From 79ef854f70fbaad4edd4b0e671b14e1e31210b4f Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 12:36:29 +0000 Subject: [PATCH] Counter ASIC 3.0 status: the shipper's clock call (a second one-shot pod for the wipe canary, line about 14:15Z) Co-Authored-By: Claude Fable 5.1 --- docs/plans/counter-asic-3-status.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index 4e17222aa..9a38fbbfe 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -338,7 +338,7 @@ the project lead gave the go in advance for tonight: the shipper runs publish 1 | THE ANALYSIS (the hash lane, ca3-v4-uniform 095f84a7, `docs/analysis/ca3-v4-uniform.md`, the tool on igneum-build-1) | the window model moves the null from 0.115 to 0.160 percent (1.39x, not 4.05x); the rest is a FAULT beyond it: site 15 reads a register last written by `or r6, r4`, so all-ones recurs at (3/4)^32 per read and the era map sends it to F8's hottest item exactly (the popcount model predicts 77,348 all-ones reads against 78,479; the top-0.1-percent share 0.58 against 0.52); it passes the acceptance rule because part (a) takes any write as a fresh source and part (c) counts saturation on final values only. The census of 1,024 chain-shaped v4 programs: 96.6 percent carry a lossy-sourced load (or, mul, mulhi as the last writer), 48.5 percent an or-sourced one (0.30 percent of all reads per site), 4.9 percent an or-of-or chain (4.6 percent of all reads on 0.1 percent of items); F8's 1.2x gate fails 96.6 percent of today's programs. Worth to a chip: 1.07 MB of SRAM ($0.25) serving 0.52 percent of a typical program's reads and 4.6 percent of the worst class's, at most 1.005x and 1.048x in rate; the ceiling under rule (c)'s 120-of-128 floor one site repeating its item in all 8 iterations, 6.25 percent of reads, 1.067x in 64 bytes; the 2x margin stands; the public line says "bounded at 1.067x", not "uniform" (the public text corrected) | | The two options, priced, STOPPED at the coordinator for the project lead's word | A: a 0.3.19 class amendment before the flip (the generator draws a load's source from the registers whose last writer injects): a new program stream, new vectors, the seven gate packs re-exported, the six gates again (G1 to G3 and the verifier about an hour on the Mac and PC 2; G4 to G6 the node lane), every node before the flip under the one-box-at-a-time rule; the risk a node that misses the build splits the chain at the flip. B: hold the flip at the floor with v4 as it is; the bound documented; the source rule to class v5: a hot set worth up to 1.005x on about half the hours and 1.05x on 5 percent, 1.067x at the ceiling; no chain risk. The number: 1.067x at the ceiling against the 2x margin. The lane recommends B | | The v5 bound (sent to the v5 lane) | H = W_0.1 (the window term, 0.115 to 0.251 percent) + the sum over load sites of h(last writer) (or 0.30 percent, an or chain 4.5, mul 0.067, mulhi 0.049, an injecting op or a rotate 0), H at or under 1.2 x W_0.1, which is the static rule "every load's source was last written by an injecting op or a rotate"; as a rejection it costs 96.6 percent of candidates (about 30 attempts per seed), as a generator draw nothing; gate F8's 64-seed census with the saturated-source count | -| [user]'S WORD (15:2x UK, 7 October): OPTION A, "do this but limit the testing, get it pushed" | the class v4 amendment: a load's source drawn only from registers whose last writer injects or is a rotate (the v5 rule applied now), a new program stream and vectors, the seven gate packs re-exported, the amended class with its own generator stamp; rides 0.3.20, the feature node (release-0.3.20-node = dc141409; 0.3.19 is an app-only cut with nothing of ours), on the shipper's line. The rollout arithmetic for the flip clock (the shipper): the standing fleet's one-box-at-a-time rollout took 32 minutes for 14 boxes (04:56 to 05:28Z, 7 October), the hands and the seed about 3 minutes after the miners, the Mac and the PCs within minutes of the publish; every 0.3.20 worker must accept the amended stamp before any flip. Owners: the hash lane (ca3-v4-amend: the generator, the vectors, the packs, the pairing on the box, one G1 run on PC 2, the ledger row), the node lane (release-0.3.20-node: the stamp agreed with the hash lane, the split-protection mechanism and the earliest flip time, the digest test, the mixed-version Devnet 2 gate), the attack-pass lane (the F8 census at 2^24 on the new stream, the gate 1.2x of the window model over 64 seeds), the shipper (the cut, the rollout order that sets the earliest flip). Testing limited to what prevents a split and proves the fix; G2, G3, the ladder re-measure and the rest of G4 to G6 OWED. THE STAMP agreed (the node and hash lanes, 7 October afternoon): generator 4 with sub-version 1 inside igneum-pow's id function, so the amended v4's program id for a seed differs from the old v4's (the old devnet epoch-0 id c120d7963abdcd96 pinned as the must-differ vector in kaspa-pow's test). SPLIT PROTECTION SETTLED (the node lane, plan section 6.6, ca3-v4-node fa5bc9e6; the node side on release-0.3.20-node): a fresh object byte. CLASS_SIGNAL_V4 is 5; the amended binary stamps 5 and the tally counts a block only at byte 5 or above; object 4 was stamped only by the unpublished dc141409 canary, so no published block carries it and a byte-4 block never counts; a node of the 6 October stream that sees byte 5 counts it as v4 (its rule is at least 4), flips to its own stream at the same epoch and forks ALONE (its blocks fail the amended id check, generator 4 sub-version 1 inside every id; the amended blocks fail its own), ours to upgrade in the sweep; object 6 is class v5's; the two holds already in the rule keep the window shut until every node is on 0.3.20 (a node stamps and tallies only with both v4 fields in its file; the fields publish only after the one-sweep rollout); a lagging worker refuses the amended pack at packcheck and mines nothing after the flip, costing that box, never the chain; no extra window hold: seven full day-windows are the hold. THE EARLIEST FLIP (approximate, measured 09:40Z: DAA 270,659, 1.095 DAA/s over 25 hours, 1.165 over 4; epoch 3,600, lead 600; seven windows 604,800 DAA wholly after the sweep's end D_s = T + about 40 minutes; the flip epoch the first e with 3600 e - 600 >= D_s + 604,800): T + 6 days 10 hours to T + 6 days 11 hours UK; for a publish at 12:00 UK on 7 October, 13 October between 22:20 and 23:10 UK (about 13:00 UK if the 4-hour rate holds). The floor as it stands (831,600, about 13 October 09:00 UK) would fire before any seven-window signal from a publish today completes, so it moves by the 0.3.16 rule to the publish DAA + 604,800 rounded up to the epoch boundary (882,000 for a 12:00 UK publish), firing about 30 minutes before the earliest signal flip: either way about 6 days 10 hours after the publish, never before every node has had the sweep plus a week. THE CLOCK (the node lane, 11:3x UK, after a Mac reboot moved its runs to the box): the 0.3.20 node line (dc141409 plus the proof archive aea0ca5c plus the amended v4 at object byte 5, igneum-pow at the hash lane's a0aaca92 beside the fork on the box) tested on the box, committed on release-0.3.20-node, pushed to the mirror and origin, igneumd and igneum-miner built, the tip to the shipper: about 12:00 UK; the mixed-version Devnet 2 gate (node-compat.mjs on the box, the amended node beside the 5899f603 pair for ten minutes) and the digest test (digest-compat.mjs): about 12:45 UK; the object-byte pin 5 unless the v5 lane answers both lanes with another assignment (v5 at 6 proposed). THE HASH SIDE on ca3-v4-amend (tip 8c728ca3, read from the branch 14:0x UK; the hash lane's own report pending): 1748fd1d the PC 2 G1-only playbook; e1f48d63 the fud-ledger entry AP-F8-1 (the fault, the project lead's ruling, the amendment, the split protection, the owed tests); d8859522 the G1 line (the eight fingerprints equal on the RTX 5090, self-test PASS) and the node lane's signal byte 5; 4aa0c665 the v4 unit test following the amendment; 965d9e96 igneum-pow taken from release-0.3.20's 3f1652bf (the ladder's chain_program_shadow with the reps argument, never on master) with the amendment re-applied, the seven packs re-exporting byte-identical; 8c728ca3 the source rule keyed on the class with the shadow's pass count set aside, so every ladder rung draws under it (the fork's ladder test). The shipper took this igneum-pow tree into release-0.3.20 (00249643, byte-equal); nothing after 8c728ca3 touches igneum-pow. THE VECTORS AND THE PACKS (read from the branch and its ledger entry, 14:1x UK): the seven amended v4 packs (v4-devnet-epoch0, v4-era-0 to 5) carry generator 4, sub-version 1, one program id 1a4230699a6b9c60 (the 2.0 one-id-per-seed rule across the eras; the old c120d7963abdcd96 pinned as must-differ); the v3 control mx8-devnet-epoch0 untouched (73bcbfe8ccf988f1, fingerprint 90f794dd556f7a3b); the seven 2^24 fingerprints, Metal equal to Apple OpenCL: 867dbc45cfb36b4d, 2146ecacc8c75a8e, fe52602393f6d3d4, 3b206471a13912b4, c3f03c4a5d7333aa, f1dfd7209f15bb97, 8c194da64fadf31d; the zip of the eight packs sha256 889ec99976d2728b4b5035bfa476032e5b6a13b928968fc45236d5f25084aa39; the per-pack vectors.json sha256 prefixes 756301bf (devnet epoch 0), 1b5f4568, d430cadc, 1a1b21d8, 460fff9e, 4a85d49d, f83a1196 (eras 0 to 5). G1 on the RTX 5090 (PC 2 job run-ca3-v4-amend-g1-pc2-20261007, 09:41:07 to 09:41:28Z, exit 0, the installed worker): every fingerprint equal to the Mac's (the seven above and the control), NVRTC 188 to 332 ms per pack, the 1 GiB build 38 to 49 ms. hash-gates.md's older table still lists the pre-amendment fingerprints (f410c731... and the eras), which no longer apply to the amended packs; the ledger entry is the record. THE FIRST GREEN (11:31 UK, the box): the kaspa-pow suite on release-0.3.20-node (dc141409 plus the proof archive aea0ca5c plus the object-5 change) against the hash lane's igneum-pow 8c728ca3: 17 passed, 0 failed; the amended devnet epoch-0 id 1a4230699a6b9c60 pinned equal and c120d7963abdcd96 differing, the ladder's rung test green under the rekeyed rule, the v3 control unchanged; the consensus-core and exec RPC suites follow, then the node line (commit, push, box build, the tip to the shipper), then the digest and mixed-version gates. CLOCK RE-CUT (the node lane, 13:0x UK): the node line now carries, beside the object-5 change and the vector test, the lane's 0.3.20 fixes from the day (isSynced from the hook's stamp, the lazy template snapshot, the weight-table cache, the submit path returning after the block task, the watchdog, the RPC fields), about 13:30 UK if the box suites are green; the shipper's fresh-join canary 60 to 100 minutes after the cut; PC 1 as its first machine about 16:00 UK at the earliest, approximate until the shipper names the cut; the earliest flip about 6 days 10 hours after the publish. BUILD-2 LINES (12:28 to 12:33 UK): consensus-core 123 passed (the 60x file test green with the ladder window and activation pinned), the behind test green, kaspa-pow 17 passed (the amended vectors, earlier on build-1), the exec RPC suite green, the flows and rpc-service checks green with the submit-path change; the 24-requester latency test's first run tripped an unrelated flapping-fork double insert (24 equal forks from one parent; the test now builds on the sink as a real miner does; the double insert owed to a small fork harness before it is called a bug); THE NODE LINE COMMITTED (13:1x UK): release-0.3.20-node = 8097d600 (dc141409 + the proof archive aea0ca5c + one commit) on the mirror, pairing igneum-pow 8c728ca3, the hash with the shipper; in it the amended class v4 as object 5 (CLASS_SIGNAL_V4 = 5, byte 4 never counts, the kaspa-pow vector test pinning 1a4230699a6b9c60 equal and c120d7963abdcd96 differing, the daemon's window line naming object 5 and sub-version 1) beside the day's fixes (isSynced from the hook's stamp, the weight-table cache, the lazy snapshot, the submit path, the 100 ms template wait); the suites green on build-2 (consensus-core 123, the exec RPC suite, the four finality tests including 24 requesters under 200 ms: the worst template 100 ms, the worst submit 102 ms) and kaspa-pow 17 on build-1. Next: igneumd and igneum-miner building from 8097d600 on build-1, then the two gate lines (the mixed-version Devnet 2 gate: the 8097d600 node mining beside the 5899f603 pair for ten minutes on the live file without the v4 fields, the old node accepting every block; the digest test: the thirteen-field file b18ed271 unchanged, the sixteen-field object re-read on the 8097d600 binary), expected about 13:30 UK; the shipper picks the cut point. THE DATE FIXED (the node lane, from the hub's live file, 13:3x UK): publish 2 of 6 October (22:49:45Z, digest eada4bda) already put BOTH v4 fields on the live devnet (floor 831,600, window 86,400), so the 0.3.17 fleet has stamped object byte 4 since 7 October 00:2x UK and the floor is live at about 13 October 09:00 UK, before any seven-window signal completes; a 0.3.17 node left on that file flips to the OLD v4 stream at epoch 231 whatever anyone signals, a 0.3.20 node to the amended stream at the same epoch, and the two never share an id, so each straggler forks alone there. REQUIREMENT for the 0.3.20 publish (with the shipper and main): a new file with the floor at the publish DAA + 604,800 rounded up (about 882,000 for a publish today), the digest moving, the one-sweep rollout replacing every 0.3.17 node before 13 October 09:00 UK; any node that misses the sweep is alone then; the earliest flip after that about 6 days 10 hours past the publish; plan section 6.6 amended today. IN THE 0.3.20 PLAN (the shipper, 13:4x UK): both requirements; the node pin by main's rule is the node lane's second commit (the claim floor, the listener watchdog, the claim RPCs, on top of 8097d600) if its suites, both gates and the fleet's 12 GB prover line are green by 15:30 UK, else 8097d600; igneum-pow 8c728ca3 either way; the digest read on whichever binary pins. THE LINE AT 13:5x UK: three commits on release-0.3.20-node, 8097d600 (the object-5 amended class v4 and the day's fixes), 6b94c823 (test-only: the stale PC 1 test from 500ddd66 inverted by the isSynced ruling; the FALLBACK pin, code byte-identical to 8097d600, so the module reads green whole) and 6a3432a3 (the app lane's key methods, the observer's claims, the settled claim floor, the listener watchdog); suites on build-2 on 6a3432a3's code (the whole finality module 25, the exec suite 29 with the watchdog test, the kaspad, flows and rpc-service checks; consensus-core 123 and kaspa-pow 17 earlier); the cut 6a3432a3 if its gates and the fleet's 12 GB settled-claim line are green by 15:30 UK, else 6b94c823; both binaries building on build-1, the two gates (the digest gate, then the ten-minute mixed-version gate beside the 5899f603 pair) on the 8097d600 build, lines about 14:05 UK. GATE NEWS (13:53 UK): on 6a3432a3's own digest gate the listener watchdog counted a bind failure (the four harness nodes share one exec JSON-RPC port) as a listener death and exited three of four nodes at 20 s, where 0.3.17 and 8097d600 only warn and live without the exec RPC; the digest facts came out first and stand (the thirteen-field file a89be8a7 on both binaries, the compat case; the sixteen-field object db9a85f9 refused with the mismatch line, the refusal case); the ten-minute gate on 6a3432a3 stopped as void for the same cause. The fix: a bind failure is a retry every poll, one line a minute, no death counted and never an exit, with a second watchdog test whose known-failed shape is the old rule's exit on a held port; the third commit and its build about 14:15 UK, its gates about 14:35 UK; the fallback 6b94c823's gates on build-1 on their own binary (no watchdog there), lines about 14:20 UK; ledger row N12 for the bind-failure class. A ROLL BLOCKER on every kept datadir (the node lane, 14:1x UK, ledger N13): the fleet started 6a3432a3 on a kept 0.3.17 datadir (pool-1's copy) and it died at start (virtual_state.rs:250, DeserializationError(UnexpectedEof)); the cause 10db4b61 on the 0.3.16 feature line added `silent: bool` to BlockRewardData under serde(default), which bincode ignores, so every build from 10db4b61 on (dc141409, 8097d600, 6b94c823, 6a3432a3, 09124180) reads a 0.3.17 node's virtual-state row short; no canary saw it because every canary wiped, and a one-box roll keeps datadirs, so it blocks the roll on every standing box, the hands and the hub whatever the pin. The fix on the line: the store reads the current layout first and on a deserialization error decodes the row as a v1 mirror, converts with silent false and rewrites it under the same key, with the known-failed test first; the fourth commit and build about 14:40 UK, the fleet's kept-datadir start on the fixed binary about 14:50 UK, its gates after. THE RULE IT ADDS for every node cut from now: a kept-datadir restart gate on a standing box's datadir copy beside the wiped canary. THE CANDIDATE PIN (14:2x UK): b7cc37e7 (8097d600, 6b94c823, 6a3432a3, 09124180, b7cc37e7; igneum-pow 8c728ca3): the N13 fix with its test green on build-2 at 14:04 UK and the kaspad check green, the build on build-1; the fallback 6b94c823 is no longer a pin for the one-box roll (it dies on a kept datadir like every build since 10db4b61): if b7cc37e7's gates are not green by 15:30 UK the honest fallback is 0.3.17's 5899f603 staying live. In flight on build-1: the earlier commits' gates, then b7cc37e7's own digest and ten-minute mixed-version gates on its binary with the read-back, lines about 15:05 UK; on the fleet the kept-datadir start on b7cc37e7 about 14:50 UK and the 12 GB settled-claim line 14:50 to 15:00 UK. Plan section 6.6 amended with the hard date (ca3-v4-node 9d763edd, merged to master); N12 and N13 on the ledger. THE GATES ON THE FALLBACK'S OWN BINARY (6b94c823, sha b1b7d47b, 13:56 to 14:08 UK; code byte-identical to 8097d600, so the amendment's node side): the digest gate, the thirteen-field file a89be8a7 on both binaries (the compat case, n0 peering n1 and n2) and the sixteen-field object db9a85f9 refused with the mismatch line (the refusal case); the mixed-version gate, ten minutes, one digest b0afb2ee on all five nodes, the 5899f603 hub accepting every block the amended node mined (146 new, 246 old, 0 rejected), plain header version 2 on the thirteen-field file, counts equal on all five through the two clean joins and the restart. Two FAILED checks, both the harness's own and fixed (36d3efdc): a refused peer's count read 1 with the reconnect in flight (now the minimum of five), and six address-in-use panics in the two old nodes because the second gate reused the first's ports the second they were sent SIGTERM (a 20 s gap now). CLOCK CORRECTION (the node lane, 12:12Z = 13:12 BST): every "UK" stamp it sent today was the box's CEST, an hour fast of BST; its lines read UTC from now. Restated: b7cc37e7's build about 12:15Z, its digest and mixed-version gates on that binary with the sha and string about 12:32Z (13:32 BST), the fleet's kept-datadir start on it about 12:25Z, its 12 GB settled-claim line 12:50 to 13:00Z; the shipper's checkpoint 14:30Z (15:30 BST), two hours of room. The 13 October date stands (derived from UTC DAA rates): the floor 831,600 about 08:00Z, 09:00 BST. b7cc37e7'S OWN LINES (binary sha256 bc28331abf21f4d5, the string read back on build-1 and on the fleet's pod): the digest gate 12:14:39Z to 12:16:18Z SUMMARY PASS (thirteen fields a89be8a7 on both binaries with the peers as the gate wants them; the sixteen-field object db9a85f9 refused with the line and no peer; the live file's digest eada4bda on the binary, unmoved); the kept-datadir start on the fleet's copy of pool-1's 0.3.17 datadir: the first start 12:17:12Z reads the v1 row through the mirror and rewrites it ("1 mergeset rewards"), the finality blob converts (1,747 locks), the node comes up on its ports with no panic; the second start 12:18:53Z reads first-try with no rewrite line and no panic; 6a3432a3's death on the same copy is the known-failed shape. The ten-minute mixed-version gate beside the 5899f603 pair runs on the same binary since 12:16:39Z, its line about 12:28Z; then the only line outstanding for the shipper's 14:30Z rule is the fleet's 12 GB settled-claim line, 12:50 to 13:00Z. AP-F8-1 RESIDUAL CLASS ON THE AMENDED STREAM (attack-pass lane 12:18Z on igneum-pow 8c728ca3, sub-version 1). F9 over 1,000,000 seeds: programs flagged (hot share at least 1 percent or 7 constant address bits) 1,871 (0.19 percent) against 11,696 (1.17 percent) unamended; worst hot share 9.66 percent against 17.3; mean 0.011 against 0.063 percent; 84 percent of the flagged programs and the whole or-saturation tail gone. F8 at 30 of 64 seeds: nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, the rest 1.3x to 1.6x); the 64-seed 1.2x gate is heading to FAIL on sub-version 1. Mechanism, confirmed on the two worst seeds: an all-ones load source (image 0x0ca59e4c under the era map) delivered through a writer the source rule counts as entropy-keeping, a rotate (rotl and rotr map all-ones to itself) or a load whose own source was saturated, with the saturation made one or more writes upstream by or. The rule looks one writer back; it must look through saturation-preserving writers or test the source's values. The ceiling has not moved: rule (c)'s 120-of-128 floor still caps any program at one saturated site, 6.25 percent of reads, a chip edge of at most 1.067x, and the residual (worst seed two sites at 0.53 and 0.56) sits inside it. THE SENTENCE "no lossy-sourced load by construction" IS HELD: it goes in no plan row and no ledger entry as true; sub-version 1 removes the or-source class and bounds the rest. MAIN'S RULING (13:2x UK): 0.3.20 ships object byte 5 on sub-version 1 as it stands, strictly better than the old stream the live floor flips to on 13 October; the fix is sub-version 2 on ca3-v4-amend (object byte 6 or whatever the v5 alignment leaves free) with both fixes: (F1) the static rule made transitive (rotates do not keep entropy; a load keeps entropy only if its own source did; one draw change, no attempts lost) and (F2) the dynamic source check (saturated load SOURCE values counted per site over the 64 units' 16,384 evaluations, rejected above 163 of 16,384, the same 1 percent the final-value rule uses; costs attempts on about 0.2 percent of seeds; rides with F1 because an or-written source is all-ones only (3/4)^32 of the time). Gate before sub-version 2 is proposed, run by the attack-pass lane and not by the hash lane: the full 64-seed census under 1.2x on every seed and the hot-set census. Hash lane's estimate about an hour its side (implement, re-export seven packs, vectors, crate suite, pairing, one G1 on PC 2) plus the node lane's vector re-pin and the attack-pass re-gate. The flip floor for sub-version 1 is expected to move (the project lead's word) so the chain never flips to a stream that fails this gate. Also recorded: the crate suite at 8c728ca3 100 of 100 on the box (rc 0, 77 s); the pairing against the fork at dc141409 compiled and ran 15 of 16, the one failure the fork's own pre-amendment assertion (base equals v3's, igneum.rs:972), which 8097d600 on the release-0.3.20-node line turns into assert_ne; the pairing re-runs at b7cc37e7, its line to follow. CORRECTION (the attack-pass lane's own retraction, 13:3x UK): the F9 hot-set figures above (1,871 of 1,000,000, worst 9.66 percent, 84 percent removed, the two or-then-rotate listings) are WITHDRAWN: F9's harness draws through candidate_class with its own era class, outside candidate_from_words_class where the source rule lives, so it measured the old stream (the 8c728ca3 binary prints the identical program to the sub-version-0 binary for its worst seed). F8's 64-seed census on the chain path (pairing verified on 1a4230699a6b9c60) is the valid re-gate and STANDS: at 30 of 64 seeds, nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, p4 1.6x, p10 1.5x, p26 1.3x, p25 1.3x). The residual mechanism on the amended stream: a load-after-load chain (a saturated source reads one fixed word, which is the next load's address), admitted because a load injects; and the rotate-preserves-saturation path (generator.rs sets entropy_kept true for a rotate whatever it rotated), correct in code and a second admitted path if it occurs on the chain stream. Sub-version 2 must close both: dataflow freshness per register (a load fresh only if its source was fresh; add, sub, xor, mad, shfl fresh if either operand was; rotates only if the operand was; or, mul, mulhi never) plus the (c') count of saturated load sources per site as the backstop. The STOP holds on F8's evidence alone; the options and the 1.067x ceiling are unchanged. The sentence "no lossy-sourced load by construction" waits on the sub-version 2 census verdict and stays out of every public text until then. SUB-VERSION 2 IN BUILD (the hash lane, ca3-v4-amend, on the coordinator's direction, 13:4x UK): F1 (dataflow freshness per register, keyed on the class v4 shape on every draw path, era or not, so the candidate_class path and the chain path draw one stream) plus F2 (the (c') count of saturated load source values per site over the 64 units' 16,384 evaluations, rejected above 163, keyed on the same shape so v2 and v3 verdicts do not move); PROGRAM_SUBVERSION_V4 = 2, new ids, the seven packs re-exported, recheck.rs with 1a4230699a6b9c60 and c120d7963abdcd96 as the must-differ pair. Clock (UTC): the commit on the branch by 13:30; the crate suite on box 2 and the pairing against b7cc37e7 by about 13:50 (the pairing's vector test fails on the fork's sub-version-1 pin until the node lane re-pins; the compile and the other 15 are the pairing evidence); the G1 job on PC 2 under --cards-off by about 14:10, lock permitting; then the attack-pass lane's full 64-seed census and hot-set census on the chain path. Two consequences stated in the commit: the rule on every draw path moves the no-era sh256xN ladder packs' stream (packs-ca3-shadow's seven 256-block packs re-export with new fingerprints; the measured rates stand as the old stream's), and the class v5 lane's pinned string-seed packs move when it merges sub-version 2, so it re-exports them then. 0.3.20's sub-version-1 packs, ids and fingerprints untouched. OBJECT BYTES SETTLED (main, 13:5x UK): byte 5 = class v4 sub-version 1 (0.3.20), byte 6 = class v5 (pinned: class-v5 16afd0a0, class-v5-node 699db5a2, the flip case passed on 6,6,6; the v5 lane stopped), byte 7 = class v4 sub-version 2; the node and hash lanes told. b7cc37e7's MIXED-VERSION GATE: FAIL, the binary not the harness (12:16:39Z to 12:27:21Z, sha256 bc28331abf21f4d5, the string read back). Before the restart step everything held: one digest b0afb2ee on all five nodes, 268 new and 392 old blocks accepted, 0 rejected, header versions plain 2, counts equal on all five at 324 and 502 through both clean joins. At the new node's restart (12:24:19Z) it died at once on its own datadir ("IO error: While lock file: .../datadir/meta/LOCK: Resource temporarily unavailable", conn_builder.rs:167): the previous process was still shutting down, because the listener watchdog added on 6a3432a3 sleeps its whole 10 s poll before checking shutdown, so every node on the line since then takes up to 10 s longer to stop than 0.3.17 (the fleet saw the same shape as "a 12-second timeout does not stop the node"). Three of the four failed checks follow from that one death (counts, the restarted node's resync, the node it served frozen at 502). The fix on the line, one rule: the poll in 250 ms steps returning the moment shutdown is set, with a test that a shutdown returns within a second (the 10 s loop the known-failed shape); the exec suite on build-2, the fifth commit and its build about 12:45Z, its digest and ten-minute gates about 12:50 to 13:05Z, inside 14:30Z. b7cc37e7 is NOT the pin. The node-side re-pin for sub-version 2 (byte 7) once the hash lane's commit lands: the beside-the-fork igneum-pow copy archived from the commit, the two pinned ids moved in the kaspa-pow vector test (sub-version-2's epoch-0 id must-equal; sub-version-1's joins c120d7963abdcd96 as must-differ), CLASS_SIGNAL and tests for byte 7, the daemon's window line: about 20 minutes of edits plus one kaspa-pow suite run on build-2 (about 2 minutes). THE FIFTH COMMIT c4459193 on release-0.3.20-node (b7cc37e7's child, the watchdog poll returning on shutdown; the diff is the poll loop in rpc.rs alone), pairing igneum-pow 8c728ca3; its build on build-1 started 12:30:13Z, sha256 and string to follow. Line A, the shutdown test: rpc::watchdog_tests::a_shutdown_returns_within_a_second_whatever_the_poll green on build-2 at 12:29Z in the exec suite's 31 passed, beside the two other watchdog tests; its known-failed shape the old loop's 10 s stop. Line B, the kept-datadir start: b7cc37e7's fleet read carries to c4459193 since the store code is byte-identical between the two commits; the fleet re-reads on the c4459193 binary only if the shipper's rule wants the string on that line too. The digest gate and the ten-minute mixed-version gate on c4459193's own binary follow its build. THE SHIPPER'S CARRY RULING (14:1x UK): b7cc37e7's kept-datadir read stands as evidence that the store fix is right (the store code byte-identical) but is not the gate line for the pin, because the rule reads the binary, not the diff, and the binary changed (rpc.rs); the gate line is the kept read on c4459193's own binary with its string, which the fleet's canary already runs on c18-1 (wipe, then the kept read, then the restart) before the canary's restart step, at no extra cost; no re-read on p12-vast. THE PIN IS c4459193 pairing 8c728ca3 (object byte 5, sub-version 1); sub-version 2 (byte 7) is 0.3.21's, not 0.3.20's. The shipper's reading of main's F8 ruling: 0.3.20 ships object 5 as it stands because the live floor otherwise flips every node to the OLD stream on 13 October, and the 16:00 BST report tells the project lead the floor move is now RECOMMENDED rather than optional, so the chain never flips to a stream that fails the 1.2x gate before sub-version 2 lands. THE FLEET'S CLOCK ON c4459193 (the fleet lane, 12:5x UTC): the kept read on pool-1's 0.3.17 datadir copy and the restart (the old process's stop time on the line) run on c18-1 before the wipe, a few minutes each, so both lines land before 14:30Z; the wipe canary (IBD from the pruning-point proof, 98 minutes on this pod class) starts when c18-1 is free of the 0.3.20 cases (about 13:00Z) and the binary is in hand, so its synced line lands about 14:40Z at the earliest, PAST the 14:30Z checkpoint; the 12 GB settled-claim line: c4459193 starts on p12-vast's kept copy of pool-1's datadir beside the 6a3432a3 IBD node on alternate ports the moment the binary lands, catches up from 129,398 blocks (15 to 20 minutes) and the 12 GB prover claims against it, the line on c4459193 itself. The binary not yet in the fleet's hand (build-1 building since 12:30:13Z); a wait armed on the sha and string, a report by 13:10Z if nothing. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +| [user]'S WORD (15:2x UK, 7 October): OPTION A, "do this but limit the testing, get it pushed" | the class v4 amendment: a load's source drawn only from registers whose last writer injects or is a rotate (the v5 rule applied now), a new program stream and vectors, the seven gate packs re-exported, the amended class with its own generator stamp; rides 0.3.20, the feature node (release-0.3.20-node = dc141409; 0.3.19 is an app-only cut with nothing of ours), on the shipper's line. The rollout arithmetic for the flip clock (the shipper): the standing fleet's one-box-at-a-time rollout took 32 minutes for 14 boxes (04:56 to 05:28Z, 7 October), the hands and the seed about 3 minutes after the miners, the Mac and the PCs within minutes of the publish; every 0.3.20 worker must accept the amended stamp before any flip. Owners: the hash lane (ca3-v4-amend: the generator, the vectors, the packs, the pairing on the box, one G1 run on PC 2, the ledger row), the node lane (release-0.3.20-node: the stamp agreed with the hash lane, the split-protection mechanism and the earliest flip time, the digest test, the mixed-version Devnet 2 gate), the attack-pass lane (the F8 census at 2^24 on the new stream, the gate 1.2x of the window model over 64 seeds), the shipper (the cut, the rollout order that sets the earliest flip). Testing limited to what prevents a split and proves the fix; G2, G3, the ladder re-measure and the rest of G4 to G6 OWED. THE STAMP agreed (the node and hash lanes, 7 October afternoon): generator 4 with sub-version 1 inside igneum-pow's id function, so the amended v4's program id for a seed differs from the old v4's (the old devnet epoch-0 id c120d7963abdcd96 pinned as the must-differ vector in kaspa-pow's test). SPLIT PROTECTION SETTLED (the node lane, plan section 6.6, ca3-v4-node fa5bc9e6; the node side on release-0.3.20-node): a fresh object byte. CLASS_SIGNAL_V4 is 5; the amended binary stamps 5 and the tally counts a block only at byte 5 or above; object 4 was stamped only by the unpublished dc141409 canary, so no published block carries it and a byte-4 block never counts; a node of the 6 October stream that sees byte 5 counts it as v4 (its rule is at least 4), flips to its own stream at the same epoch and forks ALONE (its blocks fail the amended id check, generator 4 sub-version 1 inside every id; the amended blocks fail its own), ours to upgrade in the sweep; object 6 is class v5's; the two holds already in the rule keep the window shut until every node is on 0.3.20 (a node stamps and tallies only with both v4 fields in its file; the fields publish only after the one-sweep rollout); a lagging worker refuses the amended pack at packcheck and mines nothing after the flip, costing that box, never the chain; no extra window hold: seven full day-windows are the hold. THE EARLIEST FLIP (approximate, measured 09:40Z: DAA 270,659, 1.095 DAA/s over 25 hours, 1.165 over 4; epoch 3,600, lead 600; seven windows 604,800 DAA wholly after the sweep's end D_s = T + about 40 minutes; the flip epoch the first e with 3600 e - 600 >= D_s + 604,800): T + 6 days 10 hours to T + 6 days 11 hours UK; for a publish at 12:00 UK on 7 October, 13 October between 22:20 and 23:10 UK (about 13:00 UK if the 4-hour rate holds). The floor as it stands (831,600, about 13 October 09:00 UK) would fire before any seven-window signal from a publish today completes, so it moves by the 0.3.16 rule to the publish DAA + 604,800 rounded up to the epoch boundary (882,000 for a 12:00 UK publish), firing about 30 minutes before the earliest signal flip: either way about 6 days 10 hours after the publish, never before every node has had the sweep plus a week. THE CLOCK (the node lane, 11:3x UK, after a Mac reboot moved its runs to the box): the 0.3.20 node line (dc141409 plus the proof archive aea0ca5c plus the amended v4 at object byte 5, igneum-pow at the hash lane's a0aaca92 beside the fork on the box) tested on the box, committed on release-0.3.20-node, pushed to the mirror and origin, igneumd and igneum-miner built, the tip to the shipper: about 12:00 UK; the mixed-version Devnet 2 gate (node-compat.mjs on the box, the amended node beside the 5899f603 pair for ten minutes) and the digest test (digest-compat.mjs): about 12:45 UK; the object-byte pin 5 unless the v5 lane answers both lanes with another assignment (v5 at 6 proposed). THE HASH SIDE on ca3-v4-amend (tip 8c728ca3, read from the branch 14:0x UK; the hash lane's own report pending): 1748fd1d the PC 2 G1-only playbook; e1f48d63 the fud-ledger entry AP-F8-1 (the fault, the project lead's ruling, the amendment, the split protection, the owed tests); d8859522 the G1 line (the eight fingerprints equal on the RTX 5090, self-test PASS) and the node lane's signal byte 5; 4aa0c665 the v4 unit test following the amendment; 965d9e96 igneum-pow taken from release-0.3.20's 3f1652bf (the ladder's chain_program_shadow with the reps argument, never on master) with the amendment re-applied, the seven packs re-exporting byte-identical; 8c728ca3 the source rule keyed on the class with the shadow's pass count set aside, so every ladder rung draws under it (the fork's ladder test). The shipper took this igneum-pow tree into release-0.3.20 (00249643, byte-equal); nothing after 8c728ca3 touches igneum-pow. THE VECTORS AND THE PACKS (read from the branch and its ledger entry, 14:1x UK): the seven amended v4 packs (v4-devnet-epoch0, v4-era-0 to 5) carry generator 4, sub-version 1, one program id 1a4230699a6b9c60 (the 2.0 one-id-per-seed rule across the eras; the old c120d7963abdcd96 pinned as must-differ); the v3 control mx8-devnet-epoch0 untouched (73bcbfe8ccf988f1, fingerprint 90f794dd556f7a3b); the seven 2^24 fingerprints, Metal equal to Apple OpenCL: 867dbc45cfb36b4d, 2146ecacc8c75a8e, fe52602393f6d3d4, 3b206471a13912b4, c3f03c4a5d7333aa, f1dfd7209f15bb97, 8c194da64fadf31d; the zip of the eight packs sha256 889ec99976d2728b4b5035bfa476032e5b6a13b928968fc45236d5f25084aa39; the per-pack vectors.json sha256 prefixes 756301bf (devnet epoch 0), 1b5f4568, d430cadc, 1a1b21d8, 460fff9e, 4a85d49d, f83a1196 (eras 0 to 5). G1 on the RTX 5090 (PC 2 job run-ca3-v4-amend-g1-pc2-20261007, 09:41:07 to 09:41:28Z, exit 0, the installed worker): every fingerprint equal to the Mac's (the seven above and the control), NVRTC 188 to 332 ms per pack, the 1 GiB build 38 to 49 ms. hash-gates.md's older table still lists the pre-amendment fingerprints (f410c731... and the eras), which no longer apply to the amended packs; the ledger entry is the record. THE FIRST GREEN (11:31 UK, the box): the kaspa-pow suite on release-0.3.20-node (dc141409 plus the proof archive aea0ca5c plus the object-5 change) against the hash lane's igneum-pow 8c728ca3: 17 passed, 0 failed; the amended devnet epoch-0 id 1a4230699a6b9c60 pinned equal and c120d7963abdcd96 differing, the ladder's rung test green under the rekeyed rule, the v3 control unchanged; the consensus-core and exec RPC suites follow, then the node line (commit, push, box build, the tip to the shipper), then the digest and mixed-version gates. CLOCK RE-CUT (the node lane, 13:0x UK): the node line now carries, beside the object-5 change and the vector test, the lane's 0.3.20 fixes from the day (isSynced from the hook's stamp, the lazy template snapshot, the weight-table cache, the submit path returning after the block task, the watchdog, the RPC fields), about 13:30 UK if the box suites are green; the shipper's fresh-join canary 60 to 100 minutes after the cut; PC 1 as its first machine about 16:00 UK at the earliest, approximate until the shipper names the cut; the earliest flip about 6 days 10 hours after the publish. BUILD-2 LINES (12:28 to 12:33 UK): consensus-core 123 passed (the 60x file test green with the ladder window and activation pinned), the behind test green, kaspa-pow 17 passed (the amended vectors, earlier on build-1), the exec RPC suite green, the flows and rpc-service checks green with the submit-path change; the 24-requester latency test's first run tripped an unrelated flapping-fork double insert (24 equal forks from one parent; the test now builds on the sink as a real miner does; the double insert owed to a small fork harness before it is called a bug); THE NODE LINE COMMITTED (13:1x UK): release-0.3.20-node = 8097d600 (dc141409 + the proof archive aea0ca5c + one commit) on the mirror, pairing igneum-pow 8c728ca3, the hash with the shipper; in it the amended class v4 as object 5 (CLASS_SIGNAL_V4 = 5, byte 4 never counts, the kaspa-pow vector test pinning 1a4230699a6b9c60 equal and c120d7963abdcd96 differing, the daemon's window line naming object 5 and sub-version 1) beside the day's fixes (isSynced from the hook's stamp, the weight-table cache, the lazy snapshot, the submit path, the 100 ms template wait); the suites green on build-2 (consensus-core 123, the exec RPC suite, the four finality tests including 24 requesters under 200 ms: the worst template 100 ms, the worst submit 102 ms) and kaspa-pow 17 on build-1. Next: igneumd and igneum-miner building from 8097d600 on build-1, then the two gate lines (the mixed-version Devnet 2 gate: the 8097d600 node mining beside the 5899f603 pair for ten minutes on the live file without the v4 fields, the old node accepting every block; the digest test: the thirteen-field file b18ed271 unchanged, the sixteen-field object re-read on the 8097d600 binary), expected about 13:30 UK; the shipper picks the cut point. THE DATE FIXED (the node lane, from the hub's live file, 13:3x UK): publish 2 of 6 October (22:49:45Z, digest eada4bda) already put BOTH v4 fields on the live devnet (floor 831,600, window 86,400), so the 0.3.17 fleet has stamped object byte 4 since 7 October 00:2x UK and the floor is live at about 13 October 09:00 UK, before any seven-window signal completes; a 0.3.17 node left on that file flips to the OLD v4 stream at epoch 231 whatever anyone signals, a 0.3.20 node to the amended stream at the same epoch, and the two never share an id, so each straggler forks alone there. REQUIREMENT for the 0.3.20 publish (with the shipper and main): a new file with the floor at the publish DAA + 604,800 rounded up (about 882,000 for a publish today), the digest moving, the one-sweep rollout replacing every 0.3.17 node before 13 October 09:00 UK; any node that misses the sweep is alone then; the earliest flip after that about 6 days 10 hours past the publish; plan section 6.6 amended today. IN THE 0.3.20 PLAN (the shipper, 13:4x UK): both requirements; the node pin by main's rule is the node lane's second commit (the claim floor, the listener watchdog, the claim RPCs, on top of 8097d600) if its suites, both gates and the fleet's 12 GB prover line are green by 15:30 UK, else 8097d600; igneum-pow 8c728ca3 either way; the digest read on whichever binary pins. THE LINE AT 13:5x UK: three commits on release-0.3.20-node, 8097d600 (the object-5 amended class v4 and the day's fixes), 6b94c823 (test-only: the stale PC 1 test from 500ddd66 inverted by the isSynced ruling; the FALLBACK pin, code byte-identical to 8097d600, so the module reads green whole) and 6a3432a3 (the app lane's key methods, the observer's claims, the settled claim floor, the listener watchdog); suites on build-2 on 6a3432a3's code (the whole finality module 25, the exec suite 29 with the watchdog test, the kaspad, flows and rpc-service checks; consensus-core 123 and kaspa-pow 17 earlier); the cut 6a3432a3 if its gates and the fleet's 12 GB settled-claim line are green by 15:30 UK, else 6b94c823; both binaries building on build-1, the two gates (the digest gate, then the ten-minute mixed-version gate beside the 5899f603 pair) on the 8097d600 build, lines about 14:05 UK. GATE NEWS (13:53 UK): on 6a3432a3's own digest gate the listener watchdog counted a bind failure (the four harness nodes share one exec JSON-RPC port) as a listener death and exited three of four nodes at 20 s, where 0.3.17 and 8097d600 only warn and live without the exec RPC; the digest facts came out first and stand (the thirteen-field file a89be8a7 on both binaries, the compat case; the sixteen-field object db9a85f9 refused with the mismatch line, the refusal case); the ten-minute gate on 6a3432a3 stopped as void for the same cause. The fix: a bind failure is a retry every poll, one line a minute, no death counted and never an exit, with a second watchdog test whose known-failed shape is the old rule's exit on a held port; the third commit and its build about 14:15 UK, its gates about 14:35 UK; the fallback 6b94c823's gates on build-1 on their own binary (no watchdog there), lines about 14:20 UK; ledger row N12 for the bind-failure class. A ROLL BLOCKER on every kept datadir (the node lane, 14:1x UK, ledger N13): the fleet started 6a3432a3 on a kept 0.3.17 datadir (pool-1's copy) and it died at start (virtual_state.rs:250, DeserializationError(UnexpectedEof)); the cause 10db4b61 on the 0.3.16 feature line added `silent: bool` to BlockRewardData under serde(default), which bincode ignores, so every build from 10db4b61 on (dc141409, 8097d600, 6b94c823, 6a3432a3, 09124180) reads a 0.3.17 node's virtual-state row short; no canary saw it because every canary wiped, and a one-box roll keeps datadirs, so it blocks the roll on every standing box, the hands and the hub whatever the pin. The fix on the line: the store reads the current layout first and on a deserialization error decodes the row as a v1 mirror, converts with silent false and rewrites it under the same key, with the known-failed test first; the fourth commit and build about 14:40 UK, the fleet's kept-datadir start on the fixed binary about 14:50 UK, its gates after. THE RULE IT ADDS for every node cut from now: a kept-datadir restart gate on a standing box's datadir copy beside the wiped canary. THE CANDIDATE PIN (14:2x UK): b7cc37e7 (8097d600, 6b94c823, 6a3432a3, 09124180, b7cc37e7; igneum-pow 8c728ca3): the N13 fix with its test green on build-2 at 14:04 UK and the kaspad check green, the build on build-1; the fallback 6b94c823 is no longer a pin for the one-box roll (it dies on a kept datadir like every build since 10db4b61): if b7cc37e7's gates are not green by 15:30 UK the honest fallback is 0.3.17's 5899f603 staying live. In flight on build-1: the earlier commits' gates, then b7cc37e7's own digest and ten-minute mixed-version gates on its binary with the read-back, lines about 15:05 UK; on the fleet the kept-datadir start on b7cc37e7 about 14:50 UK and the 12 GB settled-claim line 14:50 to 15:00 UK. Plan section 6.6 amended with the hard date (ca3-v4-node 9d763edd, merged to master); N12 and N13 on the ledger. THE GATES ON THE FALLBACK'S OWN BINARY (6b94c823, sha b1b7d47b, 13:56 to 14:08 UK; code byte-identical to 8097d600, so the amendment's node side): the digest gate, the thirteen-field file a89be8a7 on both binaries (the compat case, n0 peering n1 and n2) and the sixteen-field object db9a85f9 refused with the mismatch line (the refusal case); the mixed-version gate, ten minutes, one digest b0afb2ee on all five nodes, the 5899f603 hub accepting every block the amended node mined (146 new, 246 old, 0 rejected), plain header version 2 on the thirteen-field file, counts equal on all five through the two clean joins and the restart. Two FAILED checks, both the harness's own and fixed (36d3efdc): a refused peer's count read 1 with the reconnect in flight (now the minimum of five), and six address-in-use panics in the two old nodes because the second gate reused the first's ports the second they were sent SIGTERM (a 20 s gap now). CLOCK CORRECTION (the node lane, 12:12Z = 13:12 BST): every "UK" stamp it sent today was the box's CEST, an hour fast of BST; its lines read UTC from now. Restated: b7cc37e7's build about 12:15Z, its digest and mixed-version gates on that binary with the sha and string about 12:32Z (13:32 BST), the fleet's kept-datadir start on it about 12:25Z, its 12 GB settled-claim line 12:50 to 13:00Z; the shipper's checkpoint 14:30Z (15:30 BST), two hours of room. The 13 October date stands (derived from UTC DAA rates): the floor 831,600 about 08:00Z, 09:00 BST. b7cc37e7'S OWN LINES (binary sha256 bc28331abf21f4d5, the string read back on build-1 and on the fleet's pod): the digest gate 12:14:39Z to 12:16:18Z SUMMARY PASS (thirteen fields a89be8a7 on both binaries with the peers as the gate wants them; the sixteen-field object db9a85f9 refused with the line and no peer; the live file's digest eada4bda on the binary, unmoved); the kept-datadir start on the fleet's copy of pool-1's 0.3.17 datadir: the first start 12:17:12Z reads the v1 row through the mirror and rewrites it ("1 mergeset rewards"), the finality blob converts (1,747 locks), the node comes up on its ports with no panic; the second start 12:18:53Z reads first-try with no rewrite line and no panic; 6a3432a3's death on the same copy is the known-failed shape. The ten-minute mixed-version gate beside the 5899f603 pair runs on the same binary since 12:16:39Z, its line about 12:28Z; then the only line outstanding for the shipper's 14:30Z rule is the fleet's 12 GB settled-claim line, 12:50 to 13:00Z. AP-F8-1 RESIDUAL CLASS ON THE AMENDED STREAM (attack-pass lane 12:18Z on igneum-pow 8c728ca3, sub-version 1). F9 over 1,000,000 seeds: programs flagged (hot share at least 1 percent or 7 constant address bits) 1,871 (0.19 percent) against 11,696 (1.17 percent) unamended; worst hot share 9.66 percent against 17.3; mean 0.011 against 0.063 percent; 84 percent of the flagged programs and the whole or-saturation tail gone. F8 at 30 of 64 seeds: nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, the rest 1.3x to 1.6x); the 64-seed 1.2x gate is heading to FAIL on sub-version 1. Mechanism, confirmed on the two worst seeds: an all-ones load source (image 0x0ca59e4c under the era map) delivered through a writer the source rule counts as entropy-keeping, a rotate (rotl and rotr map all-ones to itself) or a load whose own source was saturated, with the saturation made one or more writes upstream by or. The rule looks one writer back; it must look through saturation-preserving writers or test the source's values. The ceiling has not moved: rule (c)'s 120-of-128 floor still caps any program at one saturated site, 6.25 percent of reads, a chip edge of at most 1.067x, and the residual (worst seed two sites at 0.53 and 0.56) sits inside it. THE SENTENCE "no lossy-sourced load by construction" IS HELD: it goes in no plan row and no ledger entry as true; sub-version 1 removes the or-source class and bounds the rest. MAIN'S RULING (13:2x UK): 0.3.20 ships object byte 5 on sub-version 1 as it stands, strictly better than the old stream the live floor flips to on 13 October; the fix is sub-version 2 on ca3-v4-amend (object byte 6 or whatever the v5 alignment leaves free) with both fixes: (F1) the static rule made transitive (rotates do not keep entropy; a load keeps entropy only if its own source did; one draw change, no attempts lost) and (F2) the dynamic source check (saturated load SOURCE values counted per site over the 64 units' 16,384 evaluations, rejected above 163 of 16,384, the same 1 percent the final-value rule uses; costs attempts on about 0.2 percent of seeds; rides with F1 because an or-written source is all-ones only (3/4)^32 of the time). Gate before sub-version 2 is proposed, run by the attack-pass lane and not by the hash lane: the full 64-seed census under 1.2x on every seed and the hot-set census. Hash lane's estimate about an hour its side (implement, re-export seven packs, vectors, crate suite, pairing, one G1 on PC 2) plus the node lane's vector re-pin and the attack-pass re-gate. The flip floor for sub-version 1 is expected to move (the project lead's word) so the chain never flips to a stream that fails this gate. Also recorded: the crate suite at 8c728ca3 100 of 100 on the box (rc 0, 77 s); the pairing against the fork at dc141409 compiled and ran 15 of 16, the one failure the fork's own pre-amendment assertion (base equals v3's, igneum.rs:972), which 8097d600 on the release-0.3.20-node line turns into assert_ne; the pairing re-runs at b7cc37e7, its line to follow. CORRECTION (the attack-pass lane's own retraction, 13:3x UK): the F9 hot-set figures above (1,871 of 1,000,000, worst 9.66 percent, 84 percent removed, the two or-then-rotate listings) are WITHDRAWN: F9's harness draws through candidate_class with its own era class, outside candidate_from_words_class where the source rule lives, so it measured the old stream (the 8c728ca3 binary prints the identical program to the sub-version-0 binary for its worst seed). F8's 64-seed census on the chain path (pairing verified on 1a4230699a6b9c60) is the valid re-gate and STANDS: at 30 of 64 seeds, nine over 1.2x of the window model (p31 29.3x, p11 5.5x, p19 3.3x, p6 3.1x, p23 2.0x, p4 1.6x, p10 1.5x, p26 1.3x, p25 1.3x). The residual mechanism on the amended stream: a load-after-load chain (a saturated source reads one fixed word, which is the next load's address), admitted because a load injects; and the rotate-preserves-saturation path (generator.rs sets entropy_kept true for a rotate whatever it rotated), correct in code and a second admitted path if it occurs on the chain stream. Sub-version 2 must close both: dataflow freshness per register (a load fresh only if its source was fresh; add, sub, xor, mad, shfl fresh if either operand was; rotates only if the operand was; or, mul, mulhi never) plus the (c') count of saturated load sources per site as the backstop. The STOP holds on F8's evidence alone; the options and the 1.067x ceiling are unchanged. The sentence "no lossy-sourced load by construction" waits on the sub-version 2 census verdict and stays out of every public text until then. SUB-VERSION 2 IN BUILD (the hash lane, ca3-v4-amend, on the coordinator's direction, 13:4x UK): F1 (dataflow freshness per register, keyed on the class v4 shape on every draw path, era or not, so the candidate_class path and the chain path draw one stream) plus F2 (the (c') count of saturated load source values per site over the 64 units' 16,384 evaluations, rejected above 163, keyed on the same shape so v2 and v3 verdicts do not move); PROGRAM_SUBVERSION_V4 = 2, new ids, the seven packs re-exported, recheck.rs with 1a4230699a6b9c60 and c120d7963abdcd96 as the must-differ pair. Clock (UTC): the commit on the branch by 13:30; the crate suite on box 2 and the pairing against b7cc37e7 by about 13:50 (the pairing's vector test fails on the fork's sub-version-1 pin until the node lane re-pins; the compile and the other 15 are the pairing evidence); the G1 job on PC 2 under --cards-off by about 14:10, lock permitting; then the attack-pass lane's full 64-seed census and hot-set census on the chain path. Two consequences stated in the commit: the rule on every draw path moves the no-era sh256xN ladder packs' stream (packs-ca3-shadow's seven 256-block packs re-export with new fingerprints; the measured rates stand as the old stream's), and the class v5 lane's pinned string-seed packs move when it merges sub-version 2, so it re-exports them then. 0.3.20's sub-version-1 packs, ids and fingerprints untouched. OBJECT BYTES SETTLED (main, 13:5x UK): byte 5 = class v4 sub-version 1 (0.3.20), byte 6 = class v5 (pinned: class-v5 16afd0a0, class-v5-node 699db5a2, the flip case passed on 6,6,6; the v5 lane stopped), byte 7 = class v4 sub-version 2; the node and hash lanes told. b7cc37e7's MIXED-VERSION GATE: FAIL, the binary not the harness (12:16:39Z to 12:27:21Z, sha256 bc28331abf21f4d5, the string read back). Before the restart step everything held: one digest b0afb2ee on all five nodes, 268 new and 392 old blocks accepted, 0 rejected, header versions plain 2, counts equal on all five at 324 and 502 through both clean joins. At the new node's restart (12:24:19Z) it died at once on its own datadir ("IO error: While lock file: .../datadir/meta/LOCK: Resource temporarily unavailable", conn_builder.rs:167): the previous process was still shutting down, because the listener watchdog added on 6a3432a3 sleeps its whole 10 s poll before checking shutdown, so every node on the line since then takes up to 10 s longer to stop than 0.3.17 (the fleet saw the same shape as "a 12-second timeout does not stop the node"). Three of the four failed checks follow from that one death (counts, the restarted node's resync, the node it served frozen at 502). The fix on the line, one rule: the poll in 250 ms steps returning the moment shutdown is set, with a test that a shutdown returns within a second (the 10 s loop the known-failed shape); the exec suite on build-2, the fifth commit and its build about 12:45Z, its digest and ten-minute gates about 12:50 to 13:05Z, inside 14:30Z. b7cc37e7 is NOT the pin. The node-side re-pin for sub-version 2 (byte 7) once the hash lane's commit lands: the beside-the-fork igneum-pow copy archived from the commit, the two pinned ids moved in the kaspa-pow vector test (sub-version-2's epoch-0 id must-equal; sub-version-1's joins c120d7963abdcd96 as must-differ), CLASS_SIGNAL and tests for byte 7, the daemon's window line: about 20 minutes of edits plus one kaspa-pow suite run on build-2 (about 2 minutes). THE FIFTH COMMIT c4459193 on release-0.3.20-node (b7cc37e7's child, the watchdog poll returning on shutdown; the diff is the poll loop in rpc.rs alone), pairing igneum-pow 8c728ca3; its build on build-1 started 12:30:13Z, sha256 and string to follow. Line A, the shutdown test: rpc::watchdog_tests::a_shutdown_returns_within_a_second_whatever_the_poll green on build-2 at 12:29Z in the exec suite's 31 passed, beside the two other watchdog tests; its known-failed shape the old loop's 10 s stop. Line B, the kept-datadir start: b7cc37e7's fleet read carries to c4459193 since the store code is byte-identical between the two commits; the fleet re-reads on the c4459193 binary only if the shipper's rule wants the string on that line too. The digest gate and the ten-minute mixed-version gate on c4459193's own binary follow its build. THE SHIPPER'S CARRY RULING (14:1x UK): b7cc37e7's kept-datadir read stands as evidence that the store fix is right (the store code byte-identical) but is not the gate line for the pin, because the rule reads the binary, not the diff, and the binary changed (rpc.rs); the gate line is the kept read on c4459193's own binary with its string, which the fleet's canary already runs on c18-1 (wipe, then the kept read, then the restart) before the canary's restart step, at no extra cost; no re-read on p12-vast. THE PIN IS c4459193 pairing 8c728ca3 (object byte 5, sub-version 1); sub-version 2 (byte 7) is 0.3.21's, not 0.3.20's. The shipper's reading of main's F8 ruling: 0.3.20 ships object 5 as it stands because the live floor otherwise flips every node to the OLD stream on 13 October, and the 16:00 BST report tells the project lead the floor move is now RECOMMENDED rather than optional, so the chain never flips to a stream that fails the 1.2x gate before sub-version 2 lands. THE FLEET'S CLOCK ON c4459193 (the fleet lane, 12:5x UTC): the kept read on pool-1's 0.3.17 datadir copy and the restart (the old process's stop time on the line) run on c18-1 before the wipe, a few minutes each, so both lines land before 14:30Z; the wipe canary (IBD from the pruning-point proof, 98 minutes on this pod class) starts when c18-1 is free of the 0.3.20 cases (about 13:00Z) and the binary is in hand, so its synced line lands about 14:40Z at the earliest, PAST the 14:30Z checkpoint; the 12 GB settled-claim line: c4459193 starts on p12-vast's kept copy of pool-1's datadir beside the 6a3432a3 IBD node on alternate ports the moment the binary lands, catches up from 129,398 blocks (15 to 20 minutes) and the 12 GB prover claims against it, the line on c4459193 itself. The binary not yet in the fleet's hand (build-1 building since 12:30:13Z); a wait armed on the sha and string, a report by 13:10Z if nothing. THE SHIPPER'S CALL ON THE CLOCK (14:2x UK): the wipe canary is the decisive read by the deploy rule; the pin never cuts without it and b7cc37e7's lineage does not stand in (the binary changed). The fleet rents a second one-shot pod of c18-1's class now and starts the wipe canary on c4459193's binary the moment the build lands, synced line about 14:15Z (15:15 BST), inside the checkpoint; c18-1 keeps the 0.3.20 cases and the pool window. If the wipe line slips past 15:30 BST the pin holds to it and main hears the clock (a slip is a report, not a cut). The set: the node lane's digest and mixed-version gates (12:50 to 13:05Z), the kept read and restart on the new pod, the wipe line on the new pod, the 12 GB settled-claim line on p12-vast. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the project lead's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule