From 88c02728f6f35415581a8e2b137ecc27fbdc4013 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 18:59:38 +0000 Subject: [PATCH] Igneum 2.0 register: review B's thirteen rows (F04 and F14 the founder's rulings; the 20:0x coverage); Counter ASIC 3.0 status: the pool seat's early item, the 19:4x lines (the miner base-unit root cause, the hubs' memory caps, the three object candidates on the live line, P22 stage 1, F0), the 20:00 words and read-back, review B, the founder's two rulings, the roll correction Co-Authored-By: Claude Fable 5.1 --- docs/plans/counter-asic-3-status.md | 11 +++++++++++ docs/plans/igneum-2.0-register.md | 16 +++++++++++++++- 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index 538e63000..065c3519a 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -483,6 +483,17 @@ MAIN'S FREEZE RULING (19:1x BST): the post-review object is the 23:30 D1 object THE 19:2x LINES AND THE 19:30 COVERAGE (BST). Capacity: the founder's three AX162-1 dedicated servers assigned (188.40.146.44/.45/.46, FSN1-DC24) as build-7, build-8, build-9, staging in parallel since 19:18:44 on the build-server lane's recipe (rescue to first gate in one run inside 30 minutes); the lease classes mapped so the P01 campaign, the object matrix, the census, the family gate, the review and the fast-time case take every freed core first; main's order that every row waiting on cores re-clocks to the new boxes as they go green. The build-server lane's rolling site deploy stopped by its pid file at 19:16:27 (ad5a54c5's Vercel upload hung nine minutes, the fault; 0ae450bd reached the edge at 19:05:29); the site lane deploys its own landings; the node sha ef0f2ed8 embeds proving/igneum-prove/elf/prior, a path on key-succession-pin and not on master, so its pair builds only beside that branch's tree. The node lane at 19:17: two object candidates cut and gating, (a) class-v6-node dab9259f (the generator at c245d50b9, a65e4c5a; the default literal on every network: the v6 floor never, class_v6_dataset_steps [(0, 4096 MiB)], class_v6_family_flags 0xf; the dataset-policy digest 70a6c703; the harness tree b3528574 at v5-fasttime 92bf6a7f0; on build-2) and (c) class-v6-node-review 50589749 (dab9259f plus the post-review generator; on build-1); "+nowin" as a fifth family flag 1 << 4 by default; the D1 record drafted on d1-record e0c8ec7f8 (docs/spec/01-lottery-hash.md version 0.3: 1.0 the frozen object by digest, 1.4.8 generator 6, 1.8.7 and 1.13.4 the dataset policy, 1.16 the parameters the freeze fixes, 1.17 the class v6 vectors open to 01:00); the rule v4 rows on fin-v4-rows 63dc9de2f (the four bee41b5e runs into sim/results_v2.md with the criterion per variant; v3.mjs's split50 pass line keyed on finality_v4_recovery), the HEAL=400 reruns on the successor pair on build-2 (about 20:10); the successor 12424341 placed on both boxes with canaries green and named to the pool seat. The hash lane at 19:2x: the post-review sha moved to class-v6 04442d9ca (6d602859f did not compile, a private import, fixed by 9b687f631; the suite queued on box 2, verdict by 20:00); A FAULT FOUND BY LANE D ON THE PRE-REVIEW OBJECT: accept::is_class_v4_shape set fold and rw aside but not nowin, reg64 or reg64_chain, so on the chain's own path a +nowin or +reg64c program was judged by the class v2 parts alone (no fresh-source rule, no saturated-source check, no index floors, no 32-attempt cap); the family harness's own predicate hid it from every census so far (the census PASS lines were the harness's full rule, which is the rule wanted and now the crate's); fixed in 04442d9ca with the test that every v6 flag keeps the class v4 shape and the attempt cap; the default sent to main: a third candidate (b) = (a) plus that one fix, gated beside the two; never (a) as it stands. The steward at 19:23: the evidence rules on master at e2adc2c1 (a PASS needs existing evidence, evidence moves with its row, a stale manifest never PASS, no run_status without the approval); the write-back batches lost rule 26's race three times (the registry a hot file), the fix 5877760c landing 19:35 (a landing carries its batches as tools/ci/batches/.json and merge-to-master.sh replays them onto master's copy at the merge, self-tested where both sides add rows); the three batches riding it (200-417c4a57-b2 with 30 cases RUNNING, the review harness cross-check on POW-01, part B on POW-06); the P01 pods run hl-v5-win first (reference by 19:45) and hold the v6 packs for the re-export (about 20:10). The update-return lane at 19:21: PC 2 (1ccfe586) started the 2.0.0 install at 19:19:42 through its own OTA path (no administrator prompt; the window host away at 19:19:47); PC 1 (ae432dc7) fetched and verified the Setup exe at 18:58:48 ("installs at the next safe moment"), the install pushed through the signed-jobs channel at 19:11 (its relay agent silent since 17:58, the logon task's takeover by a signed job); UX-01 RUNNING. The attack seat's POW-05 row on master at 3555af7a. The census lane's A03 landed on master at cdbdda05 (19:18) by the landing hand. The research lane's landing hand: twenty-seven landings. Lane D's 6.11 read: the class-string port built and proven on 542cd7028 (the class's own 83-point table, nowin, fold, rw and reg64c composed from the string), the chain-predicate mode in the diff, the run staged on build-4 (five minutes to rebuild, 25 to run), 22:00 with the ids and sha by 20:30, 22:30 plus the delay after 21:00, the default a run on the latest mirror sha at 21:30. The coverage line at 19:2x to main: 113 pins, 113 owned, 30 open, 44 in flight, 34 landed, 5 passed; cases 10 PASS team-run, 3 FAIL, 62 RUNNING, 52 NOT RUN, 1 DEFERRED; profiles P12 FAIL, P04 FAIL, P03 PASS at stock with the lock at 20:30, P01/P06/P08/P09/P10 RUNNING, P00/P02/P05/P07/P11/P14/P15/P16 NOT RUN, P13 DEFERRED; four BLOCKED fields for the founder's word in F0 (the workload W, the fault model's thresholds, the 30-participant study, the second and third AMD configurations); the gap table docs/plans/igneum-2.0-gap-table.md written; the rows waiting on cores re-clocked (the post-review suite 20:00 to 19:50 on build-7, the P01 references 20:20 to 20:05, the fast-time case to the first 16 free cores, the census re-run 22:30 to 22:00 on build-8). MAIN'S WORD ON THE FOUR BLOCKED F0 FIELDS (19:3x BST), written into F0 by the steward as "main's word, 19:3x": the workload W (P07) the pilot plan's shape (one SP1 program pinned by vk, the shard fixture's size class, compressed proofs, one job an hour the floor and the fleet's measured rate the ceiling, requests/hour from the pipeline record's day); P00 and P08's fault model and thresholds the finality spec's own (two thirds of the sliding table, the anchored table under rule v4, the recovery variant as the founder's default, the 40/40/20 fixture, the spec's expiry cases); P10's 30-participant study NOT RUN ("unaffiliated participants not yet recruited"), kept open, never a staff run; P02's second and third AMD configurations the 9070 XT and the RX 7600 on PC 1 as the two retail AMD cells, rented AMD cells added when a provider lists one, the row PARTIAL until then. The freeze default confirmed by main: the fallback is (a) with the acceptance fix and its census re-read, cut now as the third candidate; if neither (c) nor the fixed (a) is fully green by 00:30 the freeze holds for the fixed (a)'s green with the clock named, never a known fault frozen. The gap table docs/plans/igneum-2.0-gap-table.md (one row per profile P00 to P16: the cases governed, today's value, the verdict today, the first confirmatory run) landed with this entry, ahead of the 20:30 ask. +THE FIFTY-NINTH LANDING, THE FIRST LOCK AND THE HUB INCIDENT (19:3x BST). The fifty-ninth landing on master at 10e7e88a5 (the gap table docs/plans/igneum-2.0-gap-table.md with main's word on the four F0 fields; the record). Devnet-4's first finality lock: checkpoint 241, block ef2d953a0ca9da68ef571a36b87a53085474615cca3555fd94ee0380da341fee (blue score 7155), at 19:08:25, signed by 77.8 percent of active weight; locks ran to checkpoint 249 (181c5dfd) at 19:13:08, nine locks; the first paid segment on the live chain 3728..3735, 0.7795 IGN, carrier 3877, read at 19:19:39 on lp-4090-43 (3768..3775 paid 0.9097 IGN to lp-4090-04 at 19:19:42); the first refusal at 19:19:49, segment 3776..3783 "segment already paid" on a second prover (a steal, not a verdict refusal; 62 submissions, 14 paid-to-another); the reference-apps lane's inclusion receipt verified through the live service at checkpoint 241 (719 headers) and the certificate 241 recorded on the devnet-4 verifier by the DEX lane. THE HUB INCIDENT: every dial target died together with no exit line, no panic, no OOM and no kill in dmesg or the journal: build-1's seed (log ends 18:16:46Z) and hand (18:23:59Z), the fleet's dn4-seed on the dn3-g1 box (19:15:32 BST) and lp-4090-01 (19:16:55), an external SIGKILL or a session-group kill at two different minutes; the locks stopped with them and every home node found no peer (PC 2's 2.0.0 node up at 19:22:01 with mining resumed 19:22:13 and no click, every card waiting at 0 MH/s for want of a peer). Nothing of the node lane's touched them after its 17:56Z restart (which itself restarted both at once, read now as a fault class: both dial targets down for three seconds together). The candidates asked of the build-server lane and the fleet lane for 18:10Z to 18:25Z: the build-server lane's rolling site deploy stopped by pid file at 19:16:27 BST (18:16:27Z) with "its in-flight deploy subtree ended with it", nineteen seconds before the seed's last line; the fleet's roll step at 18:18Z (dn2-2's restart between the two deaths); a unit install on build-1. All four back by pid files on their kept datadirs: build-1's pair at 18:27:05Z and 18:27:06Z (pids 3511072 and 3511735, ports 26631 and 26671 listening, the digest be5f4068 unchanged, synced, 14 and 21 peers reconnecting within a minute), dn4-seed open at 19:28:50 and lp-4090-01 at 19:29:24 (peers 3, syncing); hub-1 at 19:29 reads DAA 7,623, finalityActive true, settledNumber 0xf09, 1,482 verified records, paidShards 172. The rule from the class: a roll or heal never leaves fewer than two dial targets listening, one at a time with the port read back; the node lane writes systemd units with Restart=always for build-1's seed and hand now. Open: with the hubs down the prover boxes' own nodes read different carriers for segment 3728 (3865, 3877, 3884 on three boxes, each on its own tip), the partition's view and not a double payment, settled by the read after the hubs rejoin. PC 1: still 0.3.26, the Setup exe verified at 18:58 and held for "the next safe moment", the update-now signed job of 19:11 behind the hash lane's long jobs in PC 1's one-at-a-time queue, the relay agent silent since 17:58; the order set: the 2 GiB read, the knee rows by 20:30, update-now, the 7600 overnight grid; default update-now at 20:45 regardless. A third kill by name today: the hash lane's `pgrep -f "igneum-pow hash-bound" | xargs kill` on box 2 at 19:3x after the sanctioned pid stop of its stalled P01 run (it matched only its own processes; named by the lane itself). The P01 reference generator rewritten (igneum-pow hash-bound --count hashes one warp per 32 nonces, class-v6 3909327fb, a tool commit in main.rs only): a pack's million-line file in minutes; the re-exported packs (hl-v6-all, hl-v6-foldrw, hl-v6-all-nowin, hl-v5-nowin; the pre-review ones kept as *-prereview.tgz on build-1) by about 20:25 with their new ids, the references by 20:30, the suite on 04442d9ca green by 20:05. The site lane's chip sentence: whole machine (1.5x to 3.1x; 1.5x to 2.3x on the GPU's own node) with the core-only row beside it (2.8x a node ahead, 2.4x node for node, placed and routed, plus or minus 15 percent) and the P04 target beside both, from this landing. The update-return lane's PC 2 line: the 0.3.26 engine installed 2.0.0 through its own OTA path at 19:19:42 with no administrator prompt, 2.0.0 up at 19:22:01, the node at 19:22:05, mining resumed at 19:22:13 with no click (UX-01's team-run evidence; the P10 study NOT RUN by main's word). +PC 1's RESTART RISK (19:3x BST): the hash lane published restart-app-pc1-20261008-grid-hold (kind restart) to free the runner its withdrawn grid job holds; on 0.3.26 the restart kind spawns the relaunch helper that races the window host (the race PC 1 lost on 6 October and at 14:50 today; fixed in v2.0.0 only) with the relay agent down; the update-return lane and the coordinator ordered it withdrawn before the runner reaches it; no app restart on PC 1 until it runs 2.0.0; the held runner frees at the grid job's own cap, or the founder's one click (Settings, Update now) installs 2.0.0 first. The relay agent handover fix (the agent writes its pid; the installer ends console copies and reports success only when the task's own agent is live; one double-click) green on the relay tests, the re-baked PC 1 zip to its tokened path. +THE FINALITY READ AFTER THE OUTAGE (19:36 BST, the node lane, from build-1's seed and hand on ef0f2ed8, both synced, finalityActive true, no pause). The last lock on both: index 249 (block 181c5dfd, DAA 7,449), its certificate replaced by a heavier one at 19:29:17 (30 of 38 voters, weight 5,849). Why 250 did not lock: the selected chain flipped under it during the outage window (19:15 to 19:29, the seed, the hand and the two hubs down at once, each island mining its own tip): "checkpoint 250 re-determined: block fa1d4816 (blue 7,409), was 24e88331" at 19:27:45, "251 un-determined: 55bbf2e7 left the selected chain" the same second, then at 19:32:10 "251 determined: 55bbf2e7" and "250 re-determined: 24e88331 (blue 7,408), was fa1d4816": two chains of equal work, the voters signing whichever 250 their node had determined (the 51 / 31 / 4 / 0 percent split), 251 to 253 with no stable determination to sign; a partition fact of the outage, not the 2.0.1 vote path (the hand and the seed on ef0f2ed8 both sign, 16 and 25 vote lines since the restart, both peering with 4cdcc488 nodes on the unchanged digest). At 19:36 both build-1 nodes agree on 250 = 24e88331 and 251 = 55bbf2e7 ("proposed"), 252 and 253 determined on the hand, the hubs peered again (64.119.209.250 inbound on the seed at 19:35:43); the next lock expected on 250 within two or three checkpoint intervals (about 19:45). The roll halted until a checkpoint locks again; the rule: a roll proceeds only while finality is locking. The kill path: one kill reached four processes on three hosts in 90 s (18:15:32Z, 18:16:46Z, 18:16:55Z, 18:23:59Z), a subtree or session-group kill walking ssh children; the node lane's processes were setsid'd, so the path is not yet seen; the build-server lane's read decides it. The systemd units are the build-server lane's to install (the build user has no sudo on build-1, ~/.config root-owned); until then the port watcher on build-1 (/tmp/dn4-port-watch.pid) re-raises a missing port within 60 s by the one-at-a-time heal. +MAIN'S THREE WORDS (19:4x BST): P03's "paired tuned baseline" is the card at its tuned operating point, the knee under the lock where lock control exists (NVIDIA with power control, AMD through ADLX), stock where it does not (Apple, cards without control), both sides of a pairing at the same point; the genesis dataset size is the baseline being frozen, not a P03 change. H and W for key succession: not tonight; H named tomorrow after the real next-pair fast-time case passes, the first lock has formed and the chain has run clean for a few hours; W one epoch; the digest move at the shipper's minute from kept datadirs; the capability rides tonight's roll inert. The dataset size (4 GiB at genesis) and the finality switch (recovery) take their defaults at 20:00 unless the founder names otherwise, applied as his word. The roll halted until a checkpoint locks again (the 19:35 incident order). The site lane's sweep gate red once on the income page edited by hand instead of through its generator (fixed, the class recorded), re-gating about 19:43. + +THE INCIDENT'S ROOT CAUSE AND THE 19:4x LINES (BST). THE ROOT CAUSE (read by the shipper on the mini at 19:41, confirmed by the fleet lane across hub-1, the hubs and 18 mining boxes at 19:44): the shipped igneum-miner (2.0.0 of the 4cdcc488 pair, the same code in ef0f2ed8) installed the node's base unit only on the `inspect` command, so `mine` decoded every amount at 8 decimals and refused every devnet-4 template whose merged coinbase exceeded 2^64 base units (about 18.4 IGN, six blue parents' subsidies at 0.48 bps with 28 keys) with "amount high word 2", then "NODE SLOW: no template", 0 MH/s (hub-1 323 refusals, dn2-3 163, p1-4070 167); p1-5090 kept mining (its merges under the bound) and its 295 of the last 300 blocks are the "solo branch": the fleet's weight was not mining elsewhere, it was not mining; the vote split and the no-lock since 249 follow from one key producing the chain while the voters' nodes drifted and the seeds were down. The fix 777214af on release-2.0.0-node (every miner command installs the base unit from the node's network before any amount is read; the seeder's genesis line reads the network's; a known-failed test with the mini's exact words), on ef0f2ed8, digest-preserving; the miner suite, the pair under /srv/artefacts/200-777214af/node-lane, the devnet-4 canary and a live canary on build-2, lines by 20:10; 777214af the 2.0.1 roll sha (one box first, hubs last, under the two rules); the roll halt until a lock stands. The rule 25 class in a new form: a wei-sized amount read at the wrong base unit is a refusal of every honest template, not a wrong number. The hubs' deaths: both RunPod hubs killed by their container memory caps (cgroup memory.events: dn3-g1 cap 16 GiB, oom_kill 3 then 4 at 19:34 when it died again; lp-4090-01 cap 28 GiB, oom_kill 1, the launch prover started on it at 19:11 peaking 11.9 GB beside an 8.6 GB node), a SIGKILL with no exit line; the build-server lane's kill path exact (single Mac-local pids, no group, no session; nothing of its reached the four processes; the seed and hand ran outside any lease, reparented to init), so build-1's seed and hand deaths at 18:16:46Z and 18:23:59Z stay unexplained by any lane's command (the build-1 box's own OOM is not read; asked). Fixes: dn4-seed node-only (MINE=0) from 19:37:24; the prover on lp-4090-01 stopped by pid (rule: no prover on a dial target; a dial target runs node-only on a box with headroom); both seeds had the house IP 2.121.2.18 banned from the outage ("peer is banned"), unbanned 19:35:20 and 19:38:10 (the rules into 2.0.2: a seed's peer ban does not survive its own restart; a peer dropped during the seed's outage is never banned); both seeds with a 32-inbound cap and a guard; the two held hubs for the six-target list lp-4090-07 (213.192.2.71:40045, 116 GiB cap) and lp-4090-02 (103.196.86.97:10034, 57 GiB), neither destroyed or re-addressed without a line to the shipper. The branch read at 19:41: build-1's seed and hand (60 and 68 inbound peers) reorganised at 19:36 onto hub-1's selected branch (executedTip 4,346, DAA 8,174, tip 0xfb29a619, mined by the 5090's key), the heavier by blue work; the fleet's nodes take it as they peer (the re-dial to the five targets finished 19:40:52, 12 of 19 re-peered and synced, 7 at zero); the signing on the table frozen at lock 249 read 40.3 and 41.1 percent on the seed and hand at 18:40Z against hub-1's 30 percent, rising with each re-peered voter; the first lock when it passes two thirds, next index 273 on this branch (the island ran 20 intervals ahead at collapsed difficulty); the light-reader on build-1 (igneum-light-reader.service, EVM 26881, loopback peers only) still on the old side at tip 3,893, needing --addpeer to the seed (the build-server lane's unit). Segment 3728..3735 on hub-1's selected chain: no payment yet, carried twice by one key (0x92e99c at carriers 4304 and 4305); the three "paid" reads were on branches that reorganised away; an assignment-fairness steal row for INC, not a duplicated reward; the same for 3824..3831. The fleet census at 19:36: 102 boxes, 98 nodes up, 57 synced, 19 with no peers, 38 MINE=1 with 37 miners, 4 down. hub-1 at 19:38: finality paused "under two thirds of the weight is signing (31.99 percent; the frozen table at lock 249 has 30.15 percent)", reorganised from DAA 7,646 to 8,287 between 19:35 and 19:38. The object candidates rebased on the live line (release-2.0.0-node ef0f2ed8 merged into class-v6-node 0f8c7475, the literal be5f4068 / 4465, rule v4 with the recovery variant, key succession inert, the 4 GiB floor from genesis): (a) 3bd95052, (b) 83bb8ea6 (plus the acceptance fix abdecf2e6), (c) 6d9016f2 (04442d9ca), the chains restarted at 19:4x; (c) reads six suites green on build-1 (core 184, consensus 143, exec 74, miner 30, p2p 38, pow 19), its pair building; the pre-merge (c) green on the old fork point's literal (77581277, 0x116f) is the first green and not the object. The pool seat's two clocks met early at 19:4x: pool-2.0 91f58349 (release-2.0.0 plus pool-finish-22, KeyReveal naming its scheme, job and share carrying vote_key_hash as the node's 64-hex Hash string, verify::check comparing before the hash with code vote_key), 29 of 29 ok on build-2 against the node lane's successor-2.0.1 a4a8d7ca, the known-pass and known-fail among them; the batch pool-2.0-20261008-01 under the steward's form; the sidechain's session-key check next (the codec on successor-2.0.1, the dependency met). P22 stage 1 green and committed at 19:41 (p22-stage-1 67e22b9ef; p22-stage-1-node b580b3ba off 291ee6ae: the mirror function, the statement bytes 328 to 360, the block statement 340 to 372, the segment record 586 to 618, the veto naming "inputs"; igneum-exec 76, kaspa-consensus-core 175 on build-4), ZKP-04 and ZKP-08's proof side PENDING with section 4's label; stage 2 started. The next-pair key-succession case seated on build-2 at 19:37 (H 240, W 120, the prior pair pinned, no start refusal: the daemon fix reading right live), result about 19:52. F0 on master at 8bdd1ff0 as docs/plans/igneum-2.0-f0-manifest.md (sha256 7a1e0fa5e116ad22): the identity pins (miner cut tip 2826f37e, node roll ef0f2ed8, devnet-4 4465 by digest be5f4068, the class v5 freeze, the dataset schedule, roles and kits), main's four rulings, an unresolved-field register with owners and defaults, the signing block for 23:30; the registry at 19:45 reads 73 RUNNING, 53 NOT RUN with reasons; six lanes' batches through the replay. The finality lane's FIN rows on master at 38757fc13 (FIN-02 and FIN-08 RUNNING; its work complete). The build-server lane: the GitHub runner units on build-1 and build-2 stopped, disabled and masked; the lease pool's livelock (three waiters polling on the same 10 s step, each reading 0 free for 20 minutes) serialised by a mutex with a jittered step (25cecb71 on build-1, 2, 4, 5, 6), the in-loop waiters to be restarted by their owners; build-7/8/9 first gates running since 19:41:03. The joint chip table (floor lane 2 and the adversary lane, 19:5x): the two genesis cores within 6 percent on the board identity (2.41x and 2.28x same node), the 18-family bank a further 0.23x, the machine terms the rest; the served line "1.5x to 1.8x for the complete machine, 2.0x to 2.4x for the board alone, same node, both placed; a node ahead 1.8x to 2.1x and 2.45x to 2.8x". Main's order at 19:40: build-5 at load 0.11 and build-6 at 0.00 while work queued on build-2 and build-4 is a fault; the P01 references and the corpus to build-5, the census and family-gate reads to build-6, the matrix cells wherever a cell waits, build-7/8/9 the object matrix and the fast-time cases on green; the 20:00 line lists every box with its load and jobs. +THE POOL SEAT's 23:30 ITEM DONE AT 19:5x: the open pool refuses a share whose claimed key, header key and coinbase reveal are not one key, before its PoW (sidechain::check_key in accept; known-pass make_share; known-fail the claim swapped, the header's key swapped, a foreign reveal), pool-2.0 at 72cc306e, suite 30 of 30 on build-2 against successor-2.0.1 a4a8d7ca, the release binary f9c03bbf; the pair on pool2-a and pool2-b next (devnet-4 from empty datadirs on 12424341, members on the 2.0.1 hive kit's CUDA worker), UX-05 by 00:30, UX-04 and UX-06 mode A by 01:30 (mode C not in the member side, BLOCKED with the shipper's agreement). + +THE 20:00 WORDS AND READ-BACK (BST). The founder's defaults taken as his word at 20:00: the genesis dataset 4 GiB (class_v6_dataset_steps [(0, 4096 MiB)]; the served policy from PROPOSED to decided); the finality switch the recovery variant, with review B's F04 condition (a recovery lock never presented as final: recovery_lock on every CheckpointRecord, lock_kind "final" or "recovery", lockKind, recoveryLock and latestLockKind on igneum_getFinalityCheckpoints, on successor-2.0.1 e9ab052f, the reference apps and the explorer reading them by 23:00). REVIEW B dispatched by main (docs/analysis/review-2026-10-08-b/dispatch.md on review-b-landing 0c0d7f80b, the steward landing it by 20:15 and adding suite REV with 44 regressions by 20:45): F01 proof-verdict cache omits the statement (P0; the enforced lane: ProofPool::verdict_for returns a cached success keyed by proof hash alone, so a proof cached against its correct statement passes under another statement, and a context refusal cached first poisons the correct use, plus the zero-id host wildcard; the fix by construction on verdict-cache-fix off 5eab958f, immutable verified facts per proof hash, no zero accepted id, bounded entries and in-flight, known-failed tests first, sha by 21:30 for 2.0.2); F02 the proof rule fails open (the IGNEUM_TEST_SKIP_PROOF_RULE bypass behind a build feature off in release; missing oracle or keys after activation not-ready, never pass); F03 one release manifest (the steward, the hash lane's ProgramClass::V6, the pool lane); F04 recovery lock weaker than final (the node lane as above; the native 40/40/20 case past the window with equivocation and the pause-only alternative planned by 23:00 for build-7/8/9 tomorrow, pass line "two valid contradictory certificates = FAIL"); F05 the reg64 address mixer's exact incremental form (hash, adversary, floor lane 3); F06 acceptance and census do not cover the final execution (hash lane, lane D; "frozen pending D1 census" if the live census is not green by 00:30); F07 one per-device scheduler (app, fleet; explicit modes); F08 the proving pipeline hides expired work (the outcome ledger by 23:00); F09 the economic table's cells generated from the declared inequality (research, floor lane 3, coordinator); F10 the CUDA readback select pass (a worker lane); F11 Ember search and identity (an Ember lane); F12 pool payout durability and F13 pool admission bounds (the pool lane); F14 lab fleet control is not the public trust model (two builds from 2.0.2: public without remote execution, lab for the fleet; app and relay lanes). Main's three founder decisions with defaults: F04 keep recovery labelled never final (22:00); F14 the two builds (20:30); F06 "frozen pending D1 census" (00:30). The enforced lane's daemon fix green at 19:47 (key-succession-node 5eab958f: igneum-exec 74, kaspa-consensus 141, core 175); the both-pairs run 19:37 to 19:46 on build-2 with no red for the pin (the attacker's carrier with five forged records refused in 0.000 to 0.004 s per record and dropped, its descendants refused, nothing paid at or after H) but three harness faults hiding the pair reasons across the epochs (the proof floor set equal to H, the reason classes read from lines the node never prints, the attacker's chain dying at its first refused carrier); the redesign (the floor at 0, the two real proofs to an honest node's pool per epoch with the verdict read back) by 20:15. The shipper's correction: the 2.0.1 node sha is 7cfa422a (777214af's connect_with_unit called itself, E0733, caught by the Mac chain and the steward's miner cell at 19:47, nothing of it on any box); the miner cut tip aa0e0f45; the DMG 20:02, the hive 20:30, the Windows payload 20:40, the Setup 21:05; the roll lp-4090-11 first with four read-backs, then tens, the hubs' nodes untouched, hub-1's miner last. build-7, build-8, build-9 GREEN at 19:44:37, 19:44:40 and 19:44:40 (AX162-1, 96 threads each, 139 s on master 0f2e214f under lease pool 24; no GitHub runner unit); node-only devnet-4 seeds under igneum-dn4-seed.service on build-7 (188.40.146.44:26631) and build-8 (.45:26631); build-1's seed and hand under igneum-dn4-seed and -hand units (taken over one at a time, hand 19:43:09, seed 19:43:22, ports read back); seeds.igneum.network A x7 at 19:46; the GitHub runner units on build-1 and build-2 stopped, disabled and masked. THE 20:00 PER-BOX LINE (read 19:55): build-1 (96) load 20, no lease, the devnet-4 seed and hand under units, the observer, explorer, faucet, light reader (resyncing from genesis), the 2.0.1 cross builds done; build-2 (96) load 11, 88 cores held by the hash lane's igneum-pow suite, queue hash-lane-p01 and pool-2 (moving to build-5); build-3 down since 16:40; build-4 (96) load 130 of 96, OVER (three family-gate holders on 20 leased cores running unbounded cargo jobs; lane D told to stop by pid and run bounded on build-6); build-5 (32) load 0.0, the hash lane's P01 worktree ready at /srv/builds/igneum-wt-hash-p01 since 19:53, no answer (a fault named to the hash lane); build-6 (32) load 16, 23 cores to the census (worktree /srv/builds/igneum-wt-census; the family gate's at /srv/builds/igneum-wt-family-gate); build-7 (96) load 1, 12 cores to the enforced lane's P22 stage 2 suites; build-8 (96) load 1.3, the seed only (GOV-03's reproducible-build comparison on it at 22:00); build-9 (96) load 2.7, idle (the node lane told to move the (a) and (b) chains there); PC 1 the hash lane's 7600 AMD grid since 19:51; PC 2 the B580 energy read done 19:54, then the 2.0.1 Setup build and the Arc bench; the mini synced and mining since 19:37. The first lock after 249 still owed at 20:00 (signing 40 to 43 percent on build-1's nodes; the fixed miners not yet rolled). The 20:00 read-back sent to main with the faults named (build-4 over its leases; build-5, 8 and 9 under 20 percent with jobs queued on build-2; build-3 down). +THE FOUNDER'S TWO RULINGS (19:57 UK, through main): F04, the recovery lock is kept and is always labelled "recovery", never "final", on every surface (the checkpoint field, the explorer, receipts, the light client, the oracle, the site; the app's Cards and status words with them); F14, the public miner ships from 2.0.2 without remote jobs, our own fleet on the lab build with its own signing root. Main's correction on the roll: "halted until a lock" is a deadlock (no lock forms while the unfixed miners refuse templates, 0 blocks per minute at 19:54; the fixed miners' blocks carry the voters' weight back): the 7cfa422a pair rolls the moment its canary parses templates with no refusal (about 20:20), lp-4090-11 first with the four read-backs, then tens, the hubs' nodes untouched, hub-1's miner last; the lock is the measure after the roll, not the gate before it. The mini (the shipper's read): the node re-peered and synced at 19:37; the miner idle on the template class since 19:41 (17 "amount high word" refusals, the last at 19:58), the last rate above zero 12.46 MH/s at 19:22:53; at 19:58:02 "0.00 MH/s, mining | node 8562 blocks, 3 peers, synced"; the fixed miner reaches it after lp-4090-11 through the Mac 2.0.1 entry (about 20:10 on the canary line), the MINING-ON read-back about 20:25 as the Mac fresh-install evidence. PC 1's knee rows cannot come by 20:30: the runner held by the withdrawn overnight 7600 grid job until its 600-minute cap (the withdrawal stops only a refetch; a restart job out on 0.3.26; the relay agent down); the founder's click (Settings, Update now) the one lever, put to main with the default (the layer stays; the "+nowin" row RUNNING at stock, FAIL for want of the lock rows; the AMD grid at the cap about 05:50). The hash lane on build-5 from 20:0x (the P01 references and the re-export), the suite on build-7, the pack-reader fuzz PASS on build-4; the 04442d9ca suite's one red (tests/ds55's byte-identical check, A06's kernel hashes having gone into program.json) fixed in 5a095e64a (the hashes in a thirteenth file identity.json, the pinned twelve byte for byte); F03 ProgramClass::V6 (generator 6 for every v6 class, "v6" in program_class, the id recipe's generator byte) by 20:45, the suite 21:05, the final re-export and references 21:20 (the census hand and lane D read the final packs from 21:20); F05 the prefix-XOR incremental form as a native equivalence test by 21:05, the kernel measurement on the rented 5090 and 4090 by 23:30. Floor lane 3's review B answers at 19:56 (class-v6-floor-sram 3a16190a): F09(c) the hand-written "USD 18 M against 40 to 80 M: PASSES" cell contradicted the inequality (a third of the chain times the ticket must exceed a year's revenue); every (c) cell now generated from it (market.py M3, section 12): no chip meets (c) at any price in the window (the board 1.2x to 5.9x short, the hybrid 2.3x to 11.6x, the die 6.5x to 35x), every chip 3x to 15x cheaper per MH/s than the GPUs setting the equilibrium; the board six of seven, never seven; F09(g) the hybrid operator keeps 85 to 90 percent of the sunk owner's proving surplus on consumer cards (holds for the GPU as a device, not the owner as a business; no verdict moves); F05 the cached prefix tree at 1.8x fewer fold ops for 260 bytes of prefix state per lane, the chip's energy per hash down 2.6 percent, the connected-state KILL unchanged. Floor lane 2's slip: the placed 64-register window core in detailed route, its row 20:40; the placed gated 32-register base's two-length solve 6.7 pJ per lane-op at ASAP7 (3.4 at N3, k 0.54 at the lock, the board 2.4x node for node and 2.8x a node ahead); the 8 KB flop scratch 207 pJ per random read at ASAP7, 104 at N3, against the card's L2 hit at 1,400 (k 0.074, closing the record's "L2 hit 0.1 to 0.3" band at its low end). The reference-apps lane's F04: lockKind mapped to lock_state on /light, /balance and /receipt, the negative set green (a receipt claiming final under a reported recovery lock refused); the oracle: both Sepolia verifiers accept the two-thirds rule only, so a recovery certificate reverts in submitCertificate and every stored root passed the final rule; no contract change tonight, the line on /oracle and the README (a byte and redeploy only on word by 22:30). The fleet's four review B jobs (F05 the 5090 and 4090 by 23:00; F07 the 8, 12 and 16 GB cells, the 16 GB rental on the 2.0.2 modes, first rows 01:00; F08 the two-hour hold after 2.0.2's cut; F10 the 5090 and 3090 at 23:15). The register at 20:0x: 126 pins (13 of review B, F04 and F14 RULED), 126 owned. + A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the founder's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | diff --git a/docs/plans/igneum-2.0-register.md b/docs/plans/igneum-2.0-register.md index 7af372fbd..397fe2145 100644 --- a/docs/plans/igneum-2.0-register.md +++ b/docs/plans/igneum-2.0-register.md @@ -119,6 +119,20 @@ Built 8 October 2026, 18:3x BST (the founder's order: no feature left out, no st | 112 | External source review of the mining algorithm (docs/analysis/review-2026-10-08/, on master at 0ae450bd; it examined the Mac checkout's older V2 to V4 crate, not class v6, and says so) | Finding A08 "An operation described as bijective is not always bijective" (on master at 0ae450bd, the harness run on build-2 to its end with every anchor it asserts agreeing with the tree, the v5 and v6 vectors outside its model); the review's harness is the cross-check evidence; the verdict reads fixed by construction, not applicable, or known open with a clock, and nothing reads PASS without the native test | hash lane (a690540514aa453d7); the node lane carries the verdict into the 23:30 freeze | 22:30 | RUNNING tonight (main's dispatch, 18:5x BST) | docs/analysis/review-2026-10-08/ | POW-02 (the review's harness as cross-check; the native test decides) | | 113 | External source review of the mining algorithm (docs/analysis/review-2026-10-08/, on master at 0ae450bd; it examined the Mac checkout's older V2 to V4 crate, not class v6, and says so) | Finding A09 "A naive stronger rejection test can exhaust all candidates" (on master at 0ae450bd, the harness run on build-2 to its end with every anchor it asserts agreeing with the tree, the v5 and v6 vectors outside its model); the review's harness is the cross-check evidence; the verdict reads fixed by construction, not applicable, or known open with a clock, and nothing reads PASS without the native test | hash lane (a690540514aa453d7); the node lane carries the verdict into the 23:30 freeze | 22:30 | RUNNING tonight (main's dispatch, 18:5x BST) | docs/analysis/review-2026-10-08/ | POW-04 (the review's harness as cross-check; the native test decides) | -## Coverage at 19:0x BST: 113 pins (104 of the plan, 9 of the review), 113 owned, open 30, in flight 44, landed 34, passed 5. Cases: 128 in 16 suites, every case owned; run under the standard: EVM-02 to 06 and VER-03, 04, 05, 06, 08 PASS (10), ECO-05 FAIL, VER-01 and VER-02 FAIL by design and disclosed, 62 RUNNING, 52 NOT RUN, 1 DEFERRED (P13). +| 114 | External review B (docs/analysis/review-2026-10-08-b/dispatch.md, 8 October 19:44 UK; fourteen findings F01 to F14) | F04 recovery lock weaker than final: THE FOUNDER'S RULING (19:57 UK): the recovery lock is kept and is always labelled "recovery", never "final", on every surface (the checkpoint field, the explorer, receipts, the light client, the oracle, the site) | node lane (a283f5f0d364ceef0) with the reference-apps lane and the site lane | the node field on successor-2.0.1 e9ab052f (pair about 20:45); the reference apps by 23:00; the explorer with them | RULED; in flight | docs/analysis/review-2026-10-08-b/dispatch.md; successor-2.0.1 e9ab052f | FIN-01 to FIN-08, VER-03, VER-05, VER-06, VER-08 | +| 115 | External review B (the same) | F14 lab fleet control is not the public trust model: THE FOUNDER'S RULING (19:57 UK): the public miner ships from 2.0.2 without remote jobs; our own fleet runs the lab build with its own signing root | shipper (ae892a8b0f78fe31c) with the relay lane (a22d765a2e0355a9f) | 2.0.2's cut (the app and relay lanes, 23:00 for the split's plan) | RULED; in flight | docs/analysis/review-2026-10-08-b/dispatch.md | UX-01, UX-07, OPS-02, OPS-04, OPS-06 | +| 116 | External review B (the same) | F01 the proof-verdict cache omits the statement (P0): the cache holds immutable verified facts per proof hash and every lookup compares the carried statement and the accepted identities; no zero accepted id; a context refusal never cached | enforced-proving lane (a6e8f84588b809d62) with the node lane (the two-node cache-history test) | verdict-cache-fix off 5eab958f, suites green by 21:30; rides 2.0.2 | RUNNING, dispatched | docs/analysis/review-2026-10-08-b/dispatch.md | ZKP-01, ZKP-05, ZKP-06 | +| 117 | External review B (the same) | F02 the proof rule fails open: the test bypass behind a build feature off in every release build (a CI check); a missing oracle or keys after activation is not-ready and never passes | enforced-proving lane with the steward | with F01 by 21:30 | RUNNING, dispatched | the same | ZKP-01, ZKP-03, GOV-05 | +| 118 | External review B (the same) | F03 one release manifest pinning node, generator, dataset policy, acceptance, host ABI, miner app, pool, guests, keys and activation; the hash lane's ProgramClass::V6 on the freeze | steward (a2ecfa95d3206016c), hash lane, pool seat | F0 at 8bdd1ff0 is the base; ProgramClass::V6 by 20:45 in the object's commit; the pool's build against the manifest | RUNNING, dispatched | docs/plans/igneum-2.0-f0-manifest.md | GOV-01, GOV-02, POW-07 | +| 119 | External review B (the same) | F05 the reg64 address mixer has an exact incremental form: the prefix-tree form natively with an equivalence test across every source register; the kernel-level measurement on a 5090 and a 4090; the chip side priced (floor lane 3: 2.6 percent of the chip's energy, the connected-state KILL unchanged) | hash lane, adversary lane, floor lane 3, the fleet lane (the two cards) | the native test by 21:05; the cards by 23:00; the row 23:30 | RUNNING, dispatched | class-v6-floor-sram 3a16190a section 4a | POW-02, ADV-02, ADV-05 | +| 120 | External review B (the same) | F06 acceptance and census do not cover the final execution: the freeze object's acceptance evaluates the actual 64-register schedule; the live census on the final packs; main's default: "frozen pending D1 census" if the live census is not green by 00:30 | hash lane, lane D (a07a99a3788566af2), the census hand (afb2fb655385dc259) | the final packs 21:20; the census and 6.11 reads by 22:00 on build-6 | RUNNING, dispatched | class-v6 04442d9ca (is_class_v4_shape), e72d4f202 (the liveness rule) | POW-02, POW-03, POW-04 | +| 121 | External review B (the same) | F07 one per-device scheduler with explicit modes (simultaneous on measured headroom, time-share with the dataset evicted and memory confirmed free, mining-only); the memory and crash rows on 8, 12 and 16 GB cells | app lane (the shipper), fleet lane | the modes in 2.0.2 (23:00); the fleet's rows from 01:00 | RUNNING, dispatched | the dispatch | GPU-05, UX-02, CAP-02 | +| 122 | External review B (the same) | F08 the proving pipeline hides expired work: an outcome ledger for every eligible job (completed, active, expired, cancelled), deadline misses and accepted-proof throughput published, failure by cause | enforced-proving lane, fleet lane, site (the ops page) | the ledger by 23:00; the two-hour declared-load hold after 2.0.2's cut | RUNNING, dispatched | the dispatch | CAP-03, CAP-04, CAP-05, OPS-01 | +| 123 | External review B (the same) | F09 the economic table and the failed specialist: every pass or fail cell generated from the declared inequality and its inputs | research lane, floor lane 3, coordinator | done 19:56 (3a16190a: the hand-written (c) cell was wrong, the criterion stands; no chip meets (c) at any price in the window; the board six of seven) | landed on the branch; in the 21:00 landing | class-v6-floor-sram 3a16190a (market.py M3, section 12) | ECO-03, ECO-05, ECO-06 | +| 124 | External review B (the same) | F10 the CUDA readback: a separate selection pass with sentinels, exact comparison and overflow fallback, then asynchronous overlap; kernel throughput and energy published | worker lane (new; the hash lane spawns it) | the 5090 and 3090 rented 23:15 for 23:30 to 01:00 | NOT RUN, dispatched | the dispatch | GPU-02, POW-08 | +| 125 | External review B (the same) | F11 Ember search and identity: objective-aware bounded two-sided search, rebase on goal change, a workload fingerprint invalidating stale results | Ember lane (new; the shipper spawns it) | 2.0.2 or later; the plan by 23:00 | NOT RUN, dispatched | the dispatch | UX-02, GPU-03 | +| 126 | External review B (the same) | F12 pool payout durability (durable idempotent intent, the exact signed transaction before broadcast, balance reserved atomically, the state machine) and F13 pool admission bounds (frame size enforced while reading, bounded write queues, one membership per session, nonce dedup after validation) | pool seat (a3832b1c3b274b310) | the plan by 23:00; the code on pool-2.0 after UX-05's runs | NOT RUN, dispatched | the dispatch; pool-2.0 72cc306e | UX-04, UX-05, INC-06 | + +## Coverage at 20:0x UK: 126 pins (104 of the plan, 9 of review A, 13 of review B), 126 owned, 2 RULED by the founder (F04, F14), open 30, in flight 56, landed 35, passed 5. Cases: 128 in 16 suites plus suite REV (44 regressions, the steward adds it by 20:45), every case owned; the registry at 19:45: 73 RUNNING, 53 NOT RUN with reasons, 1 DEFERRED (P13); team-run PASS 10 (EVM-02 to 06; VER-03, 04, 05, 06, 08), FAIL 3 (ECO-05 under P12; VER-01, VER-02 by design); nothing PASS under the procedure until the steward's test-record writes it. The pass criteria are the Test and Acceptance Standard's (docs/plans/igneum-2.0-test-standard.pdf, 128 cases, approved as proposed by the founder on 8 October 2026 with P13 deferred; the live registry docs/plans/igneum-2.0-test-registry.json): a row reads passed only when its cases pass under the standard. The plan's own conditions, per section: D1 an independent operator reproduces the baseline from the served kit alone; D2 the candidate improves against re-optimised adversaries within the preset limits, else published as a failure; D3 the best supported advantage inside the chosen envelope with uncertainty published; D4 the model names credible conditions for sustained commodity participation and where it fails; D5 specified behaviour with no emergency change and no privileged intervention; the launch requirements live; the claim ladder earned rung by rung.