources: `docs/analysis/chip-model-v3.md` sections 5 and 6, `docs/analysis/latency-shadow-2026-10-06.md`, `docs/plans/counter-asic-3-status.md`, `docs/analysis/attack-pass/f8-uniform.md` and `f4-weakday.md` (branch attack-pass), `docs/design/class-v5-stored-state.md`, the datacentre and market-cap rows of 7 October (lanes 3 and the fleet), the cryptanalysis plan in `docs/plans/funding.md`. ## 1. The home page's chip line (replaces the hero sentence served since 6 October 16:21Z) -Built for graphics cards. At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block. Class v5 then makes the dataset the chain's own state, so a chip that stores it or recomputes it is wrong on every item. Without class v4 the same chip would reach 5x to 9x. The model and every measurement are public. +Built for graphics cards. At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane, 3.4x with one three times better, under class v4 from the first block; a 5090 locked at its knee pays 82 W for that shadow work. Class v5 then makes the dataset the chain's own state, so a chip that stores it or recomputes it is wrong on every item. Without class v4 the same chip would reach 5x to 9x. The model and every measurement are public. ## 2. The litepaper's chip section (replaces the paragraph that begins "The chip model: 5x to 9x per joule") @@ -12,11 +12,11 @@ The chip model. We price the strongest chip we can design against an RTX 5090 an | The chip and the class | Edge over an RTX 5090 per joule | Label and date | |---|---|---| -| At launch: a memory-controller chip that stores the whole dataset, under class v4 (about 100,000 integer ops per hash in the latency shadow, so the chip carries a GPU-class datapath beside its memory) | 2.1x with a core as costly per op as the GPU's (k = 1); 3.9x with the core Bitmain claimed for its Antminer X9 (k about 0.33), a product withdrawn before any unit shipped | modelled on measured card watts, 6 October 2026; the X9 figure claimed, never measured | +| At launch: a memory-controller chip that stores the whole dataset, under class v4 (about 100,000 integer ops per hash in the latency shadow, so the chip carries a GPU-class datapath beside its memory) | 2.1x with a core as costly per op as a GPU lane (k = 1); 3.4x with a core three times better per op (k about 0.33); no core below about 1.8 pJ per op is in the model's range, and the withdrawn Antminer X9's claimed figure is a ratio against a CPU core, not a GPU lane, so it is not a chip core against us | modelled on the 5090's measured watts at its knee, 7 October 2026 (the shadow's premium 81.8 W at the best points: class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W; a user gets there through Ember Tune's core-clock knob, 0.3.24) | | The same chip at the ladder's second rung (about 200,000 ops per hash), reached by miner signal | about 2.8x | modelled, 7 October 2026 | | Any chip under class v5, where the dataset is the chain's own state | a stateless or stale chip is wrong on every item, so the stored-dataset chip and the recompute chip are removed as categories; the verifier pays 0.2 ms more per warp | designed, 7 October 2026 | | A chip caching the hottest 0.1 percent of items (about 1 MB of SRAM) | bounded at 1.067x at the ceiling, 1.005x on about half the hours and 1.048x on 5 percent | measured census of 1,024 programs, 7 October 2026; the source rule in the next class | -| A per-day FPGA that recomputes the dataset with cheap multipliers on a weak day | at most 12 percent more hash rate on 12 days a century, nothing on the other days and nothing for any chip | measured census of 2^24 days, 7 October 2026; the rule in the next class | +| A per-day FPGA that recomputes the dataset with cheap multipliers on a weak day | at most 12 percent more multiplier area on an FPGA's per-day build on 15 days a century, nothing on the other days and nothing for any chip | measured census of 2^24 days, 7 October 2026; the rule in the next class | | When a stored-dataset chip pays for itself | at about USD 100 M of market cap in the first two years, not before | modelled, 7 October 2026 | | The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class) | 5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x) | modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state | @@ -24,10 +24,10 @@ What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 perce ## 3. The miner page's line -Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 350 W (measured 6 October 2026); at launch the chip reaches 2.1x to 3.9x per joule under class v4 (modelled on measured watts), and under class v5 it is wrong on every item because the dataset is the chain's own state (designed). Without class v4 it would be 5x to 9x. The model and the measurements are public. +Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 350 W (measured 6 October 2026); at launch the chip reaches 2.1x per joule under class v4 with a core as good as a GPU lane, 3.4x with one three times better (modelled on measured watts at the 5090's knee: the shadow costs that card 82 W at its best point, and Ember Tune lands the lock by itself), and under class v5 it is wrong on every item because the dataset is the chain's own state (designed). Without class v4 it would be 5x to 9x. The model and the measurements are public. ## 4. The ledger row (docs/evidence.md row 17, in the table's eight columns as served) | # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification | |---|---|---|---|---|---|---|---| -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index 7c18c5f24..c8424f73f 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -455,7 +455,17 @@ Reading so far: the class v4 premium at the unlocked clock is +145 W on this car | 1,400 | 134.98 | 316.3 | 0.427 | 134.68 | 228.0 | 0.591 | 1,387 | | unlocked, end | 136.75 | 473.0 | | 136.5x | 329.7 | | 2,843 / 2,850 | -Reading: the class v4 premium is 145.3 W at the unlocked clock (not the 80 W of 6 October, which was read at the app's tuned cap) and 88.3 W at the 1,400 MHz lock; v4's rate is +0.18 percent over v3 unlocked and +0.23 percent at the lock; the rate is memory-bound on the whole grid (136.8 to 135.0 MH/s from 2,850 to 1,400); the best MH per watt sits at the lowest lock on the grid, so the knee is below 1,400 MHz. the founder's thesis holds in part: 57 W of the 145 W premium comes back by the lock alone; 88 W stays as the shadow's ALU work at the floor clock. Throttle reasons: the SW power-cap governor (0x400) from unlocked to 2,163, the lock itself (0x4) from 2,100 down on v4 and 1,650 down on v3; 75 C at the top, 59 C at 1,400. The owed 5090 clock rows (2,781 / 2,472 / 2,163 / 1,854) are in this table. Per tier: a 5090 owner on class v4 who locks the core at 1,400 MHz pays 316 W instead of 476 W for 1.4 percent less rate, MH per watt up 48 percent, the v4 premium down from 145 to 88 W; the lever is NVIDIA's -lgc through the helper; AMD has the helper's ADLX tune line or nothing; the Mac has no lever. MAIN'S ORDERS ON IT (20:2x UK): (1) the second pass now, 1,400 MHz down to the driver's floor in 100 MHz steps on v4 and the v3 control, to find the knee and the premium at it, then the same grid on the 5080; (2) the knob into Ember Tune for 0.3.23 (after the power-cap search, a core-clock search downward from the cap's point until the rate falls more than 1 percent, taking the best MH/W, the fingerprint on every step, stored per card; the Mac stated as no lever) through the UI lane; (3) the bench table's 5090 row gains the locked point and the class v4 cost column reads the locked premium beside the unlocked one (done: the 1,400 MHz row 134.98 MH/s at 316.3 W, 0.427 MH/W, the Hive values 1,400 / 13,801 / 575 as the driver's default limit). DEVNET 3's FIRST LOCK (the fleet lane): 19:02:46Z, checkpoint 235 LOCKED on block 50266abe... (blue score 7,050), identical on dn3-g1 (signed 98.4 percent of active) and dn3-g2 (100.1 percent), at DAA about 7,298 (the 7,200 window filled at 19:01Z); wave 1 of the second nodes GREEN on all five at 19:17:00Z, wave 2 from 19:17Z; the 0.3.22 pin candidate 34a2dbaa passed its last gate at 19:07Z (the join-and-restart read on dn3-c1 with the N15 line) and the Devnet 3 sweep to it runs. The fleet's 19:03Z table: 43 rows, 44 GPUs, USD 257 a day, today about USD 460 of the ceiling at 19:20Z; dn3-twin (a broken CUDA host) and dn3-q02 (never answered) destroyed; p12-vast, w-target and w-poison repurposed to Devnet 3. THE SITE: a0e0c83a deployed 19:17:28Z with the Hive column. THE BOXES: build-1 read 601 / 552 / 471 and build-2 401 / 417 / 400 at 19:17Z, the sum being adversarial binaries started by hand over ssh at 64 to 89 threads each (the crypto lane's one-sweep lock not holding the sum); MAIN'S RULE for every lane under this one: no run starts on a box except through the build-server lane's `lease pool -- cmd` (landing within the quarter hour); hand-started runs killed by their kill files and re-queued through the lease; the release builds and the v5 suites outrank the sweeps. THE SHIPPER cuts class v5 as 0.3.24 the minute every v5 gate is green, at any hour; this lane's gate board is the only clock. THE (c''') CENSUS NUMBER (the v5 lane, 21:03 UK; 4,600 f8 seeds, box 2, 48 cores, 1,256 s; log docs/design/class-v5-harness/v5-census-4600-0.log): the 0.995 per-site floor rejects 112 of 4,600 class v4 sub-version 3 accepted programs (2.435 percent); the same 112 move to a later class v5 attempt; the attempts mean 2.174 to 2.248 (+3.4 percent; the tail unchanged, max 24 on both); 0 class v5 accepted programs under the floor. The spread of the v4-accepted programs' minimum site ratio at the 2^20 sample: min 0.9807, p0.1 0.9831, p1 0.9906, p5 0.9962, median 0.9999; under 0.98 none, under 0.99 43 (0.935 percent), under 0.995 112, under 0.998 517, under 0.999 868. Two corrections to the relayed premise: the clean spread is not "0.9960 minimum, p1 0.9990" on the chain's own draw (a smaller sample), and 0.99 would NOT refuse the exemplar (0.9919). So 0.995 is the lowest round floor that refuses seed 100767 with the model's spread under it, at one extra draw attempt on 2.4 percent of epochs (about 0.3 s of acceptance each, no consensus cost, no change to the hash or the kits); the band it rejects is where every measured program so far is a weak hot-set program (adv-accept's live-low20 row: the first read, seed 3664 at 1.31x, beyond the 1.2x gate; its four measured lowest-ratio seeds all beyond). The per-site hot-item test is the same statistic at the 2^20 sample and costs 30 s per candidate at 2^24 against the floor's 0 extra, so it is not a competitor. The defender's call: keep 0.995; the freeze commit carries the number into accept.rs and section 14 and goes the minute the full suite and the gate read green (f17849eb staged). THE PRE-PUBLIC SCRUB: master's text pass (9b8eb23a, 3b4b6c63) names the founder as "the founder" in every tracked text file and the CI check founder-strings refuses the name; this record follows it from here (three lines of the efficiency pass reintroduced the name through a merge and are fixed). THE V5 FAST-TIME LINES ON THE FIRST MATCHED PAIR 959b57c9 (igneumd 519ee6c4..., igneum-pow ab6f980b; harness v5-fasttime 6de9cf74): (1) the ladder climb plus the v5 crossing with the stale node: rung 1 by miner signal from epoch 6 at 19:56:38Z; class v5 by signal from epoch 8 (DAA 480) at rung 1 at 19:58:31Z on 3 of 3 honest nodes, byte 6 at 9,985 bps, before the floor; the prelude reads v4 at epochs 0 and 1 (b1680b57 verified); honest nodes 0 PoW rejections; the stale node 122 of 122 refused by its own node; the SUMMARY FAIL at 20:04:00Z on line 3 alone. (2) Digest-compat SUMMARY PASS 20:08:30Z (one digest c0d6998e with the v5 key absent on the new binary and on the pre-v5 control 2720d8d2; the set key moves it to 8d8f6208 with no peer and the refusal line; 180 s of mixed mining, 79 new and 101 old blocks, 0 rejected). (3) THE RESTART STEP FAILED: n2 stopped at DAA 457 and restarted on its own datadir at DAA 500 (19:59:10Z), the IBD catch-up engaged and did not complete: the relay flow treated the engine's "class v5 needs the execution state" on a relayed epoch-8 block as a rule refusal twelve seconds in, the flow error tore down the peer's flows and the catch-up's body sync with them, the block went into the N6 refused memory, the peer was banned 600 s at 20:00:09Z, and the deferred headers were never validated; n2 on its own fork to the end (600 against 660). FIXED by the node lane at a3b2049d on class-v5-node-wire (20:0xZ): the relay flow holds off a block in the v5 state-wait class at its three validation sites (no strike, no N6 memory, the flow stays up; the next inv or the catch-up's deferred chunk brings it back once the executor has the state), is_v5_state_wait shared with the IBD catch-up, kaspa-p2p-flows 38 of 38 at 20:08:23Z. (4) One program id per epoch equal to the CLI's v5 id: 11 of 11 (v4 at rungs 0 and 1, v5 at rung 1 with the window's stream), the Devnet 3 genesis pack's e5a4ac5978462156 reproduced; the known-failed shape FAIL as it must at 19:04:01Z. THE SECOND MATCHED PAIR 63524e28 landed 20:16:49Z on build-1 (/srv/artefacts/v5-pair-63524e28/, igneumd sha256 4f93697f5b97c30205b7e1c8e521924ba85f849a5d35f1470ff0a1b2a17cbbae; fork v5-object-0323 = 959b57c9 + the relay hold-off a3b2049d + the pool lane's tag rename 7455b8d5 + main's chain id by height, Devnet 3 chain id 4464 from the v5 floor; igneum-pow ab6f980b; suites consensus 126, core 154, pow 19, exec 46, p2p-flows 38, miner 25); the fast-time lane re-runs the crossing with the restart step on it; the v5 object commit waits on that PASS, the freeze commit and dn3-g1's DAA at the cut. THE IN-HOUSE PASS: adv-accept's tally at 2^24: of the 16 lowest stand-in-ratio seeds, 9 beyond the 1.2x gate and 3 hot sets (100767 at 2.05x; 4346 at X/f 1.78, 2.24x; 5245 at 1.29, 1.86x); of 17 random accepted programs 1 beyond and 0 hot sets; the selector's false-positive rate 7 of 16 on the gate, 13 of 16 on the hot-set test; each hot set about 1 MB of items at 0.3 percent of reads, 1.002x; whether the 0.995 floor refuses 4346 and 5245 is a measurement in hand (their minimum-site ratios at 2^20), not a given. adv-accept-2 at its natural end (92168536): header grinding BOUND by measurement and by tail (1e8 hashes per real program on the windowed random baseline down to the 3e-7 tail, net gain 3e-7x); the rotate-identity repeat class present in 21.0 percent of 300 drawn programs at under 0.1 percent of loads on the worst, absent from the two real programs, a rule question for the next class. Lanes at a natural end: adv-cache, adv-accept-2. THE SITE: b8f501e9 deployed 20:17:42Z with the compact table; its 1600 px capture read five columns clipped at the article column's edge (about 900 px against a 1,400 px table), so the table now fits the column (nine columns, the generator in the detail row, the text columns wrapping and the numbers not, no forced width). A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +Reading: the class v4 premium is 145.3 W at the unlocked clock (not the 80 W of 6 October, which was read at the app's tuned cap) and 88.3 W at the 1,400 MHz lock; v4's rate is +0.18 percent over v3 unlocked and +0.23 percent at the lock; the rate is memory-bound on the whole grid (136.8 to 135.0 MH/s from 2,850 to 1,400); the best MH per watt sits at the lowest lock on the grid, so the knee is below 1,400 MHz. the founder's thesis holds in part: 57 W of the 145 W premium comes back by the lock alone; 88 W stays as the shadow's ALU work at the floor clock. Throttle reasons: the SW power-cap governor (0x400) from unlocked to 2,163, the lock itself (0x4) from 2,100 down on v4 and 1,650 down on v3; 75 C at the top, 59 C at 1,400. The owed 5090 clock rows (2,781 / 2,472 / 2,163 / 1,854) are in this table. Per tier: a 5090 owner on class v4 who locks the core at 1,400 MHz pays 316 W instead of 476 W for 1.4 percent less rate, MH per watt up 48 percent, the v4 premium down from 145 to 88 W; the lever is NVIDIA's -lgc through the helper; AMD has the helper's ADLX tune line or nothing; the Mac has no lever. MAIN'S ORDERS ON IT (20:2x UK): (1) the second pass now, 1,400 MHz down to the driver's floor in 100 MHz steps on v4 and the v3 control, to find the knee and the premium at it, then the same grid on the 5080; (2) the knob into Ember Tune for 0.3.23 (after the power-cap search, a core-clock search downward from the cap's point until the rate falls more than 1 percent, taking the best MH/W, the fingerprint on every step, stored per card; the Mac stated as no lever) through the UI lane; (3) the bench table's 5090 row gains the locked point and the class v4 cost column reads the locked premium beside the unlocked one (done: the 1,400 MHz row 134.98 MH/s at 316.3 W, 0.427 MH/W, the Hive values 1,400 / 13,801 / 575 as the driver's default limit). DEVNET 3's FIRST LOCK (the fleet lane): 19:02:46Z, checkpoint 235 LOCKED on block 50266abe... (blue score 7,050), identical on dn3-g1 (signed 98.4 percent of active) and dn3-g2 (100.1 percent), at DAA about 7,298 (the 7,200 window filled at 19:01Z); wave 1 of the second nodes GREEN on all five at 19:17:00Z, wave 2 from 19:17Z; the 0.3.22 pin candidate 34a2dbaa passed its last gate at 19:07Z (the join-and-restart read on dn3-c1 with the N15 line) and the Devnet 3 sweep to it runs. The fleet's 19:03Z table: 43 rows, 44 GPUs, USD 257 a day, today about USD 460 of the ceiling at 19:20Z; dn3-twin (a broken CUDA host) and dn3-q02 (never answered) destroyed; p12-vast, w-target and w-poison repurposed to Devnet 3. THE SITE: a0e0c83a deployed 19:17:28Z with the Hive column. THE BOXES: build-1 read 601 / 552 / 471 and build-2 401 / 417 / 400 at 19:17Z, the sum being adversarial binaries started by hand over ssh at 64 to 89 threads each (the crypto lane's one-sweep lock not holding the sum); MAIN'S RULE for every lane under this one: no run starts on a box except through the build-server lane's `lease pool -- cmd` (landing within the quarter hour); hand-started runs killed by their kill files and re-queued through the lease; the release builds and the v5 suites outrank the sweeps. THE SHIPPER cuts class v5 as 0.3.24 the minute every v5 gate is green, at any hour; this lane's gate board is the only clock. THE (c''') CENSUS NUMBER (the v5 lane, 21:03 UK; 4,600 f8 seeds, box 2, 48 cores, 1,256 s; log docs/design/class-v5-harness/v5-census-4600-0.log): the 0.995 per-site floor rejects 112 of 4,600 class v4 sub-version 3 accepted programs (2.435 percent); the same 112 move to a later class v5 attempt; the attempts mean 2.174 to 2.248 (+3.4 percent; the tail unchanged, max 24 on both); 0 class v5 accepted programs under the floor. The spread of the v4-accepted programs' minimum site ratio at the 2^20 sample: min 0.9807, p0.1 0.9831, p1 0.9906, p5 0.9962, median 0.9999; under 0.98 none, under 0.99 43 (0.935 percent), under 0.995 112, under 0.998 517, under 0.999 868. Two corrections to the relayed premise: the clean spread is not "0.9960 minimum, p1 0.9990" on the chain's own draw (a smaller sample), and 0.99 would NOT refuse the exemplar (0.9919). So 0.995 is the lowest round floor that refuses seed 100767 with the model's spread under it, at one extra draw attempt on 2.4 percent of epochs (about 0.3 s of acceptance each, no consensus cost, no change to the hash or the kits); the band it rejects is where every measured program so far is a weak hot-set program (adv-accept's live-low20 row: the first read, seed 3664 at 1.31x, beyond the 1.2x gate; its four measured lowest-ratio seeds all beyond). The per-site hot-item test is the same statistic at the 2^20 sample and costs 30 s per candidate at 2^24 against the floor's 0 extra, so it is not a competitor. The defender's call: keep 0.995; the freeze commit carries the number into accept.rs and section 14 and goes the minute the full suite and the gate read green (f17849eb staged). THE PRE-PUBLIC SCRUB: master's text pass (9b8eb23a, 3b4b6c63) names the founder as "the founder" in every tracked text file and the CI check founder-strings refuses the name; this record follows it from here (three lines of the efficiency pass reintroduced the name through a merge and are fixed). THE V5 FAST-TIME LINES ON THE FIRST MATCHED PAIR 959b57c9 (igneumd 519ee6c4..., igneum-pow ab6f980b; harness v5-fasttime 6de9cf74): (1) the ladder climb plus the v5 crossing with the stale node: rung 1 by miner signal from epoch 6 at 19:56:38Z; class v5 by signal from epoch 8 (DAA 480) at rung 1 at 19:58:31Z on 3 of 3 honest nodes, byte 6 at 9,985 bps, before the floor; the prelude reads v4 at epochs 0 and 1 (b1680b57 verified); honest nodes 0 PoW rejections; the stale node 122 of 122 refused by its own node; the SUMMARY FAIL at 20:04:00Z on line 3 alone. (2) Digest-compat SUMMARY PASS 20:08:30Z (one digest c0d6998e with the v5 key absent on the new binary and on the pre-v5 control 2720d8d2; the set key moves it to 8d8f6208 with no peer and the refusal line; 180 s of mixed mining, 79 new and 101 old blocks, 0 rejected). (3) THE RESTART STEP FAILED: n2 stopped at DAA 457 and restarted on its own datadir at DAA 500 (19:59:10Z), the IBD catch-up engaged and did not complete: the relay flow treated the engine's "class v5 needs the execution state" on a relayed epoch-8 block as a rule refusal twelve seconds in, the flow error tore down the peer's flows and the catch-up's body sync with them, the block went into the N6 refused memory, the peer was banned 600 s at 20:00:09Z, and the deferred headers were never validated; n2 on its own fork to the end (600 against 660). FIXED by the node lane at a3b2049d on class-v5-node-wire (20:0xZ): the relay flow holds off a block in the v5 state-wait class at its three validation sites (no strike, no N6 memory, the flow stays up; the next inv or the catch-up's deferred chunk brings it back once the executor has the state), is_v5_state_wait shared with the IBD catch-up, kaspa-p2p-flows 38 of 38 at 20:08:23Z. (4) One program id per epoch equal to the CLI's v5 id: 11 of 11 (v4 at rungs 0 and 1, v5 at rung 1 with the window's stream), the Devnet 3 genesis pack's e5a4ac5978462156 reproduced; the known-failed shape FAIL as it must at 19:04:01Z. THE SECOND MATCHED PAIR 63524e28 landed 20:16:49Z on build-1 (/srv/artefacts/v5-pair-63524e28/, igneumd sha256 4f93697f5b97c30205b7e1c8e521924ba85f849a5d35f1470ff0a1b2a17cbbae; fork v5-object-0323 = 959b57c9 + the relay hold-off a3b2049d + the pool lane's tag rename 7455b8d5 + main's chain id by height, Devnet 3 chain id 4464 from the v5 floor; igneum-pow ab6f980b; suites consensus 126, core 154, pow 19, exec 46, p2p-flows 38, miner 25); the fast-time lane re-runs the crossing with the restart step on it; the v5 object commit waits on that PASS, the freeze commit and dn3-g1's DAA at the cut. THE IN-HOUSE PASS: adv-accept's tally at 2^24: of the 16 lowest stand-in-ratio seeds, 9 beyond the 1.2x gate and 3 hot sets (100767 at 2.05x; 4346 at X/f 1.78, 2.24x; 5245 at 1.29, 1.86x); of 17 random accepted programs 1 beyond and 0 hot sets; the selector's false-positive rate 7 of 16 on the gate, 13 of 16 on the hot-set test; each hot set about 1 MB of items at 0.3 percent of reads, 1.002x; whether the 0.995 floor refuses 4346 and 5245 is a measurement in hand (their minimum-site ratios at 2^20), not a given. adv-accept-2 at its natural end (92168536): header grinding BOUND by measurement and by tail (1e8 hashes per real program on the windowed random baseline down to the 3e-7 tail, net gain 3e-7x); the rotate-identity repeat class present in 21.0 percent of 300 drawn programs at under 0.1 percent of loads on the worst, absent from the two real programs, a rule question for the next class. Lanes at a natural end: adv-cache, adv-accept-2. THE SITE: b8f501e9 deployed 20:17:42Z with the compact table; its 1600 px capture read five columns clipped at the article column's edge (about 900 px against a 1,400 px table), so the table now fits the column (nine columns, the generator in the detail row, the text columns wrapping and the numbers not, no forced width). THE FOUNDER'S QUESTION ON THE CLASS V4 PREMIUM ("we need a solution, deep research, other methods, something must be doable even if it is revolutionary"; a research lane, counter-asic-4, on the literature and the alternatives by 23:30Z). THE ONE COMPUTATION FROM THIS LANE (chip-model-v3 section 5.10, on the mirror's master at aa829826): class v5 ON and the shadow at ZERO leaves the strongest chip, the f = 1 stored-dataset chip, at 5.1x (GDDR7, the 5090's own 16 devices without the GPU: 166 MH/s at 78 W with a farm-shared node) to 9.1x (HBM3 eight stacks: 666 MH/s at 175 W) per joule over the 5090's 0.417 MH/W, the class v3 figures of 5.6 less a rounding, because the node is a farm cost and not a chip cost (class-v5 2a.2: one node serves a farm, the leaves ship at 16.5 KB/s to 10,000 members, the rebuild is the same 32 ms per window every GPU pays); only a chip forced to carry its own node (85 W, approximate) falls near 2x, and only the small ones (one HBM3 stack 1.8x, the GDDR7 board 2.5x; the eight-stack package 6.2x). So the shadow stays the only lever in the model that reaches the memory-system chip, and the premium is its price; what class v5 buys is the recompute and stale chips gone as categories and every miner holding and following the chain. THE RESEARCH LANE's READING of the three shapes (21:4x UK; its identity edge = (E_card + F) / (E_mem + k F), F the GPU's premium per hash, k the chip core's energy per op over the GPU's): at the 1,400 MHz lock (v3 1.69 uJ per hash, v4 2.34, the premium 0.65 uJ = 6.5 pJ per counted op) the premium-free edge is 3.6x on GDDR7 and 5.3x on one HBM3 stack, 2.1x at F = 0.65 and k = 1, the asymptote 1/k; the premium needed for 2x at k = 1 is 0.76 uJ (103 W) at the lock and 1.41 uJ (175 W) at the stock point; at k at or under 0.5 no premium reaches 2x; a premium of zero is impossible by any hash-side lever (a joule the chip must spend is a joule the GPU spends first). Shape 1 (the shadow at the floor clock): correct and measured by the 1,400 row; it halves the premium and leaves k as the whole question (the edge's derivative in F at F = 0 is minus 5.7x per uJ at k = 1 and minus 0.2x per uJ at k = 0.3; the family mix with the highest k, shuffles and multiplies, is the right content; the tensor block has k near 1 but 0.056 pJ per MAC, so it forces no joules without 26x the verifier). Shape 2 (per-read work a chip cannot amortise): no construction found (the chip's lane count is set by its own latency, lane state is SRAM at pJ per access, extra reads scale both rates; row, bank, refresh and burst shaping have no asymmetry); one candidate for a measurement, not a claim: a hot table kept L2-resident through cache-policy hints (dataset loads evict-first, hot loads evict-last), since a 64 MiB SRAM read on a chip is not cheaper than a GPU L2 hit (the 3.0 layer 5 measurement used no hints and lost 13 to 16 percent). Shape 3 (the refresh as the cost): dead by arithmetic (a 1 GiB rebuild about 0.1 J on a chip against 280 kJ of hashing an hour). What lowers the premium-free floor is the card's own E_card: the 5090's idle 74 to 91 W plus its memory system's 55 W bound the floor near 2.0x on GDDR7 at any operating point; the two measurements that read how much of the 100 W between is reachable are the knee below 1,400 MHz (the floor pass, on PC 1's queue) and an SM-sparse kernel (the hash on a fraction of the SMs with 4 to 8 chains per thread, the rest clock-gated), both ordered to the hash lane with the L2 cache-policy hot table as PC 1 queue tail items (worker launch shapes, --bench only, no consensus change). THE FIVE RATIOS (adv-accept, 21:35 BST, at the acceptance's 2^20 sample, closed form and live to 1e-4): 4346 (bbb38e847011c354) minimum site 2 at 0.9840 REFUSED by (c''') at 0.995; 5245 (beaad44840bb9e4e) site 8 at 0.9831 REFUSED; 106924 at 0.9821 and 107022 at 0.9877 REFUSED; Devnet 3's epoch-0 class v4 program (fce15bf61030be57) site 0 at 0.9992 (live 0.9993) MISSED; era-fixed-20 (11f9f955b21d56c9) site 11 at 0.9997 MISSED; era-drawn-2 (7ceb797d31eedb3e) site 13 at 0.9992 MISSED. THE DEFENDER'S RULING: the (c''') floor at 0.995 closes the HOT-SET HALF of the class (every program with X_f at or above f that any lane measured, 100767 included) and NOT the class; the residual is the shadow-block-written value-level concentration below a ratio floor's resolution (1.26x to 1.45x of the top 0.1 percent share, 0.03 to 0.1 percent of a hash's reads each, minimum sites 0.9992 to 0.9997, which no floor reaches without sitting inside the clean seeds' own spread), chip gain under 1.001x, its lever a value-level source test at live scale or a per-site hot-item test, routed to the next class as a named item; section 14 of the v5 design says so with the five numbers verbatim; the freeze proceeds on the suite's green, both the floor's number and its reach measured. adv-mixer-2 (49656c2e) confirms AP-F4-1's class from outsider inputs (model A an FPGA LUT-area gain for a per-day build, 1.0 on every GPU, verifier and chip with a general multiplier; P(A at or above 1.1x) = 2^-10.8 per day on the exact median 226; model C under 2^-20 at 1.1x), the two censuses' medians (226 against 231) to be reconciled side by side in the record; its redraw rule to the v5 lane as a second independent statement. The kits lane's box-side body moved to tools/class-v5/kits-on-box.sh run by path under the inline-rm rule (v5-kits 4f9d96d2); the kit zip stands. MAIN'S RULINGS (21:4x UK). (1) The class v5 freeze does not wait on the three milder concentrations the 0.995 floor misses (Devnet 3's first program among them): their chip gain is bounded under 1.002x by their size, so the freeze proceeds with the floor as it is, the record names them as the residual, and the fix question (a value-level source test at live scale) is a 0.3.25 item. (2) The weak-day census reconciled at median 226 (F4's NAF weight had counted the carry digit at position 32, which a 32-bit multiplier never pays; 0.333 digits per word, 5.3 adders per day, the whole of 231 against 226 and of 12 against 15 days a century, the same worst day in both; F4's record section 9 carries both medians side by side, mirrored in adv-mixer-2's report): 5.69e-4 of days (2^-10.8), 15 days a century over 1.1x on FPGA LUT area, worst 2050-04-28 at 1.113x, the DSP-bound readings at 0 for k at least 2, F4's PASS against class v4 unchanged; every public text saying "12 days a century" becomes "15 days a century" (done in this landing on the litepaper table, /claims through it, evidence row 17 and the public text file, the sentence now "at most 12 percent more multiplier area on an FPGA's per-day build on 15 days a century, nothing on the other days and nothing for any chip"); the site audit lane told. (3) THE HALVING, ruled to the fleet (21:4x UK), neither (a) nor (b) as written: on every standing box the OLD shared-devnet miner stops and the Devnet 3 miner keeps the card at full rate (one miner per card, the exception over); hub-1, pool-1 and the live seed stay on the old chain as its voters and miners until every poller has moved; the old-chain nodes on the boxes stay up as voters without mining; no 3070 fallback; the fleet reports per-box restore lines. THE IN-HOUSE PASS, MORE CLOSES: adv-cache-3 COMPLETE (bc2d01d5, 0.23 slot-hours; every row BOUND or PASS, every plant fired; the exhaustive w = 2 image census at all 64 depths equal to the random-function recursion to 2 x 10^-5; the flip-table ladder at 2^18 lines no single-bit bias from two double rounds up). adv-accept-3 (aa359962): a correctness FINDING for the rule's owners, no chain consequence: the deterministic last-resort program (after 256 failed attempts) FAILS the real rule in 223 of 2,500 seeds (209 by part (a), a cyclic stale load) yet is handed to the chain unchecked, unreachable at 4.6e-44 per epoch; ruled to class v5's generator as the commit after the freeze (the last resort passing the rule by construction, known-failed first on one of the 223 seeds; sub-version 3's stated as unreachable and unverified, class v5's as verified); also the 256-unit stand-in ratio is noise as a selector (the three lowest of 4,975 clean live at 1.0002x worst), the selector working only at the 2^20-unit read. Lanes complete or at a natural end: adv-cache, adv-accept-2, adv-cache-3; adv-mixer on its last solve. The kits lane's box-side body moved to tools/class-v5/kits-on-box.sh by path (v5-kits 4f9d96d2) under the inline-rm rule. THE SECOND 5090 PASS, THE KNEE (run-ca3-pc1-v4-eff-5090-floor-20261007, exit 0 at 20:41:14Z; the 5090 alone, 60 s steps, memory 13,801 MHz, every fingerprint matched): + +| Core lock MHz | v4 MH/s | v4 W | v4 MH/W | v3 MH/s | v3 W | v3 MH/W | sm read | +|---|---|---|---|---|---|---|---| +| unlocked | 136.84 | 473.7 | 0.289 | 136.50 | 329.9 | 0.414 | 2,842 / 2,850 | +| 1,400 | 135.02 | 320.0 | 0.422 | 134.85 | 229.0 | 0.589 | 1,387 | +| 1,300 | 134.76 | 312.5 | 0.431 | 134.62 | 223.3 | 0.603 | 1,290 | +| 1,200 | 133.80 | 305.1 | 0.439 | 129.54 | 215.7 | 0.601 | 1,192 | +| 1,100 | 122.43 | 287.3 | 0.426 | 118.70 | 209.4 | 0.567 | 1,087 | + +The knee by main's rule (more than 1 percent lost against unlocked): 1,300 MHz on both classes (the rate within 1.5 percent of unlocked down to it; v3 falls 5.1 percent at 1,200, v4 10.5 percent at 1,100); the best MH per watt one step past it: v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W, 168.6 W recovered for 2.2 percent of rate), v3 at 1,300 (134.62, 223.3 W, 0.603, 106.6 W for 1.4 percent). The v4 premium 143.8 W unlocked, 81.8 W at the best points; the v4 rate 0.25 percent over v3 unlocked and 0.61 percent under at the best points; the residual at the floor is the shadow's ALU work, not the clock. Per tier: a 5090 owner on class v4 locked at 1,200 to 1,300 MHz draws 305 to 313 W instead of 474 for 1.5 to 2.2 percent less rate, MH per watt up 49 to 52 percent; the Ember knob (0.3.24, the hash lane on the engine side, the UI lane's drawing) carries these as its reference rows. A FAULT FOUND AND FIXED: the steps 1,000 down to 300 and the closing reset got no answer from the Power Helper and the card sat at the 1,100 lock for about five minutes after the job (118 to 122 MH/s live); the installed app's own Ember tune on the 5080 wrote the same cmd.txt with higher sequence numbers while the script wrote lower ones, and the helper skips any sequence at or under the last run; the restore job run-ca3-pc1-clocks-restore-20261007 (exit 0 at 20:45:58Z) put the 5090 back at 2,865 MHz; the fix 45f9497f on the mirror (the sequence base from helper.log and cmd.txt, re-based after a timeout, an unanswered lock stops the grid, the task restarted before every reset); the rule for the knob: it takes its sequences from the engine's counter and no script shares the file with a running tune. The driver's floor below 1,100 is unmeasured. THE PC 1 QUEUE after the shipper's 0.3.23 host job (main, 21:5x UK): the 5080 full grid with the fix; the research lane's SM-sparse kernel job (the hash on a fraction of the SMs, several chains per thread, the rest clock-gated; the research lane hands the kernel to the hash lane); the third 5090 pass from 1,100 down to the driver's floor at the tail; then the 9070 XT G1 and ladder, the v5 AMD bench, item 6 on AMD, the 5080 and 9070 XT tunes, the L2 cache-policy hot table; each exit line to the shipper and the coordinator; the honest site sentence (the premium at the knee and the floor it buys, labelled measured, the Ember knob named as how a user gets there) once the 5080 reads. THE DERIVATION FINDING FIXED (the hash lane, 15008aca and 0f45c8be on the mirror): one byte recipe (generator::IdRecipe) builds the id and the printed text; program.json states the generator 4 suffix and the rung form; spec 1.4.6 corrected (class v5 = generator 5, no suffix); tests/derivation.rs re-derives all 18 pinned packs from their own text (the plain text gives 8aa9f185d63f269e for the devnet v4 pack, the known-failed case); 38 packs' program.json re-exported with ids, kernels and fingerprints byte-identical; the full igneum-pow suite green on box 2. CLASS V5 FROZEN: class-v5 1c420786 on both box mirrors at 21:53 UK (the (c''') floor with its number; section 14 with seven of seven live hot sets refused at 0.9821 to 0.9919, seed 170 at 0.9880 the seventh, and the three mild residuals at 0.9992 to 0.9997 named at about 1.0004x; the pinned pack unchanged; the flip-stale harness PASS on the matched binaries at 21:03 UK; the AP-F4-1 first form and the AP-F1-1 shadow rule, the latter's measured trigger 11 permille maximum over 6,000 first draws against the 30 bound, 0 redraws; the igneum-pow suite green on box 2: 73 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7; the gate GREEN at 58 checks). The kits lane: the 0.3.24 kit is packs-ca3-v5-20261007T183921Z.zip sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 (state.igsd1 included), fingerprint 82b19cbde8557ea5 on Metal, Apple OpenCL and a CUDA 4090; AMD on PC 1's queue, Intel deferred; the shipper has the line. The attack-pass lane runs F8 at 2^24, F9 at 10^5 and F1 on 1c420786 under class v5. The v5 lane's next commit on the freeze: AP-F4-1 in the agreed form (cost at most 205 against the median 226, w32 without the position-32 digit, k >= 1 and all-ROT-equal rejected, the known-failed day 29,337 = 2050-04-28) and the verified last resort (part (a) repaired by re-sourcing stale loads, then the whole rule over a 256-candidate scan, known-failed first on adv-accept-3's adv3/steer/2); both move the stream only on days and seeds the chain never reaches. THE FOURTH EXCEPTION ON THE RESTART STEP (the fast-time lane's held-miner run on the third pair 63524e28, 20:4xZ): the IBD catch-up's body sync anchored on the node's own sink and moved only on a whole chunk's successful join, so with the honest headers arriving as one chunk failing on its v5 tail it fetched nothing and the executor never reached the seed block; the relay hold-off and the mining hold from the earlier fixes read green on that run. FIXED by the node lane at f0c56f50 (the refused chunk split by consensus's own record, the anchor moved to the highest validated header, the honest v4 prefix through the seed block, only the unvalidated headers deferred; kaspa-p2p-flows 38). PAIR 4 = v5-object-0323 c8f9b383, re-archived from the frozen 1c420786 (generator.rs and accept.rs moved since ab6f980b, memhard.rs not), building on build-1 at gate priority since 20:54:32Z with the line's gates beside it; the restart step's PASS must come from pair 4; the object commit lands the minute it does, with dn3-g1's DAA at the cut plus 7,200 rounded up to the 3,600 boundary and its UTC clock named; the testnet lane told to pair its re-cut with 1c420786. The crossing clock is not yet a reading: about 22:15Z (23:15 BST) at the earliest if every line reads green on its first pass. The site audit lane: no other "12 days" form served; its row-17 edit keeps main's outside-check clause and adds the 5090 efficiency numbers. THE CHIP TEXTS, THE X9 WORDING RETIRED (main's order from the counter-asic-4 research file d7721ebe, 22:0x UK): the withdrawn Antminer X9's claimed ratio ("a third of a CPU's energy per RandomX hash") is against a CPU core (about 100 pJ per instruction, Horowitz and Dally, claimed), not a GPU lane (6.5 to 10.4 pJ measured), so a chip three times better than a CPU is worse than a GPU lane per op and the X9 is not a pessimistic chip core against us. The served texts (the home line, the litepaper's lead, chip table, ladder sentence and chip bullet, /claims through it, the miner line, evidence row 17) now give the floor and the premium as measured numbers at the 5090's knee: the chip at 2.1x per joule with a core as good as a GPU lane (k = 1) and 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the shadow's premium 81.8 W at the best points (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W, 7 October 2026), Ember Tune's core-clock knob named as how a user gets there; the ledger text check's pins X35 and X36 moved with the wording; no "3.9x" remains on any served page. One number stated against main's wording: main's line read "2.9x with one three times better", which in the research file is the figure for the RE-WEIGHTED op mix (row 3, held by the coordinator until the SM-sparse read); today's mix at a core three times better reads 3.4x in the same file, so the served text carries 3.4x and the 2.9x waits for the re-weight to ship. THE RESEARCH FILE's TWO ORDERS: (1) the texts as above; (2) one zero-code measurement at the PC 1 tail after the third 5090 pass: the 5 October hot-table packs (packs-ca2-hot, 32 and 64 MiB) with the worker's `--variant ldcs` (dataset loads streaming, evict-first; the hot loads plain and L2-resident) against base on the 5090, the rate ratio g and the watts (the 5 October rows without the hint g 0.84 to 0.87); the one class where a chip's cost per op (a 64 MiB SRAM read, 0.2 to 0.5 nJ approximate) may exceed the GPU's (an L2 hit, 0.1 to 0.3 nJ); Metal has no such hint. The shadow stays at rung 0; the op-mix re-weight waits for the SM-sparse read (the research lane's worker variants sp170/85/43/21/11-w32, one block of 32 warps per SM, run through the hash lane's efficiency script in its ca4 mode at 4f3a064e; the no-prompt and sequence rules hold by the same code). A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the founder's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule diff --git a/docs/plans/release-0.3.22.md b/docs/plans/release-0.3.22.md index 03ef2b509..0fe4d6b59 100644 --- a/docs/plans/release-0.3.22.md +++ b/docs/plans/release-0.3.22.md @@ -122,3 +122,9 @@ Three commits on 96161037: bd710a36 the sub-version 3 re-pin (byte 7, igneum-pow **LG-4 (the founder: "use PC 1 or PC 2 or get another machine"; main's ruling):** on PC 2 tonight after both smokes, a fresh Windows user account created by job (no Igneum state, no card cache), the three timed steps (download and install, sync to the tip, dataset build to the first accepted share) as FIRST-SHARE lines, ten runs with the app uninstalled and the profile wiped between runs, no click anywhere, the rows on /evidence labelled "PC 2, fresh user account, not a fresh image, 7 October 2026", the 9-of-10 under-10-minutes bar read against them; macOS the same way as a fresh user account on the Mac tomorrow; a rented Windows VM only if the account shape fails the bar for a reason an image would change. PC 1 stays the founder's desk. **0.3.22 Windows take 2 FAIL (21:13 BST) and the skip:** the job's detached helper was ended with the job's process tree before its first sleep ran out (Start-Process stays in the runner's tree; a survivor needs Win32_Process.Create or a scheduled task); nothing was installed, every file still 0.3.21, the payload untouched. Ruling: no take 3; the 0.3.22 Windows entry is skipped (the Mac and HiveOS entries stand); the first install over a running app is 0.3.23's installer with install-close-23 in the simplest job shape (Start-Process -Wait; the installer's own stop step and the install-running flag do the work), its smoke read the gate line for both; the Discord card publishes on the 0.3.23 Windows entry. **The version miss, second layer (21:30 BST):** the box cross of 0.3.23's exes failed in build.rs because igneum-app.rc still read 0.3.22 (Info.plist and the installer's AppVersion too); fixed at release-0.3.23 = 7c7489ac, the rule 15 check extended to six places and green on the tree; the 0.3.23 node pairs under /srv/artefacts/0323-2720d8d2/ (hands f2cf6a87/fb147dd1, seed 3edaf83d/be5ca735, win 8326d78a/38c74545) with the engine string. + +## 12. The 2720d8d2 split and the one-minute form (21:1x to 21:4x BST) + +The 0.3.23 node's heights move Devnet 3's digest to ba75bf6f, and the one-box-at-a-time sweep to it split the network: dn3-g1 flipped at 21:18 BST and sat alone twenty minutes on its own fork (blocks 12,553 to 12,793, peers 0; the 83eb50cd nodes refuse ba75bf6f at the handshake; build-1's seed logged 27 digest-mismatch rejects by 21:37); the fleet stopped the pass at 21:31 after that one box (the Vast ssh proxies ssh1, 3, 4, 5, 6 refused the next five, so nothing else flipped) and reverted dn3-g1 to 34a2dbaa on its kept datadir, where it reorgs onto the network's heavier chain; no record or share of the network's sat on the solo blocks; the pool pair, the provers and the second nodes stayed on 83eb50cd. The shipper's part of the fault: the 0.3.23 Mac entry (both folders, 21:39:09 BST, DMG 4ada2807 on 7c7489ac) and the 0.3.23 HiveOS alias (0d716ed9, 21:37) were published ahead of the fleet's move, against rule 5's own word; both pulled back to 0.3.22 (live again at 21:41:08 and 21:44:48 BST; the Mac still runs 0.3.22; the 0.3.23 hive package held in scratch r0323/held-public). The move to 2720d8d2 is the 0.3.20 form (rule 5 extended): binaries pre-placed on every Devnet 3 node (the fleet's thirty, build-1's three, the pool pair's two), every node restarted inside one minute at a clock the fleet names ten minutes ahead once the proxies answer, the digest read back per node, the first lock on the new side as the line; the 0.3.23 Mac entry, the hive alias and the Windows entry publish at that minute or after. Pool split: the hour's 13,209 + 7,200 = 20,409 lands before the 0.3.24 publish minute, so the split goes into the 0.3.24 object at or after the v5 floor on IGNH/IGNW (pending main); the node lane holds it out of the v5 object commit. PC 1: the 5090 floor grid exited 0 at 21:41 BST but the Power Helper hung at its 1,000 MHz step and the 5090 mines at the 1,100 MHz lock until the hash lane's unelevated restore job runs; the grid gets the fix (stop at the first helper timeout, restart the task before the reset). + +**Decimals (the founder, 21:40 BST): 18.** The testnet GO object re-cut goes on the 0.3.24 line as its second item on top of the v5 object commit (the 0.3.23 pin 2720d8d2 is frozen in the move): base_unit_decimals 18 with the UTXO/EVM scale fixed and tested, the 16-byte subsidy layout, the emission rescaled, the final 5 October message, the cache-rung field at 0, class v5 at 0 only if its Devnet 3 crossing reads clean, chain id 4462, the override file refused; the seeds re-armed on the dry run, nothing mining until the founder's go. **Pre-place for the one-minute move (the fleet, 21:5x BST):** the 2720d8d2 pair as .new on all 34 Devnet 3 nodes (20 rented, 14 standing second nodes), 2 of 34 placed while the Vast ssh proxies ssh1 to ssh9 refuse or time out since about 21:30; build-1's three pre-placed at 21:46 BST with the restart armed on the minute; dn3-g1 re-peered on 34a2dbaa at 21:43:32 BST (13 peers, three reorg lines, the 25 minutes of solo blocks orphaned). One miner per card restored by the fleet's v2 pass (p2-4090-3 first at 21:51:55 BST: the Devnet 3 miner alone at 55.96 MH/s, supervisors 4 to 1). **A pool-mode miner finding (0.3.24 item, the pool lane):** --exit-on-seed-change does not fire in pool mode; pool-b hashed the epoch-2 pack for 56 minutes after the 20:53 BST seed change (47,700 shares wrong_hash) until a re-export and restart by hand; the settled pool hour holds pool-b's shares to 20:53:09 only. PC 1: the Power Helper hang cleared by the hash lane's restore job at 21:45:58 BST (the 5090 back at 2,865 MHz); the 0.3.23 host slot open from 21:51 BST. diff --git a/docs/plans/release-rules.md b/docs/plans/release-rules.md index ecddb7a3a..9f9282b2d 100644 --- a/docs/plans/release-rules.md +++ b/docs/plans/release-rules.md @@ -9,7 +9,7 @@ Every cut of the Igneum Miner app and its node runs under these. The dated plan 4c. **The proving ids gate (main, 7 October 2026, after the 0.3.20 blocker).** On every candidate, a node started on the LIVE override file reports both proving ids (the shard program id and the aggregator id) on its proving v1 start line, and a prover's first statement against it is accepted; a zero-id statement is the known-failed shape. It runs beside the kept-datadir read, since both share the warm pod. Why: c4459193 read the ids as unknown, built statements with zeros and refused every proof; a sweep would have stopped every prover's pay. 4a. **Every gate starts on every candidate the moment its binary builds, never after the pin (the founder, 7 October 2026).** The digest and mixed-version gates, the kept-datadir start, the relay and poison cases and the wipe canary all begin on each candidate binary as it lands; a struck candidate's runs are stopped and its successor's begin. The post-pin wait is then the longest single form (about 80 minutes, the wipe), not the sum. 4b. **Warm pods per gate class (the founder, 7 October 2026, ordered to the fleet lane).** The fleet keeps synced pods warm for each gate class so a case form's target starts at the tip (a kept copy of the live line, caught up), never from a kept copy far behind it; the wipe canary is the only full IBD in the set. -5. **Rollout in waves, each box read back (the founder, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). The wave list is written, not remembered: every sweep's first wave names each Hetzner seed by address (188.245.5.161:26611 for the shared devnet; the testnet seeds when they move) beside the hands and the fleet, and the seed's row closes only on its own read-back line (string, digest, first accepted block) from the lane that holds its key (the build-server lane, infra/devnet/restart-seed.sh). Added 7 October 2026 after the 0.3.20 sweep left the seed on the old object for one hour forty, found by the 0.3.21 wipe canary's reject lines. +5. **Rollout in waves, each box read back (the founder, 7 October 2026, replacing one-box-at-a-time):** PC 1 first, then PC 2, the Mac, the seed, the hands and the fleet in parallel waves as the lock lines allow; a lock line from the hub between waves; hold if the frozen table's signed share reads under 75; every box read back by its commit string. When the publish moves the consensus floor (a new digest), every 0.3.x node on the old file refuses the new ones as peers until it is swept, so the seed, the hands and the fleet move in the first wave with the apps' pollers, not last. Every lock line of a sweep that replaces nodes carrying a consensus floor names the date the sweep must finish (0.3.20: before 13 October 2026 09:00 UK). The wave list is written, not remembered: every sweep's first wave names each Hetzner seed by address (188.245.5.161:26611 for the shared devnet; the testnet seeds when they move) beside the hands and the fleet, and the seed's row closes only on its own read-back line (string, digest, first accepted block) from the lane that holds its key (the build-server lane, infra/devnet/restart-seed.sh). Added 7 October 2026 after the 0.3.20 sweep left the seed on the old object for one hour forty, found by the 0.3.21 wipe canary's reject lines. **Digest-moving node releases (7 October 2026, after the 2720d8d2 split):** when the node commit moves the consensus params digest (a height, a floor, a new switch field), a one-box-at-a-time sweep is a network split (dn3-g1 sat alone twenty minutes on its own fork at 21:18 BST), so the move is the 0.3.20 floor-move form: the binaries pre-placed on every node of the network (the fleet's, the hands, the seeds, the pool pair, every second node), every node restarted inside one minute at a clock named ten minutes ahead, the digest read back per node after, the first lock on the new side as the line; the apps' entries (manifest, HiveOS alias) publish at that minute or after, never before, so no app sits alone on the new digest. The one-box form is for digest-preserving releases only (34a2dbaa tonight). The release note names which form a release takes before its first box moves. Gate check (main, 7 October 2026): the publisher refuses an app entry whose node pin's digest (the pinned binary with no file on the entry's network) differs from the network's current digest (the hub's RPC) unless the move's clock is recorded in the entry's notes (--move-clock), known-failed self-test on tonight's shape; tooling on the 0.3.24 publish (the build-server lane). 6. **Read-back is by commit string plus digest plus engine:** on 0.3.18+ nodes igneum_getNodeInfo powEngine must read "igneum-pow" ("stub" = FAIL); on earlier trees `strings igneumd | grep -c igneum-pow/src/` above zero. The miner embeds no commit string; its pairing is the build line and the sha. 7. **igneum-pow pairing:** a fork build takes igneum-pow by path from the igneum worktree it sits in; build each node tree inside its own app worktree whose igneum-pow is the pinned tree; the pairing log line names it. Master's build tools need rust-toolchain.toml in the tree (the app tree's pin applies to a vendor worktree under it; a standalone node checkout is unpinned until the node line carries its own file). Extended 7 October 2026 (the Devnet 3 pool pair, three WRONG HASH rounds each a tree a step behind the chain): the rule binds every crate that embeds kaspa-pow, the node, the pool daemon (igneum-pool) and the app's CPU re-check alike, each built against the pinned igneum-pow by path from the release worktree (017e7037 on 0.3.22 and 0.3.23), and the packs pin travels with the generator (the proto-cuda packs are the pin's export, never an older one); the read-back is the paired miner's "class v4 program id <16 hex>" line equal to the node's per epoch, and the daemon accepting its shares. 8. **glibc classes:** HiveOS 2.31 (`--ship hive`, smoke in ubuntu:20.04 on the box), seeds and generic 2.35 (`--ship seed`), fleet 24.04 boxes native 2.39. diff --git a/site/claims.html b/site/claims.html index e643810ae..347fd71c5 100644 --- a/site/claims.html +++ b/site/claims.html @@ -222,7 +222,7 @@

Here are the limits, stated before anyone else states them.

  • A proof in seconds. Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.
  • -
  • A chip is impossible. No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as the GPU’s (k = 1, modelled on measured card watts, 6 October 2026) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.9x at the X9’s claimed core, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • +
  • A chip is impossible. No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane and 3.4x with one three times better, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as a GPU lane (k = 1, modelled on the 5090’s measured watts at its knee, 7 October 2026) to a core three times better per operation (k about 0.33); the withdrawn Antminer X9’s claimed figure is a ratio against a CPU core, not a GPU lane, so it does not stand for a chip core against us; the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.4x at a core three times better, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • A guaranteed income floor. No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.
  • A memory-hard prototype on every vendor. Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.
  • Finality in the first month. No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.
  • diff --git a/site/evidence.html b/site/evidence.html index ba9b19f4b..a24934014 100644 --- a/site/evidence.html +++ b/site/evidence.html @@ -254,7 +254,7 @@ td.mono{font-family:var(--f-mono);font-size:12.5px;min-width:180px}td.iv{color:v 14Ethereum bytecode runs unchanged, with the documented differences of spec 7.1
    Homepage Build card; litepaper Building
    tested by the teamas row 13; fixes F-exec-A, F-exec-B (spec 7.5)tools/evm-smoke/smoke.mjs: deploy via viem, increment, hashLoop, eth_estimateGas, eth_getLogs; tools/exec-attacks scenarios 1 and 3; bench-log "execution layer attack fixes"Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The Prover precompile, proof records and the shard planner are not in the nodenone yet 15Every block is proven, with the proof landing within about a minute at launch
    Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate
    implementedrepo d7e1f89 (GPU proof), e01a3cc, 292e800, eedd136 (proving/igneum-prove: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6proving/windows-wsl2 (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; igneum-prove-host --mode block on proving/fixtures/; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture block-78-increment (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in docs/benchmarks/proving-e2e.md. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on the RTX 5090 Windows rig in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind proving_v1_activation_daa (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is onenone yet 16A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)
    Litepaper Proving ("The proving budget"); roadmap gate 2
    designedspec 5.1 (Target), 7.6 (S_p provisional, 7,500,000 pgas = B_p / 4)PROVE-SHARD.bat on the RTX 5090 (pending); the end-to-end standard in docs/benchmarks/proving-e2e.md; bench-log "proving: devnet v4 shards"Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional S_p is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB cardnone yet -17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (k = 1) to 3.9x (k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 12 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 core claimed and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); the class v4 efficiency pass of 7 October 2026 on the same card: 136.84 MH/s at 475.5 W unlocked, 134.98 MH/s at 316.3 W at the 1,400 MHz core lock, the class v3 control 134.68 MH/s at 228.0 W (docs/plans/counter-asic-3-status.md); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.9x, 2.8x at launch; 1.067x at the ceiling; 12 percent on 12 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word +17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word 18The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache
    Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page
    tested by the teamreadwidth e752fc7 (docs/plans/read-width.md), ca2-era 78c0ee4, ca2-cache 2de19e5 (docs/plans/hot-table.md)The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per loadLatency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026none yet 19The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors
    Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page
    tested by the teamca2-mixer 1ab8b21 (tests/mixer.rs, tests/scratch.rs), ca2-era 78c0ee4, ca2-soundness a465881 (docs/analysis/scratch-soundness.md), igneum-pow/tests/packs.rsThe crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per cardClass v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT) job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)none yet 20No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)
    Homepage stats and Economics tiles; litepaper Supply, Economics
    implementedrepo 6ac80a3; fork "igneum-node devnet v0"; consensus/core/src/igneum.rs, coinbase.rscargo test -p kaspa-consensus-core igneum (8 pass: subsidy table, ramp, split, cap) and cargo test -p kaspa-consensus coinbase (8 pass); igneum-miner inspect 40; bench-log "igneum-node devnet v0"Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the igneum-proving-pool-v0 output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happenednone yet diff --git a/site/forbidden-strings.txt b/site/forbidden-strings.txt index 899d1506f..ac88ce391 100644 --- a/site/forbidden-strings.txt +++ b/site/forbidden-strings.txt @@ -13,16 +13,9 @@ intake[_-]?key Tailscale tailscale ts\.net -# the founder's name, logins and the earlier businesses, base64-encoded so the list is not itself a hit (a `b64:` line is decoded -# and compiled case-insensitive by site/scrub.mjs and tools/ci/launch-gates-check.mjs; the same patterns live in tools/ci/founder-strings.b64) -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] -b64:[encoded-pattern-removed] +# the founder's name, logins and the earlier businesses are NOT in this file in any encoding (a base64 line is a disclosure to any reader, found +# 7 October 2026, 21:3x UK, on the public host): they live in the private list ~/.config/igneum/founder-strings, read by site/scrub.mjs, +# tools/ci/launch-gates-check.mjs and tools/ci/founder-strings-check.sh where it exists; the Mac's pre-push hook is the guard on every push. Hetzner igneum-seed /root/ diff --git a/site/index.html b/site/index.html index 3f9d3d2f9..716624fbb 100644 --- a/site/index.html +++ b/site/index.html @@ -236,7 +236,7 @@
    01
    The same card finds the block and proves it.

    Both jobs pay. When you stop, the card still games.

    02
    A fair start.

    Nobody holds a coin before block one. The protocol carries no fee. The one payment to the project is the Ember software’s optional 1% dev fee, like other GPU miners, off with one flag.

    -
    03
    Built for graphics cards.

    At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block. Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item. Without class v4 the same chip would reach 5x to 9x. The model and every measurement are public.

    +
    03
    Built for graphics cards.

    At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane, 3.4x with one three times better, under class v4 from the first block; a 5090 locked at its knee pays 82 W for that shadow work. Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item. Without class v4 the same chip would reach 5x to 9x. The model and every measurement are public.

diff --git a/site/litepaper.html b/site/litepaper.html index 65ab184ba..512360f08 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -314,7 +314,7 @@ body.all .pager{display:none}

Abstract

-

Igneum is a proof-of-work blockchain built for graphics cards, where NVIDIA cards also prove every block with zero-knowledge proofs and sell proving to other chains. At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block; class v5 makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item; without class v4 the same chip would reach 5x to 9x: the chip model, every number labelled measured, modelled, claimed or designed.

+

Igneum is a proof-of-work blockchain built for graphics cards, where NVIDIA cards also prove every block with zero-knowledge proofs and sell proving to other chains. At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane, 3.4x with one three times better, under class v4 from the first block; class v5 makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item; without class v4 the same chip would reach 5x to 9x: the chip model, every number labelled measured, modelled, claimed or designed.

It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program changes every hour, so a chip built for one program is useless for the next, and a chip for the whole program space is a GPU without the graphics parts. No scheduled human release is needed to keep it that way. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.

1 / s
blocks, rising to 10
@@ -437,20 +437,20 @@ body.all .pager{display:none}

Three ideas carry the chip resistance. The hash rewrites itself. A new program every hour, drawn from the chain. Its memory pattern changes with it. The rules change on a schedule fixed at launch. No release, no vote. These are automatic schedule changes: they defeat a chip wired for one datapath and they need no human fork. Against a chip that stores the dataset every drawn parameter is firmware, and what meets that chip is the latency-shadow work (class v4) and the price per joule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

-

The work that waits can grow. Class v4 adds a block of latency-shadow arithmetic to every hash, about 100,000 integer operations that run while the memory reads are in flight, so a chip that stores the whole dataset still has to pay for a core. That size sits on a ladder fixed at genesis, six rungs from about 100,000 to about 1,000,000 operations, and it moves one rung at a time only when 90 percent of blue blocks in each of seven consecutive days ask for it; it can never move two rungs inside a week and never past a rung the reference verifier cannot check under 10 ms with its sibling thread busy (measured on the build server, 6 October 2026: the first three rungs pass at 8.8, 8.9 and 9.2 ms, the fourth misses by 0.08 ms on a loaded box and stays out until a quiet re-measurement, the two doublings are out at 12.4 and 15.0 ms). What it buys, on the measured cards: against a dataset-storing chip whose core costs what an RTX 5090's does per operation, the chip's per-joule edge falls from 2.1x at the first rung to 1.3x at the third; against a core as good as the one Bitmain claimed for its withdrawn Antminer X9 (about 3x per joule over a desktop CPU, never measured), from 3.9x to 2.8x. What it costs, per rung, is measured too: the Apple tier gives up 3 points of rate at the first step and 6 more at the second, the RTX 5090 nothing until the second; so the miners who pay for a step are the ones who take it (ledger M34).

+

The work that waits can grow. Class v4 adds a block of latency-shadow arithmetic to every hash, about 100,000 integer operations that run while the memory reads are in flight, so a chip that stores the whole dataset still has to pay for a core. That size sits on a ladder fixed at genesis, six rungs from about 100,000 to about 1,000,000 operations, and it moves one rung at a time only when 90 percent of blue blocks in each of seven consecutive days ask for it; it can never move two rungs inside a week and never past a rung the reference verifier cannot check under 10 ms with its sibling thread busy (measured on the build server, 6 October 2026: the first three rungs pass at 8.8, 8.9 and 9.2 ms, the fourth misses by 0.08 ms on a loaded box and stays out until a quiet re-measurement, the two doublings are out at 12.4 and 15.0 ms). What it buys, on the measured cards: against a dataset-storing chip whose core costs what an RTX 5090's does per operation, the chip's per-joule edge falls from 2.1x at the first rung to 1.3x at the third; against a core as good as the one Bitmain claimed for its withdrawn Antminer X9 (about 3x per joule over a desktop CPU, never measured), from 3.4x to 2.8x. What it costs, per rung, is measured too: the Apple tier gives up 3 points of rate at the first step and 6 more at the second, the RTX 5090 nothing until the second; so the miners who pay for a step are the ones who take it (ledger M34).

The chip model

-

We price the strongest chip we can design against an RTX 5090 and publish the arithmetic. Class v4 is live from the first block on the testnet and the mainnet (the ladder’s rung 0 at genesis), so the launch number is the class v4 row. The honest card: an RTX 5090 mines class v3 at 136 MH/s on 350 W in the bench and 290 W in the app (measured, 6 October 2026); under class v4 the same card reads 136.84 MH/s at 475.5 W unlocked and 134.98 MH/s at 316.3 W at a 1,400 MHz core lock, against a class v3 control of 134.68 MH/s at 228.0 W (measured, 7 October 2026); an Apple M5 Max at 27 MH/s on 21 W (measured, 6 October 2026); an H100 SXM at 249 MH/s, 98 percent of its random-read ceiling like the 5090, 1.78x the 5090’s hash at 1.15x the tuned 5090’s hash per watt and a third of the hash per rented dollar (measured, 7 October 2026), so datacentre silicon does not change the chip question. The CPU verifier takes 2.33 ms per warp of 32 hashes on one M5 Max core under class v4 (measured, 6 October 2026), against a gate of 10 ms.

+

We price the strongest chip we can design against an RTX 5090 and publish the arithmetic. Class v4 is live from the first block on the testnet and the mainnet (the ladder’s rung 0 at genesis), so the launch number is the class v4 row. The honest card: an RTX 5090 mines class v3 at 136 MH/s on 350 W in the bench and 290 W in the app (measured, 6 October 2026); under class v4 the same card reads 136.84 MH/s at 475.5 W unlocked and 134.98 MH/s at 316.3 W at a 1,400 MHz core lock, and 133.80 MH/s at 305.1 W at 1,200 MHz, against a class v3 control of 134.68 MH/s at 228.0 W (measured, 7 October 2026); an Apple M5 Max at 27 MH/s on 21 W (measured, 6 October 2026); an H100 SXM at 249 MH/s, 98 percent of its random-read ceiling like the 5090, 1.78x the 5090’s hash at 1.15x the tuned 5090’s hash per watt and a third of the hash per rented dollar (measured, 7 October 2026), so datacentre silicon does not change the chip question. The CPU verifier takes 2.33 ms per warp of 32 hashes on one M5 Max core under class v4 (measured, 6 October 2026), against a gate of 10 ms.

- + - +
The chip and the classEdge over an RTX 5090 per jouleLabel and date
At launch: a memory-controller chip that stores the whole dataset, under class v4 (about 100,000 integer ops per hash in the latency shadow, so the chip carries a GPU-class datapath beside its memory)2.1x with a core as costly per op as the GPU’s (k = 1); 3.9x with the core Bitmain claimed for its Antminer X9 (k about 0.33), a product withdrawn before any unit shippedmodelled on measured card watts, 6 October 2026; the X9 figure claimed, never measured
At launch: a memory-controller chip that stores the whole dataset, under class v4 (about 100,000 integer ops per hash in the latency shadow, so the chip carries a GPU-class datapath beside its memory)2.1x with a core as costly per op as a GPU lane (k = 1); 3.4x with a core three times better per op (k about 0.33); no core below about 1.8 pJ per op is in the model’s range, and the withdrawn Antminer X9’s claimed figure is a ratio against a CPU core, not a GPU lane, so it is not a chip core against usmodelled on the 5090’s measured watts at its knee, 7 October 2026 (the shadow’s premium 81.8 W at the best points: class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W; a user gets there through Ember Tune’s core-clock knob, 0.3.24)
The same chip at the ladder’s second rung (about 200,000 ops per hash), reached by miner signalabout 2.8xmodelled, 7 October 2026
Any chip under class v5, where the dataset is the chain’s own statea stateless or stale chip is wrong on every item, so the stored-dataset chip and the recompute chip are removed as categories; the verifier pays 0.2 ms more per warpdesigned, 7 October 2026
A chip caching the hottest 0.1 percent of items (about 1 MB of SRAM)bounded at 1.067x at the ceiling, 1.005x on about half the hours and 1.048x on 5 percentmeasured census of 1,024 programs, 7 October 2026; the source rule in the next class
A per-day FPGA that recomputes the dataset with cheap multipliers on a weak dayat most 12 percent more hash rate on 12 days a century, nothing on the other days and nothing for any chipmeasured census of 2^24 days, 7 October 2026; the rule in the next class
A per-day FPGA that recomputes the dataset with cheap multipliers on a weak dayat most 12 percent more multiplier area on an FPGA’s per-day build on 15 days a century, nothing on the other days and nothing for any chipmeasured census of 2^24 days, 7 October 2026; the rule in the next class
When a stored-dataset chip pays for itselfat about USD 100 M of market cap in the first two years, not beforemodelled, 7 October 2026
The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class)5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x)modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state
-

What a miner sees from this. Class v4 costs a 5090 88 W more at a 1,400 MHz core lock and 145 W more unlocked, for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). Devnet 3 runs class v4 from its first block (7 October 2026); the first devnet started on class v3 and reaches class v4 by miner signal at a published height. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.

-

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: the numbers; the claim is tested by the in-house adversarial pass and the public benchmark. Monero has run on RandomX since 2019 (approximate) with no chip shipped. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. A box with about a 2x per joule edge over the best CPUs, and about 3x over a desktop, was withdrawn rather than face a RandomX re-tune of 1.5x or more. That is the band Igneum’s class v4 model sits in (2.1x to 3.9x over an RTX 5090), and the defence that held was a maintained algorithm with a credible upgrade path, which is what the ladder is.

+

What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). Devnet 3 runs class v4 from its first block (7 October 2026); the first devnet started on class v3 and reaches class v4 by miner signal at a published height. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.

+

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: the numbers; the claim is tested by the in-house adversarial pass and the public benchmark. Monero has run on RandomX since 2019 (approximate) with no chip shipped. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. A box with about a 2x per joule edge over the best CPUs, and about 3x over a desktop, was withdrawn rather than face a RandomX re-tune of 1.5x or more. That is the band Igneum’s class v4 model sits in (2.1x to 3.4x over an RTX 5090), and the defence that held was a maintained algorithm with a credible upgrade path, which is what the ladder is.

One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.

@@ -806,7 +806,7 @@ body.all .pager{display:none}

Here are the limits, stated before anyone else states them.

  • A proof in seconds. Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.
  • -
  • A chip is impossible. No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as the GPU’s (k = 1, modelled on measured card watts, 6 October 2026) to the core Bitmain claimed for its withdrawn Antminer X9 (k about 0.33, never measured); the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.9x at the X9’s claimed core, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • +
  • A chip is impossible. No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane and 3.4x with one three times better, under class v4 from the first block: a memory-controller chip that stores the whole dataset and carries a GPU-class datapath beside its memory for the 100,000 ops per hash in the shadow, the range running from a chip core as costly per operation as a GPU lane (k = 1, modelled on the 5090’s measured watts at its knee, 7 October 2026) to a core three times better per operation (k about 0.33); the withdrawn Antminer X9’s claimed figure is a ratio against a CPU core, not a GPU lane, so it does not stand for a chip core against us; the ladder’s second rung takes that bracket to about 2.8x (modelled, 7 October 2026). Class v5 then makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The baseline the work started from, never the launch state: without class v4 the same stored-dataset chip would reach 1.2x per chip and 5x to 9x per joule in our model (6 October 2026); the Ethash chips of this class reached 2.1x to 4.8x (Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the chip model analysis (6 October 2026); the ASIC history’s Ethash rows; Counter ASIC 3.0 item 8 (the chip’s per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at k = 1 and to 3.4x at a core three times better, the 5090 at 0.2% less rate; gates G1 to G6 passed, 6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held for about seven years; the one chip announced against it, Bitmain’s Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core (k about 0.33) never measured. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • A guaranteed income floor. No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.
  • A memory-hard prototype on every vendor. Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.
  • Finality in the first month. No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.
  • diff --git a/site/miner.html b/site/miner.html index 6c987c9d2..d67a178a6 100644 --- a/site/miner.html +++ b/site/miner.html @@ -306,7 +306,7 @@ pre b{color:var(--molten-text);font-weight:500}

    Graphics cards only. A new mining program every hour, so no chip is built for it. 80% of every block to the card that finds it, 20% to the cards that prove it. No premine, no stake, no fee to any team. Every number above has a row in the bench table.

    -

    Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 350 W (measured 6 October 2026); at launch the chip reaches 2.1x to 3.9x per joule under class v4 (modelled on measured watts), and under class v5 it is wrong on every item because the dataset is the chain’s own state (designed). Without class v4 it would be 5x to 9x. The model and the measurements are public.

    +

    Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 350 W (measured 6 October 2026); at launch the chip reaches 2.1x per joule under class v4 with a core as good as a GPU lane, 3.4x with one three times better (modelled on measured watts at the 5090's knee: the shadow costs that card 82 W at its best point, and Ember Tune lands the lock by itself), and under class v5 it is wrong on every item because the dataset is the chain’s own state (designed). Without class v4 it would be 5x to 9x. The model and the measurements are public.

    diff --git a/site/scrub.mjs b/site/scrub.mjs index 9faab0bde..73cf152df 100644 --- a/site/scrub.mjs +++ b/site/scrub.mjs @@ -3,6 +3,7 @@ // so the build runs the same on this Mac, on Vercel and on the CI runner. The build fails if any pattern in // site/forbidden-strings.txt survives, so a private name, host or address can never reach the page. import { readFileSync } from 'node:fs'; +import { homedir } from 'node:os'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:url'; const here = dirname(fileURLToPath(import.meta.url)); @@ -59,13 +60,21 @@ const RULES = [ [/\(local time, UTC\+1\)/g, '(UTC)'], [/\bB[S]T\b/g, 'UTC'], ]; +// the private founder list (~/.config/igneum/founder-strings or $IGNEUM_FOUNDER_STRINGS; perl regex, a tab, a sample per row; # comments); +// absent here: no founder patterns from this reader (the Mac's pre-push hook carries the file and is the guard) +function founderPatternsFromFile() { + try { + const f = process.env.IGNEUM_FOUNDER_STRINGS || join(homedir(), '.config', 'igneum', 'founder-strings'); + return readFileSync(f, 'utf8').split('\n').map((l) => l.trim()).filter((l) => l && !l.startsWith('#')).map((l) => new RegExp(l.split('\t')[0], 'i')); + } catch { return []; } +} export function scrubBench(text) { let out = text; for (const [re, rep] of RULES) out = out.replace(re, rep); const pats = readFileSync(join(here, 'forbidden-strings.txt'), 'utf8').split('\n').map(l => l.trim()).filter(l => l && !l.startsWith('#')) - .map(l => (l.startsWith('b64:') ? new RegExp(Buffer.from(l.slice(4), 'base64').toString('utf8'), 'i') : new RegExp(l))); // a b64: line is an encoded, case-insensitive pattern + .map(l => new RegExp(l)).concat(founderPatternsFromFile()); // plus the private founder list where it exists const hits = []; - out.split('\n').forEach((line, i) => { for (const p of pats) if (p.test(line)) { hits.push(`${i + 1}: ${p.source.startsWith('(? { for (const p of pats) if (p.test(line)) { hits.push(`${i + 1}: ${p.flags.includes('i') ? '(a founder pattern from the private list)' : p.source}`); break; } }); if (hits.length) throw new Error(`scrub: forbidden strings remain on the bench page:\n${hits.slice(0, 20).join('\n')}`); return out; } diff --git a/tools/ci/README.md b/tools/ci/README.md index 28971dade..82495fbc4 100644 --- a/tools/ci/README.md +++ b/tools/ci/README.md @@ -4,6 +4,11 @@ |---|---|---| | no text overlaps (`overlap-check.mjs`) | A served page, or a miner or wallet screen (behind `IGNEUM_OVERLAP_APPS=1`), where a visible run of text is covered by another element (a pill over a caption, a label over a value, a card over its neighbour, text under the header at rest), clipped by an overflow-hidden ancestor, or past the viewport; a page that scrolls sideways. Five widths, light and dark, the home hero at rest and at each step. A fixture with one deliberate overlap of each kind must be flagged first (`--self-test`). Needs a headless Chromium: CI installs Playwright; the Mac ships the pages to build-2 (`infra/build-server/overlap-browser.sh`). | 7 October 2026: the hero's step pill sat on the caption's second line ("Two thirds of the weight sign. The checkpoint locks.") at every desktop width, found by the founder on the live site | +| master takes only CI-passed commits (`ci-state.mjs`, `merge-to-master.sh`, the hook's `master_ci_ok`) | A push to master whose commit, or whose merge's branch parent, has no green `ci` run on that exact sha (the runs API through gh: red, queued, none or gh unreachable all refuse); a merge onto a master whose last compiled run is red, unless declared the fix (`--fixes-master`). The merge tool pushes an unrun branch for a run and waits for a queued one with the clock. A feature-branch push prints the branch's previous red first (`--branch-red`). | 7 October 2026: era-vdf's tip 0e2d6b1c merged with no ci run; master's igneum-pow suite red from 16:31 UK under five docs-only green merges | +| every workflow job carries timeout-minutes (`workflow-timeouts-check.sh`) | A job in .github/workflows without `timeout-minutes`, or a budget off its measured line (site 15, changes 10, pow 60, sims 45). | 7 October 2026: three hosted site jobs on master hung over two hours each in the tree gate; the six-hour default was the only stop | +| a box or network check gets one retry (`retry-once.sh`) | Nothing by itself: wraps the box-locks check, the scene parity check and the live public API check so a first failure is printed and retried once; the second is the verdict. The checks keep their own skip line on a runner without the resource. | 7 October 2026 | +| the red watcher fires on cancelled and timed-out runs too (`ci-red.yml`, `red-watch.mjs`) | The watcher's `if` missing any of failure, cancelled, timed_out, or the conclusion not handed to the record step (the self-test reads the workflow file); the line names the kind: CI red, CI cancelled, CI timed out. | 7 October 2026 | + | kill by exact command or pid file (owed as a check) | 6 October 2026, 21:09Z: a Mac-side `pkill -f ` matched nothing (the log name was a redirect, not part of the command line), the roll-everything script lived on and wiped a box it had been told to hold. Rule: a job is stopped by its pid file (`tools/fleet/fleet-bg.sh start|stop `) or by a pattern anchored on its exact command line (`^python3 -u /root/fleet/in/box-prover.py`), never by a word that may or may not appear in it. The check that flags a `pkill -f`/`pgrep -f` whose literal is a path or a name that never starts a command line is owed to the CI lane | ## No inline deletion in a shell string (7 October 2026) diff --git a/tools/ci/founder-strings-check.sh b/tools/ci/founder-strings-check.sh index 1b507bb72..ecdce35b1 100755 --- a/tools/ci/founder-strings-check.sh +++ b/tools/ci/founder-strings-check.sh @@ -1,37 +1,49 @@ #!/usr/bin/env bash -# No founder name, personal login, earlier business or personal address in any tracked text file (the pre-public scrub, -# 7 October 2026, main's item (4): forbidden strings over tracked files on every merge, known-failed first). The identity -# check (tools/ci/identity-check.sh) reads the public EXPORT list; this one reads EVERY tracked file, because the repository -# itself goes public at the testnet (docs/fud-fixes.md section 5). +# No founder name, personal login, earlier business or personal address in any tracked text file, in plain text OR in an encoding +# (the pre-public scrub, 7 October 2026; a never-push class since 20:5x UK: every push, every branch). The identity check +# (tools/ci/identity-check.sh) reads the public EXPORT list; this one reads EVERY tracked file, because the repository itself +# is public (git.igneum.network). # -# The patterns are not written in this tree in plain text: a plaintext list would be the hit it looks for. They live -# base64-encoded in tools/ci/founder-strings.b64 (one decoded line per pattern: perl regex, a tab, a sample the self-test plants; -# case-insensitive; # comments ignored) -# and are decoded into a private temporary file at run time. The login's pre-rename spelling is in the list too (main's ruling, -# 7 October 2026: the public tree names igneum-labs only); the fresh-repository step rewrites it in the history (tools/repo/fresh-repo.sh). +# The patterns are NOT in the repository in any form. They live in a private file, ~/.config/igneum/founder-strings +# ($IGNEUM_FOUNDER_STRINGS overrides; one row per pattern: perl regex, a tab, a sample the self-test plants; # comments), on the +# Mac that pushes. A base64 copy in the tree (tools/ci/founder-strings.b64, 19:5x to 21:3x UK) was a disclosure to any reader of +# the public host and is gone from every commit. Where the file is absent (a hosted CI runner, a box) the check prints a skip +# line and passes; the Mac's pre-push hook, which has the file, is the guard. # -# tools/ci/founder-strings-check.sh # exit 1 with file:line for every hit over the tracked text files -# tools/ci/founder-strings-check.sh --self-test # a fixture tree with one hit per pattern class fails and names the file; a clean -# # fixture passes; the encoded list decodes to at least five patterns +# Two passes over every tracked text file: the plain text, then every encoded blob decoded and scanned (base64 literals of 24 +# characters or more, every *.b64 file whole, hex literals of 24 characters or more), so an encoding never hides a term again. +# +# tools/ci/founder-strings-check.sh # exit 1 with file:line for every hit (decoded hits say so); exit 0 with a skip line without the list +# tools/ci/founder-strings-check.sh --self-test # with a FIXTURE list of made-up names (never the real file): a clean tree passes; each +# # sample planted in plain text, in a .b64 file, as a base64 literal and as a hex literal is +# # caught and names its file; a tree without the list skips with the line set -euo pipefail HERE="$(cd "$(dirname "$0")" && pwd)" -LIST="$HERE/founder-strings.b64" +LIST="${IGNEUM_FOUNDER_STRINGS:-$HOME/.config/igneum/founder-strings}" REPO="${FOUNDER_CHECK_REPO:-$(cd "$HERE/../.." && pwd)}" -decode() { # [samples]: the regexes (or, with "samples", the sample per regex), one per line, into a 0600 file whose name is printed - local f col=1; [ "${1:-}" = samples ] && col=2 - f="$(mktemp)"; chmod 600 "$f" - base64 -d < "$LIST" | grep -vE '^\s*(#|$)' | cut -f"$col" > "$f" - echo "$f" -} -scan() { # : every tracked text file against the decoded list; prints file:line:text, exit 1 on any hit (perl: the Mac's grep has no -P) - local repo="$1" pats hits - pats="$(decode)" - hits="$(cd "$repo" && git ls-files -z -- . ':!*.png' ':!*.jpg' ':!*.jpeg' ':!*.gif' ':!*.ico' ':!*.woff' ':!*.woff2' ':!*.ttf' ':!*.pdf' ':!*.zip' ':!*.bin' ':!*.b64' \ +rows() { grep -vE '^\s*(#|$)' "$LIST"; } # the live rows +scan() { # : plain pass, then the decoded pass; prints "file:line:text" or "file:line:(decoded ) text"; exit 1 on any hit + local repo="$1" list="$2" pats hits + pats="$(mktemp)"; chmod 600 "$pats"; grep -vE '^\s*(#|$)' "$list" | cut -f1 > "$pats" + hits="$(cd "$repo" && git ls-files -z -- . ':!*.png' ':!*.jpg' ':!*.jpeg' ':!*.gif' ':!*.ico' ':!*.woff' ':!*.woff2' ':!*.ttf' ':!*.pdf' ':!*.zip' ':!*.bin' \ | xargs -0 perl -e ' + use MIME::Base64 qw(decode_base64); my $pf = shift @ARGV; open(my $ph, "<", $pf) or die; my @pats = map { chomp; qr/$_/i } grep { /\S/ } <$ph>; close $ph; - for my $f (@ARGV) { next unless -f $f && -T $f; open(my $h, "<", $f) or next; my $n = 0; - while (my $l = <$h>) { $n++; for my $p (@pats) { if ($l =~ $p) { chomp $l; print "$f:$n:" . substr($l, 0, 160) . "\n"; last } } } close $h; } + sub hit { my ($t) = @_; for my $p (@pats) { return 1 if $t =~ $p } 0 } + for my $f (@ARGV) { + next unless -f $f && -T $f; open(my $h, "<", $f) or next; my $n = 0; my $whole = ""; + while (my $l = <$h>) { + $n++; $whole .= $l; + if (hit($l)) { chomp $l; print "$f:$n:" . substr($l, 0, 160) . "\n"; next } + # the encoded pass on this line: base64 literals and hex literals of 24 characters or more + while ($l =~ /([A-Za-z0-9+\/]{24,}={0,2})/g) { my $d = decode_base64($1); next unless length $d; if (hit($d)) { print "$f:$n:(decoded base64) " . substr($d =~ s/[^\x20-\x7e]/./gr, 0, 120) . "\n"; last } } + while ($l =~ /\b([0-9a-fA-F]{24,})\b/g) { my $x = $1; next if length($x) % 2; my $d = pack("H*", $x); if (hit($d)) { print "$f:$n:(decoded hex) " . substr($d =~ s/[^\x20-\x7e]/./gr, 0, 120) . "\n"; last } } + } + close $h; + # a .b64 file as one blob + if ($f =~ /\.b64$/) { (my $b = $whole) =~ s/\s+//g; my $d = decode_base64($b); if (length $d && hit($d)) { print "$f:1:(decoded .b64 file) " . substr($d =~ s/[^\x20-\x7e]/./gr, 0, 120) . "\n" } } + } ' "$pats" 2>/dev/null || true)" rm -f "$pats" if [ -n "$hits" ]; then printf '%s\n' "$hits" | sed 's/^/founder-strings: /' >&2; return 1; fi @@ -39,28 +51,34 @@ scan() { # : every tracked text file against the decoded list; prints fi } if [ "${1:-}" = "--self-test" ]; then - n="$(base64 -d < "$LIST" | grep -vcE '^\s*(#|$)')" - [ "$n" -ge 5 ] || { echo "self-test failed: the encoded list decodes to $n pattern(s), expected at least 5"; exit 1; } - fx="$(mktemp -d)"; trap 'rm -rf "$fx"' EXIT - ( cd "$fx" && git init -q -b master . ) - mkdir -p "$fx/docs" - # a clean tree: the standing login, the project, a neutral owner word + top="$(mktemp -d)"; trap 'rm -rf "$top"' EXIT; fx="$top/repo"; mkdir -p "$fx" + fixture="$top/list"; printf '# fixture\n\\bfoundername\\b\tfoundername\n\\bsurnamex\\b\tSurnamex\n\\bbiznamez\\b\tbiznamez\n' > "$fixture" + ( cd "$fx" && git init -q -b master . ); mkdir -p "$fx/docs" "$fx/tools/ci" "$fx/site" printf 'Commit as igneum-labs. The founder decided on 5 October 2026. Igneum Labs LTD, DIFC.\n' > "$fx/docs/clean.md" + printf 'aGVsbG8gd29ybGQsIG5vdGhpbmcgaGVyZQ==\n' > "$fx/tools/ci/clean.b64" # "hello world, nothing here" ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m c ) - FOUNDER_CHECK_REPO="$fx" bash "$0" >/dev/null 2>&1 || { echo "self-test failed: a clean tree was reported"; exit 1; } - # one hit per pattern class, each from the encoded list's own sample column, so this script never spells them; every hit - # must name its file - samples="$(decode samples)"; i=0; fails=0 - while IFS= read -r word; do - i=$((i + 1)); [ -n "$word" ] || continue - printf 'a line that names %s in passing\n' "$word" > "$fx/docs/hit-$i.md" - ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "h$i" ) - if out="$(FOUNDER_CHECK_REPO="$fx" bash "$0" 2>&1)"; then echo "self-test failed: pattern $i was not caught"; fails=1 - else case "$out" in *"docs/hit-$i.md"*) ;; *) echo "self-test failed: the hit for pattern $i did not name its file: $out"; fails=1 ;; esac; fi - rm -f "$fx/docs/hit-$i.md"; ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "r$i" ) - done < "$samples"; rm -f "$samples" - # a binary file carrying a pattern is not read (images are not text) - [ "$fails" = 0 ] && echo "self-test passed: a clean tree passes; every pattern class in the encoded list is caught in a fixture file and named; the list decodes to $n patterns" + fails=0 + scan "$fx" "$fixture" >/dev/null 2>&1 || { echo "self-test failed: a clean tree (with a harmless .b64) was reported"; fails=1; } + i=0 + while IFS=$'\t' read -r re sample; do + i=$((i + 1)); [ -n "$sample" ] || continue + for kind in plain b64file base64 hex; do + case "$kind" in + plain) f="docs/hit-$i.md"; printf 'a line that names %s in passing\n' "$sample" > "$fx/$f" ;; + b64file) f="tools/ci/hit-$i.b64"; printf 'a line that names %s in passing\n' "$sample" | base64 > "$fx/$f" ;; + base64) f="site/hit-$i.mjs"; printf 'const X = "%s";\n' "$(printf 'a line that names %s in passing' "$sample" | base64 | tr -d '\n')" > "$fx/$f" ;; + hex) f="site/hit-$i-hex.mjs"; printf 'const H = "%s";\n' "$(printf 'a line that names %s in passing' "$sample" | xxd -p | tr -d '\n')" > "$fx/$f" ;; + esac + ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "h" ) + if out="$(scan "$fx" "$fixture" 2>&1)"; then echo "self-test failed: pattern $i was not caught as $kind"; fails=1 + else case "$out" in *"$f"*) ;; *) echo "self-test failed: the $kind hit for pattern $i did not name $f: $out"; fails=1 ;; esac; fi + rm -f "$fx/$f"; ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "r" ) + done + done < <(grep -vE '^\s*(#|$)' "$fixture") + # without a list: the skip line, exit 0 + out="$(IGNEUM_FOUNDER_STRINGS="$fx/no-such-list" FOUNDER_CHECK_REPO="$fx" bash "$0" 2>&1)" && case "$out" in *"skipped, no private list"*) ;; *) echo "self-test failed: no skip line without the list: $out"; fails=1 ;; esac || { echo "self-test failed: a tree without the list did not pass with a skip line"; fails=1; } + [ "$fails" = 0 ] && echo "self-test passed: a clean tree passes; every fixture pattern is caught in plain text, in a .b64 file, as a base64 literal and as a hex literal, each naming its file; without the private list the check skips with its line" exit $fails fi -scan "$REPO" && echo "founder-strings: no founder name, personal login, earlier business or personal address in any tracked text file" +if [ ! -s "$LIST" ]; then echo "founder-strings: skipped, no private list at $LIST (the Mac's pre-push hook carries the list and is the guard; a runner or box has none)"; exit 0; fi +scan "$REPO" "$LIST" && echo "founder-strings: no founder name, personal login, earlier business or personal address in any tracked text file, plain or encoded ($(rows | wc -l | tr -d ' ') patterns from the private list)" diff --git a/tools/ci/launch-gates-check.mjs b/tools/ci/launch-gates-check.mjs index 19106610e..3f99dcf2b 100644 --- a/tools/ci/launch-gates-check.mjs +++ b/tools/ci/launch-gates-check.mjs @@ -12,7 +12,8 @@ // node tools/ci/launch-gates-check.mjs --self-test # a gate row without a check fails; a handoff with the founder's name fails import { existsSync, readFileSync, mkdtempSync, writeFileSync, mkdirSync, rmSync } from 'node:fs'; import { tmpdir } from 'node:os'; -import path from 'node:path'; +import path, { join } from 'node:path'; +import { homedir } from 'node:os'; import { fileURLToPath } from 'node:url'; const HERE = path.dirname(fileURLToPath(import.meta.url)); @@ -21,11 +22,18 @@ const GO = 'docs/plans/testnet-go.md'; const PACK = 'docs/plans/launch-pack.md'; const INCOME = 'docs/analysis/income-tiers.md'; +// the private founder list (~/.config/igneum/founder-strings or $IGNEUM_FOUNDER_STRINGS; perl regex, a tab, a sample per row; # comments); +// absent here: no founder patterns from this reader (the Mac's pre-push hook carries the file and is the guard) +function founderPatternsFromFile() { + try { + const f = process.env.IGNEUM_FOUNDER_STRINGS || join(homedir(), '.config', 'igneum', 'founder-strings'); + return readFileSync(f, 'utf8').split('\n').map((l) => l.trim()).filter((l) => l && !l.startsWith('#')).map((l) => new RegExp(l.split('\t')[0], 'i')); + } catch { return []; } +} function patterns(root) { const read = f => { try { return readFileSync(path.join(root, f), 'utf8'); } catch { return ''; } }; const lines = [...read('site/forbidden-strings.txt').split('\n'), ...read('tools/ci/forbidden-strings.txt').split('\n')]; - return lines.map(l => l.trim()).filter(l => l && !l.startsWith('#')) - .map(l => (l.startsWith('b64:') ? new RegExp(Buffer.from(l.slice(4), 'base64').toString('utf8'), 'i') : new RegExp(l))); // b64: = an encoded founder pattern + return lines.map(l => l.trim()).filter(l => l && !l.startsWith('#')).map(l => new RegExp(l)).concat(root === process.cwd() || root === ROOT ? founderPatternsFromFile() : []); // plus the private founder list for the real tree } export function gateRows(text) { @@ -100,7 +108,7 @@ function selfTest() { const fx = mkdtempSync(path.join(tmpdir(), 'launch-gates-')); try { for (const d of ['docs/plans', 'docs/analysis', 'site', 'tools/ci', 'tools/launch']) mkdirSync(path.join(fx, d), { recursive: true }); - writeFileSync(path.join(fx, 'site/forbidden-strings.txt'), 'b64:XGJmb3VuZGVybmFtZVxi\n'); // an encoded, case-insensitive pattern for a made-up name + writeFileSync(path.join(fx, 'site/forbidden-strings.txt'), '(?i)\\bfoundername\\b\n'.replace('(?i)', '')); // a made-up name as a plain pattern (the private list is not read for a fixture root) writeFileSync(path.join(fx, 'tools/ci/forbidden-strings.txt'), '/Users/\n'); writeFileSync(path.join(fx, 'tools/launch/x.mjs'), ''); const sentences = Array.from({ length: 8 }, (_, i) => `${i + 1}. sentence (8.3 sentence ${i + 1})`).join('\n'); @@ -117,8 +125,8 @@ function selfTest() { r = run(fx); if (!r.problems.some(p => /does not exist/.test(p))) throw new Error('self-test: a check naming a missing script passed'); writeFileSync(path.join(fx, GO), good); // the founder's name in the handoff, an em dash, a missing sentence - writeFileSync(path.join(fx, PACK), goodPack.replace('1. sentence', '1. Foundername says')); - r = run(fx); if (!r.problems.some(p => /forbidden pattern .*foundername/i.test(p))) throw new Error('self-test: the founder\'s name in the handoff passed (the encoded pattern did not match case-insensitively)'); + writeFileSync(path.join(fx, PACK), goodPack.replace('1. sentence', '1. foundername says')); + r = run(fx); if (!r.problems.some(p => /forbidden pattern .*foundername/i.test(p))) throw new Error('self-test: the founder\'s name in the handoff passed'); writeFileSync(path.join(fx, PACK), goodPack.replace('2. sentence', '2. a \u2014 dash')); r = run(fx); if (!r.problems.some(p => /em dash/.test(p))) throw new Error('self-test: an em dash in the handoff passed'); writeFileSync(path.join(fx, PACK), goodPack.replace('(8.3 sentence 5)', '')); diff --git a/tools/ci/ledger-text-check.mjs b/tools/ci/ledger-text-check.mjs index 9393f02f8..59094533e 100644 --- a/tools/ci/ledger-text-check.mjs +++ b/tools/ci/ledger-text-check.mjs @@ -15,7 +15,7 @@ const REQUIRED = { ['X7', 'hello@igneum.network'], ['X31', 'The public testnet is armed: three seed nodes and the public RPC are up, and it opens on the go word.'], // 7 Oct 2026, 18:3x: the launch-first chip line of docs/plans/counter-asic-3-public-text-2026-10-07.md section 1 - ['X35', 'At launch the strongest chip in our public model reaches 2.1x to 3.9x per joule against an RTX 5090, under class v4 from the first block'], + ['X35', 'At launch the strongest chip in our public model reaches 2.1x per joule against an RTX 5090 with a core as good as a GPU lane, 3.4x with one three times better, under class v4 from the first block'], ], 'litepaper.html': [ ['X3', 'Live rows arrive with the public testnet.'], @@ -26,8 +26,8 @@ const REQUIRED = { ['X34', 'was withdrawn in mid-May 2026 before any unit shipped; RandomX 2.0 shipped on 25 March 2026'], ['X36', 'Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked.'], ['X35', 'so the launch number is the class v4 row'], - ['X35', '3.9x with the core Bitmain claimed for its Antminer X9 (k about 0.33), a product withdrawn before any unit shipped'], - ['X36', 'the X9 figure claimed, never measured'], + ['X35', '3.4x with a core three times better per op (k about 0.33); no core below about 1.8 pJ per op is in the model’s range'], + ['X36', 'the withdrawn Antminer X9’s claimed figure is a ratio against a CPU core, not a GPU lane, so it is not a chip core against us'], ['M34', 'The work that waits can grow.'], ['M2', 'computing items on the fly runs 4.8x slower than loading them'], ['M4', 'ProgPoW, as KAWPOW on Ravencoin since 2020'], diff --git a/tools/community/discord-hooks.mjs b/tools/community/discord-hooks.mjs index 678e339ad..936a22924 100755 --- a/tools/community/discord-hooks.mjs +++ b/tools/community/discord-hooks.mjs @@ -49,12 +49,18 @@ const STATE_FILE_LIVE = process.env.IGNEUM_DISCORD_STATE || path.join(os.homedir // ---------- guards ---------- // Forbidden in any post: the founder's name and logins, rented-box and build hosts, machine ids, internal paths, IP addresses, // a standalone 32-hex token (a sha256 is 64 hex and passes), any dl.igneum.network path outside /public/, any mention. -// The founder's name, logins and the earlier businesses come from tools/ci/founder-strings.b64 (base64, so no tracked file -// spells them; the first three decoded patterns are the founder, the rest the earlier businesses). fs is read once at load. -const FOUNDER_LIST = path.join(HERE, '..', 'ci', 'founder-strings.b64'); -export function founderPatterns(file = FOUNDER_LIST) { - const rows = Buffer.from(fs.readFileSync(file, 'utf8'), 'base64').toString('utf8').split('\n').filter((l) => l.trim() && !l.startsWith('#')).map((l) => l.split('\t')); - return rows.map(([re, sample], i) => ({ re: new RegExp(re, 'i'), sample, why: i < 3 ? "the founder's name or login" : i < 8 ? 'an earlier business' : "the founder's address" })); +// The founder's name, logins and the earlier businesses come from the PRIVATE list (never a tracked file in any encoding: a base64 +// copy in the tree was a disclosure on the public host, 7 October 2026, 21:3x UK): $IGNEUM_FOUNDER_STRINGS, else +// ~/.config/igneum/founder-strings (the Mac), else /srv/discord-hooks/founder-strings (build-1, beside the webhook env). One row per +// pattern: perl regex, a tab, a sample. Absent everywhere: no founder rows (the host that posts carries the file). +export function founderListPath(env = process.env) { + for (const f of [env.IGNEUM_FOUNDER_STRINGS, path.join(os.homedir(), '.config', 'igneum', 'founder-strings'), '/srv/discord-hooks/founder-strings']) if (f && fs.existsSync(f)) return f; + return ''; +} +export function founderPatterns(file = founderListPath()) { + if (!file) return []; + const rows = fs.readFileSync(file, 'utf8').split('\n').filter((l) => l.trim() && !l.startsWith('#')).map((l) => l.split('\t')); + return rows.map(([re, sample], i) => ({ re: new RegExp(re, 'i'), sample, why: i < 3 ? "the founder's name or login" : i < 8 ? 'an earlier business' : i === 8 ? "the founder's address" : 'the login before its rename' })); } export const FORBIDDEN = [ ...founderPatterns().map(({ re, why }) => ({ re, why })), diff --git a/tools/community/discord-hooks.test.mjs b/tools/community/discord-hooks.test.mjs index d82cd8a24..ac7b85acd 100644 --- a/tools/community/discord-hooks.test.mjs +++ b/tools/community/discord-hooks.test.mjs @@ -7,11 +7,14 @@ import fs from 'node:fs'; import os from 'node:os'; import path from 'node:path'; import { fileURLToPath } from 'node:url'; -import { +// the founder guard reads a private list; the test writes a FIXTURE list of made-up names and points the module at it before loading +import { mkdtempSync as _mkd, writeFileSync as _wf } from 'node:fs'; import { tmpdir as _tmp } from 'node:os'; import { join as _join } from 'node:path'; +{ const d = _mkd(_join(_tmp(), 'founder-fixture-')); _wf(_join(d, 'list'), '\\bfoundername\\b\tFoundername\n\\bsurnamex\\b\tSurnamex\n\\bloginx\\b\tloginx\n\\bbiz1\\b\tbiz1\n\\bbiz2\\b\tbiz2\n\\bbiz3\\b\tbiz3\n\\bbiz4\\b\tbiz4\n\\bbiz5\\b\tbiz5\n\\bmail@x\\.y\\b\tmail@x.y\n\\boldlogin\\b\toldlogin\n'); process.env.IGNEUM_FOUNDER_STRINGS = _join(d, 'list'); } +const { shapePulse, shapeDigest, shapeWeekly, shapeRelease, shapeIncidentOpen, shapeIncidentResolve, changedLinesFromPlan, plainLine, guardText, guardPayload, embed, embedLength, LIMITS, snapshot, devnet2Line, versionShare, watchPass, WATCH, WATCH_CONDITIONS, Poster, postWebhook, dueNow, ukStamp, londonParts, fmtHash, fmtDur, fmtDelta, fmtChangePct, renderPreview, ICON, EMBER, - shapeFeed, feedMilestones, shapeMilestone, hashOriginLine, runFeed, FEED_MILESTONES, founderPatterns } from './discord-hooks.mjs'; + shapeFeed, feedMilestones, shapeMilestone, hashOriginLine, runFeed, FEED_MILESTONES, founderPatterns } = await import('./discord-hooks.mjs'); const HERE = path.dirname(fileURLToPath(import.meta.url)); const fx = name => JSON.parse(fs.readFileSync(path.join(HERE, 'fixtures', 'discord', `${name}.json`), 'utf8')); diff --git a/tools/repo/fresh-repo.sh b/tools/repo/fresh-repo.sh index 22ad54be8..166960b33 100755 --- a/tools/repo/fresh-repo.sh +++ b/tools/repo/fresh-repo.sh @@ -27,7 +27,9 @@ set -euo pipefail export TZ=UTC HERE="$(cd "$(dirname "$0")" && pwd)" ROOT="$(cd "$HERE/../.." && pwd)" -STANDING_LOGIN="${IGNEUM_STANDING_LOGIN:-$(base64 -d < "$(cd "$(dirname "$0")/../.." && pwd)/tools/ci/founder-strings.b64" | grep -vE '^#' | sed -n '10p' | cut -f2)}" # the login's pre-rename spelling, from the encoded list (no tracked file spells it) +FOUNDER_LIST="${IGNEUM_FOUNDER_STRINGS:-$HOME/.config/igneum/founder-strings}" # the PRIVATE list (perl regex, tab, sample per row); never a tracked file in any encoding +[ -s "$FOUNDER_LIST" ] || { echo "fresh-repo: no private founder list at $FOUNDER_LIST (the Mac holds it; the rewrite needs its rows)" >&2; exit 1; } +STANDING_LOGIN="${IGNEUM_STANDING_LOGIN:-$(grep -vE '^#' "$FOUNDER_LIST" | sed -n '10p' | cut -f2)}" # row 10: the login's pre-rename spelling ORG="igneum-network" SOURCE="" WORK="" NEW_REPO="$ORG/igneum-core" NEW_LOGIN="" PUBLIC_CLAUDE="" CLEAN=0 while [ $# -gt 0 ]; do @@ -90,14 +92,14 @@ PERSONAL_EMAILS="$(printf '%s\n' "$PERSONAL_PAIRS" | awk -F'|' 'NF==2{print $2}' PERSONAL_NAMES="$(printf '%s\n' "$PERSONAL_PAIRS" | awk -F'|' 'NF==2 && $1 ~ / /{print $1}' | grep -v -E "^($STANDING_LOGIN|$TARGET_LOGIN)$" | sort -u || true)" # a name has a space; a login is not a name # the founder's first name, surname and second login from the encoded list (rows 1 to 3, sample column), so the rules never depend on # which commits a given mirror carries (7 Oct 2026: build-1's mirror holds none of the 40 personal-identity commits) -LIST_ROWS="$(base64 -d < "$ROOT/tools/ci/founder-strings.b64" | grep -vE '^#')" +LIST_ROWS="$(grep -vE '^#' "$FOUNDER_LIST")" LIST_FIRST="$(printf '%s\n' "$LIST_ROWS" | sed -n '1p' | cut -f2 | awk '{print $1}')"; LIST_LAST="$(printf '%s\n' "$LIST_ROWS" | sed -n '2p' | cut -f2)"; LIST_SECOND="$(printf '%s\n' "$LIST_ROWS" | sed -n '3p' | cut -f2)" FIRST_NAMES="$( { printf '%s\n' "$PERSONAL_NAMES" | awk 'NF>=2{print $1}'; printf '%s\n' "$LIST_FIRST"; } | grep . | sort -u)" LAST_NAMES="$( { printf '%s\n' "$PERSONAL_NAMES" | awk 'NF>=2{print $NF}'; printf '%s\n' "$LIST_LAST"; } | grep . | sort -u)" SECOND_LOGINS="$( { printf '%s\n' "$PERSONAL_EMAILS" | sed -nE 's/^[0-9]+\+([A-Za-z0-9-]+)@users\.noreply\.github\.com$/\1/p'; printf '%s\n' "$LIST_SECOND"; } | grep . | grep -v -E "^($STANDING_LOGIN|$TARGET_LOGIN)$" | sort -u || true)" # the other businesses named in the plan (brand names, not people), from the encoded list tools/ci/founder-strings.b64 (rows 4 to 8; # no tracked file spells them: the founder-strings check reads every tracked file) -OTHER_BUSINESSES="$(base64 -d < "$ROOT/tools/ci/founder-strings.b64" | grep -vE '^#' | sed -n '4,8p' | cut -f1 | sed -E 's/\\b//g' | paste -sd'|' -)" +OTHER_BUSINESSES="$(grep -vE '^#' "$FOUNDER_LIST" | sed -n '4,8p' | cut -f1 | sed -E 's/\\b//g' | paste -sd'|' -)" [ -n "$OTHER_BUSINESSES" ] || { echo "fresh-repo: the encoded founder list decoded to no business names" >&2; exit 1; } # the secrets: whichever of the four files exist, plus every dated copy the rotation left behind # (log-intake-key.old-, dl-token.old-: rotation phase 2 section 5 step 2 renames the .next files to the @@ -157,6 +159,12 @@ while IFS= read -r login; do printf '\\b%s\\b\n' "$login" >> "$IDENT" done <<< "$SECOND_LOGINS" printf 'regex:(?i)\\b(%s)\\b==>[other-business]\n' "$OTHER_BUSINESSES" >> "$REPLACE" +# the encoded forms: the base64 of every list regex (site/forbidden-strings.txt carried them as b64: lines until 21:3x UK on 7 October 2026) +while IFS= read -r re; do + [ -n "$re" ] || continue; b="$(printf '%s' "$re" | base64 | tr -d '\n')" + printf 'literal:%s==>[encoded-pattern-removed]\n' "$b" >> "$REPLACE" + printf '%s\n' "$b" | sed 's/[][\\.*^$?+(){}|/]/\\&/g' >> "$IDENT" +done < <(printf '%s\n' "$LIST_ROWS" | cut -f1) printf '\\b(%s)\\b\n' "$OTHER_BUSINESSES" >> "$IDENT" say "rules: $(grep -c . "$REPLACE") replace lines, $(grep -c . "$MAILMAP") mailmap lines, $(grep -c . "$IDENT") identity patterns, $(grep -c . "$SECRETS") secret patterns (files under $RULES, removed at exit)" @@ -169,7 +177,7 @@ scan_blobs() { | perl -ne 'BEGIN { open(P, "<", shift) or die; @p = map { chomp; qr/$_/i } grep { /\S/ }

    ; $n = 0 } for my $p (@p) { if ($_ =~ $p) { $n++; last } } END { print "$n\n" }' "$1" } scan_meta() { git log --all --format='%an%n%ae%n%cn%n%ce%n%s%n%b' | perl -ne 'BEGIN { open(P, "<", shift) or die; @p = map { chomp; qr/$_/i } grep { /\S/ }

    ; $n = 0 } for my $p (@p) { if ($_ =~ $p) { $n++; last } } END { print "$n\n" }' "$1"; } -DROPPED=(docs/review) # the ledger, its fixes file and the ledger page are published with the repository (decision of 5 October 2026, docs/fud-fixes.md section 5); the review folder stays internal +DROPPED=(docs/review tools/ci/founder-strings.b64) # the encoded founder list (19:5x to 21:3x UK, 7 October 2026) leaves every commit # the ledger, its fixes file and the ledger page are published with the repository (decision of 5 October 2026, docs/fud-fixes.md section 5); the review folder stays internal counts() { #